Skip to main content

Privacy Policy

Effective Date: February 17, 2026 Last Updated: February 17, 2026 This Privacy Policy describes how Headless Commerce (“Company”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use the Headless Commerce platform, including the API, Dashboard, SDK, CLI, and related services (the “Service”). This policy applies to Merchants and their team members who use our platform. For information about how we process data on behalf of Merchants (i.e., your end-customers’ data), see our Data Processing Agreement.

1. Data Controller

The data controller for the personal data described in this policy is: Headless Commerce Email: privacy@headlesscommerce.io Address: [Company Address] Data Protection Officer / 개인정보 보호책임자: Email: dpo@headlesscommerce.io

2. Data We Collect

2.1 Account Data

When you register and use the Service, we collect:

2.2 Organization & Billing Data

2.3 Technical & Usage Data

2.4 Data We Do NOT Collect

  • Credit card numbers — All payment card data is handled directly by Stripe. We never see, transmit, or store card numbers.
  • End-customer passwords — Customer authentication credentials are hashed and never accessible in plaintext.

3. Data We Process on Your Behalf

As a data processor, we process the following data that your end-customers submit through your store via our API:
  • Customer names, email addresses, phone numbers
  • Shipping and billing addresses
  • Order details and history
  • Cart contents and session data
This processing is governed by our Data Processing Agreement. You (the Merchant) are the data controller for this data and are responsible for obtaining appropriate consent from your end-customers.

4.1 Under GDPR (EU/EEA)

4.2 Under Korean Personal Information Protection Act (개인정보 보호법)

We obtain separate, specific consent for each purpose as required by Korean law. Consent is freely given and may be withdrawn at any time.

5. Data Sharing & Sub-processors

We share personal data only with the following categories of recipients:

5.1 Sub-processors

5.2 We Do NOT

  • Sell your personal data to any third party
  • Share data for advertising purposes
  • Use your data for profiling or automated decision-making

5.3 Law Enforcement

We may disclose data when legally compelled (court order, subpoena) or when necessary to prevent imminent harm. We will notify you unless prohibited by law.

6. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction:

6.1 EU/EEA Transfers

For transfers outside the EEA, we rely on:
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable

6.2 Korean Cross-Border Transfers

In accordance with the Personal Information Protection Act (개인정보 보호법 제17조, 제28조의2):
  • We obtain your consent for international data transfers
  • We ensure that receiving parties maintain equivalent data protection standards
  • Details of cross-border transfers are listed in the sub-processor table above

7. Data Retention

After the retention period, data is permanently deleted or anonymized.

8. Your Rights

8.1 Under GDPR

If you are in the EU/EEA, you have the right to:
  • Access your personal data
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”)
  • Port your data to another service
  • Restrict or object to processing
  • Withdraw consent at any time
  • Lodge a complaint with your local supervisory authority

8.2 Under Korean Law (개인정보 보호법)

If you are in Korea, you have the right to:
  • 열람 (Access) — Request access to your personal data
  • 정정·삭제 (Rectification/Erasure) — Request correction or deletion
  • 처리정지 (Restriction) — Request suspension of processing
  • 동의 철회 (Withdraw Consent) — Withdraw previously given consent
  • 개인정보보호위원회 신고 — File a complaint with the Personal Information Protection Commission (PIPC)

8.3 Exercising Your Rights

To exercise any of these rights, contact us at privacy@headlesscommerce.io. We will respond within:
  • GDPR: 30 days
  • Korean law: 10 days

9. Security Measures

We implement appropriate technical and organizational measures to protect your data:

10. Cookies & Tracking

10.1 Cookies We Use

10.2 What We Don’t Use

  • No third-party advertising cookies
  • No cross-site tracking pixels
  • No fingerprinting technologies

11. Children’s Privacy

The Service is not directed to individuals under the age of 16 (or 14 in Korea under 개인정보 보호법). We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via:
  • Email notification to your account email
  • Dashboard notification
  • At least 30 days before taking effect

13. Contact

For privacy-related inquiries: