Privacy Policy

Last updated: September 16, 2026

This Privacy Policy explains how UniShopping ("we", "us", or "our") collects, uses, discloses, and protects personal information when you use our retail commerce platform — as a shopper browsing or ordering from a merchant's storefront, or as a merchant or staff member running a shop.

UniShopping is a multi-tenant platform. Each merchant operates their own branded storefront, dashboard and point of sale on our infrastructure, and each shop's data is kept separate from every other shop's.

1. Our Role and the Merchant's Role

When you order from a storefront, you are buying from the merchant who runs it, not from us. The merchant decides what they sell, what they ask you for, and how they use what you tell them. We provide the software that stores and processes it on their behalf, and we do not use a merchant's customer data for our own purposes.

In the language of data protection law, the merchant is the controller of their shop's customer data and we are their processor: we handle it to run the shop for them, on their instructions, and for nothing else. For our own accounts — merchant and staff sign-ups, billing, platform security — we are the controller. Where Australian law applies, we are each an APP entity in respect of the information we hold.

Most merchants publish their own privacy policy at /policies/privacy-policy on their storefront. Where it differs from this one on how that shop handles your information, theirs governs the shop's own practices and this one governs the platform underneath it.

For a request about a specific shop's data — access, correction or erasure — contact that merchant first. If you cannot reach them, contact us using the details in section 16 and we will help.

2. Information We Collect

2.1 Shoppers

When you browse, order, or create an account on a merchant's storefront, we may collect:

  • Contact details: name, email address, and phone number.
  • Delivery and billing addresses: street address, suburb, state, postcode, and country. Address autocomplete at checkout is provided by Stripe's Address Element, which is already part of the payment flow — no separate mapping or address provider receives what you type.
  • Order details: the items you bought, variant choices, quantities, per-item options such as engraving, delivery or pickup method, order notes, gift wrapping choices and any gift message, discount codes applied, and your order history with that shop.
  • Payment references: card details are entered on Stripe's hosted checkout and processed directly by Stripe. They are never stored on, or transmitted through, our servers. We retain only the references and amounts — Stripe checkout session, payment intent and connected account identifiers, order totals, payment and refund status, and the platform fee recorded against the order.
  • In-store purchases: where a merchant rings up a sale on their point of sale, we record the sale, its payment method, and for card payments a reference to the Stripe Terminal reader used. For cash we record the amount tendered and the change given, and nothing about you unless the merchant attaches the sale to a customer record.
  • Cart contents: your cart is held on our servers against a random 128-bit token in a HttpOnly cookie, along with any email address, phone number, gift options or discount codes you have entered before completing the order.
  • Account information: shopper accounts sign in with a one-time code emailed to you — there is no shopper password to store. An account holds your order history, saved details, wishlist, and any store credit balance the merchant has issued you.
  • Marketing consent: whether you agreed to marketing email, when you agreed, where you agreed (checkout, account, or a newsletter sign-up), and the IP address the consent came from. That IP address is kept as proof the consent was given, and for no other purpose. If you withdraw consent we record when.
  • Reviews: the display name you choose, your rating, title and review text, and your email address — which is kept to de-duplicate reviews and to reach you, and is never published. Where the review was written against an order that contained the product, the link to that order is kept as evidence of a verified purchase.
  • Back-in-stock requests: the email address you gave and the item you asked about. The record is deleted once the notification has been sent, so there is no list to unsubscribe from.
  • Returns: the items, the reason, and any note you write when requesting a return.

You do not have to create an account to shop. Guest checkout asks only for what an order needs — where to send it, and how to tell you it is on its way — and you can browse a storefront without identifying yourself at all.

2.2 Merchants and Staff

When you sign up, onboard, or are invited as staff, we collect:

  • Account credentials: your email address and either a password — stored only as a salted, computationally hard hash, never in plain text — or a Google, Apple, or GitHub sign-in. Email verification is required before an account can be used.
  • Two-factor authentication: if you enable it, an encrypted TOTP secret and single-use recovery codes stored as hashes. A recovery code is shown exactly once and never appears in a log, an email beyond the one that issues it, or an error message.
  • Business information: company and shop name, ABN or tax ID, business address, phone, email, trading locations, and staff names and roles.
  • Payment account information: your Stripe Connect account identifier, its onboarding and capability status, and the platform fee rate applied to your online orders. Stripe collects your identity documents and bank details directly during onboarding — we never see, receive or store them, and customer funds settle into your own Stripe account rather than being held by us.
  • Uploaded content: logos, favicons, product and collection images, storefront page content, and catalog data you import.
  • Integration secrets: analytics API secrets are encrypted at rest and never returned to a browser; API tokens and webhook signing secrets are stored hashed with a display suffix and shown exactly once.
  • Activity records: every change made in the dashboard is written to an append-only staff activity log — who did it, what they changed, and the IP address and browser they did it from. The summary records changed fields only and redacts personal information and secrets.

2.3 Automatically Collected Information

  • Session information: the IP address and user agent attached to each sign-in session, used to secure the account.
  • Abuse prevention: IP addresses are hashed, never stored in the clear, for rate limiting on cart changes, checkout creation, search, and discount-code attempts.
  • First-party storefront analytics: aggregate funnel counts for the merchant — sessions, product views, carts started, checkouts started, orders. These are keyed to an opaque per-visit identifier that is not stable across visits and says nothing about who you are.
  • Device information: browser type, operating system, and screen size, used to render the site correctly.
  • Print devices: where a merchant uses our desktop or iPad app, the app registers a device identifier and platform so print jobs reach the right till. Receipts and tickets travel from that device to a printer over the shop's own local network.

3. Cookies and Local Storage

We use cookies only where a feature cannot work without them. We do not use advertising or cross-site tracking cookies of our own.

CookieWhat it is forLifetime
cart-tokenA random, unguessable value that identifies your cart. HttpOnly, Secure, SameSite=Lax.30 days from your last change
Session cookiesSigned, HttpOnly cookies that keep merchants and staff signed in, plus a short-lived cookie during a two-factor challenge.The session; the two-factor cookie, minutes
current-shop-idRemembers which shop a merchant with several was last working on.The session
us_analytics_consentRecords whether you allowed third-party analytics tags on a storefront. It carries your decision, the date and where you made it, and no identifier of any kind, so it cannot be used to track you.12 months, after which we ask again

Every cookie above except the last is strictly necessary: blocking them does not make the site track you less, it stops the cart, sign-in or shop switcher working. The analytics consent cookie is the only one that records a choice, and declining is a complete answer — nothing loads in its place.

Your browser also keeps a short recently viewed list per shop in localStorage. It stays on your device, is never sent to our servers, and clearing your browser data removes it.

4. Third-Party Analytics Tags

A merchant may connect their own Google Analytics 4 property and Meta pixel to their storefront. Where they have:

  • Nothing loads and nothing is sent until you give consent on that storefront. Consent fails closed — no decision, an expired decision, or a decision we cannot read all mean no tag runs.
  • No personal information leaves in an analytics event, hashed or otherwise. We deliberately omit the hashed email and phone that Meta's conversions API invites, because a hash is still a key that joins you to every other dataset holding the same hash. Events carry items, amounts and order identifiers only.
  • The data those tags collect is then held by Google or Meta under their own policies and the merchant's account with them.

Where a merchant has connected nothing, no third-party tag runs on their storefront at all.

5. How We Use Your Information

We use the information described above to:

  • Provide the service: process orders, reserve and move stock, calculate tax and shipping, take payments, manage fulfilment, pickup, returns and refunds, and run the point of sale.
  • Communicate with you: send order confirmations, shipping and pickup notices, cancellation and refund notices, return updates, back-in-stock notifications, review requests, sign-in codes, email verification and password resets. Transactional messages of this kind are part of the service and cannot be switched off while you have an open order or account.
  • Send marketing, including abandoned-cart reminders, only where the applicable consent has been given. Abandoned-cart recovery requires marketing consent by default on every shop; a merchant can change that only for their own shop and only in line with their own legal advice.
  • Process payments and fees: facilitate payment between you and the merchant through Stripe Connect, and calculate, collect and reverse the platform fee recorded against each online order.
  • Support merchants: produce sales, funnel, inventory and customer reports, exports, and business analytics for the merchant's own shop.
  • Keep the platform secure: prevent fraud, discount-code guessing, oversell and unauthorised access, and maintain an audit trail of administrative actions.
  • Meet legal obligations: including tax and record-keeping requirements.

We do not sell personal information, and we do not use one merchant's customer data to benefit another merchant or ourselves.

We do measure the platform itself — how many shops are trading, how many orders cross it, how fast pages render, which features are used. Those measures are aggregated across the platform and carry no shopper's name, contact details or order history, and nothing derived from one shop's customers is ever shown to another shop.

5.1 Legal Bases (shoppers in the EEA and the UK)

Where the GDPR or UK GDPR applies to a merchant's shop, the merchant identifies the basis for their own processing. For the processing we carry out as controller, our bases are:

What we doBasis
Take, price and fulfil an order; run the cart and checkoutPerformance of a contract
Send transactional email about an order or an accountPerformance of a contract
Send marketing email and abandoned-cart remindersConsent
Load a merchant's Google or Meta analytics tagConsent
First-party aggregate funnel counts, device renderingLegitimate interests — understanding whether a shop works
Rate limiting, fraud prevention, session security, audit logsLegitimate interests — keeping the platform and its accounts safe
Keep order and tax recordsLegal obligation

Where we rely on legitimate interests we have weighed them against your rights, which is why the measures in question use hashed IP addresses, per-visit identifiers and aggregate counts rather than anything that follows you. For shoppers in Australia, the Australian Privacy Principles apply and no separate legal basis is required.

6. How We Share Your Information

6.1 With the Merchant You Ordered From

The merchant receives your name, contact details, delivery address where the order is shipped or delivered, the order itself, and any note or gift message you attach. They see only their own shop's customers.

6.2 With Service Providers

ProviderWhat forWhere
StripePayments, connected-account onboarding, in-store card terminals, refunds, disputes, and collection of our platform fee. Because payments are direct charges on the merchant's connected account, Stripe acts as that merchant's payment processor and handles card data under its own privacy policy.Australia, United States, European Union
ResendTransactional and marketing email delivery. Merchants may verify their own domain so their shop's email is sent from their own address.United States
Cloudflare R2Image and file storage. Uploads use short-lived presigned links, are limited by file type and size, and are namespaced per shop.Global edge network
Neon (PostgreSQL)Database hosting.Australia or the region selected for the deployment
VercelApplication hosting and scheduled jobs.Global edge network, United States

These providers access only what they need to perform their service and are bound by written agreements and by their own privacy and security obligations. We do not authorise any of them to use what they process for their own purposes.

6.3 At a Merchant's Direction

A merchant can, for their own shop, export their customer and order data, issue read-only API tokens scoped to particular resources, and subscribe their own systems to webhooks. Export links are signed, expire after 24 hours, can be revoked, and record when they were used. Webhook payloads deliberately carry identifiers, amounts and statuses only — never a name, email address, phone number or street address — and this is enforced by an automated test rather than by convention. What a merchant then does with an export they have downloaded is governed by their own policy and their own obligations.

6.4 For Legal Reasons

We may disclose information where required by law, regulation, legal process or government request, or to protect the rights, property or safety of UniShopping, our users, or the public. Where we are permitted to tell you about such a request, we will.

6.5 In a Business Transfer

If UniShopping is involved in a merger, acquisition, financing, or sale of all or part of its business, information covered by this policy may be transferred as part of that transaction. The recipient would be bound to handle it under a policy no less protective than this one, and we will notify merchants before their data becomes subject to a different policy.

6.6 Overseas Disclosure

As the table in section 6.2 shows, our service providers may store or process data outside Australia, including in the United States and the European Union. We take reasonable steps to ensure any overseas recipient handles your information consistently with the Australian Privacy Principles. For transfers of EEA or UK personal data we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, in our agreements with those providers.

7. Artificial Intelligence and Automated Decisions

We do not use your personal information, or a merchant's customer data, to train artificial intelligence or machine-learning models, and we do not sell, licence or otherwise supply it to anyone who does. The platform contains no AI feature that reads your order, your messages or your account.

Public storefront pages — products, descriptions, prices and images — are open to search engines and to AI crawlers, because a shop wants to be found and quoted. Pages that are not public are excluded from crawling: the dashboard, onboarding, checkout, order pages, and the API.

We do not make decisions about you by automated means that produce legal effects or similarly significant effects. Some routine steps are automatic — a rate limiter may slow repeated discount-code attempts from one hashed IP address, and a payment may be declined by Stripe's own fraud checks — but none of these decides anything about you as a person, and a merchant reviews the orders in their own shop. If that ever changes, we will describe the decision, the information it uses and how to ask for human review here before it is switched on.

8. Data Security

We implement appropriate technical and organisational measures, including:

  • Passwords stored only as salted, computationally hard hashes.
  • Optional two-factor authentication for every staff and owner account, which a company can require of everyone; recovery codes are single-use and stored hashed.
  • Signed, HttpOnly, Secure session cookies, and cart tokens that are 128 bits of server-generated randomness — never placed in a URL.
  • Staff permissions enforced server-side on every action, not merely hidden in the interface.
  • Server-side validation of every input, and every amount charged re-derived from our own records rather than trusted from the browser.
  • Rate limiting on public endpoints, with IP addresses hashed rather than stored.
  • Stripe's PCI-compliant infrastructure for all card handling, and Stripe webhook signatures verified before any payload is read.
  • Secrets stored hashed or encrypted, kept out of client bundles, logs, webhook bodies and error messages.
  • Tenancy isolation between shops, enforced in queries and covered by automated tests, so one shop cannot read another's data.

While we take these measures seriously, no method of electronic transmission or storage is completely secure.

9. Data Breach Notification

If we become aware of unauthorised access to, disclosure of, or loss of personal information, we will investigate promptly and contain it.

Where a breach is likely to result in serious harm to the people affected, we will notify the Office of the Australian Information Commissioner and those individuals as soon as practicable, as required by the Notifiable Data Breaches scheme, and we will tell the merchants whose shops are affected so they can meet their own obligations. Where the GDPR applies we will notify the lead supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk to them is high.

A notification will describe what happened, what information was involved, and what you can do about it.

10. Data Retention

We keep personal information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires.

  • Orders: retained for as long as needed to provide the service and to meet legal and tax obligations — in Australia, generally five years. On an erasure request the person is removed from the order rather than the order deleted: name, address, email and phone are redacted while the date, the lines and the figures remain, so the merchant's books still balance.
  • Customer records: retained while the account or relationship is active; anonymised on request as described above.
  • Carts: your cart cookie expires 30 days after your last change. The cart record behind it is kept so a returning shopper finds their cart and so a merchant can send the single recovery message described in section 5; completing an order converts the cart, and the order's retention applies from that point.
  • Reviews: kept while the product is listed, and removed at your request or the merchant's.
  • Marketing consent records: the record of a consent — and of its withdrawal — is kept for as long as it has legal effect and for a reasonable period afterwards, because it is the evidence that the consent existed.
  • Sign-in sessions: the IP address and user agent attached to a session are kept for the life of that session; signing out or deleting the session removes them.
  • Rate-limiting records: hashed IP addresses are kept for the short window the limit is measured over, and are never reversible to an address.
  • First-party analytics: per-visit identifiers are not stable across visits and are not retained beyond the aggregate counts they contribute to.
  • Staff activity logs: 12 months, then deleted automatically by a scheduled job.
  • Exports: no export file is stored. The link streams the rows from the database when it is followed, and the link itself stops working 24 hours after the export is ready.
  • Back-in-stock requests: deleted as soon as the notification has been sent.
  • Merchant accounts: business information is retained while the account is active and for a reasonable period afterwards. Merchants can delete their account from the dashboard or the desktop and iPad apps, which ends the session immediately.

11. Marketing Choices

Marketing email is sent only with consent, and every marketing message includes an unsubscribe link. Withdrawal is honoured immediately, not queued — the flag is what every send checks. You can also withdraw consent from your account on the storefront, or by asking the merchant.

Transactional messages about an order you have placed or an account you hold are not marketing and continue regardless.

12. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we or a merchant hold about you. Every merchant can produce a complete export of a customer's record and order history in JSON or CSV.
  • Correct inaccurate or incomplete information.
  • Delete your personal information, subject to the legal retention limits in section 10 — in practice, anonymisation of your orders rather than their destruction.
  • Object to or restrict certain processing, including processing we base on legitimate interests.
  • Data portability: receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent where processing relies on it, at any time, without affecting what was done before you withdrew.
  • Deal with us anonymously or under a pseudonym where it is lawful and practicable to do so — you can browse without identifying yourself and check out as a guest.

To exercise any of these rights, contact the merchant whose shop holds the data, or contact us at the address in section 16 and we will assist.

We will acknowledge your request promptly and respond within 30 days, or within one month where the GDPR applies. If a request is complex we may extend that period and will tell you why before the original deadline passes. Exercising these rights is free; we will only charge where a request is manifestly unfounded or repetitive, and we will tell you before we do. We will never treat you differently — worse prices, fewer features, a refused order — for exercising a privacy right.

Because a wrongly answered access request is itself a disclosure, we need to be reasonably satisfied you are who you say you are before we act. Usually that means replying from the email address on the account or the order; we will not ask for identity documents where something lesser will do, and anything we are sent for verification is used for that and then deleted.

13. Complaints

If you think we have mishandled your personal information or breached the Australian Privacy Principles, tell us first — write to the address in section 16 with "Privacy complaint" in the subject line and set out what happened.

We will acknowledge your complaint within 5 business days, investigate it, and give you a written response within 30 days, telling you what we found and what we will do about it.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or in writing to GPO Box 5288, Sydney NSW 2001. If you are in the EEA or the UK, you may instead complain to your local data protection supervisory authority.

14. Children's Privacy

Our platform is not directed at children, we do not knowingly collect personal information from a child under 16, and we do not market to them.

If you are a parent or guardian and believe a child has given us personal information, contact us at the address in section 16 and we will delete it and close any account involved. Individual merchants may sell products intended for adults and are responsible for any age verification their own goods require.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date above shows when it was last revised, and the previous version is available from us on request.

We will notify merchants of material changes by email or a dashboard notice at least 30 days before they take effect. Shoppers will see the revised policy at this address, and where a change materially affects how a shop's shoppers are treated we will ask the merchant to notify them. Where a change requires your consent, we will ask for it rather than assume it.

16. Contact Us

UniShopping is operated by [LEGAL ENTITY NAME] (ABN [ABN]), [REGISTERED BUSINESS ADDRESS], Australia.

If you have any questions about this Privacy Policy, wish to exercise your rights, or want to make a privacy complaint, contact our Privacy Officer at:

Email: contact@unishopping.com.au

Post: Privacy Officer, [LEGAL ENTITY NAME], [POSTAL ADDRESS], Australia

Privacy Policy | UniShopping