Your trust runs your business on Storek, so we treat privacy as a core feature, not an afterthought. This policy explains what personal data we collect when you use the platform, why we collect it, how we protect it, and the choices and rights you have. It also makes clear the two different roles we play: for your own account data we are the controller, and for the customer data your store processes we act only as your processor.
At a glance
Scope & Who We Are
This policy applies to the personal data Storek processes through its marketing website, merchant dashboard, and point-of-sale application.
Storek is the operator of the platform and, for the purposes of data-protection law, the controller of the personal data we collect about you as a merchant, a member of your staff, or a visitor to our website. Where your store collects personal data about your own customers, you are the controller and we act as your processor under our Terms of Service.
This is not your customers’ notice
This policy covers how we handle data. As a merchant, you are responsible for giving your own customers a privacy notice for the data you collect from them through your store.
Information We Collect
We collect only what we need to provide, secure, and improve the platform. The categories fall into three groups:
Data you give us
- Account & identity — your name, business name, email, phone number, and the password (stored only as a secure hash).
- Billing — your plan, invoices, and the limited payment details our processor returns to us (never your full card number).
- Content you enter — products, prices, branches, staff, suppliers, and the settings that configure your store.
- Communications — messages you send to support, feedback, and survey responses.
Data we collect automatically
- Usage — the features you use, actions you take, and pages you view, so we can improve the product.
- Device & log — IP address, browser and device type, and timestamps, kept for security and troubleshooting.
- Cookies — as described in our Cookie Policy.
Customer data you process
Through your store you may enter personal data about your customers — names, contact details, and purchase history. We process this only as your processor, on your instructions, to run the platform for you.
Please don’t send us sensitive data
Do not enter special-category data (such as health or biometric data) into free-text fields unless a feature is explicitly designed for it and you have a lawful basis to do so.
How We Use Your Information
We use personal data for clearly defined purposes — to run the service you asked for, to keep it secure, and to make it better.
| We use your data to… | For example |
|---|---|
| Provide the service | Create and run your account, host your store, and deliver the features in your plan. |
| Process billing | Charge your subscription, issue invoices, and prevent payment fraud. |
| Support you | Answer your questions, diagnose issues, and notify you about your account. |
| Secure the platform | Detect and prevent abuse, protect against threats, and keep audit logs. |
| Improve the product | Understand which features help, fix problems, and build what merchants need. |
| Meet legal duties | Keep records the law requires and respond to lawful requests. |
We may send you essential service messages (such as security or billing notices) that you cannot opt out of while you hold an account. Marketing messages are separate and always optional — you can unsubscribe at any time.
No advertising profiles
We do not build advertising profiles from your store data, and we do not use your customers’ personal data for our own marketing.
Legal Bases for Processing
Where data-protection law requires a legal basis, we rely on one of the following for each purpose:
- Contract
- To provide the platform and fulfil our Terms of Service with you.
- Legitimate interests
- To secure, maintain, and improve the platform, balanced against your rights and freedoms.
- Legal obligation
- To keep records and comply with tax, accounting, and other legal duties.
- Consent
- For optional things like marketing emails or non-essential cookies — which you can withdraw at any time.
Controller & Processor Roles
Because Storek is a platform that businesses use to serve their own customers, our role changes depending on whose data it is:
- Your account data
- Storek is the controller. We decide how your merchant account data is processed, as described in this policy.
- Your customers’ data
- You are the controller and Storek is your processor. We process it only to run the platform and only on your documented instructions.
As a processor, we will help you meet your own obligations — for example, by assisting with data-subject requests and by not engaging sub-processors without appropriate safeguards.
How We Share Information
We share personal data only where necessary, and never in exchange for money. Recipients fall into these categories:
- Service providers (sub-processors) — vetted vendors who host, secure, or support the platform under contracts that bind them to protect your data.
- Payment processors — to take your subscription payment and prevent fraud; they receive only what they need.
- Integrations you enable — the third-party services you choose to connect, which then handle data under their own terms.
- Legal & safety — authorities or advisers, where required by law or to protect our rights, users, or the public.
- Business transfers — a successor entity, if Storek is involved in a merger, acquisition, or sale, subject to this policy.
No sale of data
We do not sell personal data, and we do not share your customers’ data for any third party’s own marketing.
Cookies & Similar Technologies
We use cookies and similar technologies to keep you signed in, remember your preferences (such as language and theme), keep the service secure, and understand how it is used. Some are essential for the platform to work; others are optional.
Our Cookie Policy explains each category in detail and how to control non-essential cookies.
Data Retention
We keep personal data only as long as we need it for the purpose we collected it, or as the law requires.
- Account & store data — kept while your subscription is active, and for a limited window after cancellation so you can export or reactivate.
- Invoices & financial records — kept for the period required by tax and accounting law, even after you leave.
- Logs & security data — kept for a limited period appropriate to their purpose, then deleted or anonymized.
When the retention period ends, we delete or irreversibly anonymize the data. Our Data Collection Policy sets out a fuller retention schedule.
How We Protect Your Data
We apply technical and organizational measures designed to protect personal data against loss, misuse, and unauthorized access:
- Encryption of data in transit, and passwords stored only as salted hashes — never in plain text.
- Strict multi-tenant isolation so one store can never read another store’s data.
- Role-based access controls and audit logging of sensitive actions.
- Regular backups and least-privilege access for our own team.
A shared responsibility
Please help us keep your data safe: use a strong, unique password, keep staff permissions current, and tell us at [email protected] if you notice anything suspicious.
Your Privacy Rights
Subject to your local law, you have rights over your personal data, and we make them straightforward to exercise:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is inaccurate or incomplete.
- Erasure — ask us to delete your data where there is no overriding reason to keep it.
- Portability — receive your core data in a common, machine-readable format.
- Objection & restriction — object to or limit certain processing.
- Withdraw consent — opt out of marketing or non-essential cookies at any time.
To exercise a right, email [email protected]. We will respond within the time the law allows and may need to verify your identity first. If your request concerns customer data held in a store, we will direct it to the relevant merchant, who is the controller.
International Data Transfers
We aim to process and store data in the region appropriate to your account. Where data is transferred across borders — for example, to a sub-processor — we put appropriate safeguards in place, such as contractual protections, so your data keeps a comparable level of protection wherever it is handled.
Children’s Privacy
Storek is a business tool and is not directed to children. We do not knowingly collect personal data from children to open merchant accounts. If a store you run serves minors as customers, you are responsible for any consent the law requires.
Changes to This Policy
We may update this policy as the platform and the law evolve. When we make a material change, we will update the effective date and version above and, where appropriate, notify you by email or an in-dashboard notice. Continued use after a change takes effect means you accept the updated policy.
Contact & Data Protection
For any question about this policy or to exercise your rights, reach us at:
- Privacy requests [email protected]
- Security reports [email protected]
- General [email protected]
- Website storek.com
This summary is provided for convenience only — the full clauses below are what legally apply.
Back to top