Privacy Policy

Last updated: 12 July 2026

What we collect from merchants

When you sign in with Google we receive your email address and name — nothing else. We never request access to your Google Drive files; your product sheet is read only through the public view link you provide. We store your store configuration, orders, and (if you enable notifications) push subscription tokens.

What we process about buyers

When a buyer places an order, the details they enter (name, email, phone, address, note, custom fields) are stored so the merchant can fulfill the order. We process this data on the merchant's behalf; the merchant is the data controller for their buyers. Buyer data is never sold, never used for advertising, and never published — it is visible only to the merchant of that store.

Cookies and analytics

Storefronts set no tracking cookies and load no trackers; store analytics are aggregate and cookieless (page counts, country, referrer — no personal identifiers). The merchant dashboard uses a session cookie strictly for login. This marketing website uses Google Analytics to understand visits.

Service providers

We run on Cloudflare (hosting, database, security). Google provides sign-in and sheet reading. Transactional email, where enabled, is delivered by our email provider. Stripe acts as a sub-processor for merchants who enable card payments: SpreadFront shares the order amount, currency, order reference, and the buyer's email with Stripe to create the checkout session, and receives payment status back; card data is entered only on Stripe's own pages and never touches SpreadFront. Other payments are handled by whatever provider the merchant chose.

Creem (creem.io) is the merchant of record for SpreadFront's own paid plans: when you upgrade, checkout runs on Creem's pages under Creem's privacy policy — Creem collects your billing details and payment method, handles taxes and invoices, and tells us only your subscription status. Your card data never touches SpreadFront.

Retention and your rights

Order data is kept while the store exists so merchants retain their business records. You can request access, correction, or deletion of your data — merchants via the dashboard or contact; buyers should contact their merchant first, or us if that fails, and we will assist in line with applicable law, including the EU General Data Protection Regulation (GDPR), which we treat as our baseline standard.

Security

All traffic is encrypted, secrets are stored in a dedicated secret store, sessions are cryptographically signed, and buyer data is never placed in any public location.

Contact

Privacy questions: contact page.