Last updated: [DATE] — template, not yet finalized
StoreLink ("we", "us") operates a platform that lets sellers create online stores and lets buyers purchase from them. This policy explains what personal data we collect, why, and what rights you have over it.
Payment gateways processing your transaction; shipping/logistics partners a seller uses to fulfil an order; our infrastructure providers; and regulators or law enforcement where legally required. We do not sell personal data.
[TEMPLATE: describe where data is stored/processed and the legal mechanism for any cross-border transfer — e.g. Standard Contractual Clauses for EU data leaving the EEA. This must be filled in accurately for your actual infrastructure before publishing.]
Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to or restrict certain processing. [TEMPLATE: list the specific regional frameworks that apply — GDPR (EU/UK/EEA), CCPA/CPRA (California), NDPR (Nigeria), POPIA (South Africa), etc. — and how to exercise each.]
[TEMPLATE: specify how long account, order, and verification data is kept, and the basis for that period — e.g. tax/accounting record requirements often mandate multi-year retention regardless of account closure.]
Questions about this policy: [TEMPLATE: insert a real contact email/address, and a Data Protection Officer contact if one is required for your scale/jurisdiction].