Legal

Privacy Policy

Last updated: February 2026

1. Information We Collect

Information you provide

Account details (name, email address), store content and brand assets, payment and payout information (processed and stored by Stripe), and communications with our support team.

Information collected automatically

Usage data such as pages visited, features used, and session duration. Device information including browser type, operating system, and IP address. Cookies and similar technologies for authentication and session management.

Information from third parties

Public Instagram profile data when you connect your account, and payment verification data from Stripe.

2. How We Use Your Information

  • Provide, maintain, and improve the Platform
  • Process transactions, payouts, and tax obligations
  • Generate AI-powered store content and product recommendations
  • Send transactional communications (order confirmations, payout notifications)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our terms

3. Data Sharing

We share data only when necessary to operate the Platform. Payment data is shared with Stripe for transaction processing. Order and shipping data is shared with fulfillment partners to deliver products. We use analytics providers to understand Platform usage. We do not sell your personal information to third parties and never will.

4. AI-Generated Content

Brand concepts, messages, and assets you provide are processed by AI models to generate store content. This data is used solely for your store creation and is not used to train AI models or shared with other users. Generated content is stored in association with your account and can be deleted upon request.

5. Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.3) and at rest (AES-256). Payment credentials are handled exclusively by Stripe (PCI DSS Level 1 certified) and are never stored on our servers. Access to production data is restricted to authorized personnel with multi-factor authentication.

6. Data Retention

Account data is retained for the lifetime of your account plus 30 days after deletion. Transaction records are retained for 7 years to comply with tax and financial regulations. AI-generated content is deleted within 30 days of account deletion. Analytics data is anonymized after 26 months.

7. Your Rights

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information through your account settings
  • Deletion: Delete your account and associated data at any time
  • Export: Request a machine-readable export of your data
  • Opt-out: Unsubscribe from non-essential communications

To exercise these rights, contact us at the email below or use the controls in your account settings. We respond to all requests within 30 days.

8. Cookies

We use essential cookies for authentication, session management, and security. We use analytics cookies (PostHog) to understand how the Platform is used. We do not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings.

9. International Transfers

Your data is processed and stored in the United States. If you access the Platform from outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place for any international data transfers.

10. Children’s Privacy

The Platform is not intended for users under 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform. Your continued use after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions or to exercise your data rights, contact us at support@storehaus.ai