Privacy Policy
How litecommerce handles personal data it controls — tenant account holders and prospects.
Draft scaffold — not a legal document
This page is a placeholder. It has not been reviewed by counsel, it is not in effect, and it creates no rights or obligations for anyone. It lists what the Privacy Policy will need to cover — the operative language is deliberately absent.
Nothing here may be relied on, quoted, or presented to a customer as litecommerce's terms.
litecommerce's role
litecommerce is the controller for tenant-account and prospect data. For end-customer data a tenant loads into the platform, litecommerce is a processor and the DPA governs instead.
Sections this document must cover
Scope only. These describe what each section has to establish, not what it will say.
1. Scope — what this policy does and does not cover
Must state clearly that this covers data litecommerce controls, and that a shopper's relationship is with the tenant, not litecommerce. The most common reader confusion is a shopper landing here expecting their store's policy.
2. Personal data collected
Account registration data, signup and contact-form submissions, billing and tax-location data, authentication events, request metadata and logs.
3. Purposes and legal bases
Per category. GDPR requires the legal basis stated, not just the purpose.
4. Bot protection disclosure
Cloudflare Turnstile runs on public forms and processes request data for abuse prevention. Disclose it explicitly.
5. Retention
Per category, with actual periods. Note that the security-reporting mailbox posture is already recorded as indefinite retention in the owner's mailbox; this policy must not contradict it.
6. Sharing and subprocessors
Cross-reference the subprocessor list in the DPA.
7. Data-subject rights (GDPR / CCPA)
Access, correction, deletion, portability, objection, and the request channel. A right described here has to be operationally deliverable.
8. International transfers
Transfer mechanism, once subprocessor regions are confirmed.
9. Privacy contact
A monitored address. Not a placeholder inbox.
Open questions for counsel
- Every stated right must be deliverable by an actual implemented process — a documented right with no runbook is a liability, not a compliance win.
- Retention periods must be reconciled with what the platform actually deletes today, which in several places is nothing.
- CCPA and GDPR obligations differ; confirm which apply given the operating entity and customer base.
Tracked by issue #1828. Tenant storefront policies are a separate thing entirely — each tenant publishes its own shopper-facing policies, which are not covered by any document here.