Privacy Policy

Storelib Inc. — storelib.com

Effective Date: 3 March 2026Last Updated: 3 March 2026

1. Introduction

Welcome to Storelib. This Privacy Policy explains how Storelib Inc. ("Storelib," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our platform, services, and applications.

This Privacy Policy applies to all users of the Storelib platform, including:

  • The Storelib website at storelib.com and all associated subdomains (e.g., yourstore.storelib.com)
  • The Storelib iOS application available on the Apple App Store
  • The Storelib Android application available on the Google Play Store
  • All related tools, features, APIs, and services provided by Storelib (collectively, the "Services")

Storelib is a digital product marketplace platform that enables creators and entrepreneurs ("Sellers") to sell digital products, manage links, capture emails, and grow an audience, while enabling customers ("Buyers") to discover and purchase digital products. By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our Services.

We encourage you to read this Privacy Policy carefully. If you have any questions, contact us at privacy@storelib.com or team@storelib.com.

2. Who We Are (Data Controller)

Storelib Inc. is the data controller responsible for your personal information. For the purposes of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other applicable data protection laws:

Company Name: Storelib Inc.

Website: https://storelib.com

Privacy Email: privacy@storelib.com

General Support: team@storelib.com

If you are a Seller on the platform, you may also act as an independent data controller with respect to the personal information of your own customers. You are responsible for your own compliance with applicable privacy laws regarding any data you collect through your Storelib store.

3. Information We Collect

We collect different types of information depending on how you interact with our Services, whether you are a Seller, a Buyer, or a general visitor.

3.1 Information You Provide Directly

For Sellers (Creators/Entrepreneurs):

  • Full name, email address, and profile photo
  • Username and password (encrypted)
  • Store name, OnePage URL, and custom domain settings
  • Address and business information (required for Stripe Connect verification)
  • Financial and banking information provided to Stripe for payout purposes
  • Product listings, descriptions, pricing, images, and digital files uploaded for sale
  • Email content created through the Storelib email system (newsletters, broadcast emails)
  • Timezone, language preferences, and dashboard settings
  • Billing plan and subscription information

For Buyers (Customers):

  • Full name and email address (provided at checkout)
  • Payment information — processed and stored securely by Stripe; Storelib does not store your full card details
  • Purchase history and transaction records
  • Product reviews and ratings submitted on seller product pages
  • Email address when subscribing to a Seller's newsletter or email list
  • Optional tip amounts added during checkout

For All Users:

  • Any information you provide when contacting us for support, feedback, or inquiries
  • Information you voluntarily include in your public profile or store pages

3.2 Information Collected Automatically

When you access or use our Services, we automatically collect certain technical and usage information:

  • IP address
  • Device type, operating system, and browser type/version
  • Mobile device identifiers (e.g., device ID, advertising ID) when using our iOS or Android apps
  • Pages visited, time spent on pages, click-through data, and navigation paths
  • Referring URL and exit pages
  • Approximate geographic location derived from IP address (country and region level)
  • Traffic source data including UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term)
  • Product page views, tracked natively using IP-based deduplication
  • Crash logs and error reports from our mobile applications

3.3 Information from Third Parties

We may receive information from third-party services connected to your account:

  • Stripe: Account verification status, payout information, transaction confirmations, and refund statuses.
  • Social login providers: If you sign up or log in using Google or Apple, we receive your name, email address, and profile picture as permitted by that provider.
  • App stores: Apple App Store and Google Play Store may provide us with aggregated download and usage analytics.

4. How We Use Your Information

4.1 To Provide and Operate the Services

  • Create and manage your Seller or Buyer account
  • Process transactions between Buyers and Sellers via Stripe Connect
  • Deliver purchased digital products to Buyers via email and download links
  • Facilitate payouts to Sellers through Stripe Connect
  • Enable Sellers to manage their stores, product listings, OnePage, email subscribers, and analytics dashboards
  • Process refunds when applicable
  • Connect custom domains to Seller stores

4.2 To Provide Analytics to Sellers

  • Track and display product views, sales, revenue, and conversion rates on Seller dashboards
  • Identify traffic sources (direct, organic search, social media, email, referral, paid search) and UTM campaign data
  • Provide geographic/country-level data on visitors and customers
  • Generate aggregated performance metrics and KPIs

Note: All analytics are built natively into the Storelib platform. We do not use Google Analytics or any third-party analytics service for product view tracking.

4.3 To Communicate with You

  • Send transactional emails (purchase confirmations, download links, refund notifications, payout confirmations, first sale notifications)
  • Send account-related notifications (security alerts, verification requests, billing reminders)
  • Enable Sellers to send newsletters and marketing emails to their subscribers through Storelib's built-in email system
  • Respond to your support requests and inquiries

4.4 To Improve and Protect Our Services

  • Monitor and analyze usage trends to improve user experience
  • Detect, prevent, and address fraud, abuse, security incidents, and technical issues
  • Debug and fix errors in our website and mobile applications
  • Enforce our Terms of Service and prevent prohibited activities

4.5 To Comply with Legal Obligations

  • Comply with applicable tax, accounting, and financial reporting requirements
  • Respond to lawful requests from law enforcement or regulatory authorities
  • Establish, exercise, or defend legal claims

5. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another jurisdiction that requires a legal basis for processing personal data, we rely on the following grounds:

Contractual Necessity: Processing is necessary to perform our contract with you (e.g., providing the Services, processing transactions, managing your account, delivering digital products, facilitating payouts).
Legitimate Interests: Processing is necessary for our legitimate interests, including improving our Services, preventing fraud, ensuring platform security, and providing analytics to Sellers. We balance these interests against your rights and freedoms.
Consent: Where required, we process your data based on your freely given consent (e.g., subscribing to a Seller's email list, opting into marketing communications). You may withdraw consent at any time.
Legal Obligation: Processing is necessary to comply with a legal obligation to which we are subject (e.g., tax reporting, responding to lawful data requests).

6. Payments, Stripe Connect, and Financial Data

6.1 How Payments Work

When a Buyer purchases a digital product from a Seller on Storelib:

  • The Buyer enters payment information on the Storelib checkout page powered by Stripe Elements.
  • Payment card information is transmitted directly to Stripe's servers. Storelib never receives, processes, or stores your full payment card details.
  • Stripe processes the charge and automatically splits the payment: the Seller's share is sent to their connected Stripe account, and Storelib's platform fee is collected as an application fee.
  • Stripe handles all PCI-DSS compliance requirements for payment data security.

6.2 Seller Financial Information

To receive payouts, Sellers connect their Stripe account to Storelib via Stripe Connect. Stripe may collect identity verification documents, banking details, tax identification information, and address directly. This information is provided to and controlled by Stripe, not Storelib. Storelib receives only limited information such as the Seller's Stripe account ID, verification status, and payout history.

6.3 Platform Fees

Storelib collects a platform transaction fee on each sale, which varies based on the Seller's subscription plan (Free, Growth, or Professional). These fees are collected automatically via Stripe Connect's application fee mechanism.

6.4 Stripe's Privacy Policy

Stripe is an independent data controller for the payment and financial data it processes. For details, refer to Stripe's Privacy Policy at https://stripe.com/privacy.

7. Analytics, View Tracking, and Cookies

7.1 Native Analytics

Storelib provides Sellers with a built-in analytics dashboard. All analytics tracking is performed natively by Storelib — we do not use Google Analytics or any third-party analytics service for tracking views on Seller product pages and stores.

Our native analytics system tracks:

  • Product page views (deduplicated by IP address and product ID within a time window)
  • Traffic sources (direct, organic search, social media, email, referral, paid search)
  • UTM campaign parameters
  • Geographic/country-level data (derived from IP addresses)
  • Sales, revenue, and conversion rate metrics

IP addresses used for view deduplication are not shared with Sellers. Sellers see only aggregated analytics data and cannot identify individual visitors.

7.2 Cookies and Similar Technologies

Our website and applications use cookies and similar technologies for the following purposes:

  • Essential Cookies: Necessary for the operation of our Services, such as maintaining your login session, remembering your authentication state, and ensuring security. These cookies cannot be disabled.
  • Functional Cookies: Remember your preferences and settings to provide you with a personalized experience.
  • Analytics Cookies: Help us understand how users interact with our Services so we can improve them.

We do not use advertising cookies or sell data collected through cookies to third parties. We do not engage in cross-site tracking for advertising purposes.

7.3 Managing Cookies

You can control and manage cookies through your browser settings. If you block essential cookies, some features of our Services may not function properly. For our mobile applications, you can manage tracking permissions through your device's privacy settings (e.g., iOS App Tracking Transparency, Android advertising ID settings).

8. Email System and Subscriber Data

8.1 Storelib's Built-In Email System

Storelib provides Sellers with a built-in email system to communicate with their subscribers and customers. This includes newsletters, product announcements, and automated emails. The email system is hosted and operated by Storelib.

8.2 Subscriber Email Collection

Buyers and visitors may voluntarily provide their email addresses to Sellers through Subscribe Bars on Seller stores, OnePage link-in-bio pages, free product downloads (lead magnets), or at checkout. When a visitor subscribes to a Seller's email list, that Seller can view the subscriber's email address in their Storelib dashboard and send them emails through the platform.

8.3 Unsubscribing

Every email sent through Storelib's email system includes a clearly visible unsubscribe link. Subscribers can unsubscribe at any time. Once unsubscribed, the Seller will no longer be able to send them marketing emails through Storelib.

8.4 Email Limits by Plan

The number of emails a Seller can send per month depends on their subscription plan: Free plan: 500 emails/month; Growth plan: 2,000 emails/month; Professional plan: 5,000 emails/month.

9. How We Share Your Information

We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes. We may share your information in the following limited circumstances:

9.1 With Sellers (for Buyer Data)

When you make a purchase from a Seller or subscribe to a Seller's email list, the Seller receives your name, email address, purchase details, and any review you submit. Sellers are independent data controllers for the Buyer data they receive and are responsible for their own compliance with privacy laws.

9.2 With Stripe

We share transaction information with Stripe to process payments, manage payouts, handle refunds, and comply with financial regulations.

9.3 With Service Providers

We may share information with trusted third-party service providers who assist us in operating our Services, including hosting providers, email delivery services, customer support tools, and error monitoring services. These providers are contractually obligated to use your data only for the purposes we specify.

9.4 For Legal Reasons

We may disclose your information if required by law, in response to a valid legal process (such as a court order, subpoena, or government request), or to protect the rights, property, or safety of Storelib, our users, or the public.

9.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your personal information may be transferred as part of the transaction. We will notify you of any such change.

9.6 Aggregated and Anonymized Data

We may share aggregated or anonymized information that cannot reasonably be used to identify you with third parties for business, research, or statistical purposes.

10. Data Retention

We retain your personal information for as long as necessary to provide our Services and fulfill the purposes described in this Privacy Policy. Specific retention periods include:

Account DataRetained for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where required for legal, tax, or regulatory purposes.
Transaction RecordsRetained for a minimum of 7 years to comply with financial, tax, and accounting obligations.
Analytics DataIP addresses used for view deduplication are retained for a limited period (typically 24 hours). Aggregated analytics data is retained indefinitely as part of Seller dashboard data.
Email Subscriber DataRetained for as long as the Seller's account is active or until the subscriber unsubscribes. Unsubscribed records are retained in an anonymized form for compliance purposes.
Support CommunicationsRetained for up to 3 years after the last interaction.

11. Data Security

We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it, including:

  • All data transmitted between your device and our servers is encrypted using TLS/SSL (HTTPS)
  • Passwords are hashed and salted; we cannot view your plain-text password
  • Payment card data is processed exclusively by Stripe and never touches our servers. Stripe maintains PCI-DSS Level 1 certification
  • Access to personal data within our organization is restricted to authorized personnel on a need-to-know basis
  • Regular security reviews and updates to our systems and infrastructure
  • Secure hosting infrastructure with encryption at rest for stored data

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to taking all reasonable steps to safeguard your data.

12. Your Rights

12.1 Rights Under the GDPR (EEA and UK)

If you are located in the European Economic Area or the United Kingdom, you have the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request that we correct inaccurate or incomplete personal data.
  • Right to Erasure (“Right to Be Forgotten”): You can request that we delete your personal data, subject to certain legal exceptions.
  • Right to Restriction of Processing: You can request that we restrict the processing of your personal data in certain circumstances.
  • Right to Data Portability: You can request to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: You can object to the processing of your personal data based on our legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw your consent at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence.

12.2 Rights Under the CCPA/CPRA (California)

  • Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You can request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

12.3 Rights Under Other Privacy Laws

If you are located in a jurisdiction with specific privacy legislation (such as Brazil's LGPD, Canada's PIPEDA, or various US state privacy laws), you may have similar rights. Please contact us at privacy@storelib.com to exercise your rights.

12.4 How to Exercise Your Rights

You can exercise your rights by emailing privacy@storelib.com with your request. Please include sufficient information to verify your identity and describe your request clearly. We will respond within the time frame required by applicable law (generally 30 days for GDPR and 45 days for CCPA requests). We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.

13. International Data Transfers

Storelib operates globally. Your personal information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country.

When we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms.

By using our Services, you acknowledge and agree to the transfer of your information as described in this section.

14. Children's Privacy

Our Services are not directed to children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under this age. If we become aware that we have collected personal information from a child under the applicable age without parental consent, we will take steps to delete that information as promptly as possible.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at privacy@storelib.com.

15. Mobile Applications (iOS and Android)

15.1 App Store and Google Play Requirements

Our mobile applications are available on the Apple App Store and the Google Play Store. When you download and use our apps, the respective app store may collect information about you in accordance with its own privacy policy. We encourage you to review Apple's and Google's privacy policies.

15.2 Device Permissions

Our mobile applications may request certain permissions on your device, such as:

  • Camera and photo library access: To allow Sellers to upload product images and profile photos
  • Push notifications: To send you alerts about sales, orders, and account activity
  • Internet access: Required for all core functionality
  • Storage access: To enable downloading of purchased digital products

You can manage these permissions at any time through your device's settings.

15.3 App Tracking and Identifiers

On iOS, we comply with Apple's App Tracking Transparency (ATT) framework. We will request your permission before tracking your activity across other companies' apps and websites. On Android, we respect your advertising ID settings. We do not use your mobile device identifiers for advertising purposes.

15.4 Crash Reporting

Our mobile applications may collect crash reports and diagnostic data to help us identify and fix bugs. This data may include device type, operating system version, app version, and technical logs. This data does not include your personal content or financial information.

16. Discover Marketplace

Storelib features a Discover section where Buyers can browse and discover digital products from various Sellers on the platform. Product listings in Discover are public and may include the Seller's store name, profile photo, product titles, descriptions, prices, cover images, and review ratings. Sellers should be aware that any information they include in their public product listings and store profiles is visible to all visitors of the platform.

17. Third-Party Links and Services

Our Services may contain links to third-party websites, products, or services that are not owned or controlled by Storelib. This includes links in Seller OnePage profiles, product descriptions, and external websites. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you interact with.

18. "Do Not Sell or Share My Personal Information"

Storelib does not sell your personal information as defined under the CCPA/CPRA or any other applicable privacy law. We do not share your personal information with third parties for cross-context behavioral advertising. Because we do not sell or share your personal information, there is no need to opt out. However, if you have any concerns, please contact us at privacy@storelib.com.

18.1 "Do Not Track" Signals

Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no universally accepted standard for how DNT signals should be interpreted, we do not currently alter our data collection and use practices in response to DNT signals. We will update this Privacy Policy if a standard for responding to DNT signals is established.

19. Affiliate Program

Storelib offers an affiliate program that allows users to earn commissions by referring new Sellers to the platform. If you participate in our affiliate program, we collect your name, email address, payment information for commission payouts, and referral tracking data (such as referral links and conversion data). This information is used solely for managing the affiliate program and processing payouts.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" and "Last Updated" dates at the top of this Privacy Policy
  • Notify registered users via email about material changes
  • Post a prominent notice on our website and/or within our mobile applications

We encourage you to review this Privacy Policy periodically. Your continued use of our Services after any changes constitutes your acceptance of the updated Privacy Policy.

21. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Email: privacy@storelib.com

General Support: team@storelib.com

Website: https://storelib.com

We aim to respond to all privacy-related inquiries within 30 days. For GDPR-related requests, we will respond within the time frame required by applicable law.

If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 Storelib Inc. All rights reserved.

storelib.com · Terms of Service · privacy@storelib.com