This is a draft template prepared for a GDPR-oriented, international/EU customer base. It is not legal advice and must be reviewed and completed by a qualified privacy/data-protection lawyer before publishing, based on your actual data processing activities, tools, and the specific countries you operate in.
Who we are
[Legal company name], [registered address], is the data controller for personal data collected through this store. Contact: [privacy contact email].
What we collect
[List categories actually collected: name, email, shipping/billing address, order history, payment details processed by our payment provider, marketing preferences, device/browsing data via cookies, etc. — confirm against your actual apps/integrations.]
Why we process it
[Map each purpose to a legal basis under GDPR Art. 6, e.g. contract performance for order fulfillment, legitimate interest for fraud prevention, consent for marketing emails.]
Sharing with third parties
[List processors: Shopify, payment providers, shipping carriers, email marketing platform, analytics/ads tools — confirm the actual list.]
International transfers
[Describe safeguards if data leaves the EU/EEA, e.g. Standard Contractual Clauses — confirm with legal counsel.]
Retention
[State how long each data category is kept.]
Your rights
Under GDPR you may have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing, including direct marketing. To exercise these rights, contact [privacy contact email]. You also have the right to lodge a complaint with your local data protection authority.
Cookies
See our Cookie Policy for details on cookies and similar technologies used on this site.