Data Processing Terms
Last updated 11 October 2026
This policy is a draft while it is reviewed by our lawyers. It describes how the service works today; the final version may change its wording.
1. Roles
For the personal data of your customers and store visitors (“shopper data”), you are the controller: you decide why and how it is used. Stores. processes shopper data on your behalf, only to provide the Service. For data about you and your staff we are the controller, as described in our Privacy Policy.
These terms form part of our Terms of Service and apply for as long as we process shopper data for you.
2. What we process
Names, phone numbers, e-mail addresses, delivery addresses, order and payment status (never card numbers), messages sent to customers, customer account sign-ins and first-party storefront analytics, for the purposes of running your store: taking orders, sending messages, arranging deliveries, preventing fraud, reporting and support.
3. Your instructions
We process shopper data only on your instructions — the settings and actions in your admin are those instructions — unless the law requires otherwise, in which case we will tell you unless the law forbids it.
4. Confidentiality and our staff
Only staff who need it to run and support the Service can access shopper data, under confidentiality obligations. Support access to a store is read-only, needs two-factor authentication, is limited in time and is recorded in an audit log.
5. Security
Each store’s data is isolated from every other store’s at the database level. Data is encrypted in transit and at rest. Payment, courier and other credentials you connect are stored in an encrypted vault. You and your staff can turn on two-factor authentication for your admin accounts; our own staff must use it. Admin actions are recorded in an audit log. Backups are encrypted and stored separately from the main hosting.
6. Sub-processors
You agree that we use these providers to process shopper data: Supabase (database, sign-in and file storage — Singapore); Vercel (web hosting — Singapore, with a global network that delivers pages); Upstash (caching and rate limiting — Singapore); Resend (e-mail delivery); Meta (WhatsApp messages); our SMS gateway (text messages); Cloudflare (bot protection on checkout); Sentry (error monitoring — personal data is removed from error reports before they are sent); and our backup storage provider (encrypted backups).
We require each of them to protect the data at least as well as these terms do. We will announce changes to this list in your admin or by e-mail at least 30 days before a new provider starts processing shopper data, so you can object; if we cannot reasonably address an objection you may end your plan and we will refund any unused prepaid period.
Payment gateways and couriers you connect are not our sub-processors: they work for you under your own agreements with them.
7. Personal data breaches
If we become aware of a breach affecting shopper data, we will tell you without undue delay, and aim to do so within 72 hours, with what we know about what happened, the data and customers affected and what we are doing about it. We will help you meet any duty you have to inform authorities or customers.
8. Helping you with your customers’ requests
Your admin lets you find, export and erase a customer’s data. If a request reaches us directly we will pass it to you rather than answer it ourselves.
9. When your plan ends
You can export your data while your account is active. After a store is cancelled we delete shopper data within 90 days, except records the law requires us to keep. Copies in encrypted backups are removed as those backups expire (daily copies after 35 days, monthly copies after 12 months).
10. Information and audits
On reasonable request we will give you the information you need to check that we meet these terms, such as a description of our security measures and answers to a security questionnaire.