Privacy Policy
Effective date: May 9, 2026
This Privacy Policy explains how ShopFlow (“we,” “us”) collects, uses, and shares information when you use our service. We act in two capacities: as a data controller for store owners’ account data, and as a data processor for the customer data store owners collect from their shoppers.
1. Information we collect
From store owners
- Account data: name, email, password (managed by Clerk), profile photo.
- Billing data: last four digits of card, billing address, transaction history (stored by Stripe; we never see full card numbers).
- Store metadata: store name, subdomain, custom domain, branding settings, products, orders, customers.
- Usage data: pages visited, IP address, device type, browser, referrer.
From buyers (on behalf of store owners)
- Account data: email, name, password (hashed with bcrypt), and Google OAuth identifier when applicable.
- Order data: shipping address, phone, items purchased, payment method, payment status.
- Cookies: session cookies for cart and authentication.
2. How we use information
- operate, maintain, and improve the Service;
- process payments via Stripe;
- send transactional emails (order confirmations, password resets);
- detect and prevent fraud and abuse;
- comply with legal obligations.
We do not sell personal information.
3. Sharing & sub-processors
We share information with the following service providers, only as needed to operate the Service:
- Vercel, application hosting
- Neon, database hosting (PostgreSQL)
- Clerk, store owner authentication
- Stripe, payment processing
- ImageKit, image & video hosting
- Resend, transactional email
- Google, OAuth login (when buyers choose it)
Each sub-processor is bound by its own privacy and security commitments.
4. Cookies
We use a small number of strictly necessary cookies (auth tokens, cart state). We do not use third-party advertising or tracking cookies.
5. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information. To exercise these rights:
- If you’re a store owner, use the dashboard or email privacy@shopflow.app.
- If you’re a buyer, contact the store owner first; they are the data controller for their store. You may also email us and we’ll forward your request.
6. Data retention
Account data is retained while your account is active and for up to 60 days after deletion to allow recovery. Backups may persist for up to 30 additional days. Order records may be retained longer to comply with tax and accounting laws.
7. International transfers
Our infrastructure is hosted in the United States. By using the Service, you consent to your information being transferred to and processed in the U.S. We rely on Standard Contractual Clauses or other appropriate safeguards where required.
8. Security
We use industry-standard security: encryption in transit (TLS 1.2+), encryption at rest, bcrypt-hashed passwords, JWT-signed session tokens, and least-privilege access controls. No system is perfectly secure, however; you use the Service at your own risk.
9. Children
The Service is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If we discover such collection, we will delete the data promptly.
10. Changes
We may update this Policy. Material changes will be announced 14 days in advance.
11. Contact
Questions or requests? Email privacy@shopflow.app.
This document is provided as a starting point and does not constitute legal advice. Have an attorney review and customize for your jurisdiction before launch.