Privacy Policy

What personal data eCrate handles, why, how long it is kept, and the rights you have over it.

Placeholder — not reviewed legal advice. This document is unreviewed boilerplate written to give eCrate a complete surface, not a lawyer’s work. It must be replaced with counsel-drafted copy before eCrate relies on it.

This policy explains how [LEGAL ENTITY NAME] ("eCrate") handles personal data. It covers the eCrate platform itself. When you buy from a store hosted on eCrate, the merchant running that store decides what happens to your data — they are the controller, eCrate is their processor, and their own policy applies alongside this one.

What we collect

From merchants and partners (our own users): name, email address, password hash, store and profile details, payout account identifiers held by our payment provider, and the usual operational records — sessions, IP address, and audit logs of security-relevant actions.

From shoppers, on behalf of a merchant: the details needed to place and deliver an order — name, email address, shipping address, order contents and totals, and the email correspondence between the shopper and the store. Card numbers are handled by our payment provider and never reach eCrate's database.

Automatically: the cookies the platform needs to work. A session cookie keeps you signed in; a cart cookie remembers what you put in a basket; a referral cookie remembers, for 30 days, which partner link brought you to a store so the merchant can pay the right commission; and an analytics cookie holds a random identifier, for 30 days, so the merchant can see how their own pages perform — which pages are viewed, which sections are seen, what leads to a sale. That identifier is random, first-party, never shared across stores' own domains, and never joined to your name or account; if your browser sends Do Not Track or Global Privacy Control, it is not set and nothing is measured. We do not run third-party advertising trackers.

Why we use it

  • To run the service: authentication, storefronts, carts, checkout, and the merchant dashboard.
  • To take payment and pay out, through our payment provider.
  • To send transactional email — order confirmations, shipping notices, password resets — which is not marketing and cannot be unsubscribed from.
  • To send marketing email a merchant has configured, which always carries a one-click unsubscribe link.
  • To keep the platform secure and to meet our legal obligations, including keeping financial records of what was sold.

Depending on where you live, our legal bases are performance of a contract, legitimate interests (security, fraud prevention, running the platform), consent (marketing email), and legal obligation (financial records).

Who we share it with

We use sub-processors to run eCrate, each with access only to what their job needs: [HOSTING PROVIDER] for hosting, [DATABASE PROVIDER] for the database, [PAYMENTS PROVIDER] for payments and payouts, [EMAIL PROVIDER] for email delivery, and [FILE STORAGE PROVIDER] for uploaded media. A current list is available on request.

We do not sell personal data. We disclose it otherwise only where the law requires it, or to enforce our terms.

Where data is transferred outside your region, we rely on [TRANSFER MECHANISM].

Google user data

A merchant may connect their own Google account to an eCrate store, from Settings → Email, so that customer conversations appear in eCrate beside the order they are about. Connecting is optional, it is the merchant's own choice, and a store that does not connect one is unaffected by anything in this section.

When a merchant connects a Google account, eCrate asks Google for these scopes, and only these:

  • https://www.googleapis.com/auth/gmail.readonly — read the messages in the connected mailbox, including their subject, body, and attachments. This is what puts a customer's email into the store's eCrate inbox next to their order.
  • https://www.googleapis.com/auth/gmail.send — send mail as the connected account, so a reply written in eCrate leaves from the merchant's own address and stays in the thread the customer started. This scope cannot read, change, or delete anything in the mailbox.
  • https://www.googleapis.com/auth/userinfo.email — read the address of the account being connected. eCrate stores it as the store's mailbox address, shows it in Settings so the merchant can see which account is linked, and uses it as the From address on replies.

eCrate does not request gmail.modify, gmail.labels, or any other write access to a mailbox. Nothing in the feature labels, archives, moves, or deletes a merchant's mail.

Limited Use. eCrate's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features described above — showing a store's customer conversations in its eCrate inbox, threading them, matching them to orders and customers, and sending the merchant's replies.
  • We do not sell Google user data, and we transfer it to others only as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after giving notice and obtaining consent.
  • We do not use Google user data for advertising of any kind, including retargeted, personalised, or interest-based advertising.
  • We do not allow humans to read Google user data, unless we have the merchant's affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data is aggregated and de-identified.
  • We do not use Google user data to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models.

The account's access and refresh tokens are encrypted before they are stored, are never written to a log, and are never returned to a browser. Messages pulled from a connected account are held in that store's eCrate inbox so they can be shown next to orders, and are subject to the retention and erasure rules below exactly as any other email correspondence is. Disconnecting the account in Settings → Email revokes eCrate's access and deletes the stored credentials.

How long we keep it

The short version: we keep what we are required to keep, and remove the rest when it stops being needed. docs/RETENTION.md in the eCrate repository is the authoritative, per-table version. The parts that matter to a person:

  • Orders are financial records. They are retained for as long as tax and accounting law requires, even after an erasure request — but with the person removed from them (see below).
  • Email correspondence, and any files attached to it, is kept while the store needs it and is erased on request — the files are deleted outright, not just unlinked.
  • Carts are anonymous bags of items; an email address captured at checkout is removed when the person is erased.
  • Gift cards keep their balance. A gift card is money a store owes to whoever holds the code, so erasing you does not cancel it: the card and the record of every amount added to or spent from it are retained, with your email address and any message removed from them. We never store the code itself — only a one-way hash of it — so the card keeps working and nothing we hold can be used to spend it.
  • Storefront analytics events (the page-view and section-view measurements above) are kept for 365 days and then deleted. When a person is erased, the link between their orders and that measurement identifier is removed.
  • Abandoned-cart recovery links stop working 30 days after they are sent.
  • Password reset and email verification links are single-use and expire within an hour.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to erase it, object to processing, or complain to your supervisory authority ([SUPERVISORY AUTHORITY]).

eCrate implements the two hardest of these directly in the product, so a merchant can action a request the day it arrives:

  • Access. A merchant can export everything their store holds about one customer as a JSON file, from that customer's page in the dashboard.
  • Erasure. Erasing a customer deletes their profile, removes the address captured on any cart, strips the content and addresses from their email correspondence — including deleting any files they sent as attachments, from file storage as well as from our database — and replaces the recipient address on every marketing and transactional send record. Their name, street address, and email are removed from past orders; the order itself — what was sold, for how much, when, and to which region — is retained as a financial record, as is the balance of any gift card issued to you. Where a merchant has answered a card dispute about a purchase, the evidence they submitted (including any documents attached to it) is likewise retained as a financial and legal record. Every erasure writes an audit record naming who ran it and when, identifying the person only by a one-way hash of their email address.

Erasure cannot be undone.

Where a merchant moved their store to eCrate from Shopify, a request you make through Shopify reaches us too: Shopify forwards deletion requests to us and they run exactly the erasure described above. A request to see what we hold is recorded and passed to the merchant, who holds the data and answers it. When a merchant disconnects or uninstalls our Shopify app, we delete our access credentials for their Shopify store and the record of what we read from it; the products, customers and orders they moved into their own eCrate store belong to them and are not deleted.

To exercise a right against a store, contact that merchant. To exercise one against eCrate itself, contact [PRIVACY CONTACT EMAIL].

Security

Passwords are stored hashed. Sign-in links and reset tokens are stored hashed, are single-use, and expire. Access to production data is limited to the people who need it. Repeated failed sign-in attempts are rate-limited.

No system is perfectly secure; if a breach affects you we will notify you and any regulator as required.

Children

eCrate is not intended for children, and we do not knowingly collect their data.

Changes

We will post any update here and, where the change is material, tell account holders before it takes effect.

Questions: [PRIVACY CONTACT EMAIL].