Legal document · Shop Tek
Shop Tek privacy policy
This policy explains the data Shop Tek processes to operate the store platform, why it is used, who may process it with us, and the choices available to merchant and shopper. We process what is needed to provide, protect, support, and legally operate the service. We do not sell personal data.
Last updated: 20 July 2026
1. Who handles the data
Shop Tek is a BarmajTek service for operating an independent online store. The merchant is generally responsible for shopper data collected through the store, while Shop Tek processes that data to provide the platform on the merchant behalf. For merchant account, billing, and support data, Shop Tek processes information to operate the relationship. Legal roles may vary with the request and applicable law. This policy does not mean the platform owns merchant or shopper data; it describes the general purpose, boundaries, and procedures of processing.
2. Data we collect
Account data can include name, email, phone, business name, team membership, roles, login records, and support history. Store data can include products, images, prices, stock, policies, settings, and domain. Order and customer data can include name, phone, delivery address, landmark, items, options, price, payment method, and state. Technical data may include IP address, browser type, session identifier, error and security logs, and a storefront visitor measurement-consent record. We do not request external provider passwords in a support form, and merchants should not store payment secrets in order notes.
3. Why we use data
We use data to create account and store, present products, run cart and checkout, guard against overselling, operate orders and delivery, issue documents, apply permissions, provide support, protect the service, and prevent abuse. Subscription data supports trial, billing, suspension, and renewal operations. We may use aggregated or de-identified information to improve performance and understand feature use when it cannot reasonably identify a person. We do not use a store customer data to build a BarmajTek marketing audience without a separate basis and consent.
4. Cookies and measurement
The platform uses necessary cookies for session, protection, language preference, and cart. They should not be disabled when needed for login or purchase. Optional storefront measurement, such as an advertising pixel enabled by a merchant, should not run before visitor consent when consent is required. A visitor can decline optional measurement without being prevented from buying. The merchant is responsible for selecting added tools, explaining their purpose, and respecting the visitor decision, while Shop Tek provides a consent mechanism in the storefront.
5. Providers and data transfer
We may rely on hosting, database, storage, email, messaging, incident monitoring, and merchant-selected payment, invoice, or shipping providers. Each provider receives information needed for its function and remains subject to contract and controls. An integration is not automatically active because it exists. If data is processed outside the store country or approved processing region, we review an appropriate basis and safeguards as required by law and contract. Live provider names and processing locations are published after approval; this text does not imply that an unapproved provider is active.
6. Isolation and protection
Shop Tek isolates every store in tenant context and enforces PostgreSQL RLS on tenant-scoped tables through a runtime account that cannot bypass those policies. Roles limit team access, and sensitive operations such as price, stock, and refund changes leave an audit record. Production uses secure connections and appropriate secret storage, and support access should be limited, need-based, and auditable. No service is immune from every risk; we review controls and respond to incidents, while merchants must protect accounts and provider credentials.
7. Retention, export, and deletion
Store data remains during subscription and for the period needed to provide export or grace, then under legal, dispute, and backup requirements. Suspension is not immediate deletion. Data may be deleted after final termination under the retention schedule, with limited technical delay in backups. The store owner can export data through the designated path. For access, correction, or deletion, send a request from the account email. We may ask for proportionate verification to protect information from an unauthorized requester.
8. Rights, updates, and contact
Depending on law and relationship, a person may have rights to access, correct, delete, or object to certain processing. If a request concerns a shopper in a merchant store, we may direct it first to the merchant responsible for the relationship and assist the merchant technically where needed. We may update this policy when service, provider, or law changes, publishing the date and giving appropriate notice for material change. Use the contact form for a privacy request and do not put identity documents, passwords, or payment details in the first message.
