1. Commitment to Data Privacy
Frontstore ("Platform", "we", "our", or "us") is owned and operated by Built Different LTD, and serves as a conversational commerce infrastructure. We handle data for two groups of users: **Merchants** (who create storefronts and sell products) and **Shoppers** (who browse stores, negotiate via chat, and place orders).
We are committed to operating in full compliance with regional privacy laws, including the Nigeria Data Protection Act (NDPR/NDPA), Kenya's Data Protection Act, and South Africa's Protection of Personal Information Act (POPIA), alongside international guidelines such as the General Data Protection Regulation (GDPR).
2. Information We Collect
To make conversational checkouts and AI features possible, we collect the following types of information:
A. Merchant Data
- Account Information: Name, business email, login credentials, and WhatsApp-connected phone number.
- Store & Catalog Data: Product titles, descriptions, pricing currencies (NGN, GHS, KES, ZAR, etc.), size/color variants, and catalog photos.
- KYC Verification details: Legal business names, tax registry numbers, identification documents, and bank/mobile money details for payment settlements.
B. Shopper & Order Data
- Order Details: Products browsed, checkout selection, totals, and transactional timestamps.
- Delivery Details: Delivery contact name, physical shipping address, and phone number for coordinates.
C. Chat Transcripts & AI Inputs
When shoppers engage with our AI chat assistant, we collect and log the text dialogue to process requests, formulate catalog suggestions, and construct order summaries.
D. Technical Logs
Anonymized IP addresses, browser specifications, and connection speeds to deliver lightweight, fast storefront screens to mobile phones operating on Erratic 3G/4G networks.
3. Processing Data with Artificial Intelligence
Frontstore integrates state-of-the-art AI technology to generate catalog descriptions and run our AI chat assistant. Data handling for AI features follows strict protocols:
- Security of AI Pipelines: Product details, tags, and chat transcripts sent to AI models (such as secure APIs from OpenAI or Google Gemini) are encrypted during transit and processing.
- No Public Training Use: We do not allow third-party AI models to use your personal or business-sensitive transaction records to train public models.
- Language Customization: Chat logs are evaluated internally by Frontstore to calibrate our conversational agents on regional colloquialisms, Pidgin, Sheng, and localized spelling formats.
4. Information Sharing & Third Parties
We do not sell, rent, or trade merchant or shopper information to marketing companies. Data is shared only under the following strictly defined operational contexts:
- Public Storefront:A merchant's store name, bio, products, pricing, and WhatsApp phone number are publicly readable so that shoppers can discover and buy from them.
- With the Merchant: Customer order details, delivery addresses, and chat details are shared with the merchant to enable fulfillment.
- Licensed Payment Processors: We partner with licensed, PCI-DSS compliant financial providers (such as Paystack, Flutterwave, and M-Pesa channels) to process payments.
- Cloud & Hosting Infrastructure: Encrypted hosting providers (such as Vercel and Supabase) that comply with ISO security frameworks.
5. Regional Compliance & User Rights
No matter where your business is situated in Africa or globally, we recognize your control over your data.
- Right to Access & Portability: Merchants may request a complete export of their sales logs, inventory, and account details.
- Right to Rectification: You can edit your catalog, password, name, and billing details directly within the Frontstore merchant dashboard.
- Right to Erasure (Deletion): You have the right to request that we delete your store, customer lists, and all associated personal data from our servers. Once verified, deletion will occur within 30 business days.
- Data Protection Officer: For any compliance inquiries, Data Subject Access Requests (DSAR), or privacy questions, contact our Data Protection Officer at `[email protected]`.
6. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to keep storefronts fast and sessions secure on low-bandwidth connections.
- Essential Cookies: Maintain login sessions, cart contents, and authentication tokens. Disabling these will break checkout and dashboard access.
- Analytics Cookies: Help us understand storefront traffic and conversion patterns so we can improve page load times across markets.
- Preference Cookies: Remember display currency, language, and theme selections between visits.
You can disable non-essential cookies through your browser settings at any time.
7. Data Retention
- Active Accounts: Merchant and shopper data is retained for as long as the account remains active on the platform.
- Financial Records: Transaction and settlement records are kept for a minimum of 6 years to comply with tax and anti-money laundering obligations in the jurisdictions we operate in.
- Chat Transcripts: AI chat logs are retained for up to 12 months to support dispute resolution and quality review, after which they are anonymized or deleted.
- Account Closure: Personal data is purged within 30 business days of a verified deletion request, except where retention is required by law.
8. Security Measures
We apply industry-standard safeguards to protect merchant and shopper data:
- Encryption: Data is encrypted in transit via TLS and at rest for sensitive fields such as KYC documents and settlement details.
- Access Controls: Internal access to personal data is role-based and limited to staff who need it to perform their duties.
- Breach Notification: In the event of a data breach affecting your personal information, we will notify affected users and relevant regulators within the timeframes required by applicable law.
9. Changes to This Policy
We may update this policy as our practices evolve or as new legal requirements apply. Material changes will be communicated by email or dashboard notice at least 7 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent revision, and continued use of Frontstore after changes take effect constitutes acceptance of the updated policy.
10. Marketing Communications
With your consent, we may send product updates and promotional offers by email, SMS, or WhatsApp. You can opt out at any time using the unsubscribe link in any marketing message or by replying STOP. Opting out of marketing does not affect transactional notifications (order confirmations, delivery updates, account alerts), which are necessary for us to deliver the service.