StoresOmni

Websites, commerce, and operations in one workspace.

Build the public site, run the work behind it, and keep merchant control explicit.

Product

  • Features
  • Pricing
  • Theme showcase
  • Store manager

Support

  • Contact
  • Merchant login
  • Create an account

Legal & privacy

  • Privacy policy
  • Terms of service
  • Data processing addendum
  • Subprocessor list
  • Cookie policy

© 2026 StoresOmni. All rights reserved.

StoresOmni
FeaturesPricingShowcaseContact Us
Log InStart Free Trial

Privacy Policy

How StoresOmni LLC processes platform identity, merchant, customer, commerce, analytics, and AI information.

Last updated
October 3, 2026
Effective date
October 3, 2026

On this page

1. Scope and definitions2. StoresOmni and Merchant privacy roles3. StoresOmni identities and separate store relationships4. Sources of information5. Categories of Personal Data6. Purposes and legal bases7. Communications, automation, and analytics8. AI providers and data handling9. Cookies and device storage10. Recipients and disclosures11. International processing12. Security and incidents13. Retention criteria and temporary records14. Store closure, identity deletion, and retained records15. Privacy rights and requests16. Children17. Changes and related documentsContact StoresOmni
Contact StoresOmni

1. Scope and definitions

This Privacy Policy describes personal data processing by StoresOmni LLC (StoresOmni, we, us, or our) in connection with our website, software, account infrastructure, and related Services. Personal Data means information about an identified or identifiable person or other information protected by applicable privacy law. Merchant means an independent person or business operating a website or storefront using StoresOmni. Customer includes a Merchant's shoppers, visitors, and other storefront users. Merchant Customer Data means Personal Data we process on a Merchant's behalf to deliver its storefront and commerce services; references to Customer Data in our Data Processing Addendum mean the same information.

This Policy covers Merchants, account owners and team users, registered Customers, guests, visitors, and people who contact us. Available processing depends on the features used, Merchant configuration, plan, location, and connected providers. A Merchant's own privacy policy governs its independent collection and use of its store's customer information. Read that policy alongside this one; StoresOmni account services do not make StoresOmni the seller of the Merchant's products.

2. StoresOmni and Merchant privacy roles

StoresOmni acts as an independent controller, or equivalent business under applicable law, for maintaining StoresOmni identities and customer authentication; Merchant and platform account administration; subscription/billing administration; platform support and communications; authentication and security; service operations, diagnostics and product analytics; fraud/abuse prevention; legal compliance; and protecting or enforcing our rights. We determine the purposes of that processing and handle related privacy requests.

For Merchant Customer Data used to host storefronts, maintain store-specific profiles and relationships, process orders, provide Merchant-customer communications, and deliver configured commerce functions, we generally act as the Merchant's processor or service provider under its instructions and the applicable DPA. Merchants determine their business purposes, customer promises, policies, marketing, and applicable legal basis and retention duties. Our operational role does not transfer those duties to us.

A dataset may serve more than one lawful function: for example, a transaction may be processed for a Merchant's order workflow and limited metadata may also support StoresOmni security or accounting. These roles depend on the particular purpose; independent platform processing is not a blanket permission to repurpose Merchant Customer Data. Applicable processor/service-provider restrictions continue to apply where required by law.

3. StoresOmni identities and separate store relationships

Registered storefront customer accounts use a StoresOmni identity managed and authenticated by StoresOmni LLC through Firebase authentication. Choosing to create an account for a Merchant separately establishes a customer relationship with that store. An existing identity can be used with other StoresOmni-powered stores, with a separate relationship for each applicable store. Merchants receive appropriate profile, order, communication, and activity information for their own authorized store relationship. Creating a relationship does not give a Merchant unrestricted access to your other store relationships, orders, chats, or activity.

Your platform sign-in information, verification status, and profile details support the shared identity. Updating shared identity details may affect how you sign in or identify yourself across the Services; store transaction snapshots and Merchant-held information need not change with your profile. A Merchant account, store-team access, administrator capability, and customer relationship may coexist without automatically granting one another's permissions. Signing in to a new store checks access; it does not automatically establish a customer relationship without the chosen creation/joining action.

Guests may check out or use order access without registering. Necessary anonymous or temporary access, order links, or device-held order references may be used to support these functions. Where supported and verified, guest orders, chats, or access may be connected to your registered identity for the applicable store. This does not transfer another Merchant's records or another person's orders. Protect order access links and pickup verification codes; they may provide access to an order or assist collection.

4. Sources of information

We receive information you provide during account creation, enrollment, checkout, uploads, forms, support, chat, or use of the Services; information Merchants submit about their businesses and Customers; information from authentication providers you choose, including Google where enabled; and transaction, refund, dispute, tax, delivery, or integration information returned by connected providers. Browser/device requests, consent controls, authentication events, webhooks, and service operations also generate information. An integration's permissions and purpose determine what it supplies; we do not obtain unrelated records merely because a provider connection exists.

5. Categories of Personal Data

Identity and account information may include names, contact details, account identifiers, authentication information, verification status, chosen sign-in provider, account preferences, capabilities and store relationships, and evidence of Terms acceptance such as policy versions, account identifier, timestamp, and signup context. Merchant/business information may include business and billing details, domains, team invitations and roles, plan and entitlement state, tax configurations and registration information, and integration authorizations.

Commerce information may include products and variants, carts, orders and transaction history, amounts and currencies, customer/contact profiles, shipping or billing addresses, phone numbers, fulfillment and tracking details, local/scheduled pickup information and verification codes, receipts, cancellations, returns, refunds, disputes, and applicable digital-product files or download/access records. Payment and tax metadata may include provider/payer identifiers, tokens or references, capture/refund status, costs, tax location, tax-ID evidence, calculation and reversal records, and reconciliation information. Full payment card numbers are handled through payment-provider interfaces rather than ordinary StoresOmni storage.

Communications and content may include support messages, Merchant-customer chats, contact submissions, transactional email content and delivery events, uploaded media/files, website/product content, and integration or webhook information. AI information, where invoked, may include prompts, relevant authorized workspace context and tool results, attached or reference images, outputs, proposals, approvals, change/undo history, and usage/cost records. Publicly published content can be seen and copied by others.

Technical information may include IP/network signals, device and operating system information, request/browser information available to our infrastructure, referring pages, timestamps, security/authentication events, consent settings, local/session identifiers, error and operational logs, and audit events. Consented storefront analytics may include pages and product views, cart and checkout progression, session/device categories, order attribution, and geographic signals when supplied by configured infrastructure. Commerce reports also use order/payment/fulfillment records, independently of optional browsing analytics. This does not mean every category is collected in every interaction.

Ordinary Services do not require special-category or similarly sensitive information such as health, biometric, or highly private personal records. Do not submit unnecessary sensitive data, passwords, payment secrets, or information you lack authority to provide, including in AI prompts or uploaded images. Merchant-configured content may contain information we cannot determine in advance; Merchants remain responsible for its lawful submission.

6. Purposes and legal bases

We use information to authenticate and manage identities; establish and maintain requested store relationships; host and customize websites; support checkout, order access, digital delivery, fulfillment, pickup, returns/refunds, and notifications; operate configured payments, tax, and integrations; administer plans, charges and entitlements; provide support; prevent fraud and misuse; secure and troubleshoot the Services; maintain operational and financial evidence; comply with law; and enforce agreements or defend claims. AI processing occurs for authorized AI requests and tools. Analytics and aggregated information help Merchants understand commerce and help us improve reliability and product operation.

Where a legal basis is required for our controller processing, we rely as appropriate on contract performance or steps requested before a contract; legal obligations; legitimate interests in providing, securing, supporting and improving the Services, preventing abuse and defending rights, balanced against individuals' rights; or consent for optional tracking and communications where required. Required information is necessary for the applicable account or transaction function; declining it may prevent that function. Withdrawal of consent does not affect earlier lawful processing. Merchants determine the legal basis for their instructed processing; acceptance of platform Terms does not replace required privacy or marketing consent.

7. Communications, automation, and analytics

We send account verification, security, support, billing, and other service messages. Merchant order events may generate standardized transactional messages such as confirmations, receipts, shipping/pickup, returns or refunds, and customer-account welcomes. The Merchant may not edit every standardized template, but remains responsible for the transaction and supplied details. Where Merchant-configured messaging is available, the Merchant controls its authorized content, recipients, and purpose and must meet privacy and electronic communications requirements. Email providers may process message content, addresses, and delivery metadata to deliver and troubleshoot messages. Creating a store relationship is not consent to promotional messages.

Optional storefront browsing/journey analytics requires analytics consent and enabled tracking. Withdrawal stops that tracking and removes the related browser identifiers; it does not automatically erase previously received events or financial order records. Authenticated customer attribution is tied to an active relationship with the applicable store. Shared-device sign-out or identity changes may rotate analytics sessions. Merchants' sales, product, shipping, fee, and customer reports are subject to store permissions; shared authentication does not authorize reports about unrelated stores.

Automated systems support security checks, verification, rate/resource controls, payment and webhook workflows, inventory/fulfillment calculations, and configured tools. Their results may lead to additional verification or restrictions. AI proposals and business insights are not guaranteed accurate and do not replace professional advice. Where applicable law grants rights concerning solely automated decisions with legal or similarly significant effects, contact privacy@storesomni.com to request applicable safeguards or review.

8. AI providers and data handling

When OpenAI-backed assistance, site generation, or image features are configured and an authorized user invokes them, we may send OpenAI the prompt, relevant limited workspace context and tool results, and attached or reference images needed for the task. Context is selected according to the authorized functionality rather than giving the provider unrestricted platform access. Outputs and operational records may be retained by StoresOmni as described below. Merchants must review outputs and avoid supplying unnecessary Personal Data.

Our OpenAI Responses requests disable provider application-state storage for those responses. This is not a zero-retention guarantee. Under OpenAI's API data controls, API data is not used to train models unless the organization opts in; default abuse-monitoring logs may be retained for up to 30 days, or longer when legally required or reasonably necessary to protect services or others from harm. Image and other endpoint handling and approved organizational controls can differ. We do not represent that StoresOmni has zero data retention approval, a particular processing region, or special provider settings beyond those stated. Applicable providers and material changes are disclosed through our Subprocessor and Service Provider List.

9. Cookies and device storage

Authentication, checkout, cart/order access, consent memory, and security use necessary cookies or similar browser storage. Preferences and optional analytics use storage as described in our Cookie Policy. Platform and storefront consent controls default optional categories off and let you change or withdraw choices on the applicable site. Your choices are browser/site-specific. StoresOmni does not currently automatically recognize Global Privacy Control signals; use the available preference controls or contact privacy@storesomni.com for applicable privacy requests.

10. Recipients and disclosures

Service providers support hosting/content delivery, Google/Firebase identity, database and storage, scheduled/operational infrastructure, configured AI, email delivery, routing, and other operations. They receive data needed for their functions. The provider list distinguishes our service providers/subprocessors from Merchant-authorized integrations and providers with independent roles, and explains conditional use. Not every provider receives every user's information.

Merchants and authorized team users receive information relevant to their own store and permissions. Connected payment and tax providers, including PayPal, Stripe/Stripe Connect, Stripe Tax, and Quaderno where configured, may receive account, customer/location, transaction, refund, and compliance information. They may independently process data for their own payment, fraud, regulatory, tax, and contractual duties under their own notices. Other Merchant-authorized integrations receive data according to the authorized function; their own practices apply outside our instructions.

We may disclose information when legally required or reasonably necessary for valid legal process, security, fraud prevention, rights/safety protection, agreement enforcement, or claims. Business reorganizations, financing, mergers or asset transfers may involve appropriate disclosure or transfer, subject to applicable privacy duties. Public Merchant content, including business details, pages and uploaded media selected for publication, is available to visitors and may be indexed or redistributed independently.

StoresOmni does not sell Personal Data for money or use Merchant Customer Data for cross-context behavioural advertising on its own behalf. Optional marketing controls do not imply an active advertising network. Merchant-added tools may have different practices and legal sale/sharing definitions. Where applicable, you can exercise sale/sharing, targeted-advertising, or other opt-out rights through the relevant Merchant or privacy@storesomni.com, according to the processing role. We use aggregated or appropriately de-identified information for reports and improvement, maintain it in that form, and do not attempt re-identification except where legally permitted for assessing de-identification protections.

11. International processing

StoresOmni is based in the United States. Data may be processed in the United States and other jurisdictions where we or relevant providers operate, whose laws may differ from your jurisdiction. No particular residency location is promised unless expressly agreed in writing. Restricted international transfers require a lawful basis and, where required, appropriate safeguards such as an applicable adequacy decision or separately established contractual transfer mechanism. Our DPA explains the transfer obligations for Merchant Customer Data; this Policy does not itself execute standard contractual clauses or assert certification under a transfer framework. Contact privacy@storesomni.com for applicable transfer information and available safeguards, subject to lawful confidentiality limits.

12. Security and incidents

We use measures designed to protect data appropriate to the Services and processing risk. These include authenticated and store/role-scoped access, restricted server-side handling of privileged operations and credentials, protected transport, private-file access controls where appropriate, verified order access and provider events, and operational/audit records and abuse controls. Infrastructure providers supply relevant storage and transport protections. Merchants must secure their own accounts, devices, integrations, and exported data.

No transmission, system, or storage method is completely secure. We do not promise absolute protection, incident-free operation, recovery of every file, or a certification merely because a provider maintains one. We investigate relevant incidents, take reasonable mitigation steps, and provide legally required notifications. For Merchant Customer Data breaches, we notify the affected Merchant without undue delay as required by the DPA. Report concerns to security@storesomni.com.

13. Retention criteria and temporary records

We retain data as reasonably necessary for the described purposes, taking account of the type and sensitivity, active accounts/store relationships, Merchant instructions and agreements, transaction and business evidence, support, fraud/security, law, tax/accounting, disputes, enforcement, legal holds, deletion requests, and necessary recovery or backup handling. No universal retention period applies. Media and digital files may remain while used by a Merchant's content or orders; deletion and orphan-file cleanup depend on the relevant lifecycle. Provider-held data follows the provider's independent obligations and controls.

Omni temporary controls, where enabled, give uploaded conversation images and site-builder reference images a 24-hour availability window and may consume them earlier after use. Private product proposals and generated review images are assigned seven-day expiry; conversation history expires after 30 days of inactivity; ordinary approval, reversible storefront change history, and business/financial proposal records are assigned 30-day expiry; and run evidence and critical-action confirmation, event, and receipt records are assigned 90-day expiry. Brief action approval windows can end sooner than record retention. Saved/published content or media adopted into Merchant content has its own lifecycle and is not governed by the temporary review window. Raw storefront analytics events are assigned 30-day expiry; aggregates and transaction records can remain longer according to their purposes.

Expiry or loss of application access is distinct from physical deletion. Background cleanup, storage or database expiry processing, recovery copies, and lawful holds may delay removal; these intervals do not promise instantaneous erasure from every system or provider. Operational usage/cost, billing, support, audit, and legal evidence may be retained according to its separate purpose. Backups or recovery copies, where maintained, may persist until their applicable lifecycle ends and remain subject to appropriate access restrictions. We do not promise a fixed backup rotation or post-trial deletion period.

14. Store closure, identity deletion, and retained records

The customer account control closes your relationship with the specified store. It marks that relationship closed and may retain profile, chat, order, payment and other records needed for lawful purposes. It does not delete other store relationships. The underlying authentication identity may be removed when no other retained merchant account, active store relationship, administrator or team capability requires it; otherwise it remains. Closing a relationship does not cancel an order, settle a dispute, or erase Merchant or provider transaction records.

The store closure control does not provide global identity deletion everywhere. To request broader deletion or review of your StoresOmni identity and platform data, contact privacy@storesomni.com. We assess active roles, legal obligations, the relevant controller/processor role, and verification needs. Direct requests concerning a Merchant's independent records to that Merchant; we assist as appropriate under the DPA. Merchant account closure uses its applicable account lifecycle and may involve subscription cancellation, closing stores, cleanup, and retention decisions. Neither type of closure promises immediate erasure from logs, backups, third-party systems, or lawfully retained records.

15. Privacy rights and requests

Depending on applicable law and our processing role, you may have rights to know or access data and recipients; correct inaccurate information; request deletion, restriction, or portability; object to processing; withdraw consent; opt out of sale/sharing, targeted advertising or certain profiling where relevant; limit legally covered uses of sensitive data; and seek review of certain automated decisions. Rights are subject to lawful limitations, including transaction, security and legal recordkeeping requirements. We do not discriminate for exercising legally protected rights.

Send requests about StoresOmni identities, authentication, billing, security, or our other controller processing to privacy@storesomni.com. You may use available account/profile and consent controls. We verify identity and, where applicable, an authorized representative's authority using information reasonably needed for the request. We respond within applicable statutory periods; appeals where provided by law may be sent to the same address. If a request concerns processing controlled by a Merchant, we may refer it to that Merchant and assist with its verified instructions.

Where applicable, individuals in the EEA, United Kingdom, or Switzerland may also complain to the relevant data protection authority, including the UK Information Commissioner's Office. California and other U.S. state residents have the rights their applicable laws provide, including relevant access, correction, deletion, opt-out and appeal rights. These statements do not claim every jurisdiction's law applies to StoresOmni or every interaction. You may contact us for information specific to your request.

16. Children

StoresOmni registered accounts require adulthood as set out in our Terms. Our platform account services are not directed to children under 13 and we do not knowingly seek Personal Data from children in violation of applicable law. If you believe a child has provided information unlawfully, contact privacy@storesomni.com so we can investigate and take appropriate action. Independent Merchants determine the audiences for their storefronts and must comply with children's privacy and age-related rules applicable to their offerings; they must not instruct prohibited processing through StoresOmni.

17. Changes and related documents

The effective/last updated date identifies this Policy's revision. We may update it as Services, processing, or law changes and provide additional notice or seek consent for material changes where required. Our Terms, Cookie Policy, DPA, and provider list provide related information. Merchant storefront policies describe the Merchant's separate practices. Questions and privacy requests may be directed to the contacts below.

Contact StoresOmni

StoresOmni LLC, a New Mexico limited liability company. Legal and notices address: 1209 Mountain Road Pl, STE N, Albuquerque, NM 87110, United States.

storesomni.com

Support: support@storesomni.com · Privacy: privacy@storesomni.com · Security: security@storesomni.com · Legal: legal@storesomni.com · Copyright: copyright@storesomni.com

Terms of Service · Privacy Policy · Cookie Policy · Data Processing Addendum · Subprocessors and Service Providers