what we keep
Privacy policy
What we collect, why, how long we keep it, and what you can do about it.
Last updated 30 August 2026
DRAFT FOR LEGAL REVIEW — DO NOT PUBLISH WITHOUT SIGN-OFF
This document describes how the platform actually works, but it has not been reviewed by a Brazilian lawyer and the company’s own registration details are not yet configured. Nothing on this page should be relied on as the final agreement.
The short version
We collect what running a shop requires and nothing else. We do not sell data, we do not run advertising, and there are no third-party trackers on any page of this service, including this one.
If you are a merchant
We hold:
- Your name and email address, so you can sign in and we can reach you about your shop.
- A hash of your password. We never store the password itself and cannot recover it.
- Your session records, the IP address and browser that signed in, and when, so you can see and revoke your own sessions.
- Your shop's configuration, including the extended public keys you enter. We never ask for and never store a private key.
- An audit log of changes made in your shop, so you can see who did what.
If you are a buyer
The shop you bought from is the controller of your data; we process it on their behalf. For an order we hold:
- Your email address, so the goods and the receipt can be sent to you.
- The order itself: what you bought, what you paid, and what was delivered.
- The IP address, country and browser the order was placed from, and the resulting risk assessment. This exists to stop fraud against the merchant, and for no other purpose.
- Anything you typed into a product's custom fields, because the delivery needs it.
You do not need an account. An order is looked up with its number and the email address it was placed with.
Payment data
We never see a card number. Where a shop accepts cards, the fields belong to Stripe and the details go straight to them; we are told that a payment succeeded and which one, never how it was paid for. A crypto payment is recorded as the receiving address, the amount, the transaction id and the confirmation count, all of which are already public on the chain. We do not attempt to identify who owns a wallet.
Pix. A Pix payment is created on the merchant's own Mercado Pago account, so Mercado Pago is told your e-mail address, the amount and a reference for the order. Mercado Pago requires a CPF or CNPJ from some payers; where a shop asks for one, it is sent to them to create the payment and is not stored by us in readable form— it is encrypted at rest, shown masked to the merchant, and never written to a log or to any analytics. We hold no Pix key of yours and no bank details.
Merchants' provider credentials. When a merchant connects a Mercado Pago account, we store an access token and a refresh token for it, encrypted at rest with a key that is not the one protecting anything else. They are never sent to a browser, never written to a log, and are erased when the merchant disconnects. We store no password of theirs and no Mercado Pago client secret of theirs.
Notifications. Mercado Pago and Stripe tell us when a payment changes. We keep the envelope of those notifications — which resource, when, and what we did about it — and not the payment body, so a payer's name and document do not get a second home in a log table.
Cookies
We set two cookies, both strictly necessary, neither used for tracking:
- A session cookie when you sign in, holding an opaque random token.
- An order-access cookie when a buyer unlocks an order page with their email, scoped to that one order.
Your theme choice is stored in your own browser and never reaches us.
How long we keep it
- Orders and invoices: as long as the shop exists, because they are the merchant's trading records.
- Sessions: until they expire or are revoked, then deleted within a week.
- Risk and audit records: two years.
- Email delivery logs: ninety days.
Who else sees it
The merchant you bought from, for their own orders. Our hosting and email providers, to the extent they must to deliver the service. And the payment provider the merchant chose, for the payment itself: Stripe for cards and Mercado Pago for Pix, each acting on the merchant's own account under their own privacy policy. Nobody else. We do not sell or share data for advertising.
Your rights
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. A merchant can do all three from the dashboard; a buyer should ask the shop they bought from, and they must respond. Where we are the controller, for merchant accounts, write to us and we will respond within thirty days.
Changes
The date at the top of this page reflects the current version. We will tell merchants before a change that materially affects them takes effect.