🚀 Storrverse MVP is live — 100% free to start, no credit card needed. Create your store
Legal Document

Privacy Policy

Your trust matters to us. This Privacy Policy explains how Storrverse collects, uses, stores, and protects your information when you use our platform and services.

Version 1.0.0Last updated: May 17, 2026

01 Introduction

Welcome to Storrverse ("we", "us", or "our"). Storrverse is a premier multi-tenant e-commerce infrastructure platform designed specifically for merchants across Africa to build, launch, customize, and scale their online storefronts with zero technical barriers or coding requirements.

We believe that data privacy cannot be an afterthought. This Privacy Notice is written in plain language to explain exactly how we collect, use, process, share, store, and protect personal data across our ecosystem. We are committed to keeping this Privacy Notice in plain accessible language. If any technical term is unclear, you may contact privacy@storrverse.com for a simplified explanation.

Who Does This Notice Apply To?

This Notice applies to all individuals who interact with our ecosystem:

  • Merchants: Business owners, side hustlers, and entrepreneurs who sign up for Storrverse to build an online storefront.

  • Team Members: Invited staff, managers, or employees who have been granted back-office dashboard access by a store owner.

  • Customers: Buyers who visit, place items in a shopping cart, or make purchases from a merchant's storefront powered by Storrverse.

  • Platform Visitors: Anyone browsing our public website (www.storrverse.com) or marketing channels.

03 The Information We Collect

We collect different types of personal data depending on how you engage with our platform:

3.1 Information You Provide Directly to Us

  • Merchant Signup & Onboarding Data: When creating an account, we collect your full name, email address, physical phone number, and account password (stored securely in a cryptographically hashed format).

  • Identity Verification Elements: Our platform tracks security verification values, such as One-Time Passwords (OTPs) sent over email or SMS to verify identity during account onboarding, password resets, or multi-factor authentication (2FA) sequences.

  • Storefront Workspace Settings: Business metadata including your unique Store Name, operational category, business physical address, default currency mappings, timezone preferences, and Tax Identification Number (TIN/ID) for valid round-tax management configurations.

  • Media & Brand Creative Assets: Logos, store banner files, favicons, product demonstration images, or video assets uploaded into our central file service.

  • Back-Office Staff Invitations: When a merchant inputs an invited team member's email address to expand access, our systems log that email alongside the specific system access tier assigned (e.g., Manager, Sales Rep, Support, or Inventory Clerk).

  • End-Customer Purchase Parameters: To process point-of-sale activities on a storefront, the consumer provides full name, email address, active phone number, shipping coordinates, and billing addresses.

3.2 Information Collected Automatically

To monitor uptime, combat fraudulent registrations, and make our mobile and web views fully responsive, we automatically collect analytical data during platform visits:

  • Network Identifiers: IP addresses, approximate localized internet routing data, device models, web browser configurations, and underlying operating system profiles.

  • Behavioral Usage Trail Logs: Direct referral links, internal click pathways, system pages viewed, navigation durations, and background server crash reports.

  • Session State Metrics: We track active items placed within a shopper's cart within localized session storage keys. This keeps custom shopping selections and pricing valid across a brief network timeout loss initiative.

3.3 Payment Processing Mechanics

To keep financial properties secure, Storrverse does not collect or warehouse raw payment card digits, CVVs, or bank routing passwords on our servers.

All payments are managed via tokenized processing integrations with established, certified payment gateways. When you pay for a storefront transaction or software plan tier, our platform intercepts only secure background webhooks returning execution validations, transaction references, billing statuses, and total checkout amounts.

04 Intellectual Property

Storrverse processes your information under transparent use constraints to unlock specific platform features:

  • To Operate Multi-Tenant Architecture: Isolating individual store databases to ensure merchants manage their retail structures independently without data crossover leaks.

  • To Conduct System Access Checkpoints: Sending account creation verification instructions, processing step-up logins, and delivering security OTP notifications to keep management tools safe.

  • To Execute Commercial Calculations: Automating stock tracking counts, verifying real-time inventory balances prior to order updates, running localized VAT tax metrics, and auto-generating receipts.

  • To Route Transactional Notifications: Alerting store owners instantly regarding newly confirmed retail revenue, forwarding low-stock reminders, and sending dispatch records to consumers.

  • To Safeguard System Health: Monitoring application activity anomalies, stopping automated spam, blocking duplicate registration tokens, and conducting safety evaluations.

  • To Manage Content Storage Systems: Saving brand logos and product images safely to cloud systems and optimizing asset loading speeds via Content Delivery Networks (CDNs).

  • To Honor Your Marketing Consent Choices: Sourcing explicit authorization before allowing a merchant or the platform to send automated promotional materials or cart reminders.

  • To Manage Marketing Consent: You can withdraw marketing consent at any time by using the unsubscribe link in emails or adjusting preferences in your dashboard. We maintain audit logs of consent changes to ensure compliance.

06 How We Share Your Information

6.1 Third-Party Service Providers and Microservice Processors

We share data with trusted infrastructure vendors to help deliver the platform:

  • Infrastructure Hosts: Cloud hosting networks (including AWS) to host isolated multi-tenant records securely.

  • Payment Gateways: Paystack and Flutterwave to execute point-of-sale activities.

  • Delivery Partners: Localized logistics APIs (such as GIGL, Kwik, or Sendbox) configured by the merchant to calculate distance fees and deliver packages.

  • Communication Routes: Notification delivery services used to distribute system verification emails, password updates, and automated transactional text messages.

  • Vendor Transparency: For transparency, you may review the privacy policies of our infrastructure partners (e.g., AWS, Paystack, Flutterwave, GIGL, Kwik, Sendbox). These vendors process data under contractual obligations that limit their use strictly to service delivery.

6.2 Platform Transfers Between Merchants and Consumers

When a buyer initiates a checkout purchase on a store, their identity and shipping coordinates are automatically shared with the merchant running that micro-storefront so they can fulfill the order manually and trace purchase histories.

6.3 Legal and Regulatory Disclosures

We may share records if required by courts, tax collectors, or law enforcement instruments, or when necessary to stop fraud, protect public wellness, or secure platform systems.

6.4 Corporate Adjustments

If our business goes through an operational adjustment like a corporate merger, restructure, asset purchase, or complete platform acquisition, user records may transit to the succeeding entity. We will flag this with an electronic notification banner before tracking conditions change.

07 Data Retention & The 30-Day Deactivation Window

We preserve personal data only for the absolute duration necessary to complete operational configurations or satisfy local financial compliance rules.

  • Merchant Workspace Retention: Your operational database profiles remain intact while your store account is active.

  • The Deactivation Clock: If a merchant decides to close their store, they can trigger the deactivation sequence within Settings by typing "DEACTIVATE". Once confirmed, the system immediately pulls the storefront offline. To safeguard your business against catastrophic mistakes and allow for complete account restoration, we hold this deactivated store data in a secure, frozen state for exactly 30 days. If you do not request profile reactivation within this 30-day window, our automated backend systems initiate a permanent, cascading removal loop to completely erase or anonymize your data assets.

  • Consumer Procurement Records: End-customer session data points are preserved under merchant CRM controls. Merchants can use their platform dashboard console tools to soft-archive records, download full data exports, or completely anonymize personal data to surrender GDPR/NDPA consumer requests.

  • Legal Exceptions: Core accounting information, tax history, transaction references, and billing logs are kept for longer periods to satisfy statutory regional accounting parameters.

08 Data Security Architecture

We place institutional defense frameworks around your business and consumer data to prevent data leakage, loss, or unauthorized entry:

  • Multi-Tenant Isolation: Enforcing row-level access structures or separate database storage mapping matrices to ensure no tenant can view or interact with another store's private customer rows.

  • Encryption Protections: Forcing standard TLS cryptographic controls for all storefront routing parameters in transit and advanced database protection configurations for keys resting within our system hosts.

  • Identity Fencing: Restricting management layers using customizable Role-Based Access Control (RBAC) structures and mandatory OTP login verifications to keep unauthorized staff out.

  • Application Log Traces: Maintaining tamper-resistant internal audit history files tracking critical configuration mutations across core services.

09 Your Data Control Rights

Under modern international data laws, you possess comprehensive control options regarding how your identity parameters are used:

  • Right of Access & Portability: You can download a structured copy of your profile metrics or request a complete customer export file in CSV or PDF layout.

  • Right to Rectification: You can modify profile items, change contact configurations, adjust business addresses, and rewrite catalog data entries through your settings page at any point.

  • Right to Erasure (Anonymization): You can request total deletion of your personal history or trigger tools to substitute individual customer lines with anonymized placeholders.

  • Right to Restrict or Object: You can disable tracking features, opt-out of cross-site cookies, or limit processing parameters within your dashboard console tabs.

To execute these privacy choices, reach out directly to privacy@storrverse.com. We evaluate identity tokens and process requests within 30 days.

10 International Data Transfers

Storrverse operates across Africa and relies on secure cloud infrastructure hosted in various global zones. If your data moves outside your country of residence, we maintain safeguards including standard contractual clauses and isolated tenant scoping, to keep your information uniformly protected.

10.1 Destination Jurisdictions

If your data is transferred outside Africa, we will specify the destination jurisdictions (such as the European Union or United States) and apply safeguards including Standard Contractual Clauses, encryption, and strict access controls.

11 Children's Safety

Storrverse does not knowingly target, offer retail store setup infrastructure to, or collect information from minors under the age of 18. If you believe a minor has created an account, alert our privacy desk immediately so we can remove the profile assets safely.

11.1. Age Verification Measures

We use age verification prompts during merchant signup to prevent minors from registering. If we discover that a minor has bypassed these checks, we will suspend the account and notify the guardian or relevant authority.

12 Policy Changes

We may periodically update this notice to reflect system revisions, core feature growth, or new legislation. When we execute material text expansions, we will alter the date at the top of the file and push explicit alerts to your merchant dashboard interface or account email.

13 Your Rights

Under global data protection laws, you maintain the following rights regarding your personal information:

Access

Request a copy of all data stored in our systems.

Correction

Rectify any inaccurate or incomplete personal data.

Erasure

Request permanent deletion of your data logs.

Questions about your privacy?

Our dedicated Data Protection Officer is available for any technical or legal inquiries.