Privacy Policy
Last updated 6 August 2026
1. Who is responsible for what
There are two different relationships here, and it matters which one you are in.
- If you are a merchant using SHPMKR to run a shop, we are the data controller for your account.
- If you are a shopper who bought something from a shop built on SHPMKR, that merchant is the data controller for your order. We process it on their behalf. Questions about your order, including deletion, are best directed to the shop you bought from.
2. What we collect about merchants
- Your email address and, if you give one, your name.
- A password, stored only as a hash by our authentication provider. We never see it and cannot recover it.
- Your shop: its name, content, products, images and settings.
- A Stripe account identifier once you connect one. We never receive or store your bank details.
3. What we collect about shoppers
When someone buys from a shop built on SHPMKR, we store:
- Their email address
- Their name and delivery address, for physical goods
- What they bought and what they paid
- A Stripe reference for the payment
We never see or store card numbers. Card details are entered on Stripe's own checkout page and never reach our servers.
Shops selling digital goods do not ask for a delivery address at all, because nothing is posted.
4. Why we hold it
- To provide the service — you cannot have an account without an email address, or fulfil an order without an address to send it to.
- To send transactional email — order confirmations to the shopper, sale notifications to the merchant, and account emails such as confirming your address or resetting a password.
- To meet legal obligations — order records may need keeping for tax purposes.
We do not sell data, we do not share it with advertisers, and we do not send marketing email to shoppers.
5. Who else sees it
- Supabase — hosts the database, files and accounts.
- Vercel — hosts and serves the application.
- Stripe — processes payments and holds the payment record.
- Resend — delivers order and account email.
Each holds data only to do that job. Some are based outside the UK and EU, and data may be transferred to them on that basis.
6. How long we keep it
- Merchant accounts — until you ask us to delete them. Deleting an account deletes its shops and products.
- Orders — kept after an account is closed where tax law requires it, then deleted.
- Deleted products — hidden from the shop but kept against past orders, so an old receipt still shows what was actually bought.
7. Your rights
Depending on where you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email us and we will act within 30 days.
If you bought from a shop built on SHPMKR, ask that shop first — they control your order. If you cannot reach them, contact us and we will help.
In the UK you can also complain to the Information Commissioner's Office; in the EU, to your local supervisory authority.
8. How it is protected
- Everything is served over HTTPS.
- Access is enforced in the database itself, so one merchant cannot read another's orders or customers even if the application has a bug.
- Passwords are hashed, never stored in readable form.
- Payment details never touch our servers.
No system is perfect. If we discover a breach affecting your data, we will tell you and the relevant regulator as required.
9. Cookies
We set one kind of cookie: the one that keeps a merchant signed in. There are no advertising or tracking cookies, and no third-party analytics. Shoppers browsing a shop are not given a cookie by us.
10. Contact
Privacy questions or requests: privacy@shpmkr.com.