Skip to content
Legal

Privacy Policy

How litecommerce handles personal data it controls — tenant account holders and prospects.

Draft scaffold — not a legal document

This page is a placeholder. It has not been reviewed by counsel, it is not in effect, and it creates no rights or obligations for anyone. It lists what the Privacy Policy will need to cover — the operative language is deliberately absent.

Nothing here may be relied on, quoted, or presented to a customer as litecommerce's terms.

litecommerce's role

litecommerce is the controller for tenant-account and prospect data. For end-customer data a tenant loads into the platform, litecommerce is a processor and the DPA governs instead.

Sections this document must cover

Scope only. These describe what each section has to establish, not what it will say.

  1. 1. Scope — what this policy does and does not cover

    Must state clearly that this covers data litecommerce controls, and that a shopper's relationship is with the tenant, not litecommerce. The most common reader confusion is a shopper landing here expecting their store's policy.

  2. 2. Personal data collected

    Account registration data, signup and contact-form submissions, billing and tax-location data, authentication events, request metadata and logs.

  3. 3. Purposes and legal bases

    Per category. GDPR requires the legal basis stated, not just the purpose.

  4. 4. Bot protection disclosure

    Cloudflare Turnstile runs on public forms and processes request data for abuse prevention. Disclose it explicitly.

  5. 5. Retention

    Per category, with actual periods. Note that the security-reporting mailbox posture is already recorded as indefinite retention in the owner's mailbox; this policy must not contradict it.

  6. 6. Sharing and subprocessors

    Cross-reference the subprocessor list in the DPA.

  7. 7. Data-subject rights (GDPR / CCPA)

    Access, correction, deletion, portability, objection, and the request channel. A right described here has to be operationally deliverable.

  8. 8. International transfers

    Transfer mechanism, once subprocessor regions are confirmed.

  9. 9. Privacy contact

    A monitored address. Not a placeholder inbox.

Open questions for counsel

  • Every stated right must be deliverable by an actual implemented process — a documented right with no runbook is a liability, not a compliance win.
  • Retention periods must be reconciled with what the platform actually deletes today, which in several places is nothing.
  • CCPA and GDPR obligations differ; confirm which apply given the operating entity and customer base.

Tracked by issue #1828. Tenant storefront policies are a separate thing entirely — each tenant publishes its own shopper-facing policies, which are not covered by any document here.