Draft policy
Privacy
This draft identifies expected data flows. It is not a final privacy policy and does not make claims about services that are not configured.
Information expected to be collected
At checkout, Stripe is expected to collect payment, contact, billing, and shipping information. The storefront expects to retain order contact, delivery, totals, and fulfilment state in Supabase. Card details are handled by Stripe-hosted Checkout and are not stored by this application.
Purposes
Expected uses include completing purchases, arranging delivery, preventing fraud, meeting legal/accounting obligations, responding to inquiries, and maintaining site security.
Service providers
Expected providers are Vercel for hosting, Supabase for database/auth/storage, Stripe for payment processing, and a future approved email-delivery provider. Their final regions, subprocessors, and retention terms must be reviewed.
Contact and rights
A real privacy contact, business identity, retention schedule, cookie/analytics position, and jurisdiction-specific access or deletion process must be added before launch.