Storefront Privacy Policy Template
Privacy Policy
Effective Date:[DATE]
This Privacy Policy describes how [YOUR STORE NAME] (“we”, “us”, or “our”) collects, uses, and protects your personal information when you visit or make a purchase from our online store.
1. Information We Collect
Information you provide:| Data | When Collected |
|---|---|
| Name | Account registration, checkout |
| Email address | Account registration, checkout, newsletter signup |
| Phone number | Checkout (for delivery updates) |
| Shipping address | Checkout |
| Billing address | Checkout |
| Account password | Account registration (stored securely hashed) |
| Data | Purpose |
|---|---|
| Cart session ID | Maintaining your shopping cart |
| Browser type and version | Ensuring compatibility |
| Pages visited | Improving our store experience |
Optional: Additional data you collect
Optional: Additional data you collect
If you collect additional data (e.g., birthday for loyalty programs, size preferences, etc.), list them here:
[ADDITIONAL DATA ITEM]—[PURPOSE][ADDITIONAL DATA ITEM]—[PURPOSE]
2. How We Use Your Information
We use your personal information to:- Process and fulfill orders — Including shipping, payment processing, and order confirmations
- Manage your account — If you create a customer account
- Communicate with you — Order status updates, delivery notifications, and customer support
- Prevent fraud — Detecting and preventing fraudulent transactions
- Comply with legal obligations — Tax records, regulatory requirements
Optional: Marketing communications
Optional: Marketing communications
With your consent, we may also use your email to send:
- Promotional offers and discounts
- New product announcements
- Newsletter content
[YOUR EMAIL].3. Payment Information
We use[Stripe / TossPayments / YOUR PAYMENT PROVIDER] to process payments. Your payment card information is sent directly to the payment processor and is never stored on our servers. We only receive a payment confirmation reference.
For more information, see:
[Stripe's Privacy Policy: https://stripe.com/privacy][TossPayments Privacy Policy: https://www.tosspayments.com/privacy]
4. Who We Share Your Data With
We share your personal information only with service providers necessary to operate our store:| Service Provider | Purpose |
|---|---|
| Headless Commerce | Commerce platform (order processing, inventory) |
[Stripe / TossPayments] | Payment processing |
[SHIPPING CARRIER NAME] | Order delivery |
[EMAIL PROVIDER, if applicable] | Transactional and marketing emails |
5. Data Retention
| Data | Retention Period |
|---|---|
| Order records | [3-5] years (for tax and legal compliance) |
| Customer accounts | Until you request deletion |
| Cart sessions | Automatically cleared after 30 days of inactivity |
| Marketing consent records | Duration of consent + [3] years |
6. Your Rights
- Global (GDPR)
- Korea (개인정보 보호법)
If you are located in the EU/EEA, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your data (“right to be forgotten”)
- Portability — Receive your data in a structured, machine-readable format
- Restriction — Request that we limit how we use your data
- Object — Object to processing based on legitimate interests
- Withdraw consent — Withdraw consent for marketing at any time
[YOUR EMAIL]. We will respond within 30 days.7. Cookies
We use the following cookies:| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Cart session | Essential | Maintaining your shopping cart | 30 days |
| Authentication | Essential | Keeping you logged in | Session |
Optional: Analytics and marketing cookies
Optional: Analytics and marketing cookies
8. Children’s Privacy
Our store is not directed to individuals under the age of[14/16]. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
9. International Data Transfers
Your data may be processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place through our platform provider (Headless Commerce) and payment processor.10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.[We will also notify you via email for material changes.]
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:- Business name:
[YOUR BUSINESS NAME] - Email:
[YOUR EMAIL] - Address:
[YOUR ADDRESS] - Phone:
[YOUR PHONE NUMBER]
- Global
- Korea
If we are unable to resolve your concern, you may lodge a complaint with your local data protection authority.