WebStore uses the minimum data needed to provide the service, protect accounts, fulfil requests and improve consented experiences. Stores also receive the information they need to serve their customers.
Who this policy covers
This policy covers visitors, consumers, store owners and staff, partner and supplier users, administrators, and people who contact WebStore. Storefront notices may add information for a particular store or service.
Who is responsible
WebStore acts as controller for platform accounts, security, support and platform analytics. Each store is normally responsible for the customer data it receives to handle its own orders, reservations, delivery, returns and communications. Store contact details are shown on its storefront or order information.
Data we process
Depending on the features used, data can include names, phone numbers, email addresses, account and language preferences, saved addresses, precise location shared on request, orders, reservations and payment proof, messages, reviews, loyalty activity, storefront and staff records, device/session data, consent choices, security events and privacy requests.
Recruitment and application data
Public vacancies contain role and business information supplied by the business. Applications contain the candidate details, answers and status history needed to review that application.
CVs and requested photos are stored privately, scanned before use and available only to the applicant and authorised users of the relevant business. Every document download is recorded in the audit log.
Unused uploads are removed automatically. Attached application documents are retained for no more than 730 days unless earlier deletion is required or a lawful retention obligation applies.
Where data comes from
We receive data directly from users and stores, from devices when a person grants permission, from activity generated while using the service, and from public business information supplied for a storefront. We do not silently request precise device location.
Purposes and legal bases
We process data to provide accounts and marketplace functions, route orders and reservations, deliver requested messages, support users, secure the service, keep required records and improve the product. The applicable basis is performance of a contract or requested pre-contract steps, compliance with law, legitimate interests such as security and service reliability, or consent for optional analytics, marketing and precise location.
Cookies, local storage and analytics
Essential cookies and browser storage keep sessions, security tokens, locale and preferences working. Optional product analytics are recorded only for the relevant consent category. Analytics rules prohibit raw passwords, one-time codes, full contact details, addresses, payment proof and free-text message content.
International transfers
Some providers or recipients may operate outside the European Economic Area. Where data protection law requires it, transfers must rely on an adequacy decision, contractual safeguards or another valid transfer mechanism. Provider-specific information can be requested through the privacy contact route.
Retention
Retention follows the purpose and record type. Login-attempt records expire after 24 hours; audit, health and WhatsApp delivery logs are generally kept for up to 90 days; background jobs for up to 30 days; and consented analytics or operational events for their registered period, generally 90 days to two years. Account, store, order, reservation and payment-proof records remain while needed for service, transaction integrity, legal duties or claims. Account deletion removes the account and anonymises completed transactional history where deletion would break required records.
Your privacy rights
Subject to applicable law, people may request access, correction, deletion, restriction or portability, object to certain processing, and withdraw consent without affecting earlier lawful processing. Consumers can export data and request account deletion from their account. A complaint may also be submitted to the competent data protection authority.
Location and public storefront data
A precise consumer location is used only after an explicit request and permission, for example to find nearby stores or meet delivery requirements. Business names, logos, product information, opening hours, addresses, public contact details, social links and store media are intentionally public and can appear in search-engine structured data.
Security and children
WebStore uses role-based access, protected sessions, rate limits, audit trails and restricted access to private files such as payment proof. No online service is risk-free. The service is not intended for children who cannot lawfully create an account or place an order without a parent or guardian.
Changes and contact
Material policy changes will be published here with a new effective date and, where appropriate, an in-product notice. Use the privacy request form for questions or rights requests. WebStore may verify identity before disclosing or changing personal data.