Shopait
PricingContact
Join early access

On this page

1. Our two roles2. What we collect3. Why we use it and on what basis4. Cookies5. Who we share it with6. Where data is kept and international transfers7. How long we keep it8. Security9. Your rights10. Children11. Automated decisions12. Changes to this policy13. Contact

Legal

Privacy Policy

Draft — effective October 8, 2026

This policy explains what personal data Shopait collects, why, who else handles it, how long we keep it and the choices you have. It covers this website, sign-in and accounts, the merchant admin, the App Store and Theme Store, the developer and partner tools, and the services we run for online stores built on Shopait.

This is a draft. It describes how Shopait works today, written in plain words and not yet reviewed by a lawyer. It will be reviewed — and updated with notice — before Shopait charges its first customer. If anything here is unclear or seems wrong, write to support@shopait.com.

Who operates Shopait

Shopait is operated by Do Xuan Truong, an individual, Vietnam. A company will take over this role once it is registered; we will update this page when it does.

Write to us about anything on this page: support@shopait.com.

1. Our two roles

Shopait is operated by Do Xuan Truong, an individual, Vietnam. A company will take over this role once it is registered; we will update this page when it does.

When we decide why and how data is used, we are the controller. That covers merchants and their staff accounts, partners, developers and affiliates of the platform, visitors of this website, and people who write to us.

When a store built on Shopait collects data about its customers, the store is the controller and we are its processor. We handle that data only to run the store for the merchant, as set out in our Data Processing Addendum. If you bought from a store built on Shopait, the store's own privacy notice applies: please contact the store first. We will help the merchant answer you.

2. What we collect

Accounts and sign-in

  • Name, email address (and a secondary one if you add it), phone number if you give it, language and time zone.
  • Your password, stored only as a salted one-way hash (scrypt); we cannot read it.
  • Two-step verification secrets, passkey public keys and recovery codes (stored hashed).
  • Sign-in sessions and devices: the IP address, the browser and device type, when the session started and was last used — so you can see and end them under Security.
  • Security records: important actions in a store's admin (who, what, when, from which IP address).

Business details, identity checks and billing

  • When selling, receiving payouts or paying requires it: the business's legal name, address and tax number, and its owners' names, contact details, nationality, home address, and identity document numbers or files you upload.
  • If automated identity checks are enabled, a business tax number is looked up in a public register, and for an individual an ID-card photo and a selfie may be passed to an identity-verification provider for matching. The images are passed on and not stored by us.
  • Billing: your plan, invoices, payments and refunds. Card and PayPal details are entered with the payment provider; we keep only a token, the card brand, last four digits and expiry date (or the PayPal account email), never the full card number.

Your store's data (as processor)

  • Whatever a merchant puts in or collects through the store: products, orders, customers and their addresses, carts and checkouts, gift cards, reviews, bookings, marketing consent and the like. See the Data Processing Addendum.

Visitors of stores (as processor)

  • Storefront analytics: a random visitor ID kept in a cookie, the pages viewed, the referring site and campaign tags, device and browser type, and an approximate location (country, region, city) that our network provider derives from the IP address. We do not store the IP address with these records.
  • Where a merchant turns on the consent banner, analytics and marketing tracking wait for the visitor's choice. The banner is off by default; merchants who sell where consent is required (for example the EU or Vietnam) are responsible for turning it on.
  • Apps a merchant installs may add their own tracking pixels; they run in an isolated frame that cannot read the page or its cookies.

This website

  • A cookie that remembers the region and language you chose. No advertising or third-party analytics cookies.
  • Messages you send through the contact form: your name, email, company if given, topic and message. They are emailed to our support mailbox.
  • Our servers' technical logs: IP address, browser, the address requested and the time — used to run and protect the service.

Partners, developers and affiliates

  • Contact details, the legal address and tax or identity number needed for payouts, and the bank details payouts go to.

Email and AI features

  • Delivery reports from our email provider: whether an email was delivered, bounced or marked as spam. An address that bounces permanently or complains is not emailed again.
  • For store emails to customers, opens and clicks are counted for the merchant.
  • When you use an AI feature (the admin assistant, writing or image tools), your request and the store data it needs are sent to the AI provider that answers it.

3. Why we use it and on what basis

PurposeLegal basis (GDPR terms; Vietnamese law has equivalent grounds)
Create and secure your account; run your store and the services you ask forPerforming our contract with you
Bill you, keep invoices and accounting records, verify identity where payment or tax rules require itLegal obligations; contract
Protect the platform: rate limits, spam and fraud prevention, security logs, investigating abuseLegitimate interests (keeping the service safe for everyone)
Answer messages sent through the contact form or by emailLegitimate interests; steps you asked for before a contract
Improve the product from aggregated usageLegitimate interests
Optional features you switch on (AI tools, identity checks, SMS)Contract; consent where the law requires it

We do not sell personal data and we do not use store customers' data for our own advertising.

4. Cookies

WhereWhat it doesHow long
This websiteRemembers your region and language; on the App Store, the store you chose1 year
Accounts and adminKeeps you signed in12 hours
AccountsRecognises a browser you trusted, so sign-in needs no code; remembers accounts used on it30 days
StoresKeeps the cart and session; keeps a customer signed in30 days
StoresRemembers the visitor's consent choice1 year
StoresAnalytics visitor ID (only after consent when the store asks for it)1 year
StoresReferral from an affiliate link; discount link; checkout queueMinutes to 1 year

All are first-party cookies set by Shopait. Most cannot be read by scripts on the page.

5. Who we share it with

  • Service providers that host, deliver or process data for us — hosting, email, content delivery, payments, AI and others listed in the Data Processing Addendum, many of them only if the feature is enabled.
  • Apps you install in your store receive the data you grant them; they are responsible for it under their own terms and privacy policies.
  • Payment providers you or your customers pay with, under their own terms.
  • Authorities, when the law requires it, or to protect people from serious harm.
  • The company that takes over operating Shopait once registered, or a buyer of the business — bound by this policy.

6. Where data is kept and international transfers

Our servers, database and backups are at Amazon Web Services in Singapore (ap-southeast-1). Our network provider (Cloudflare) serves pages from locations around the world, and some providers (for example payment and AI providers) process data in the United States and elsewhere.

Data about people in Vietnam, the European Union and other countries is therefore transferred to Singapore and, for some features, to other countries. We rely on our providers' contractual safeguards (such as standard contractual clauses where they offer them). We are reviewing, with legal counsel, the cross-border transfer requirements of Vietnam's personal data protection law and of the GDPR, and will complete the steps they require before Shopait charges its first customer.

7. How long we keep it

  • Accounts: while the account exists. Sign-in sessions end after 12 hours; trusted browsers after 30 days.
  • Invoices and accounting records: for as long as tax and accounting law requires (often 10 years).
  • Orders a merchant deletes: removed after the record-keeping period of the store's country (10 years by default), counted from the order date.
  • Store customers erased at a merchant's request: personal details are removed 10 days after the request, or 6 months after the customer's last order if that is later; order amounts stay for accounting.
  • Contact messages: in the support mailbox for as long as needed to answer and follow up, reviewed at least once a year.
  • Server logs: a few days to weeks (they are overwritten as they fill). Backups: 14 days, rolling.
  • Email bounce and complaint records: for as long as needed to stop sending to the address.
  • Storefront analytics: we have not yet set an automatic deletion period; we will set one (and state it here) before Shopait charges its first customer.

8. Security

Connections are encrypted (HTTPS with HSTS). Passwords are hashed with scrypt; two-step verification and passkeys are available; secrets kept in the database (such as API keys) are encrypted with AES-256-GCM; sign-in attempts and forms are rate-limited; only the operator has administrative access to the servers. No system is perfectly secure: if a breach affects your data, we will tell you and the authorities as the law requires.

9. Your rights

Depending on where you live — for example under the EU and UK GDPR, Vietnam's personal data protection law and decree, or US state laws — you may have the right to:

  • know what data we hold about you and get a copy;
  • correct it, or have it deleted;
  • restrict or object to some uses, and withdraw consent you gave;
  • receive data you gave us in a portable format;
  • complain to a data protection authority — in Vietnam the Ministry of Public Security, in the EU the authority of your country.

To use a right, write to support@shopait.com from the address on your account (or tell us how to verify you). We answer without undue delay and within the time the law that applies to you sets — for example one month under the GDPR. Today these requests are handled by email: there is not yet a self-service button to delete a merchant account.

Customers of a store should contact the store; merchants can request and erase a customer's data from the admin.

10. Children

Shopait is a service for businesses. It is not meant for children, and you must be an adult able to enter a contract to open an account. If you believe a child has given us personal data, write to support@shopait.com and we will delete it.

11. Automated decisions

We do not make decisions with legal or similarly significant effects about you solely by automated means. Automated checks (spam filters, rate limits, identity matching when enabled) can be reviewed by a person if you ask.

12. Changes to this policy

We will post any change on this page with a new effective date. If a change is material, we will tell account holders by email or in the admin before it applies.

13. Contact

Write to support@shopait.com or use the contact form. We have no postal address open to the public while Shopait is operated by an individual; when a company takes over, its registered address will appear here.

Other policies

Terms of ServiceData Processing AddendumAcceptable Use PolicyTalk to us
Shopait

Products

Pricing

Developers

Developer early access

Account

Join early access

Company

ContactPrivacyTermsData processingAcceptable use
© 2026 Shopait. All rights reserved.

Choose region and language