Legal
Privacy Policy
Plain-English summary, not legal advice. We may update wording with counsel.
Last updated: July 29, 2026
1. Who we are
StoreRadar is a small operation that sells access to a dataset of publicly available Shopify-store data: as a one-time CSV, as a yearly subscription (StoreRadar Annual), and through Discover, a browser tool for viewing and slicing the data. This policy explains two things: what data we collect from buyers and subscribers, and what data is inside the product we sell.
2. Data we collect from you
When you buy the File, subscribe, or use Discover, we collect:
- Email and a lightweight account: you confirm your email with a one-time code (passwordless). We create an account tied to that email so you can access downloads, manage a subscription, and use Discover. We use the email to send your download links, subscription exports, and support or billing correspondence.
- Payment and subscription metadata: Stripe handles the card. We see only what Stripe shows us: amount, country, last four, billing email, and, for subscriptions, renewal and cancellation status. We never see or store your full card number.
- Usage and download events: when a signed link is opened or you use Discover, we log a timestamp and IP address. This is how we detect abuse (for example, a link shared widely, or scraping of Discover) and how we prove a delivery happened if a chargeback is filed.
- Watermark identifier: every File we deliver is watermarked with a buyer-specific identifier embedded across the rows, so we can trace a leaked copy back to the original buyer.
- Marketing attribution: if you arrive from an online ad we may capture an ad click identifier (such as a Google
gclid) and your consent choice, to measure whether ads lead to purchases. See section 3.
3. Advertising and analytics
We want to be straight about this, because it changed as we started running ads:
- Google Ads conversion measurement. We advertise on Google. When you arrive from one of our ads we may capture the click identifier (
gclid), and, subject to your consent choice on our consent banner, share a record of a completed purchase with Google Ads so we can measure which ads work. We show a consent banner where you can accept or decline this; if you decline, we do not send ad-conversion data. - Product analytics. We use privacy-respecting product analytics (PostHog) to understand page views, referrers, and how the checkout flows perform, so we can fix what's broken.
- What we do not do. We do not run session replay, we do not sell your data, and we do not add you to a marketing list without asking.
4. How we use your data
- Deliver the File, subscription exports, and Discover access you paid for.
- Run your account and, for subscribers, manage renewals and cancellations.
- Re-issue a download link if you ask.
- Respond to support, refund, or legal requests.
- Keep a record of the purchase for accounting and tax compliance.
- Detect and respond to abuse (excessive downloads, leaked files, Discover scraping, fraudulent chargebacks).
- With your consent, measure ad conversions as described in section 3.
If you bought from us you might get one follow-up email asking how it went. That's it.
5. Sub-processors
Third parties that process data on our instructions to run the service:
- Stripe: payment processing and subscription billing.
- Our email provider: transactional email (download links, subscription exports, support replies).
- Our hosting provider and object storage: where the app and the signed Files live.
- MillionVerifier: email deliverability verification. We send store-owner email addresses from the dataset for MX/SMTP checks to produce the verified-email verdict.
- PostHog: privacy-respecting product analytics.
- Google Ads: ad-conversion measurement, where you've consented (section 3).
Vendor details and data-processing terms available on request.
6. Retention
- Account and purchase records (email, Stripe charge/subscription ID, amount, date): retained while your account or subscription is active, and for 7 years after for tax and accounting.
- Signed download tokens: active for 7 days, re-issuable for 30. Tokens are deleted or invalidated after that.
- Usage and download event logs: retained for 12 months, then deleted or aggregated.
- Ad-attribution data (gclid, consent choice): retained only as long as needed to measure and reconcile a conversion, then deleted or aggregated.
- Support emails: retained as long as needed to handle the conversation and any follow-up, typically up to 24 months.
7. What's inside the dataset
The dataset is compiled from publicly accessible storefront pages, the same pages anyone can visit by typing the store URL into a browser. Typical fields include:
- Store domain, store name, and storefront metadata
- Public business contact information posted by the store (email addresses and phone numbers from contact, about, and footer pages)
- A deliverability verdict on those email addresses (MX/SMTP checks and a verification score), where verification has been run
- Tech and platform signals (apps installed, themes, payment providers, as visible in public source)
- Country, currency, language, and other public commerce signals
We do not include data that requires logging in to a Shopify admin. We do not include consumer or shopper data. The data subjects are businesses and the contact details those businesses chose to publish.
8. Legal basis (GDPR / UK GDPR)
Where the data inside the dataset constitutes personal data under EU/UK law (for example, a sole-trader storefront where the business email is a personal name), we process it under legitimate interest (building a B2B dataset of publicly published business contact information, and verifying its deliverability) balanced against the data subject's rights, which we honor through our removal process.
For your account and purchase data (email, payment and subscription metadata, usage logs), our legal basis is contract (delivering what you paid for) and legitimate interest (fraud prevention, anti-abuse, record-keeping). For ad-conversion measurement, our legal basis is your consent, which you can give or decline on the consent banner and withdraw at any time.
9. Your rights
If you're in the EU, UK, California, or another jurisdiction with data-subject rights, you can:
- Access: ask what we hold about you.
- Correct: ask us to fix inaccurate data.
- Delete: ask us to remove your data.
- Object: object to our processing under legitimate interest.
- Withdraw consent: change your ad-tracking choice at any time.
- Portability: get a copy of your account record in a portable format.
Shopify store owners: use the dedicated form at /removal-request. It's the fastest path to having your store excluded from future snapshots and from Discover.
Honest limit: we honor removal requests for future snapshots and Discover within 14 days. We cannot recall or modify copies of a File that have already been downloaded by buyers. This is a known consequence of selling data as a file rather than only as a hosted service.
For any other request, email jeanro@storeradar.io.
10. International transfers
Our infrastructure and team may be located outside your country. Where applicable, transfers of personal data out of the EU/UK rely on Standard Contractual Clauses with our sub-processors.
11. Children
The product is sold to businesses and adults. It is not directed at children, and we do not knowingly collect data from anyone under 16.
12. Changes to this policy
We may update this policy over time. Material changes will be reflected in the "last updated" date at the top.
13. Contact
Privacy questions, data requests, or anything else: jeanro@storeradar.io.