Privacy Policy

Last updated: [Effective date]

This is a template for launch, not legal advice. Have it reviewed by a lawyer and replace the bracketed placeholders before going live. The full text is currently available in English only.

This Privacy Policy explains how [Company Legal Name] ("we", "us") collects, uses, and protects personal data when you use the Tuqui.store Service. We act as the data controller for account and platform data. For a creator’s own storefront and customer data, the creator is the controller and we act as their processor.

Data we collect

  • Account data: name, email address, password (stored only as a secure hash), and settings.
  • Storefront data: the links, text, images, products, and files you publish.
  • Lead and customer data you collect through the Service (for example, email addresses from your lead-capture form, or a buyer’s email for delivery of a purchase).
  • Usage and analytics data: pages viewed, clicks, and basic device/browser information, used to operate and improve the Service and to give you storefront analytics.
  • Communications: messages you send us, such as support requests.
  • Payment-connection data: the identifiers of the Stripe or MercadoPago account you connect in order to sell. For MercadoPago we also store the access and refresh tokens that authorize charges on your account, encrypted at rest — MercadoPago cannot accept a payment on your behalf without them. Stripe Connect Standard needs no such credential, so for Stripe we store none. We use them only to operate selling on your behalf: creating checkouts on your account, looking up the payments your customers make so we can record the order and deliver it, issuing the refunds you ask for, reconciling your own sales, checking with MercadoPago that your connection still works so we can show you whether your store can accept payments, and renewing the tokens themselves so your store keeps selling.

We do not collect or store full payment card details. Payments are handled by Stripe or by MercadoPago, depending on the market your store sells in. In both cases the payment details are entered on the processor’s own hosted checkout and never touch our servers.

How we use data

  • To provide, maintain, and secure the Service and your account.
  • To process subscriptions and to enable your connected Stripe or MercadoPago account to accept payments.
  • To provide analytics about your storefront’s performance.
  • To send service and transactional messages (for example, receipts, download links, security notices).
  • To detect, prevent, and respond to fraud, abuse, disputes, and violations of our terms.
  • To comply with legal obligations.

Legal bases

Where the GDPR or similar laws apply, we process data on the bases of performance of a contract (providing the Service), our legitimate interests (securing and improving the Service, preventing abuse), your consent (where required, for example certain communications), and compliance with legal obligations.

Service providers we share data with

We share the minimum data necessary with providers who help us run the Service, under contracts that require them to protect it:

  • Stripe — subscription billing in US dollars and, for creators in that market, payment processing on their own connected Stripe account.
  • MercadoPago — subscription billing in Argentine pesos and, for creators in that market, payment processing on their own connected MercadoPago account.
  • Our email provider — to send transactional and service email.
  • Our cloud storage and hosting providers — to store uploaded files and run the Service.

We do not sell your personal data. We self-host the fonts used on public storefronts, so viewing a storefront does not send requests to third-party font services.

International transfers

Our providers may process data in countries other than yours. Where required, such transfers are covered by appropriate safeguards such as Standard Contractual Clauses.

Retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for any period required to meet legal, tax, accounting, or dispute-resolution obligations. Raw analytics events are retained for a limited period and then aggregated or deleted.

Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise many of these directly in your account settings, or contact us at legal@[yourdomain]. You may also lodge a complaint with your local data protection authority.

If you are a customer of a creator’s storefront and want to exercise rights over data that creator holds, contact the creator directly; we will assist them as their processor.

Security

We use technical and organizational measures to protect personal data, including encryption in transit, hashed passwords, encryption at rest for the payment-provider credentials you connect, and access controls. No method of transmission or storage is completely secure, but we work to protect your information and to respond to incidents.

Children

The Service is not directed to children under the age required to consent in your jurisdiction, and we do not knowingly collect their data.

Changes and contact

We may update this Policy and will post the new effective date here. For privacy questions or requests, contact legal@[yourdomain].