GDPR Policy

Last updated: August 11, 2026

1. Scope

This policy explains how StoreKit supports compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR for merchants, and their customers, located in the European Economic Area (EEA) or United Kingdom. It supplements — rather than replaces — our Privacy Policy and Data Usage Policy.

2. Controller and processor roles

GDPR distinguishes between a data controller (who decides why and how personal data is processed) and a data processor (who processes it on the controller's instructions). On StoreKit:

  • For a merchant's own account data (name, email, login activity), StoreKit is the controller.
  • For a merchant's customer data collected through their store (orders, shopper accounts, support messages), the merchant is the controller and StoreKit acts as their processor, processing that data only on the merchant's instructions and to operate the platform.

Merchants processing EU/UK customer data remain responsible for having their own valid legal basis for that processing (e.g. fulfilling an order, or consent for marketing emails).

3. Legal bases we rely on

Where StoreKit is the controller, we process personal data on one or more of these legal bases:

  • Contract: to create and operate your merchant account and provide the services you've signed up for.
  • Legitimate interests: to secure the platform, prevent fraud and abuse, and improve our product — balanced against your rights and expectations.
  • Legal obligation: to meet tax, accounting, and other regulatory requirements.
  • Consent: for optional communications you can opt out of at any time, such as promotional email.

4. Your rights under GDPR

If you are located in the EEA or UK, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to our legal retention obligations.
  • Restrict or object to certain processing, including for direct marketing.
  • Port your data to another service in a structured, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent, without affecting processing that already took place.

To exercise any of these rights against StoreKit as controller, contact support@storekit.online. If your request concerns a specific store's customer data, we'll direct it to that merchant as the controller, or assist them in responding to you.

5. International data transfers

StoreKit's infrastructure is primarily operated from India. Where personal data of EEA/UK individuals is transferred outside the EEA or UK, we rely on appropriate safeguards recognised under GDPR, such as Standard Contractual Clauses, to protect that data in transit and at its destination.

6. Data Protection Officer

We have not appointed a statutory Data Protection Officer, as our processing activities do not currently meet the Article 37 threshold requiring one. For any data protection query, contact us at support@storekit.online and we will route it appropriately.

7. Right to complain

If you believe our handling of your personal data doesn't comply with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority, in addition to (or instead of) contacting us directly.

8. Data Processing Agreement for merchants

Merchants established in, or serving customers in, the EEA/UK who need a Data Processing Agreement (DPA) with StoreKit for their own GDPR compliance can request one from support@storekit.online.

9. Changes to this policy

We may update this GDPR Policy as our processing activities, vendors, or the regulation itself evolve. Material changes will be announced the same way as Privacy Policy changes.