Skip to content
StoreFlux
Features Developers Security Pricing Docs FAQ
Sign in Start free
Features Developers Security Pricing Docs FAQ
Start free Sign in
Home/Legal/Privacy Policy

Privacy Policy

What personal data StoreFlux collects, why, who it is shared with, how long we keep it, and the rights you have over it.

Last updated: October 3, 2026 Applies to storeflux.store, the admin panel and the API
On this page
  1. Who we are
  2. Data we collect
  3. How we use data
  4. Legal bases (EEA, UK and similar regimes)
  5. Cookies and similar technologies
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. Security
  10. Your rights
  11. California and other US state rights
  12. Children
  13. Links to other sites
  14. Changes to this policy
  15. Contact

This Privacy Policy explains how StoreFlux (“StoreFlux”, “we”, “us”) handles personal data when you visit storeflux.store, create an account in the admin panel, call our API, or contact us. It also explains the separate role we play when we process data on behalf of the merchants who run stores on the platform.

Two roles, in plain language

For our own website, accounts and billing, StoreFlux is the controller of your data. For the shoppers and orders inside a merchant’s store, the merchant is the controller and StoreFlux is the processor. If you bought something from a store that runs on StoreFlux, please contact that store about your data; we will support them in helping you.

01Who we are

StoreFlux operates a multi-tenant headless commerce platform. You can reach us about privacy at admin.storeflux@gmail.com. We do not currently have a designated Data Protection Officer; privacy requests go to this address and are handled by the team directly.

02Data we collect

Visitors to our website

  • Analytics data (only with your consent). If you choose “Accept all” or enable Analytics, Google Analytics 4 collects anonymised usage data such as pages viewed, approximate location, device and browser type, referrer and engagement. Nothing is collected by Google Analytics until you consent.
  • Contact form. When you send us a message we receive your name, email address, subject, message and, if you provide them, your company and phone number.
  • Technical logs. Our servers and API record request metadata such as IP address, timestamps, user agent and URL for security, abuse prevention and reliability.
  • Live API playground. Running the request on our site calls the public demo store API directly from your browser; it returns public demo products and requires no personal data.

Merchants and admin users

  • Account data: name, email address, role, a salted PBKDF2 hash of your password (never the password itself), account status and sign-in history including last sign-in time and IP address.
  • Session data: a refresh token (stored as a secure, HTTP-only cookie) and associated IP addresses to keep you signed in and detect token replay.
  • Store configuration: store name, slug, branding, contact details, address, currency, locale and settings you enter.
  • Billing records: plan, subscription period, invoices and payment status. Card details for any payments you make to StoreFlux are handled by the payment provider, not stored by us.
  • Audit logs: a record of administrative actions (who changed what, when, from which IP address) to protect your store and ours.
  • Integration credentials: API keys and OAuth tokens you connect (for example payment gateways, AI providers, social and advertising accounts) are stored encrypted at rest.
  • Support communications: messages you send us and our replies.

Data we process for merchants (as processor)

Merchants use the platform to store and process data about their own shoppers and operations: customer names, email addresses, phone numbers, delivery and billing addresses, orders and returns, wishlists and carts, product reviews, loyalty and referral records, consent records, and storefront activity events (for example page views and add-to-cart events tied to an anonymous session identifier). Payment card data is entered directly into the payment gateway (Stripe or PayPal) and tokenised in the shopper’s browser; StoreFlux receives and stores only references such as payment-intent IDs and the last four digits where the gateway returns them. Merchants decide what to collect and why; their privacy notices apply to this data.

03How we use data

  • To provide, operate, secure and support the Service and your account.
  • To authenticate users, prevent fraud and abuse, and keep each tenant’s data isolated.
  • To bill for subscriptions and manage plans.
  • To respond to enquiries and provide customer support.
  • To understand how our website is used and improve it (only with analytics consent).
  • To send essential service and security notices, and, where you have asked for them, product updates.
  • To comply with legal obligations and enforce our terms.

We do not sell personal data, and we do not use it for third-party advertising or profiling. We do not make decisions about people that have legal or similarly significant effects using solely automated means; AI features in the admin panel produce suggestions for the merchant to review.

04Legal bases (EEA, UK and similar regimes)

PurposeLegal basis
Providing the Service and managing accountsPerformance of a contract
Security, fraud prevention, audit logging, reliabilityLegitimate interests
Responding to enquiries and supportLegitimate interests / steps before a contract
Website analytics (Google Analytics)Consent, which you can withdraw at any time through “Cookie settings”
Billing, tax and accounting recordsLegal obligation
Processing shopper data for merchantsAs directed by the merchant (we act as processor)

05Cookies and similar technologies

We use a small amount of browser storage. Strictly necessary items work without consent; analytics runs only if you allow it. Details, including every cookie and storage item by name and duration, are in our Cookie Policy. You can change your choice at any time via “Cookie settings” in the footer.

06Who we share data with

We share personal data only with service providers that help us run the Service, under contracts that require appropriate protection, and when the law requires it. Our current sub-processors are listed in full in the Data Processing Addendum. In summary:

  • Amazon Web Services for hosting, database, cache, file storage and email delivery.
  • Stripe and PayPal when a merchant enables them, to process payments for that merchant’s store.
  • Google Analytics on our marketing website, only with consent.
  • AI providers (for example Anthropic, OpenAI, Groq or Google) only when a merchant enables AI features with their own provider key; the demo store uses a platform key.
  • Meta and other connected platforms only when a merchant connects them.
  • Error-monitoring tools (for example Sentry) where enabled, receiving technical diagnostics.

We may also disclose data if required by law or to protect rights, safety and security, and to a successor if StoreFlux is involved in a merger, acquisition or sale of assets (with notice to you).

07International transfers

StoreFlux is hosted primarily on AWS infrastructure in the United States, and our providers may process data in other countries. Where personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the Standard Contractual Clauses, as described in the DPA.

08How long we keep data

DataRetention
Account and store dataWhile your account is active; deleted or anonymised after termination as set out in the Terms (data available for export for 30 days)
Session refresh tokensUp to 7 days, then expire; revoked on sign-out or password change
Contact-form messagesAs long as needed to handle your enquiry and for a reasonable period afterwards
Billing and invoice recordsAs required by tax and accounting law
Operational performance metrics7 days (no personal data)
Shopper data inside a storeControlled by the merchant; merchants can export or anonymise individual customers with the built-in privacy tools
BackupsRotated on a fixed cycle; deleted data ages out of backups on that cycle

09Security

We protect personal data with measures that include row-level tenant isolation in the database, TLS in transit, encryption at rest for gateway secrets and integration tokens, PBKDF2 password hashing with 350,000 iterations, short-lived access tokens with rotating refresh tokens and replay detection, account lockout after repeated failed sign-ins, idempotent payment handling and immutable audit logging. See Security & Disclosure for details and how to report a vulnerability. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

10Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive a portable copy of it, and to withdraw consent at any time (without affecting earlier processing). You also have the right to lodge a complaint with your local data-protection authority.

  • How to exercise them: email admin.storeflux@gmail.com. We may need to verify your identity, and we aim to respond within 30 days.
  • If you are a shopper in a merchant’s store: contact that merchant. We will help them fulfil your request through the platform’s data export and erasure tools, and if you contact us directly we will forward your request to the relevant merchant where we can identify them.
  • Marketing: we only send promotional email if you ask for it, and every message includes a way to opt out.

11California and other US state rights

If you are a California resident, you can request to know, access, correct or delete personal information and to opt out of its “sale” or “sharing”. StoreFlux does not sell personal information or share it for cross-context behavioural advertising. We do not discriminate against you for exercising your rights. We honour browser opt-out signals such as Global Privacy Control for analytics by not enabling Google Analytics unless you actively consent.

12Children

The Service is for businesses and is not directed to children. You must be at least 18 to create an account. We do not knowingly collect personal data from children; if you believe a child has provided data to us, contact us and we will delete it.

13Links to other sites

Our site links to third-party services (for example payment gateways and documentation). We are not responsible for their privacy practices and encourage you to read their policies.

14Changes to this policy

We may update this policy as our practices or the law change. We will update the “Last updated” date above and, for material changes affecting account holders, notify you by email or in the admin panel.

15Contact

For any privacy question or request, email admin.storeflux@gmail.com or use the contact form.

Other policies

  • Terms of Service
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
  • Security & Disclosure
StoreFlux

The complete headless commerce backend. Build it yourself or let us build it for you.

All systems operational

Product

  • Features
  • API Playground
  • Security
  • Pricing
  • Documentation

Resources

  • Admin panel demo
  • Storefront demo
  • API reference
  • FAQ
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
  • Security & Disclosure

© 2026 StoreFlux. All rights reserved.

· Built on .NET 10, React 19, and PostgreSQL.

StoreFlux