PRIVACY POLICY

Effective Date: June 26, 2026

Welcome to Storeik("we," "our," or "us"). Storeik provides a cloud-based social commerce storefront and messaging automation platform (the "Service") designed to help independent merchants build storefronts, sync product catalogs, and automate customer checkouts and communications directly through third-party messaging channels.

This Privacy Policy outlines how we collect, use, store, and share information when you use our platform, dashboard, storefront templates, or messaging integrations (collectively, the "Platform"). By accessing or using Storeik, you agree to the collection and use of information in accordance with this policy.

1. Our Role: Controller vs. Processor

To understand how your data is managed, it is important to distinguish our relationship with the two types of users:

  • Storeik as a Data Controller: We act as the Data Controller for the personal data of our Merchants (the business owners who sign up to create a storefront and manage accounts on Storeik).
  • Storeik as a Data Processor: We act as a Data Processor for the personal data of End-Customers(the buyers purchasing goods from a Merchant's storefront or interacting with a Merchant's automated messaging bots). The Merchant is the Data Controller. We process this data strictly under the instructions and configuration of the Merchant.

2. Information We Collect

A. Information Collected from Merchants

When you register a Merchant account on Storeik, we collect details to establish, run, and secure your dashboard:

  • Account Registration: Name, business/store name, email address, phone number, and secure password credentials.
  • Meta Integration & OAuth Details: To integrate automated flows on messaging channels, we securely collect API credentials, Facebook OAuth access tokens, WhatsApp Business Account (WABA) IDs, and connected Instagram Page IDs.
  • Billing & Referral Data: Billing contact info, subscription plan levels, payment transaction records, and affiliate/referral codes (used to track rewards in our Affiliate System).

B. Information Processed from End-Customers (on behalf of Merchants)

When an End-Customer interacts with a Merchant's automated chatbot or storefront, we process the following order details:

  • Checkout & Shipping Information: Customer name, shipping/delivery address, email address, and phone number (crucial for order verification and notification delivery).
  • Transaction Details: Ordered products, transaction quantities, purchase totals, and payment status IDs.
  • Chat History & Logs: Incoming text messages and comments routed via Meta Webhooks to parse orders, update carts, and auto-reply on WhatsApp or Instagram.

C. Automatically Collected Technical Data

Like most cloud platforms, we collect metadata generated by your device and interaction logs:

  • IP addresses, browser type, device information, and operating systems.
  • Page load times, API response metrics, and error telemetry.
  • Referral link clicks and tracking parameters (e.g., storing a referral token in cookies/localStorage to credit affiliates).

3. How We Use Your Information

We process your information to deliver a functional, high-performance social commerce experience:

  • To Provide the Service: Redeploying dynamic storefronts, routing WhatsApp & Instagram webhook communications, and updating the merchant order dashboard.
  • To Automate Checkouts: Processing cart data, managing delivery addresses, and sending real-time transactional notifications (e.g., "Order Paid", "Shipped", "Delivered") via WhatsApp templates.
  • To Administer Billing: Verifying subscription payments, trial limits, and calculating referral rewards inside the Affiliate Dashboard.
  • To Optimize and Maintain: Monitoring performance, fixing styling leaks, optimizing loading screens, and upgrading API webhooks.
  • To Prevent Abuse: Blocking fraudulent storefronts, self-referral affiliate loops, and unauthorized payment configurations.

4. Data Sharing and Integrations

Storeik does not sell merchant or customer data. We share information only with trusted third-party services essential to delivering our Platform:

  • Meta Platforms (Facebook, Instagram, WhatsApp): We connect with Meta API infrastructures to sync business accounts, read comment/message webhooks, and trigger WhatsApp notifications.
  • Payment Processors (Stripe, Razorpay): Merchant subscription payments and end-customer checkouts are handled by secure, PCI-DSS compliant third-party gateways. Storeik never stores full credit/debit card numbers.
  • Cloud Hosting & Databases: Our databases and servers are securely hosted on infrastructure providers such as Supabase, Vercel, and Render.
  • Shipping & Logistics: We pass buyer delivery addresses to merchant-selected courier services to automate logistics and generate shipping labels.

5. Data Security and Storage

We employ standard industry security protocols to keep your information secure:

  • Encryption: Data transmitted between users, storefronts, and our backend is encrypted in transit using SSL/TLS. Meta OAuth and access tokens are encrypted before being stored in the database.
  • Referral/Email Masking: Sensitive identifiers (such as buyer emails or affiliate ledger signups) are partially masked in dashboards (e.g., da***@uplora.in) to guard individual privacy.
  • Access Control: Super Admin access to global ledgers and system configurations is strictly limited to authorized operational accounts.

6. Your Rights

Depending on your jurisdiction (such as under general privacy directives or domestic regulations), you may hold specific rights concerning your data:

  • Access and Rectification: You can access, edit, or request correction of your merchant dashboard information directly within your account settings.
  • Deletion ("Right to be Forgotten"): You can request that we delete your account and associated personal data. Upon receiving a valid request, we will deactivate credentials and scrub active database profiles, subject to regulatory or transaction ledger requirements.
  • End-Customer Requests: If you are an End-Customer seeking to access, modify, or erase data collected by a Merchant, you must submit your request directly to the Merchant (the Data Controller). As the Processor, we cannot perform operations on customer data without direct authorization from the merchant owner.

7. Policy Updates

We may revise this Privacy Policy periodically. We will notify you of any revisions by updating the effective date at the top of this policy and, if modifications are significant, by issuing an in-dashboard notification or email warning. Continued use of our Platform after revisions are published constitutes acceptance of the modified policy.

8. Contact Us

For questions or requests concerning this Privacy Policy, please contact us at:

Chat with us