Privacy Policy

Last updated: June 24, 2026

Data CollectionSupplier KYBCookiesYour RightsSecurity

Table of Contents

  1. 1. Information We Collect
  2. 2. Supplier Data & KYB
  3. 3. How We Use Your Information
  4. 4. Information Sharing
  5. 5. Cookies & Tracking
  6. 6. Data Retention
  7. 7. Your Rights
  8. 8. Security
  9. 9. Children's Privacy
  10. 10. Service Providers
  11. 11. Changes to Policy
  12. 12. Contact

1. Information We Collect

ShoperPal collects different types of information depending on your role (Shopper or Supplier):

1.1 Account Information (All Users)

  • Full name, email address, and password (stored as a bcrypt hash — never in plain text)
  • Account role (Shopper or Supplier)
  • Profile photo (optional)
  • Date of account creation and last login

1.2 Shopper-Specific Data

  • Order history: products purchased, quantities, prices, and order status
  • Shipping and billing addresses
  • Payment method details — stored and processed exclusively by Stripe (we never see or store card numbers)
  • Wishlists, followed stores, and recently viewed products
  • Product reviews and ratings you submit
  • Loyalty points balance and redemption history
  • Referral activity (who you referred, credits earned)

1.3 Usage & Technical Data (All Users)

  • Pages visited, search queries, and product views
  • Session duration and clickstream data
  • IP address, browser type, OS, and device identifiers
  • Cookies and local storage data (see Section 5)

2. Supplier Data & KYB

Suppliers are subject to a Know Your Business (KYB) verification process to protect the integrity of our marketplace. The following data is collected specifically from Suppliers:

2.1 Business Information

  • Legal business name, trading name (store name), and business type
  • Registered business address and contact information
  • Business registration number and jurisdiction of incorporation
  • Tax Identification Number (EIN for US entities, or equivalent)

2.2 KYB Verification Documents

  • Government-issued business registration certificate
  • Identity documents for the authorised representative (passport, driver's licence)
  • Proof of address (utility bill, bank statement — less than 3 months old)
  • W-9 (US entities) or W-8BEN (international entities) tax forms

KYB documents are encrypted at rest, stored in a secure system with restricted access, and are never shared with Shoppers or third parties except as required by law or to complete the verification process with our KYB service provider.

2.3 Financial & Payout Data

  • Bank account details for payouts are stored exclusively by Stripe Connect — we do not store full bank account numbers
  • Payout history and transaction ledgers
  • Sales analytics: revenue, order counts, conversion rates, return rates

2.4 Store & Listing Data

  • Store name, logo, banner images, and store description
  • All product listings: titles, descriptions, images, prices, stock levels
  • Coupon codes and promotional campaigns
  • Customer reviews received on your store and products

2.5 What Shoppers Can See About Suppliers

Shoppers can see the following public Supplier information:

  • Store name, logo, and banner
  • Store description and policies
  • KYB-verified status badge
  • Average rating and number of reviews
  • Product listings and pricing

Private business data (registration documents, bank details, personal ID) is never visible to Shoppers.

3. How We Use Your Information

3.1 For All Users

  • To create and manage your account
  • To process orders and facilitate payments
  • To send transactional emails (order confirmations, shipping updates, password resets)
  • To enforce our Terms of Service, detect fraud, and ensure platform safety
  • To comply with legal obligations and respond to law enforcement requests
  • To improve our Platform and develop new features

3.2 For Shoppers

  • To personalise your shopping experience using AI-powered recommendations
  • To calculate and apply loyalty points and referral credits
  • To send price-drop alerts for wishlisted products (if enabled)
  • To support return requests and dispute resolution

3.3 For Suppliers

  • To complete KYB verification and maintain compliance records
  • To process order fulfilment and payout remittances
  • To provide sales analytics and store performance dashboards
  • To send new order alerts and customer communication notifications
  • To calculate and report applicable taxes (1099-K forms for qualifying suppliers)
  • To assess risk and maintain marketplace integrity

4. Information Sharing

We do not sell, rent, or trade your personal data to third parties for marketing purposes. We share data only in the following limited circumstances:

RecipientData SharedPurpose
SuppliersShopper name, shipping address, order itemsOrder fulfilment
ShoppersSupplier store name, verification badgeTrust & discovery
StripePayment details, Supplier bank accountPayment processing & payouts
Shipping CarriersShopper name and addressDelivery
BrevoEmail address, nameTransactional email delivery
CloudinaryProduct and store imagesImage hosting & CDN
Law EnforcementRequired by court order or lawLegal compliance

All service providers are bound by data processing agreements that restrict them from using your data for any purpose other than providing services to ShoperPal.

5. Cookies & Tracking

We use cookies and similar technologies for the following purposes:

Strictly Necessary

  • Authentication tokens to keep you logged in
  • Cart and session state

Functional

  • Dark/light mode preference
  • Recently viewed products
  • Locale and currency preferences

Analytics

  • Page view counts and session duration (anonymised where possible)
  • Feature usage analytics to improve the Platform

You can disable non-essential cookies in your browser settings. Disabling strictly necessary cookies will break authentication and cart functionality.

6. Data Retention

6.1 Shopper Data

  • Account data: retained while account is active
  • Order and transaction records: retained for 7 years (tax and legal compliance)
  • Wishlists and recently viewed: deleted within 30 days of account closure

6.2 Supplier Data

  • Account and store data: retained while account is active
  • KYB documents: retained for 5 years after account closure (anti-money laundering compliance)
  • Financial records and payout history: retained for 7 years (tax compliance)
  • Sales analytics: retained for 3 years after account closure

Upon account closure, your public-facing content (product listings, store page) is unpublished within 24 hours. You may request a copy of your data before deletion by emailing privacy@shoperpal.com.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request deletion of your account and data (subject to legal retention requirements)
  • Portability: Receive your order history and account data in machine-readable format (JSON or CSV)
  • Restriction: Request that we restrict processing in certain circumstances
  • Opt-out: Unsubscribe from marketing emails at any time via the link in any email
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email privacy@shoperpal.com. We will respond within 30 days. We may verify your identity before processing certain requests.

California residents have additional rights under the CCPA, including the right to know what personal information is disclosed and to opt out of its sale. We do not sell personal information.

8. Security

We implement industry-standard security measures to protect your data:

  • TLS/HTTPS encryption for all data in transit
  • Passwords hashed with bcrypt (never stored in plain text)
  • PCI-DSS compliant payment processing via Stripe
  • KYB documents encrypted at rest with AES-256
  • JWT-based authentication with short expiry and refresh token rotation
  • Role-based access controls: staff access to user data is logged and audited
  • Regular security audits and vulnerability assessments

In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware, as required by applicable law.

9. Children's Privacy

ShoperPal is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact privacy@shoperpal.com immediately and we will delete the data promptly.

10. Service Providers

We rely on the following trusted third-party services to operate the Platform. Each is bound by a data processing agreement:

  • Stripe — Payment processing and Supplier payouts (US-based, PCI-DSS Level 1 certified)
  • Brevo (formerly Sendinblue) — Transactional email delivery
  • Cloudinary — Image hosting and CDN for product and store images
  • Neon (PostgreSQL) — Database hosting on US-East-1 AWS infrastructure

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. We will notify you of material changes via email and a prominent notice on the Platform at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of the Platform after changes take effect constitutes acceptance.

12. Contact

For privacy-related questions, data requests, or concerns:

ShoperPal Inc. — Privacy Team

Email: privacy@shoperpal.com

Legal: legal@shoperpal.com