Last updated: September 16, 2026
This Privacy Policy explains how UniShopping ("we", "us", or "our") collects, uses, discloses, and protects personal information when you use our retail commerce platform — as a shopper browsing or ordering from a merchant's storefront, or as a merchant or staff member running a shop.
UniShopping is a multi-tenant platform. Each merchant operates their own branded storefront, dashboard and point of sale on our infrastructure, and each shop's data is kept separate from every other shop's.
When you order from a storefront, you are buying from the merchant who runs it, not from us. The merchant decides what they sell, what they ask you for, and how they use what you tell them. We provide the software that stores and processes it on their behalf, and we do not use a merchant's customer data for our own purposes.
In the language of data protection law, the merchant is the controller of their shop's customer data and we are their processor: we handle it to run the shop for them, on their instructions, and for nothing else. For our own accounts — merchant and staff sign-ups, billing, platform security — we are the controller. Where Australian law applies, we are each an APP entity in respect of the information we hold.
Most merchants publish their own privacy policy at /policies/privacy-policy on their storefront. Where it differs from this one on how that shop handles your information, theirs governs the shop's own practices and this one governs the platform underneath it.
For a request about a specific shop's data — access, correction or erasure — contact that merchant first. If you cannot reach them, contact us using the details in section 16 and we will help.
When you browse, order, or create an account on a merchant's storefront, we may collect:
HttpOnly cookie, along with any email address, phone number, gift options or discount codes you have entered before completing the order.You do not have to create an account to shop. Guest checkout asks only for what an order needs — where to send it, and how to tell you it is on its way — and you can browse a storefront without identifying yourself at all.
When you sign up, onboard, or are invited as staff, we collect:
We use cookies only where a feature cannot work without them. We do not use advertising or cross-site tracking cookies of our own.
| Cookie | What it is for | Lifetime |
|---|---|---|
cart-token | A random, unguessable value that identifies your cart. HttpOnly, Secure, SameSite=Lax. | 30 days from your last change |
| Session cookies | Signed, HttpOnly cookies that keep merchants and staff signed in, plus a short-lived cookie during a two-factor challenge. | The session; the two-factor cookie, minutes |
current-shop-id | Remembers which shop a merchant with several was last working on. | The session |
us_analytics_consent | Records whether you allowed third-party analytics tags on a storefront. It carries your decision, the date and where you made it, and no identifier of any kind, so it cannot be used to track you. | 12 months, after which we ask again |
Every cookie above except the last is strictly necessary: blocking them does not make the site track you less, it stops the cart, sign-in or shop switcher working. The analytics consent cookie is the only one that records a choice, and declining is a complete answer — nothing loads in its place.
Your browser also keeps a short recently viewed list per shop in localStorage. It stays on your device, is never sent to our servers, and clearing your browser data removes it.
A merchant may connect their own Google Analytics 4 property and Meta pixel to their storefront. Where they have:
Where a merchant has connected nothing, no third-party tag runs on their storefront at all.
We use the information described above to:
We do not sell personal information, and we do not use one merchant's customer data to benefit another merchant or ourselves.
We do measure the platform itself — how many shops are trading, how many orders cross it, how fast pages render, which features are used. Those measures are aggregated across the platform and carry no shopper's name, contact details or order history, and nothing derived from one shop's customers is ever shown to another shop.
Where the GDPR or UK GDPR applies to a merchant's shop, the merchant identifies the basis for their own processing. For the processing we carry out as controller, our bases are:
| What we do | Basis |
|---|---|
| Take, price and fulfil an order; run the cart and checkout | Performance of a contract |
| Send transactional email about an order or an account | Performance of a contract |
| Send marketing email and abandoned-cart reminders | Consent |
| Load a merchant's Google or Meta analytics tag | Consent |
| First-party aggregate funnel counts, device rendering | Legitimate interests — understanding whether a shop works |
| Rate limiting, fraud prevention, session security, audit logs | Legitimate interests — keeping the platform and its accounts safe |
| Keep order and tax records | Legal obligation |
Where we rely on legitimate interests we have weighed them against your rights, which is why the measures in question use hashed IP addresses, per-visit identifiers and aggregate counts rather than anything that follows you. For shoppers in Australia, the Australian Privacy Principles apply and no separate legal basis is required.
The merchant receives your name, contact details, delivery address where the order is shipped or delivered, the order itself, and any note or gift message you attach. They see only their own shop's customers.
| Provider | What for | Where |
|---|---|---|
| Stripe | Payments, connected-account onboarding, in-store card terminals, refunds, disputes, and collection of our platform fee. Because payments are direct charges on the merchant's connected account, Stripe acts as that merchant's payment processor and handles card data under its own privacy policy. | Australia, United States, European Union |
| Resend | Transactional and marketing email delivery. Merchants may verify their own domain so their shop's email is sent from their own address. | United States |
| Cloudflare R2 | Image and file storage. Uploads use short-lived presigned links, are limited by file type and size, and are namespaced per shop. | Global edge network |
| Neon (PostgreSQL) | Database hosting. | Australia or the region selected for the deployment |
| Vercel | Application hosting and scheduled jobs. | Global edge network, United States |
These providers access only what they need to perform their service and are bound by written agreements and by their own privacy and security obligations. We do not authorise any of them to use what they process for their own purposes.
A merchant can, for their own shop, export their customer and order data, issue read-only API tokens scoped to particular resources, and subscribe their own systems to webhooks. Export links are signed, expire after 24 hours, can be revoked, and record when they were used. Webhook payloads deliberately carry identifiers, amounts and statuses only — never a name, email address, phone number or street address — and this is enforced by an automated test rather than by convention. What a merchant then does with an export they have downloaded is governed by their own policy and their own obligations.
We may disclose information where required by law, regulation, legal process or government request, or to protect the rights, property or safety of UniShopping, our users, or the public. Where we are permitted to tell you about such a request, we will.
If UniShopping is involved in a merger, acquisition, financing, or sale of all or part of its business, information covered by this policy may be transferred as part of that transaction. The recipient would be bound to handle it under a policy no less protective than this one, and we will notify merchants before their data becomes subject to a different policy.
As the table in section 6.2 shows, our service providers may store or process data outside Australia, including in the United States and the European Union. We take reasonable steps to ensure any overseas recipient handles your information consistently with the Australian Privacy Principles. For transfers of EEA or UK personal data we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, in our agreements with those providers.
We do not use your personal information, or a merchant's customer data, to train artificial intelligence or machine-learning models, and we do not sell, licence or otherwise supply it to anyone who does. The platform contains no AI feature that reads your order, your messages or your account.
Public storefront pages — products, descriptions, prices and images — are open to search engines and to AI crawlers, because a shop wants to be found and quoted. Pages that are not public are excluded from crawling: the dashboard, onboarding, checkout, order pages, and the API.
We do not make decisions about you by automated means that produce legal effects or similarly significant effects. Some routine steps are automatic — a rate limiter may slow repeated discount-code attempts from one hashed IP address, and a payment may be declined by Stripe's own fraud checks — but none of these decides anything about you as a person, and a merchant reviews the orders in their own shop. If that ever changes, we will describe the decision, the information it uses and how to ask for human review here before it is switched on.
We implement appropriate technical and organisational measures, including:
HttpOnly, Secure session cookies, and cart tokens that are 128 bits of server-generated randomness — never placed in a URL.While we take these measures seriously, no method of electronic transmission or storage is completely secure.
If we become aware of unauthorised access to, disclosure of, or loss of personal information, we will investigate promptly and contain it.
Where a breach is likely to result in serious harm to the people affected, we will notify the Office of the Australian Information Commissioner and those individuals as soon as practicable, as required by the Notifiable Data Breaches scheme, and we will tell the merchants whose shops are affected so they can meet their own obligations. Where the GDPR applies we will notify the lead supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk to them is high.
A notification will describe what happened, what information was involved, and what you can do about it.
We keep personal information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires.
Marketing email is sent only with consent, and every marketing message includes an unsubscribe link. Withdrawal is honoured immediately, not queued — the flag is what every send checks. You can also withdraw consent from your account on the storefront, or by asking the merchant.
Transactional messages about an order you have placed or an account you hold are not marketing and continue regardless.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact the merchant whose shop holds the data, or contact us at the address in section 16 and we will assist.
We will acknowledge your request promptly and respond within 30 days, or within one month where the GDPR applies. If a request is complex we may extend that period and will tell you why before the original deadline passes. Exercising these rights is free; we will only charge where a request is manifestly unfounded or repetitive, and we will tell you before we do. We will never treat you differently — worse prices, fewer features, a refused order — for exercising a privacy right.
Because a wrongly answered access request is itself a disclosure, we need to be reasonably satisfied you are who you say you are before we act. Usually that means replying from the email address on the account or the order; we will not ask for identity documents where something lesser will do, and anything we are sent for verification is used for that and then deleted.
If you think we have mishandled your personal information or breached the Australian Privacy Principles, tell us first — write to the address in section 16 with "Privacy complaint" in the subject line and set out what happened.
We will acknowledge your complaint within 5 business days, investigate it, and give you a written response within 30 days, telling you what we found and what we will do about it.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or in writing to GPO Box 5288, Sydney NSW 2001. If you are in the EEA or the UK, you may instead complain to your local data protection supervisory authority.
Our platform is not directed at children, we do not knowingly collect personal information from a child under 16, and we do not market to them.
If you are a parent or guardian and believe a child has given us personal information, contact us at the address in section 16 and we will delete it and close any account involved. Individual merchants may sell products intended for adults and are responsible for any age verification their own goods require.
We may update this Privacy Policy from time to time. The "Last updated" date above shows when it was last revised, and the previous version is available from us on request.
We will notify merchants of material changes by email or a dashboard notice at least 30 days before they take effect. Shoppers will see the revised policy at this address, and where a change materially affects how a shop's shoppers are treated we will ask the merchant to notify them. Where a change requires your consent, we will ask for it rather than assume it.
UniShopping is operated by [LEGAL ENTITY NAME] (ABN [ABN]), [REGISTERED BUSINESS ADDRESS], Australia.
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to make a privacy complaint, contact our Privacy Officer at:
Email: contact@unishopping.com.au
Post: Privacy Officer, [LEGAL ENTITY NAME], [POSTAL ADDRESS], Australia