Last updated: June 11, 2026
This Privacy Policy explains how Shopolo collects, uses, and protects information when you use our platform. We take privacy seriously and will never sell your data.
Shopolo is operated by Nanushi Inc. ("we", "us", "our"). We provide software tools for independent businesses including gift cards, loyalty programs, online ordering, appointments, reservations, and email campaigns.
For questions about this policy, contact us at support@shopolo.app.
We collect information in three ways:
Information you provide directly: • Account registration: name, email address, password • Business profile: business name, type, address, phone, website, logo, brand colors • Billing information: handled entirely by Stripe — we never see or store your card number
Information collected automatically: • Usage data: pages visited, features used, actions taken in the dashboard • Device and browser information: browser type, device type, operating system, and country • A cookie that keeps you signed in to your dashboard
We do not store your IP address in our analytics. It is used momentarily to work out your country and to build a one-way, salted hash that lets us tell repeat visits apart within a single day. That hash is regenerated daily and cannot be turned back into an IP address.
Information from your customers (as a data processor): When your customers use your Shopolo-powered storefront, we collect their name, email address, purchase history, and loyalty activity on your behalf. You are the data controller for this information; we process it only to provide you with the service.
We use the information we collect to:
• Provide, operate, and improve the Shopolo platform • Process transactions and send receipts • Send transactional emails (booking confirmations, gift card delivery, loyalty updates) via Resend • Send you product updates, billing notices, and support communications • Detect and prevent fraud and abuse • Comply with legal obligations
We do not use your data or your customers' data for advertising. We do not sell data to third parties.
We share information only with service providers necessary to operate the platform:
• Stripe, Inc. — payment processing and merchant payouts. When you connect a Stripe Express account to accept payments, Stripe independently collects and processes your identity and business information as part of their Know Your Customer (KYC) and Know Your Business (KYB) compliance obligations. This includes your legal name, address, date of birth, SSN (last 4 or full, depending on volume), and bank account details. This information is governed by Stripe's Privacy Policy at stripe.com/privacy — Shopolo does not receive, store, or have access to sensitive identity documents or full financial account numbers. • Supabase, Inc. — database and authentication infrastructure. Data is stored in US-based data centers. • Resend, Inc. — transactional email delivery (gift cards, booking confirmations, campaign sends), and delivery of support messages you send us from the in-app chat. • Vercel, Inc. — hosting and content delivery. Every request to Shopolo passes through Vercel's infrastructure, which processes your IP address and request metadata in order to serve the page and to protect against abuse. Vercel also provides us with aggregate traffic and performance measurements. • Turso (ChiselStrike, Inc.) — the database that stores the anonymous page-view analytics described in section 7. This database is shared with other websites we operate. It holds no account data, no customer records, and nothing that identifies you: only the page visited, coarse device and country information, and the daily rotating hash described below.
We do not share payment card data because we never receive it. All card information is entered directly into Stripe's secure hosted checkout — it never passes through Shopolo's servers.
All third-party processors are contractually required to protect your data and use it only as directed by us. We do not share your information with any other third parties without your explicit consent, except as required by law.
We do not sell your personal information, and we do not sell or share it for cross-context behavioural advertising.
Where we stand today: Shopolo does not use artificial intelligence or machine learning to process your data. We do not send your information, your customers' information, or the contents of your campaigns and invoices to any AI provider. No AI model is trained on anything you or your customers put into Shopolo.
We may add AI-assisted features in future — for example, help drafting a campaign email or summarising your own sales figures. If we do, these commitments apply:
• We will update this policy and tell account holders by email before any such feature is switched on, not afterwards. • AI features will be optional. You will not be opted in by default, and declining will not restrict any feature you already rely on. • We will not permit any AI provider to train its models on your data or your customers' data. Where a provider offers a zero-retention or no-training configuration, we will use it. • We will not put your customers' personal information into an AI system in order to generate content for other merchants. • Any AI provider we use will be named in the list of processors above, in the same way Stripe, Supabase, Resend, Vercel, and Turso are named today. • A machine will not make a decision that has a legal or similarly significant effect on you — such as suspending your account or withholding a payout — without a person reviewing it.
If any of the above ever ceases to be true, it will be because this section was changed, and the change will be dated in section 13.
When your customers interact with your Shopolo storefront — buying a gift card, joining your loyalty program, placing an order, or booking an appointment — we collect and store their data to operate those features on your behalf.
What a customer record contains: name, email address, and phone number where given; birthday day and month if they provide it for birthday rewards; any notes or tags you add yourself; whether they have opted in to your marketing; the date we first and last saw them; their total spend with you; and a count of their visits.
What a loyalty programme records: joining creates a stamp card holding the customer's name, email, current stamp count, and how many times they have completed the card. Every stamp is then written to a permanent history that records whether a stamp was added, removed, issued as a reward, or redeemed, the running total afterwards, the exact time it happened, which member of your staff performed it, and any note they attached. In practice this history is a log of when that person visited you, so treat it as you would any visit record: tell your customers it exists, and only stamp people who know they have joined.
We do not track your customers across other websites, we do not build advertising profiles from this data, and we do not combine one merchant's customer data with another's.
As the merchant, you are the data controller for your customer data. We are the data processor. You are responsible for: • Having a valid legal basis to collect your customers' data • Providing your customers with notice of how their data is used • Honoring any deletion or access requests from your customers
To request a copy of your data, or the deletion of a specific customer record or your whole account, email privacy@shopolo.app and we will action it within 30 days. We do not yet offer self-service export or deletion from the dashboard; until we do, this route is how those requests are handled.
Shopolo sends two types of emails:
Transactional emails: These are sent in direct response to user actions — gift card delivery, booking confirmations, order receipts, loyalty updates. These cannot be opted out of as they are essential to the service.
In practice these include gift card delivery and purchase confirmations, order confirmations, booking requests, confirmations and approvals, notifications to you when a booking or order comes in, and birthday rewards where you have enabled them. They are sent through Resend on our behalf.
Marketing emails: We may send you product news, tips, and updates about Shopolo. You can unsubscribe from these at any time using the unsubscribe link in any such email or by contacting us.
Campaign emails you send to your customers: we record only that a campaign was sent to a given customer, and when. We do not place tracking pixels in your campaigns, and we do not record whether a recipient opened an email or clicked a link in it. Every campaign carries an unsubscribe link secured with a signed token, and an unsubscribe applies immediately to that customer for your business.
For emails sent to your customers via the Campaigns feature, you are responsible for ensuring your recipients have opted in and for complying with CAN-SPAM, CASL, and any other applicable anti-spam laws.
We use cookies sparingly, and only where the site cannot work without them:
• Session management: keeping you logged in to your dashboard • Security: protecting against CSRF attacks
We do not use advertising cookies, and we do not track you across other websites.
Our page-view analytics use no cookies at all. We record the page visited, the referring site, your browser, device, operating system, and country, plus a daily salted hash that distinguishes repeat visits without identifying you. This data is not sold or shared, and it is not linked to your account.
If you visit from the UK, Switzerland, or the EU/EEA — or from a country we cannot determine — we ask for your consent before recording anything, and we record nothing unless you accept. You can change your mind by clearing this site's data in your browser.
You can also control cookies through your browser settings, though disabling them may prevent signing in from working correctly.
We retain your account data for as long as your account is active. If you cancel your account, we retain your data for 30 days in case you wish to reactivate, after which it is permanently deleted.
Billing records and transaction logs may be retained for up to 7 years as required for tax and financial compliance purposes.
Your customers' data (profiles, purchase history) is retained as long as your account is active. You may delete individual customer records from your dashboard at any time.
Anonymous page-view analytics are retained for 365 days and then deleted automatically.
We implement industry-standard security measures to protect your data including:
• All data transmitted over HTTPS with TLS encryption • Passwords hashed using bcrypt — never stored in plaintext • Database access restricted to application services only • Authentication managed by Supabase with 256-bit encryption
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but take reasonable precautions to protect your data.
Depending on your location, you may have the right to:
• Access the personal data we hold about you • Correct inaccurate data • Request deletion of your data • Export your data in a portable format • Object to or restrict certain processing
To exercise any of these rights, contact us at privacy@shopolo.app. We will respond within 30 days.
Shopolo is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. The "last updated" date at the top of this page reflects the most recent revision.
Continued use of Shopolo after changes take effect constitutes acceptance of the updated policy.
If you have questions, concerns, or requests related to this Privacy Policy, please contact us at:
privacy@shopolo.app — data access, correction and deletion requests support@shopolo.app — anything else
To report a security vulnerability, email security@shopolo.app.
Nanushi Inc.