Store by BirrCommerce logo Store

Legal

Privacy Policy

Last updated: 5 September 2026

Store exists to help merchants trade honestly and transparently — and that extends to how we handle data. This policy describes what we collect, why, and the choices available to you.

1. Scope of this policy

This Privacy Policy explains how Store collects, uses, stores, and shares personal data when you visit birrstore.pages.dev, create a merchant account, shop at a storefront hosted on the platform, or contact support.

Store is the data controller for platform data (merchant accounts, billing, platform analytics). For shopper data collected at an individual store, the merchant operating that store is the controller and Store processes that data on the merchant’s instructions.

2. Data we collect

We collect only what the Service needs to function:

  • Account data: name, email address, password (stored only as a salted hash), store name and slug, and store settings you configure;
  • Billing data: subscription plan and invoice history; card details are held by the payment provider, never by Store;
  • Shop order data (processed for merchants): customer name, email, phone, shipping address, order contents, and payment reference — required to create and fulfil orders;
  • Platform analytics events: page views, product views, cart and checkout events, and coarse referrer classification (direct, search, social, whatsapp), stored against an anonymous visitor id — no cross-site advertising profiles;
  • Support communications you send us, and server logs (IP address, user agent, timestamps) kept for security and abuse prevention.

3. How we use data

We use personal data to provide and secure the Service: authenticating users, creating and processing orders and invoices, sending transactional email (order confirmations, password resets), computing dashboard analytics for merchants, detecting fraud and abuse, and responding to support requests.

We do not sell personal data, and we do not use shopper data for third-party advertising.

4. Cookies and similar technologies

The Service uses a small set of strictly necessary cookies: a signed httpOnly session cookie for merchants and store customers, and a first-party analytics visitor identifier. A signed cookie also holds the store customer session where a customer signs in to a storefront.

We do not load third-party advertising or cross-site tracking scripts on storefronts. Details are in our Cookies notice.

5. Sharing and processors

We share data only with processors needed to run the Service: the Lightbase database service (data storage), Cloudflare Pages (hosting and delivery), Cloudinary (image hosting where a merchant uploads media), payment providers for transactions you initiate, and the email delivery service for transactional and merchant-configured email.

We may disclose data where required by law or to protect the rights, property, or safety of the platform, its users, or the public.

6. Security

Sessions use signed, httpOnly, secure cookies; passwords are hashed; all platform API keys are held server-side and are never exposed to the browser; every dashboard mutation is scoped to the authenticated tenant. We apply security headers and rate limiting on sensitive endpoints, and log sensitive administrative actions to an internal audit trail.

No method of transmission or storage is perfectly secure; we combine these controls with least-privilege access and prompt incident response.

7. Retention

Account and billing records are retained while your account is active and as long as required for tax and audit purposes. Order records are retained per the operating merchant’s instruction and legal obligations. Analytics events are retained in raw form for 12 months, after which only aggregates are kept.

8. Your rights

Subject to your local law, you may request access to your personal data, correction of inaccurate data, deletion where no overriding legal obligation applies, and export of data you provided. Merchants can export catalog and customer data from the dashboard; shoppers should contact the store they purchased from, or us where the store cannot help.

Requests can be sent through the contact page; we respond within 30 days.

9. Children

The Service is not directed at children under 13, and we do not knowingly collect their personal data.

10. Changes to this policy

We update this policy as the Service evolves; the current version with its last-updated date is always published at this page. Material changes are announced in the merchant dashboard.

Privacy questions or data requests? Reach us any time.

Contact the Store team

Loading...