Privacy Policy
Last updated 10 August 2026.
The short version
We hold your email address, what you asked us to build, and the API credentials you give us for your own Shopify and supplier accounts. We do not sell anything to anyone, and we do not run advertising or analytics profiling on you.
Your store credentials — the important part
To build in your store we hold a Shopify Admin API token and, for dropshipping stores, a CJ Dropshipping API key. These are powerful: the Shopify token can read and change your products, pages, theme and orders.
They are encrypted at rest and stored separately per store. They are used only to carry out what you asked for — building your store, applying your change requests, and placing the supplier orders your shoppers pay for.
You can revoke them yourself at any time, without us, by deleting the app in your Shopify admin or the key in your CJ account. That is the strongest control here and it does not depend on us doing anything.
This service runs on hardware the operator controls rather than a large cloud provider. We think you should know where your credentials physically are.
What else we hold
Your email address and a hash of your password (never the password).
Your briefs and change requests — the text you write to describe what you want — and a record of what was built.
Counts of metered actions (stores built, changes, videos) so plan allowances can be applied, and a payment status. Your card details are handled by Stripe and never reach us.
Server logs, which include IP addresses, kept so failures can be diagnosed.
Who else sees it
Shopify and CJ Dropshipping — your own accounts, where the work happens.
Google (Gemini) — your brief and change requests are sent to a language model to generate the brand, copy and product selection. Do not put anything confidential in a brief.
Stripe — payments, which they handle end to end.
An email provider — for verification, password resets and trial reminders.
Nobody else. We do not sell or share your data, and we do not use it to train anything.
Deleting everything
There is a delete button on your dashboard. It erases your account, your stores' records, your briefs and change history, and the credential files holding your encrypted tokens — not a flag marking them deleted; the rows and the files go.
Your Shopify store and its contents are untouched, because they are yours and always were.
You can also ask us: [email protected]. If you are in the UK or EU you have rights to access, correct, export and erase your data, and to object to processing; the delete button is the fastest route to the last one.
Backups are kept for a short period and then rotate out, so a copy of deleted data may persist briefly in a backup archive before it is overwritten.
Cookies
One cookie, for staying signed in. No advertising cookies, no third-party trackers, and nothing that follows you to other sites — which is why Storecraft has no cookie banner to click.
Contact
Questions, or a request about your data: [email protected]. This service is operated by the operator of this service.
Questions about any of this: get in touch.