Privacy Policy
Last updated September 2026
This policy explains what we collect and why. We aim to collect only what we need to run your shop and your orders.
What we collect
Account details (your name and email), the content a shop creates (products, photos, posts, pages, hours, address, and phone), and basic analytics about visits to a storefront. When shoppers buy, we store the order (items, totals, the pickup window or delivery address, and the shopper's name, email, and phone) so the shop can fill it. We keep the shop's pickup and delivery settings, subscription status, and Stripe account link.
Signing in
Shop owners sign in with an email and password or a Google account. Shoppers and the phone app sign in with a six-digit code we email you, so there is no password to store. Sign-up, sign-in, and password reset run a Cloudflare Turnstile bot check, which sees the browser request and nothing about your account.
Payments
Stripe handles every payment. A shop's subscription is billed through Stripe, and shopper payments go through Stripe Connect to the shop's own Stripe account. Card details go to Stripe and never touch our servers. We keep the order record and the Stripe ids needed to refund it.
Storefront visits
We count visits to each storefront with a random visitor id stored in your browser. It is not tied to your name or email, and it is used only to count a shopper once and to line up page views with cart adds and orders. We also record the page and where the visit came from (a search engine, a link, or a post). A shop owner's own visits are left out. Visit records are deleted after a year.
Messages
Messages sent through a storefront's chat or contact form are stored along with your name and email so the shop can reply.
Service providers
These companies process data for us under their own terms. Each one gets only what its job needs.
- Stripe: payments, payouts, and subscription billing.
- Cloudflare: stores uploaded photos (R2), runs the Turnstile bot check, and runs our scheduled jobs.
- Resend: sends our email (sign-in codes, receipts, order updates, and shop newsletters), so it receives the address and the message.
- Mux: hosts product videos a shop chooses to upload.
- Expo: delivers push notifications to a shop owner's phone, so it receives the device token and the notification text.
- Axiom: keeps our server logs, which can include request details and error messages.
- Telegram: sends error alerts to the person who runs Meat Tracker. Those alerts carry error details, not customer data.
- Our hosting and database providers.
How we use it
To run your shop, process orders, send the emails and notifications above, and improve the service. We do not sell your personal data.
Cookies
We use essential cookies for sign-in sessions. Your cart and the visitor id live in your browser's storage. We don't use third-party advertising trackers.
Your choices
You can update your details at any time. Shoppers and shop owners can delete their account from settings, or email us at the address on our site and we'll do it. A shop may keep the record of an order you placed for its own books.