Legal
Privacy policy
How we process personal data as a controller (merchants, visitors) and as a processor (buyers, on behalf of merchants).
Draft, last updated 2026-10-10. The operating company is being incorporated; every [ENTITY — D-006 pending] placeholder will be replaced with the registered details before launch, after counsel review.
1. Who we are
Snailcart is operated by [ENTITY — D-006 pending], [REGISTERED ADDRESS — D-006 pending]. Contact for privacy matters: hello@snailcart.com. We are established in the European Union and process personal data under the GDPR.
2. Two roles
Controller: for visitors to this website and for merchant accounts (sign-up, team members, billing, support), we decide why and how data is processed.
Processor: when a merchant uses Snailcart to run a checkout, the merchant is the controller of their buyers' data and we process it on the merchant's documented instructions under our Data Processing Agreement. Payments are processed by Whop, the merchant of record, under Whop's own privacy policy; card data never reaches Snailcart.
3. What we process and why
- Merchant account data (name, work email, password hash, organisation, role): to provide the service. Legal basis: contract (Art. 6(1)(b)).
- Buyer order data (email, delivery address, phone if given, items, amounts, consent timestamps): to run the checkout and create the order in the merchant's store. Legal basis for the merchant: contract with the buyer; we act as processor.
- Technical logs (IP address, user agent, timestamps, request ids): security, rate limiting, fraud prevention, debugging. Legal basis: legitimate interest (Art. 6(1)(f)). Retained for 90 days.
- Audit logs of merchant actions: accountability and dispute evidence. Retained for the life of the account plus 24 months.
- Analytics on this website: only with your consent (cookie banner). Legal basis: consent (Art. 6(1)(a)). Hosted in the EU.
- Leads (demo, waitlist, partner forms): to reply to you. Marketing email only with the separate consent box. Legal basis: consent / pre-contractual steps.
4. Recipients and subprocessors
We share data only with the subprocessors listed on our Subprocessors page, each under a data processing agreement and, where data leaves the EEA, Standard Contractual Clauses or an adequacy decision. We do not sell personal data.
5. Retention
Order and payment records: as long as the merchant uses the service and thereafter as required by tax and commercial law (up to 10 years for accounting records in several EU member states). Account data: deleted or anonymised within 90 days of account closure, unless a legal obligation or an open dispute requires longer retention. Logs: 90 days.
6. Your rights
You can request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, and withdraw consent at any time. Buyers should contact the merchant first; we assist the merchant. You can complain to your supervisory authority; ours will be named once the entity is registered (D-006).
7. Security
Data is stored in the EU. Access tokens and secrets are encrypted at rest, sessions are httpOnly cookies, every webhook is signature-verified, and card data is handled only inside Whop's payment elements (PCI DSS SAQ-A scope for us). See the Security page in our documentation.
8. Changes
We will post changes here and, for material changes affecting merchants, give 30 days' notice by email.
Questions: hello@snailcart.com