Privacy Policy
Last updated 28 September 2026
This policy explains what information shopat collects when you run a store or shop on one, how it is used, and the choices you have. It is written to be read — if anything is unclear, email support@shopat.app.
shopat is operated by Shopat (“we”, “us”). It covers shopat.app, the store dashboard at app.shopat.app, and every store page, such as yourstore.shopat.app.
The short version
- We collect only what's needed to run stores and carts. There's no advertising, no analytics tracking and we don't sell your data.
- Shoppers don't create accounts. A cookie remembers their cart on their device.
- When a shopper sends a cart, the store they send it to can see it, including any notes they wrote.
- Our database and servers are in India (Mumbai).
- You can ask us to see, correct or delete your information at any time.
Information we collect
From store owners: your email address and password (stored only as a one-way hash — we can never see it), your store details (name, link, Instagram handle, tagline, logo and other settings), your products, prices, stock and photos, and the changes and notes you make on requests.
From shoppers: the items in your cart, any notes you add for a store, and the carts you send. Please don't put sensitive information in notes — keep it to what the store needs, such as your delivery city.
Technical information: like every website, our servers see your IP address and basic request details. We use IP addresses briefly to protect the service (for example, to limit repeated login attempts), and they may appear in server error logs.
Cookies
We only use cookies that are needed for shopat to work. We don't use advertising, analytics or tracking cookies.
- Cart cookie (sid): an anonymous random identifier that keeps a shopper's cart on their device, for up to a year. It is set per store.
- Login cookie (osid): keeps a store owner logged in to the dashboard for up to 30 days.
- Message cookies: store one-time messages (such as “Saved”) for up to a minute.
How we use information
- To run shopat: show stores and products, keep carts, turn a cart into a shareable link, and let owners manage their requests.
- To keep shopat secure and working, and to fix problems.
- To contact store owners about their account or important changes to the service.
We don't sell personal information or use it for advertising.
Who can see what
- The store you send a cart to can see everything in it, including your notes. What they do with it, and your conversation with them on Instagram, is between you and the store. Instagram's own privacy policy applies to your chats there.
- Anyone with a sent-cart link can open it. Links are long and random so they can't be guessed, but only share them with the store.
- Service providers that run parts of shopat for us: Supabase (database, hosted in Mumbai), Amazon Web Services (servers, Mumbai), Cloudflare (image storage, backups and DNS) and Google Fonts (the fonts on our pages load from Google, which receives your IP address when they do). They may only use the information to provide their service to us.
- Authorities, but only when the law requires us to share information.
Where information is stored
Our database and servers are in Mumbai, India. Product images and backups are stored with Cloudflare in the Asia-Pacific region, and images are delivered through Cloudflare's global network so they load quickly wherever you are.
How long we keep it
- Carts that haven't changed for 60 days are deleted automatically.
- Sent carts are kept while the store exists, so the store can refer back to your order.
- Store owner information is kept until the account is deleted.
- Dashboard logins expire after 30 days.
- Database backups are kept for 30 days and then deleted.
Your choices and rights
You can ask us to show you the personal information we hold about you, correct it, or delete it. Store owners can also ask us to delete their store and account. Email support@shopat.app from the address on your account (or, as a shopper, include the cart link) and we'll respond as soon as we can. If you want a sent cart removed, you can also ask the store you sent it to.
Children
shopat is not meant for anyone under 18. Store owners must be 18 or older. If you believe a child has given us personal information, contact us and we'll delete it.
Security
All pages are served over HTTPS, passwords are stored only as hashes, and access to our systems is restricted. No system is perfectly secure, so please use a strong, unique password for your dashboard.
Changes to this policy
If we change this policy, we'll update the date at the top. For significant changes, we'll let store owners know before they take effect.
Contact and grievances
For questions, requests or complaints about how your information is handled, contact our grievance officer, Shopat, at support@shopat.app. We aim to acknowledge complaints within 48 hours and resolve them within 30 days.