Privacy Policy
Your trust matters to us. This Privacy Policy explains how Storrverse collects, uses, stores, and protects your information when you use our platform and services.
On this page
01 Introduction
Welcome to Storrverse ("we", "us", or "our"). Storrverse is a premier multi-tenant e-commerce infrastructure platform designed specifically for merchants across Africa to build, launch, customize, and scale their online storefronts with zero technical barriers or coding requirements.
We believe that data privacy cannot be an afterthought. This Privacy Notice is written in plain language to explain exactly how we collect, use, process, share, store, and protect personal data across our ecosystem. We are committed to keeping this Privacy Notice in plain accessible language. If any technical term is unclear, you may contact privacy@storrverse.com for a simplified explanation.
Who Does This Notice Apply To?
This Notice applies to all individuals who interact with our ecosystem:
Merchants: Business owners, side hustlers, and entrepreneurs who sign up for Storrverse to build an online storefront.
Team Members: Invited staff, managers, or employees who have been granted back-office dashboard access by a store owner.
Customers: Buyers who visit, place items in a shopping cart, or make purchases from a merchant's storefront powered by Storrverse.
Platform Visitors: Anyone browsing our public website (www.storrverse.com) or marketing channels.
02 Who We Are & Our Legal Roles
To understand your privacy rights, it is crucial to understand our legal role under data protection frameworks like the Nigeria Data Protection Act (NDPA) and other regional African data regulations:
A. Storrverse as a Data Controller
We act as the Data Controller for the personal data collected directly to manage your primary relationship with our company. This includes data used to set up merchant profiles, process software subscription updates, optimize platform-wide performance, and manage public website interactions.
B. Storrverse as a Data Processor
When an end-customer visits, fills a cart, or processes a payment transaction on a merchant's individual store (e.g., jovedirect.onstorrverse.com), the merchant acts as the Data Controller. Storrverse acts strictly as a Data Processor, handling the end-customer's retail parameters under the explicit technical direction of the merchant. Customers should consult the specific merchant's independent privacy policy to understand how their storefront operations handle consumer data.
Contact Details
For any inquiries regarding this document or our structural privacy practices, contact us at:
Email: privacy@storrverse.com
Address: BillyRanks Global Limited, 40 Alh. Bashorun Shittu Avenue, Ikosi Ketu, Magodo Phase 2, 100248, Lagos, Nigeria
03 The Information We Collect
We collect different types of personal data depending on how you engage with our platform:
3.1 Information You Provide Directly to Us
Merchant Signup & Onboarding Data: When creating an account, we collect your full name, email address, physical phone number, and account password (stored securely in a cryptographically hashed format).
Identity Verification Elements: Our platform tracks security verification values, such as One-Time Passwords (OTPs) sent over email or SMS to verify identity during account onboarding, password resets, or multi-factor authentication (2FA) sequences.
Storefront Workspace Settings: Business metadata including your unique Store Name, operational category, business physical address, default currency mappings, timezone preferences, and Tax Identification Number (TIN/ID) for valid round-tax management configurations.
Media & Brand Creative Assets: Logos, store banner files, favicons, product demonstration images, or video assets uploaded into our central file service.
Back-Office Staff Invitations: When a merchant inputs an invited team member's email address to expand access, our systems log that email alongside the specific system access tier assigned (e.g., Manager, Sales Rep, Support, or Inventory Clerk).
End-Customer Purchase Parameters: To process point-of-sale activities on a storefront, the consumer provides full name, email address, active phone number, shipping coordinates, and billing addresses.
3.2 Information Collected Automatically
To monitor uptime, combat fraudulent registrations, and make our mobile and web views fully responsive, we automatically collect analytical data during platform visits:
Network Identifiers: IP addresses, approximate localized internet routing data, device models, web browser configurations, and underlying operating system profiles.
Behavioral Usage Trail Logs: Direct referral links, internal click pathways, system pages viewed, navigation durations, and background server crash reports.
Session State Metrics: We track active items placed within a shopper's cart within localized session storage keys. This keeps custom shopping selections and pricing valid across a brief network timeout loss initiative.
3.3 Payment Processing Mechanics
To keep financial properties secure, Storrverse does not collect or warehouse raw payment card digits, CVVs, or bank routing passwords on our servers.
All payments are managed via tokenized processing integrations with established, certified payment gateways. When you pay for a storefront transaction or software plan tier, our platform intercepts only secure background webhooks returning execution validations, transaction references, billing statuses, and total checkout amounts.
04 Intellectual Property
Storrverse processes your information under transparent use constraints to unlock specific platform features:
To Operate Multi-Tenant Architecture: Isolating individual store databases to ensure merchants manage their retail structures independently without data crossover leaks.
To Conduct System Access Checkpoints: Sending account creation verification instructions, processing step-up logins, and delivering security OTP notifications to keep management tools safe.
To Execute Commercial Calculations: Automating stock tracking counts, verifying real-time inventory balances prior to order updates, running localized VAT tax metrics, and auto-generating receipts.
To Route Transactional Notifications: Alerting store owners instantly regarding newly confirmed retail revenue, forwarding low-stock reminders, and sending dispatch records to consumers.
To Safeguard System Health: Monitoring application activity anomalies, stopping automated spam, blocking duplicate registration tokens, and conducting safety evaluations.
To Manage Content Storage Systems: Saving brand logos and product images safely to cloud systems and optimizing asset loading speeds via Content Delivery Networks (CDNs).
To Honor Your Marketing Consent Choices: Sourcing explicit authorization before allowing a merchant or the platform to send automated promotional materials or cart reminders.
To Manage Marketing Consent: You can withdraw marketing consent at any time by using the unsubscribe link in emails or adjusting preferences in your dashboard. We maintain audit logs of consent changes to ensure compliance.
05 Legal Bases for Data Processing
We process your personal information using established legal bases defined under African regional data legislation:
Performance of a Contract: The data processing is strictly required to provide the core services you requested. This covers validating account creations, launching independent storefront names, calculating user checkouts, and facilitating inventory management tools.
Legitimate Interests: Processing required for reasonable business safety, provided it doesn't override your fundamental rights. This covers stopping network threats, verifying application performance, processing automated updates, and running localized performance metrics.
Compliance with Legal Obligations: Maintaining financial receipts, preserving historical transaction databases, calculating correct taxation liabilities, or satisfying law enforcement parameters.
Consent: When you explicitly select an opt-in toggle to receive platform newsletters or localized brand updates. You may withdraw this processing consent at any standard interval through direct link prompts.
06 How We Share Your Information
6.1 Third-Party Service Providers and Microservice Processors
We share data with trusted infrastructure vendors to help deliver the platform:
Infrastructure Hosts: Cloud hosting networks (including AWS) to host isolated multi-tenant records securely.
Payment Gateways: Paystack and Flutterwave to execute point-of-sale activities.
Delivery Partners: Localized logistics APIs (such as GIGL, Kwik, or Sendbox) configured by the merchant to calculate distance fees and deliver packages.
Communication Routes: Notification delivery services used to distribute system verification emails, password updates, and automated transactional text messages.
Vendor Transparency: For transparency, you may review the privacy policies of our infrastructure partners (e.g., AWS, Paystack, Flutterwave, GIGL, Kwik, Sendbox). These vendors process data under contractual obligations that limit their use strictly to service delivery.
6.2 Platform Transfers Between Merchants and Consumers
When a buyer initiates a checkout purchase on a store, their identity and shipping coordinates are automatically shared with the merchant running that micro-storefront so they can fulfill the order manually and trace purchase histories.
6.3 Legal and Regulatory Disclosures
We may share records if required by courts, tax collectors, or law enforcement instruments, or when necessary to stop fraud, protect public wellness, or secure platform systems.
6.4 Corporate Adjustments
If our business goes through an operational adjustment like a corporate merger, restructure, asset purchase, or complete platform acquisition, user records may transit to the succeeding entity. We will flag this with an electronic notification banner before tracking conditions change.
07 Data Retention & The 30-Day Deactivation Window
We preserve personal data only for the absolute duration necessary to complete operational configurations or satisfy local financial compliance rules.
Merchant Workspace Retention: Your operational database profiles remain intact while your store account is active.
The Deactivation Clock: If a merchant decides to close their store, they can trigger the deactivation sequence within Settings by typing "DEACTIVATE". Once confirmed, the system immediately pulls the storefront offline. To safeguard your business against catastrophic mistakes and allow for complete account restoration, we hold this deactivated store data in a secure, frozen state for exactly 30 days. If you do not request profile reactivation within this 30-day window, our automated backend systems initiate a permanent, cascading removal loop to completely erase or anonymize your data assets.
Consumer Procurement Records: End-customer session data points are preserved under merchant CRM controls. Merchants can use their platform dashboard console tools to soft-archive records, download full data exports, or completely anonymize personal data to surrender GDPR/NDPA consumer requests.
Legal Exceptions: Core accounting information, tax history, transaction references, and billing logs are kept for longer periods to satisfy statutory regional accounting parameters.
08 Data Security Architecture
We place institutional defense frameworks around your business and consumer data to prevent data leakage, loss, or unauthorized entry:
Multi-Tenant Isolation: Enforcing row-level access structures or separate database storage mapping matrices to ensure no tenant can view or interact with another store's private customer rows.
Encryption Protections: Forcing standard TLS cryptographic controls for all storefront routing parameters in transit and advanced database protection configurations for keys resting within our system hosts.
Identity Fencing: Restricting management layers using customizable Role-Based Access Control (RBAC) structures and mandatory OTP login verifications to keep unauthorized staff out.
Application Log Traces: Maintaining tamper-resistant internal audit history files tracking critical configuration mutations across core services.
09 Your Data Control Rights
Under modern international data laws, you possess comprehensive control options regarding how your identity parameters are used:
Right of Access & Portability: You can download a structured copy of your profile metrics or request a complete customer export file in CSV or PDF layout.
Right to Rectification: You can modify profile items, change contact configurations, adjust business addresses, and rewrite catalog data entries through your settings page at any point.
Right to Erasure (Anonymization): You can request total deletion of your personal history or trigger tools to substitute individual customer lines with anonymized placeholders.
Right to Restrict or Object: You can disable tracking features, opt-out of cross-site cookies, or limit processing parameters within your dashboard console tabs.
To execute these privacy choices, reach out directly to privacy@storrverse.com. We evaluate identity tokens and process requests within 30 days.
10 International Data Transfers
Storrverse operates across Africa and relies on secure cloud infrastructure hosted in various global zones. If your data moves outside your country of residence, we maintain safeguards including standard contractual clauses and isolated tenant scoping, to keep your information uniformly protected.
10.1 Destination Jurisdictions
If your data is transferred outside Africa, we will specify the destination jurisdictions (such as the European Union or United States) and apply safeguards including Standard Contractual Clauses, encryption, and strict access controls.
11 Children's Safety
Storrverse does not knowingly target, offer retail store setup infrastructure to, or collect information from minors under the age of 18. If you believe a minor has created an account, alert our privacy desk immediately so we can remove the profile assets safely.
11.1. Age Verification Measures
We use age verification prompts during merchant signup to prevent minors from registering. If we discover that a minor has bypassed these checks, we will suspend the account and notify the guardian or relevant authority.
12 Policy Changes
We may periodically update this notice to reflect system revisions, core feature growth, or new legislation. When we execute material text expansions, we will alter the date at the top of the file and push explicit alerts to your merchant dashboard interface or account email.
13 Your Rights
Under global data protection laws, you maintain the following rights regarding your personal information:
Access
Request a copy of all data stored in our systems.
Correction
Rectify any inaccurate or incomplete personal data.
Erasure
Request permanent deletion of your data logs.
Questions about your privacy?
Our dedicated Data Protection Officer is available for any technical or legal inquiries.