COMMERCE / PRIVACY
Privacy notice
The store is designed to minimise customer and payment data, keep payment details with the selected provider, and fail closed until operational, tax, policy, and data-processing checks are approved.
LEGAL STATUS: DRAFT — NOT LEGAL ADVICE — REVIEW REQUIRED BEFORE PRODUCTION CHECKOUT.
Controller
ZeroDev LLC operates this store. The final controller identity, registered address, privacy contact, company registration, markets, and effective date remain [CONFIRM LEGAL ENTITY NAME], [CONFIRM REGISTERED ADDRESS], [PRIVACY_EMAIL], [COMPANY_REGISTRATION_NUMBER], [MARKETS_AND_LANGUAGES], and [POLICY_VERSION_AND_EFFECTIVE_DATE] until confirmed.
What we process
Depending on the offer, the system may process enquiry details, design metadata, product and variant references, order references, payment status, bounded accounting facts, support messages, delivery information, security logs, and supplier operational references. Complete payment-card data is not stored by this application. The final retention schedule is [CONFIRM DATA RETENTION].
Recipients and processing roles
Depending on the selected route, recipients may include Shopify for catalog, storefront, order, shipping, or fulfillment visibility; Stripe for hosted payment and, where approved, Connect; an approved AI or MCP provider for a rights-aware design workflow; hosting and database services; and an approved print or delivery provider. The final notice must name actual providers, purposes, subprocessors, locations, lawful bases, controller/processor roles, and transfer safeguards. No supplier receives more customer data than it needs for an accepted order.
AI design processing
Design exploration is preview-first. Do not send payment information, shipping addresses, supplier KYC or banking information, private support messages, secrets, or unnecessary personal data to an AI provider. The final notice must identify [CONFIRM AI PROVIDER], processing purpose, retention, international-transfer safeguards, human review, deletion route, and the data-processing contact.
Rights, security, and complaints
Subject to applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent where consent is the legal basis. Contact [PRIVACY_EMAIL] first. You may also contact the relevant supervisory authority, including the Irish Data Protection Commission where applicable. Security controls include hosted checkout, webhook verification, bounded request bodies, minimized ledgers, restricted secrets, and manual review for mismatches.
This notice is not approved for production. Replace every placeholder and obtain qualified privacy/data-processing review before enabling the relevant provider or checkout route.