Privacy Policy

What we collect, why we collect it, and who processes it on our behalf. Written to be read rather than skipped.

Last updated 11 September 2026

Who this covers

This policy applies to storeXstore, the storeXstore dashboard, and the marketing pages on storexstore.com. It does not cover your own Magento or Adobe Commerce store, your own storefront, or the privacy practices of sites we link to.

What we collect

  • Account information. Your name, email address and password hash, plus the stores you belong to and the role you hold on each.
  • Store credentials. The API credentials you give us in order to talk to your Magento or Adobe Commerce instance. These are encrypted with AES-256 before they are written to the database and decrypted only to make a call on your behalf.
  • Store data in transit. To do its job the service reads and writes your catalog, content, orders and customers through your store's API. We hold the results only as long as needed to serve the request, and cache some of them briefly with an expiry.
  • Content you create. Pages, designs, AI prompts and generated output, and the record of changes applied to your catalog.
  • Usage and diagnostics. Product analytics events, error reports and stack traces, and server logs including IP address and user agent.
  • Billing information. If you buy AI credits, our payment processor handles your card details. We never receive or store the card number.

Why we collect it

  • To provide the service: authenticating you, enforcing which stores you may access, and carrying out the operations you ask for against your store.
  • To keep it working: detecting errors, diagnosing failures, preventing abuse, and applying rate limits.
  • To bill fairly: metering AI usage against your credit balance.
  • To improve the product: understanding which features are used and where people get stuck.
  • To contact you about your account: sign-in links, security notices, and service changes.

AI processing

When you use an AI feature, the relevant content — a prompt, product attributes, or page content — is sent to a third-party model provider to generate a result. Which provider depends on the feature and on your settings. If you supply your own model API key, requests are made with your key and are governed by your own agreement with that provider.

We do not sell your data, and we do not use your store's content to train our own models.

Who processes data on our behalf

We use a small number of infrastructure providers, each of which may process personal data in the course of running the service:

  • Hosting and content delivery
  • Managed PostgreSQL database hosting
  • Managed cache and rate-limit storage
  • Background job execution
  • Transactional email delivery
  • Error monitoring and product analytics
  • Bot and abuse protection on our forms
  • Payment processing for AI credit purchases
  • AI model providers, as described above

These providers operate in several jurisdictions, so your data may be processed outside the country you are in. Each is bound by its own agreement with us to process data only on our instructions.

Cookies

We use cookies that are strictly necessary for the service to function — keeping you signed in, remembering your language, and protecting forms from abuse. Analytics cookies are used only with your consent, which you can give or withdraw at any time using the cookie settings link in the footer of any page.

How long we keep it

Account and store data is kept for as long as your account is open. Records of changes applied to your catalog are kept for 90 days so that they can be reviewed and reversed, and are then deleted automatically. Diagnostic logs are kept for a short retention window. When you close your account, we delete or anonymise your data, except where we are required to retain records — for example, transaction records for accounting purposes.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to obtain a copy in a portable format, to object to certain processing, and to withdraw consent you previously gave. To exercise any of these, write to us at the address below. We will respond within the time required by the law that applies to you.

Security

Store credentials and API keys are encrypted at rest. Access to store data is checked on every request against your membership of that store. Sessions are signed, connections are encrypted in transit, and requests are rate limited. No system is perfectly secure, but we treat credential handling and tenant isolation as the parts that must not fail, and we test them accordingly.

Children

storeXstore is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change affects you meaningfully, notify you by email or in the dashboard before it takes effect.

Contact

Questions about this policy, or a request about your data, can go to support@storexstore.com.