Privacy Policy
Last Updated: August 8, 2026
This Privacy Policy describes how GPT-Ecommerce Inc. ("GPT-Ecommerce," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with the GPT-Ecommerce platform — including merchant dashboards, hosted storefronts, the AI builder, APIs, and all related services (the "Services"). Capitalized terms not defined here have the meanings given in our Terms of Service.
Contents
- Our Two Roles: Controller and Processor
- Information We Collect from Merchants
- Shopper Information We Process for Merchants
- How We Use Information
- AI Features and Your Data
- How We Share Information; Subprocessors
- Cookies, Pixels and Tracking
- Data Retention
- Security
- Your Rights and Requests
- Children
- United States Processing; State and International Notices
- Changes to This Policy
- Contact Us
1. Our Two Roles: Controller and Processor
1.1 For merchant account data, we are the controller. When you sign up for GPT-Ecommerce, use your dashboard, visit our marketing site, or contact us, we decide how and why your personal information is processed, and this Policy applies directly.
1.2 For Shopper data, your merchant is the controller and we are the processor. Personal information that Shoppers submit through a merchant's Store — such as names, emails, addresses, and order details — is collected under the merchant's own privacy policy. We process it on the merchant's behalf, under our Terms of Service and, where required, our Data Processing Addendum. This mirrors Section 14 of our Terms.
1.3 If you are a Shopper with questions about how a store handles your data, contact the merchant operating that store first — they control your data. You may also contact us at legal@gpt-ecommerce.com, and we will refer your request to the relevant merchant and assist them in responding as their processor.
2. Information We Collect from Merchants
2.1 Account information. Name, email address, authentication identifiers, and business details you provide when creating and operating your account, including staff accounts you create and the permissions you assign them.
2.2 Billing information. Plan and subscription details, invoices, usage-based billing records (such as bandwidth, storage, and AI usage counters), and payment method details. Card numbers are collected and stored by our payment processor, not on our servers; we retain only tokens and non-sensitive metadata (such as card brand and last four digits).
2.3 Content and configuration. Your store content, product listings, images and files you upload, custom domains, templates and design choices, custom code and automations, and integration settings (for example, connected advertising or analytics accounts).
2.4 Usage and device information. Log data generated when you use the Services, such as IP address, browser and device information, pages accessed, and timestamps, used for security, debugging, rate limiting, and metering.
2.5 Communications. Messages you send us, support requests, and lead or contact-form submissions on our marketing site.
3. Shopper Information We Process for Merchants
3.1 On behalf of merchants, we process Shopper information submitted through their Stores, which may include: contact details (name, email, phone), shipping and billing addresses, order and payment history, storefront account credentials, gift card and store credit balances, return, repair, and warranty claims (including any photos or files the Shopper attaches), and communications with the merchant.
3.2 We also process technical data generated by Shopper visits — IP addresses, device and browser information, and request logs — to serve storefronts, prevent fraud and abuse, apply rate limits, and meter infrastructure usage billed to the merchant.
3.3 Payment card details entered at checkout are handled by the merchant's payment processor under its own terms and privacy policy; we do not store full card numbers.
3.4 The Services are not designed to process sensitive personal information categories (such as health, biometric, or government identification data), and merchants agree in our Terms not to submit them.
4. How We Use Information
4.1 We use personal information to: (a) provide, operate, secure, and maintain the Services; (b) create and manage accounts and authenticate users; (c) process subscriptions and usage-based billing, including invoicing and collections; (d) provide support and respond to inquiries; (e) send transactional and service communications (such as receipts, billing and budget alerts, security notices, and policy updates); (f) detect, investigate, and prevent fraud, abuse, and security incidents; (g) debug, analyze, and improve the Services, including through aggregated and de-identified data that does not identify you, your Shoppers, or your business; and (h) comply with law and enforce our Terms.
4.2 We do not sell personal information — not yours, and not your Shoppers'. We do not use Shopper data processed for one merchant for any other merchant's benefit or for our own marketing.
5. AI Features and Your Data
5.1 AI Services use your tenant data (such as your store content, prompts, and configuration) only in the context of your own tenant, to fulfill your requests — for example, generating a storefront, analyzing an existing site you provide, or drafting a workflow.
5.2 We do not use your tenant business data — including Shopper data — to train generalized AI models. This is the same commitment made in Section 10.3 of our Terms.
5.3 We use third-party AI providers as subprocessors to run AI features. Inputs are sent to those providers only as needed to generate the requested output, subject to contractual restrictions on their use of the data.
6. How We Share Information; Subprocessors
6.1 We share personal information only with:
- Service providers and subprocessors acting on our instructions to run the platform — including cloud hosting and storage, payment processing and billing, authentication, transactional email delivery, and AI model providers — under contracts limiting their use of the data to providing services to us.
- Third parties you direct us to share with, such as payment processors, financing providers, advertising and analytics platforms, and other integrations you or your merchant enable. Their handling of the data is governed by their own terms and privacy policies.
- Legal and safety recipients, where we reasonably believe disclosure is required by law, legal process, or to protect the rights, safety, or property of GPT-Ecommerce, our merchants, Shoppers, or the public.
- Corporate transaction parties, in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations.
6.2 You may request a current list of our subprocessors by contacting legal@gpt-ecommerce.com.
7. Cookies, Pixels and Tracking
7.1 On GPT-Ecommerce surfaces (our marketing site and merchant dashboard), we use cookies and similar technologies that are necessary to operate the Services — such as session and authentication cookies and security tokens. See our Cookie & Tracking Policy for details.
7.2 On merchant storefronts, cookies are used for essential store functions such as shopping carts, sign-in sessions, and fraud prevention. Merchants may additionally enable advertising and analytics tracking (for example, ad pixels and conversion tracking) for their own Stores; those trackers are enabled by and operated for the merchant, and the merchant is responsible for any notices and consents they require. Data collected by an enabled advertising or analytics platform is also governed by that platform's own privacy policy.
7.3 Most browsers let you control cookies through settings; blocking essential cookies may prevent parts of the Services (such as sign-in or checkout) from working.
8. Data Retention
8.1 We retain merchant account data for as long as your account is active and as needed afterward for legitimate business purposes — including billing and tax records, dispute resolution, security, and legal compliance.
8.2 Shopper data processed for a merchant is retained under the merchant's instructions for as long as the merchant's account holds it, plus lawful backup and archival copies retained for a limited period.
8.3 When an account closes, data export and deletion are handled as described in our Merchant Data Export & Deletion policy and Section 20 of the Terms: you may request an export of your exportable data within 30 days after termination, after which we may permanently delete Your Materials, subject to records we must keep by law.
9. Security
9.1 We use technical and organizational measures appropriate to the nature of the data, including encryption in transit, access controls and permission-scoped staff access, isolated execution environments for merchant custom code, and logging and monitoring for abuse. No system is perfectly secure, and we cannot guarantee absolute security.
9.2 If we become aware of a breach of security affecting personal information we hold, we will notify affected merchants and/or regulators as required by applicable law. Security researchers can report vulnerabilities under our Security & Responsible Disclosure policy.
10. Your Rights and Requests
10.1 Merchants can access and update most account information directly in the dashboard. For other requests — including access to, correction of, export of, or deletion of your personal information — contact legal@gpt-ecommerce.com from your account email. We will verify your identity and respond within the time required by applicable law.
10.2 Shoppers should direct rights requests (access, correction, deletion, opt-out of marketing) to the merchant whose store they used, since the merchant controls that data. Where we receive a Shopper request directly, we will forward it to the relevant merchant and assist as their processor.
10.3 Depending on where you live, you may have additional rights under applicable law, such as the right to know what personal information is collected, to request deletion, to correct inaccuracies, and not to be discriminated against for exercising your rights. We honor these rights as required by the laws that apply to you.
11. Children
11.1 The Services are offered for business use and are not directed to children. You must be at least 18 to hold a GPT-Ecommerce account. We do not knowingly collect personal information from children under 13; if you believe a child has provided us personal information, contact legal@gpt-ecommerce.com and we will delete it.
12. United States Processing; State and International Notices
12.1 GPT-Ecommerce is a United States company and the Services are operated from the United States. If you access the Services from outside the U.S., you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
12.2 For merchants subject to the GDPR or UK GDPR, our Data Processing Addendum governs our processing of Shopper personal data on your behalf, including international transfer mechanisms.
12.3 Residents of U.S. states with comprehensive privacy laws may have specific rights described in Section 10. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined in such laws.
13. Changes to This Policy
13.1 We may update this Policy from time to time. For material changes we will give notice via your dashboard or the email on file before the changes take effect. The "Last Updated" date above reflects the current version. Continued use of the Services after the effective date constitutes acceptance.
14. Contact Us
14.1 Questions, concerns, or requests about this Policy or our data practices can be sent to legal@gpt-ecommerce.com. Written correspondence may be directed to GPT-Ecommerce Inc., Attn: Legal, Tampa, Florida, USA.