Privacy Policy
Draft for legal review — last updated 2026-09-30.
Featherstall is a platform for online stores. It is run by [owner's legal name], doing business as Featherstall, of [mailing address] ("Featherstall", "we" or "us"). This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what rights you have. Questions go to privacy@featherstall.com.
Two kinds of people use Featherstall:
- Merchants run stores with the Featherstall builder. For merchants' account data, Featherstall is the controller.
- Shoppers visit and buy from those stores. For order data, the store is the controller, and Featherstall processes the data on its behalf under our Data Processing Addendum. If you're a shopper, go to Shoppers.
If you write to us, for example to report a store, we use your email address and message to reply and to act on what you tell us.
What we don't do
- We don't use web analytics services or scripts, and we don't set advertising or tracking cookies. The only cookies we set are strictly necessary, and they're listed below.
- Stores and the builder run no third-party scripts, and their pages load nothing from other websites.
- We don't sell personal data, or use it for advertising.
Merchants
What we collect
- Your email address. It is your account.
- Sign-in records. When you ask for a sign-in link, we store a hash of the link (not the link itself), the email address, the IP address it was asked from, and the time.
- Sessions. When you sign in, we store a hash of your session token and when it expires.
- How you found us. If the link that brought you to Featherstall had campaign tags (such as
utm_source, or a Google Ads campaign number, but never an ad's click ID) or a store's or partner's code, your sign-in link keeps them, and so does your account if it's new. So does your answer to "How did you find Featherstall?" when you make your first store. - Terms acceptance. Each time you sign in, we record which version of the Terms of Service you accepted, and when.
- Your stores. Names, taglines, settings, products, photos, pages, custom CSS, domains and shipping settings, plus your Stripe account ID and whether it can take charges. We keep resized copies of your photos, not the original files, so photo metadata such as location isn't stored.
- Your store's policies. Its contact email, seller name and country, and its returns and delivery answers. Once you save them, they're public: your store shows them, search engines can read them, order confirmations name the seller, and shoppers' replies to those confirmations go to the contact email.
- AI drafting counts. The type and time of each draft, for the daily limit.
- Your orders. These contain your shoppers' data, as described under Shoppers.
- Messages you send us.
- Server logs of errors and rate limits. A log line can include an IP address, a domain name or an order reference.
Why we use it
- To provide Featherstall under our Terms of Service: signing you in, hosting your stores, recording orders, sending order emails and making drafts.
- To keep Featherstall secure and prevent abuse, which is our legitimate interest: sign-in limits, recognising your browser and network, and acting on reports.
- To keep you informed about your account, your stores, our fees and our policies.
- To learn which posts, ads and partners bring merchants, which is our legitimate interest. We look at how you found us only in totals, and we don't share it with anyone, ad platforms included. A store's or partner's code also gives the fee-free sales our Terms describe.
- To meet our legal obligations, including keeping a record of the terms you accepted.
We don't send you marketing email unless you've agreed to it.
Emails we send you
- Sign-in links.
- A new-order email when a shopper pays. It includes the shopper's name, email and shipping address (with their phone number, when checkout asked for one), and replying to it writes to the shopper.
- Notices about your account, your stores, our fees and these policies.
Cookies in the builder
__Host-sidkeeps you signed in. It holds a random token and lasts 30 days. Signing out ends the session.__Host-knownlets the builder recognise a browser you've signed in from, so sign-in limits meant for strangers don't block you. It holds your email address, sealed with encryption, and lasts a year.
Stripe and AI drafting
- When you connect Stripe, we ask Stripe to create an account for you with your sign-in email. You give your business and bank details to Stripe directly, on Stripe's site. We read back your account's status, and its business name, support email and country, which fill in any empty fields in your store's policies. We don't store your bank or identity details.
- When you ask for an AI draft, we send Anthropic's API the photo or text the draft needs, with details such as your store's name. Anthropic processes it to return the draft, under its commercial terms. We never send it order or shopper data.
Shoppers
This section is for people who buy from stores on Featherstall.
Who's responsible. Each store is run by an independent merchant. The merchant sells to you and is responsible for your order data. Featherstall hosts the store and processes your data for the merchant. The store's Shipping & returns page, linked at the bottom of every page, names the seller and gives its contact email.
Browsing. You don't need an account. A store's pages set no cookies until you add something to your cart. Then your browser gets one cookie, __Host-cart. It's encrypted, and holds only which store it's for, the products and quantities in your cart, and, at a store whose shipping depends on the country, the country you chose. It lasts 30 days, is cleared when you finish checkout, and is strictly necessary. Like every website, our servers see your IP address. We use it in memory to limit how often checkout can be used, and we don't store it with your order.
Checkout. You pay on Stripe Checkout, which Stripe runs for the store. There you give Stripe your payment details, name, email and, if the store ships, your shipping address. If the order may go abroad, Stripe also asks for your phone number, for the carrier. Featherstall never sees your card details.
What Featherstall keeps. When you complete checkout, Featherstall copies these details from Stripe: your name, email and shipping address (with your phone number, if you gave it), the items, amounts and currency, and Stripe's references for the payment.
Who sees it.
- The store. It sees your order in its Featherstall builder and in its Stripe account, and gets an email about your order.
- Stripe, which processes your payment under its agreement with the store and its own privacy policy.
- The providers that store and send the data for us: Fly.io (hosting, in the US), Cloudflare (email, and our encrypted backups) and GitHub (which makes the nightly backup); and, if you write to us, Google (our mailbox) and Anthropic (whose Claude drafts our replies).
- Nobody else, unless the law requires it. We don't sell your data or use it for advertising.
Emails. When your payment goes through, Featherstall emails you an order confirmation for the store. It comes from the store's name at orders@featherstall.com, in the store's language, and replies go to the store. It lists your items, the total and your shipping address, names the seller, and links to the store's policies. When the store marks your order shipped, we can email you how to follow it too. The store may also have Stripe send you a receipt. Featherstall doesn't send you marketing email.
How long. Your order is kept for the store's records until 30 days after the store is closed, or until the store erases your details at your request. After that we keep only the payment's amounts and dates, without your details, for our accounts. Backups of the database hold your details for up to 10 days after they're deleted.
Where. Order records are stored in the United States. Our encrypted copy, which Cloudflare keeps and can't read, may be stored elsewhere.
Who to ask. For anything about your order or your data, contact the store first. Its email is at the bottom of every page of the store and on its Shipping & returns page, and replying to your order confirmation reaches it. You can also write to privacy@featherstall.com. We'll pass your request on to the store, or handle it with them.
Who we share data with
We use these service providers (sub-processors). Each one gets only what it needs.
- Fly.io: hosting, and the Postgres database with its backups. The database is in the US (Fly.io region iad, in Virginia). Web servers run in several regions.
- Stripe: payments and merchant onboarding. US and global.
- Cloudflare: DNS, checking domain records, sending our emails (sign-in links, new-order emails to merchants and order confirmations to shoppers), and keeping our encrypted copy of the database. Global.
- Anthropic: AI drafting for merchants, and the assistant that runs our daily checks and drafts our replies to mail: it reads the mail sent to us and our error logs. US.
- Google: our mailbox (Google Workspace), where mail to support@, privacy@ and abuse@ arrives. US.
- GitHub: makes our nightly backup. It reads the database over an encrypted connection and encrypts the copy before it's stored. US.
We also disclose data when the law requires it, or when it's needed to protect people from fraud or harm.
International transfers
Featherstall's database is in the United States, and our web servers run in several regions, so your data may be handled outside your country. Where the law requires safeguards for these transfers, we use the European Commission's Standard Contractual Clauses, with the UK Addendum for UK data. For shopper data, they're part of our Data Processing Addendum with each merchant.
How long we keep data
- Sign-in links: unused links are deleted after 2 days. Used links are kept for 180 days, so sign-in limits can recognise your network.
- Sessions: until they expire after 30 days, or you sign out.
- AI draft counts: 2 days.
- Photos you upload but never use: 1 day.
- Domain claims you never verify: 7 days.
- Your account, your latest terms acceptance, and your stores: while your account is open.
- Orders: until 30 days after the store is closed, or until the store erases a shopper's details. We then keep only amounts, currency, dates and our fee, without the shopper's details, for our accounts.
- Backups: our hosting provider keeps backups of the database for 10 days, and our own encrypted copy is deleted after 7. Anything deleted from the database, such as shopper details a store erases, is gone from them within 10 days.
- Server logs: for the limited time our hosting provider keeps them.
Security
- All connections to Featherstall use HTTPS. Plain HTTP is redirected, and browsers are told to use only HTTPS for a year.
- Cookies that carry data are encrypted. Session tokens and sign-in links are stored only as hashes.
- Stores run no JavaScript, and a strict content security policy stops pages from loading anything from other sites.
- Access to the database is limited to the app and the people who run Featherstall. Our keys for providers are kept as secrets on our host, and limited to what the app needs where the provider allows it.
- If a breach affects your data, we'll tell affected merchants without undue delay.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, and to object to or restrict how we use it. Where we rely on your consent, you can withdraw it at any time. Merchants can write to privacy@featherstall.com. Shoppers should see Shoppers. We may need to confirm who you are before we act. You can also complain to your data protection authority.
Changes
We'll post changes here and update the date at the top. We'll email merchants about material changes before they take effect.
Contact
[owner's legal name], doing business as Featherstall, [mailing address]. Email privacy@featherstall.com.