Privacy Policy
Last updated: April 2026
This Privacy Policy describes how Maker Labs (“Maker”) handles personal information across two relationships: merchants and their staff who use Maker to run their store, and customers of merchant stores whose data flows through Maker as part of the merchant's operations.
1. Roles
Where you are a merchant or staff member, we act as a controller of your personal information. Where we process information about your customers on your behalf, we act as a processor; the merchant is the controller. Our Data Processing Addendum describes that relationship.
2. What we collect
From merchants and staff
- Account data: name, email, password hash, avatar URL.
- Store data: legal name, address, tax and bank identifiers as required for payments.
- Usage data: IP address, user agent, actions in the Admin (who did what, when — the Activity log).
- Billing: payment method details are handled by Stripe; we store only a token and last-4 digits.
From customers of merchant stores
- Order data: name, shipping and billing addresses, phone, email, line items, order total.
- Account data (if the customer created one): email, password hash, saved addresses.
- Device and usage data for cart-recovery and fraud prevention.
3. How we use it
- To operate Maker: authenticate merchants, run the Admin, process webhooks.
- To process payments and remit to the merchant's connected Stripe account.
- To send transactional emails (order confirmations, password resets, staff invitations).
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations (tax, sanctions, law enforcement requests).
- To improve the product, in aggregated or de-identified form only.
We do not sell personal information. We do not serve third-party advertising inside Maker and we do not share merchant data or customer data with advertisers.
4. Sharing
We share personal information with subprocessors that help us run the service: Stripe (payments), Resend (email), Railway (hosting), Cloudflare (edge), and Sentry (error monitoring). Current list at /legal/subprocessors.
We may disclose information if required by law, subpoena, or to protect the rights and safety of users or the public.
5. International transfers
We process data in the United States and the European Union. Where applicable, we rely on Standard Contractual Clauses for transfers out of the EU/UK.
6. Retention
Merchant account data is kept for the life of the account plus up to 30 days after cancellation. Customer order data tied to a merchant's store follows the merchant's retention schedule; defaults are 7 years for tax records and until deletion on request for everything else.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Customers of merchant stores should direct these requests to the merchant. Merchants and staff can email [email protected].
8. Security
We use TLS for data in transit, encrypt backups, store passwords with modern hashing, and scope access to personal data on a need-to-know basis. No system is perfectly secure, so we also run continuous monitoring and publish incidents at status.mker.ai.
9. Children
Maker is not directed at children under 16 and we do not knowingly collect their data.
10. Changes
We'll post material changes here and notify merchants by email or in-app banner at least 30 days before they take effect.
11. Contact
Privacy questions go to [email protected].