Skip to content
Storeware

Privacy Policy

Last updated 19 September 2026

This is a draft. It has not yet been reviewed by a lawyer, and passages in braces are facts still to be filled in. It does not yet bind anyone.

What personal data Storeware holds, why, and what you can ask us to do with it.

Two different roles

Storeware handles personal data in two capacities, and they carry different duties.

For merchants, we are the controller. We decide what account data we need to run the platform and bill for it, and this policy describes it.

For a merchant’s customers, the merchant is the controller and we are their processor. We hold shopper data on their instructions. The Data Processing Addendum governs that, and a shopper asking about their data should ask the shop they bought from.

What we hold about merchants

Your email address and name, your organisation and the people you invite into it.

Your shop configuration: what you sell, how you price it, where you ship, and what your shop looks like.

Billing records. Card details go to Stripe and we never see or store them; we keep the customer reference, the plan and the invoice history.

Operational logs: requests, errors and the model calls your shop made, which is also how spend limits are enforced.

What we hold on a merchant’s behalf

Orders and their contents, the buyer’s name, email address, delivery and billing address, and any phone number given at checkout.

Questions shoppers asked the shop assistant, and the answers it gave, so a merchant can see what their shop is being asked and where it answered badly.

Where a shopper has chosen to be remembered, the preferences they gave. They can clear that themselves from their account on the shop.

How fast a shop’s pages were for the people who visited them, as daily totals by kind of page and by phone or computer. Each visit’s report is added into those totals and discarded. No address, identifier, page address or time of visit is kept.

We do not receive card numbers. They go from the shopper’s browser to Stripe.

Why we are allowed to

To perform the contract with you, which covers running your shop and billing you.

Our legitimate interests in keeping the platform secure, preventing abuse and improving it, weighed against your rights.

Consent, where you have given it, for marketing email. You can withdraw it at any time and every message carries a link that does so.

Legal obligation, for tax and accounting records.

Who else sees it

Stripe, for payments and for our own subscription billing.

Supabase, which hosts the database, in the United States.

Cloudflare, which serves every request and stores uploaded images and files.

Pinecone, which holds the search index for your catalogue, in the United States.

OpenAI, which runs the models behind catalogue writing and the shop assistant. Prompts contain product and question text. We do not send them payment details.

Resend, which delivers transactional email.

We do not sell personal data, and we do not share it for advertising.

Where it goes

Data is processed in the United States and, for requests served at the edge, in the region nearest the person making the request.

Transfers out of the United Kingdom and the European Economic Area rely on the standard contractual clauses, which our processors have entered into.

How long we keep it

Account data for as long as the account is open, and 30 days after it closes.

Order records for as long as the merchant needs them for tax and accounting, which is commonly six or seven years depending on where they trade.

Operational logs for a rolling short window, currently measured in days rather than months.

What you can ask for

A copy of your data, correction of anything wrong, deletion, a machine readable export, and an objection to processing we base on legitimate interests.

Ask at privacy@storeware.ai and we will answer within 30 days.

If you are a shopper rather than a merchant, ask the shop you bought from. They hold the decision and we act on their instruction.

You may also complain to your data protection authority. In the United Kingdom that is the Information Commissioner’s Office.

Children

The platform is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.

Contact

{the contracting company}, {registered address}. Privacy questions go to privacy@storeware.ai.