Legal

Privacy Policy

What Storzy collects, why, who it is shared with, and how to have it deleted. Written against what the software actually does.

Last updated

01Who this covers

Storzy is an e-commerce platform. Merchants use it to build and run an online shop; shoppers buy from those shops. The two roles are treated differently in law, and so are treated differently here.

For merchant accounts, Storzy is the controller - we decide what we collect about you and why. For shopper data, the merchant whose shop you bought from is the controller and Storzy is their processor: we hold and handle the data on their instructions. That means a request to delete your order history is one we will act on, but the merchant is the party who decides it.

02What we collect from merchants

  • Your name and email address, and a password, which is stored only as a one-way hash - we cannot read it or recover it for you.
  • If you sign in with Google: your name, email address and profile picture, as Google supplies them. If you sign up with an email address instead, we generate a placeholder avatar from your account identifier.
  • Your business details: store name, handle, business category, contact phone number and district.
  • Everything you put into your store - products, prices, images, policies and the storefront design itself.
  • Your plan and subscription status.
  • Your billing history: what you were charged for each month, what you paid, and any reference you gave us for a transfer.

03What we collect from shoppers

  • When you place an order: your name, email address, phone number, delivery address, and any note you add to the order.
  • If you create a shopper account: your name, email address, and a hashed password.
  • If you leave a review: your name and what you wrote. Reviews are held for the merchant to approve and are public once published.
  • The contents of your cart, held in a cookie on your own device.

Card numbers are never collected by Storzy. When you pay, the payment gateway the merchant has enabled takes those details directly. We are told the amount, the currency and whether the payment succeeded - nothing more.

04Visit counting

Each storefront shows its merchant how many people visited and roughly where from. That counting is done by an analytics provider we send storefront page views to: which shop and page was viewed, when, a random identifier for your browser, and a country and approximate city looked up from your IP address. The IP address itself is not stored against the visit.

This is the only analytics on Storzy, and it is not advertising: there is no Google Analytics, no Meta pixel, no advertising network, and nothing sold to a data broker. It is not used to build a profile of you across different merchants' shops, and the merchant sees totals for their own shop, never a list of who visited it.

IP addresses are used momentarily to enforce rate limits - the mechanism that stops one machine flooding checkout or reviews. They are held in memory for that check and are not written to the database.

05Usage measurement

Merchant plans include an amount of file storage and a number of emails a month, so we measure both. Storage is a total number of bytes, recalculated by asking our file host how large the merchant's own folder is - we do not keep a separate record of individual files.

For email we record only which workspace sent it, what kind of message it was, when it went out and whether it succeeded. We do not store the recipient's address, the subject or the body of any message we send on a merchant's behalf.

06Artificial intelligence

Storzy has two AI features, both called Kiki. The first is the support chat: it appears in the merchant dashboard and on the Storzy website, and answers questions about how to use Storzy, drawing only on help articles we wrote. The second is the design assistant in the storefront editor, which suggests changes to how a merchant's own shop page looks.

When you send the support chat a message, that message is sent to Google's Gemini API to produce the reply. If you are a signed-in merchant, a short summary of your own store's setup state goes with it - store name, plan, whether the shop is published, how many products it has, domain status and which payment methods are switched on. If you are using it on our website without an account, nothing but your message is sent.

The design assistant sends what you type plus a description of the page you are editing: your store name, which design you are using, which sections are on the page and whether each is switched on, and how many images you have added. It is not sent your existing page text, your product data, your images or your files.

Shopper records, order contents and customer details are never sent to either.

Neither can change anything on its own. The support chat cannot edit a store at all. The design assistant only proposes changes to your storefront's appearance: nothing takes effect until you press Apply, and nothing is public until you publish. Neither can alter an order, take a payment, or read another merchant's data, and neither makes automated decisions about you or anyone else.

Your data is not used to train any AI or machine-learning model - not ours, and not Google's. Conversations with either are not stored on our servers: the transcript is held in your browser only, and is gone as soon as you reload or close the page. The one thing kept is which language you asked the support chat to answer in, stored in your own browser so it does not ask again.

07Who we share it with

We do not sell personal data and we do not share it for advertising. Data reaches the following companies only because they run part of the service:

CompanyWhat they receive
Cloud hosting and databaseEvery record described in this policy: accounts, stores, products, orders and shopper details.
Content delivery and file storageUploaded files - product photos, store logos, share images, size charts and digital products. Every request to Storzy also passes through hosting and network providers, which process IP addresses to route, serve and protect traffic.
Product analytics (United States)Storefront page views: which shop and page was viewed, when, and a country and approximate city derived from your IP address. Used to show a merchant how many people visited their shop and roughly where from. Your IP address is used for that lookup and is not stored against the visit. Anonymous page views for Storzy's own pages are also counted, with no cookie and no identifier.
Transactional email deliveryRecipient address and message body for transactional email only: sign-in, password reset, and order confirmations.
Payment gatewaysOrder reference, amount and currency, sent only to the gateway your merchant has enabled - you are taken to that gateway by name when you pay. Card details go directly to them and never reach Storzy.
Avatar image generationNothing about you. A default avatar is generated from your account identifier for accounts created with an email address, and your browser requests that image from the provider that draws it.
GoogleName, email address and profile picture, only if you choose to sign in with Google.
Google (Gemini API)What anyone types into either Kiki - the support chat on the Storzy website or in a merchant dashboard, and the design assistant in the storefront editor. The support chat also receives a signed-in merchant's store setup state: store name, plan, whether it is published, product count, domain status and which payment methods are switched on. The design assistant receives a description of the page being edited: store name, design in use, which sections are present and switched on, and how many images have been added - not the page's text, products, images or files. Nothing store-related is sent for a website visitor, who has no account. No shopper details, no order contents and no customer records are sent in any case. Google does not use Gemini API data to train its models.

Merchants who need the specific companies behind these categories - to name them in their own privacy policy or data-processing agreement - can request the current list at hello@storzy.lk.

Beyond those, a merchant sees the details of orders placed with their own shop - that is the point of the shop - and we will disclose data where the law requires it.

08Where it is held

The providers above operate internationally, so your data may be processed outside Sri Lanka. Where an EU or UK transfer needs a legal mechanism, it rests on the transfer terms in those providers' own data-processing agreements.

09How long we keep it

  • Merchant accounts and store content: for as long as the account is open, then deleted within 90 days of a closure request.
  • Orders and their delivery details: seven years, because they are commercial and tax records the merchant is obliged to keep.
  • Storefront visits held by our analytics provider: 12 months, their default retention for event data.
  • Uploaded files: deleted once nothing in the shop refers to them any more. A file uploaded but never saved to anything is deleted when the account is closed.
  • Cart and visit cookies: the expiry shown in the cookie policy.

10Your rights

Under Sri Lanka's Personal Data Protection Act No. 9 of 2022, and under the GDPR where it applies to you, you may ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form.

Email hello@storzy.lk and we will respond within 30 days. There is no charge. If you are asking about an order, tell us which shop you bought from, so we can act with the merchant who controls that record. Some data survives a deletion request where the law requires us to keep it - a completed order's tax record is the usual case, and we will tell you when that applies.

If you think we have handled this badly, you can complain to your data protection authority. In Sri Lanka that is the Data Protection Authority established under the Act.

11Security

Passwords are hashed, never stored in a readable form. Payment gateway credentials a merchant enters are encrypted before they are written down, with a key held outside the database, so a copy of the database alone does not yield them. Traffic is served over HTTPS.

No system is perfect. If a breach affects your data, we will tell you and the relevant authority as the law requires rather than waiting to be asked.

12Children

Storzy is not for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, email us and we will remove it.

13Changes

We update this policy when the product changes. The date at the top is when it last changed substantively. If a change materially affects how we handle your data, we will email account holders rather than quietly reposting the page. Questions go to hello@storzy.lk.