Privacy Policy
This policy explains what information Stoify may collect, how it may be used, and the choices available to visitors, customers, and merchants.
Effective date:
Who we are
The Stoify service is operated by Stoify. This is the organisation responsible for personal data that Stoify collects for its own website, account, billing, support, security, and marketing purposes.
support@stoify.appScope and roles
This Privacy Policy explains how Stoify handles personal data when you visit our marketing website, create or use a Stoify account, use the dashboard, contact support, or interact with a Stoify-powered storefront.
For account, billing, support, security, and Stoify marketing data, the Stoify operator identified above is the controller. When a merchant uses Stoify to operate a storefront, the merchant normally decides why customer information is collected and is the controller for that information. Stoify processes that information to provide the merchant's instructions and the applicable service agreement.
Information we collect and how we receive it
We collect information you provide, such as your name, email address, account credentials, company or business details, support messages, preferences, and information submitted through forms.
We collect information created through use of the platform, including storefront settings, catalogue and content data, customer and order records, inventory, media, API configuration, workflow submissions, event registrations, reviews, returns, loyalty records, and operational activity. Merchants are responsible for ensuring that they have a lawful basis to provide customer information to Stoify.
We receive subscription, invoice, payment-status, and transaction-reference information from our billing provider. Payment card details are handled by the payment provider and are not intended to be stored in Stoify.
We automatically receive technical and security information such as IP address, browser and device characteristics, pages or features used, referral information, timestamps, authentication activity, and error or audit events. We receive some information from merchants, connected services, and authentication providers when you use those integrations.
Purposes and lawful bases
We use information to create and manage accounts; authenticate users; provide, host, maintain, secure, and improve Stoify; publish and operate storefronts; process subscriptions and invoices; provide support; send transactional and service messages; and deliver features requested by merchants and shoppers.
We use information to prevent fraud, abuse, unauthorised access, and security incidents; troubleshoot and debug; monitor reliability; enforce our agreements; respond to legal requests; and meet accounting, tax, regulatory, and other legal duties.
The lawful basis depends on the activity. We rely on contract where processing is needed to provide an account or paid service, legal obligation for records we must keep, legitimate interests for security, service administration, product improvement, and business communications where permitted, and consent for optional analytics and non-essential cookies where required. You can withdraw consent at any time; withdrawal does not affect earlier lawful processing.
Merchants and customer information
A merchant using Stoify may access and control customer, order, catalogue, and storefront information for its own store. The merchant is responsible for its privacy notice, customer communications, retention decisions, legal requests, and instructions to Stoify. If you interact with a merchant's storefront, contact that merchant first for requests about the merchant's processing.
Stoify does not sell personal data. We do not use merchant customer information for unrelated advertising. We may use aggregated or de-identified information to understand service performance and improve Stoify where permitted by law and our agreements.
Service providers and disclosures
We use service providers to host and store data, authenticate accounts, process billing and payments, deliver email, provide analytics after consent, protect the service, and support platform operations. They may process personal data only as needed for their contracted services and subject to appropriate confidentiality and security obligations.
After you accept analytics, Vercel Speed Insights may measure performance signals such as Core Web Vitals on Stoify marketing pages. Google Analytics may also collect the analytics information described in our Cookie Policy. These tools are not loaded for marketing analytics before consent.
We may disclose information to professional advisers, insurers, auditors, law enforcement, courts, regulators, or another organisation involved in a merger, acquisition, financing, restructuring, or sale of assets where reasonably necessary and legally permitted.
Stoify and its providers may process information outside the UK or European Economic Area. Where a restricted transfer applies, we use an adequacy decision or another lawful safeguard, such as appropriate contractual transfer terms, and can provide further information on request.
Cookies and optional analytics
We use strictly necessary cookies and browser storage for authentication, account security, password-protected storefronts, shopping sessions, consent preferences, and core functionality. These technologies are described in our Cookie Policy.
Optional Google Analytics is loaded on Stoify marketing pages and configured storefronts only after you choose to accept analytics. If you decline, the optional tag is not loaded. Google may process analytics data under its own terms, policies, and applicable data-processing arrangements; see our Cookie Policy for provider information.
Retention
We retain account and platform information while an account or merchant relationship is active and afterwards for as long as reasonably needed for security, support, backups, dispute resolution, enforcement, and legal, tax, accounting, or regulatory requirements.
We retain consent records and security or audit records for as long as needed to demonstrate compliance and protect the service. Merchant data is retained and deleted according to the merchant's instructions, service settings, and agreement, subject to legal and backup constraints.
Security
We use technical and organisational measures appropriate to the risk, including access controls, authentication safeguards, scoped site access, encryption in transit where supported, validation, monitoring, and secure handling of credentials and tokens. No online service or storage system can be guaranteed to be completely secure.
Your rights and choices
Depending on the law that applies, you may have rights to request access to, correction of, deletion of, or restriction of processing of your personal data. You may also have a right to object, request portability, withdraw consent, and avoid direct marketing. Some rights have exceptions and may not apply in every situation.
To make a privacy request, contact us at support@stoify.app
Children and automated decisions
Stoify is a business commerce platform and is not directed to children. We do not knowingly collect children's personal data through the marketing website. Tell us if you believe a child has provided information so we can assess and remove it where appropriate.
We do not use personal data for decisions that produce legal or similarly significant effects solely through automated processing in the ordinary operation of the marketing website or platform. If this changes, we will provide the information required by law.
Changes and contact
We may update this Privacy Policy when our services, processing, or legal obligations change. We will publish the revised version here and update the effective date. If a change is material, we will take additional steps where required by law.
If you are in the UK and are unhappy with how we use your personal data, you can contact the Information Commissioner's Office.
This page is general information about Stoify's current privacy practices and is not legal advice.