Scope and contact
This Notice covers the Horcrux website, waitlist, accounts, dashboard, platform administration, support, and platform billing. For privacy questions or requests, email horcrux@dropoutstudio.co with the subject “Privacy request”. A storefront merchant controls the shopper and order data it collects for its own sales; Horcrux processes that data to provide the service under the DPA.
Information processed
We process account identity and sign-in records; verified emails; tenant, membership and permission records; merchant identity, catalog, customer, order, inventory, policy and media content; billing invoices and verified payment references; courier configuration and shipment evidence; support, feedback, feature-request, compliance, audit, consent, export and deletion records; and bounded technical events needed to operate and secure the service.
We do not retain source IP addresses in application sessions, history, security emails, audit records, or rate-limit records. Cloudflare may process request IP and device metadata at the network edge. We do not store raw payment credentials, SSLCommerz panel credentials, courier secrets in plaintext, or shopper-entered transaction IDs as proof.
Sources
Information comes from account holders, merchant staff, shoppers interacting with a merchant storefront, connected providers, authoritative payment and courier callbacks, the browser, and human platform operations. Merchants decide what lawful product and customer content they submit.
Purposes
We use information to authenticate people; provision and isolate stores; run storefront, checkout, order, inventory, billing, courier, email, support, export, recovery, security and compliance functions; preserve accepted transaction evidence; prevent abuse; satisfy legal duties; and improve the product only through approved, consented analytics.
Processing grounds and roles
Processing may be necessary to provide the requested service, perform the merchant agreement, protect the service and people, comply with law, or act on a specific choice. Optional PostHog product analytics requires a current affirmative grant and can be denied or withdrawn.
Providers and disclosures
Cloudflare provides Workers, D1, KV, R2, Images, Queues, Workflow, network delivery and security. Resend delivers account and merchant email. Google authentication is optional and used only when enabled. Google Fonts may receive ordinary browser requests for the public font files currently referenced by Horcrux. PostHog remains disabled unless its policy revision, explicit consent, production flags and project token are all current.
Merchant-directed SSLCommerz and courier connections process shopper, payment, address and delivery information under the merchant’s instructions and their own terms. They are not Horcrux subprocessors merely because a merchant connects them. We may disclose limited information when required by law, to protect rights or safety, or during a properly controlled business reorganization.
International processing
Cloudflare, Resend, Google, PostHog if enabled, and merchant-selected providers may process information outside Bangladesh. We minimize disclosures and use contractual and technical controls where applicable.
Browser and edge technologies
Necessary or functional technologies include authentication and security cookies, a random public-roadmap support cookie, cart storage, checkout/recovery state, storefront search state, and Cloudflare security features. The support cookie is HttpOnly and stores no identity or request content; Horcrux stores only its SHA-256 identity. Horcrux does not add a generic cookie banner where only necessary or functional storage is used.
Optional PostHog storage is created only after a current affirmative grant. Denial or withdrawal resets the SDK and removes Horcrux-scoped PostHog local storage, session storage, and cookies. The Privacy link beside the preference control returns to this inventory.
Retention
Active stores and stores disabled for nonpayment retain merchant data subject to merchant-directed deletion. Closure and eligible account-deletion recovery lasts 30 days. Required digital-commerce transaction evidence is retained for at least six years from the record date with unnecessary personal information detached or redacted. The separate PDPA processing register is retained for at least five years and does not authorize retaining every underlying datum. Security and non-secret email-delivery metadata is retained for 90 days and production logs for seven days as conservative Horcrux policy limits. Used, invalid or expired authentication secrets are erased immediately; deletion propagates through recoverable backups within 30 days as a conservative Horcrux policy limit.
Feedback marked as spam is deleted after 90 days. Terminal private submissions have contact, identity, and content redacted after 24 months. Curated public requests and opaque supports remain while published; withdrawn support identities are deleted after 90 days. Legacy trial identity records and their recoverable backup copies are deleted within 30 days of the no-trial migration. The final retention schedule must be checked against current legal and tax requirements.
Feedback and roadmap publication
Public feedback may include an optional reply email. Authenticated feedback is associated server-side with the verified account, immutable store, and originating dashboard section. Reviews, suggestions, and general feedback remain private. Only a feature request with explicit public-consideration choice may be rewritten by an authorized moderator into an anonymous public roadmap item.
The public roadmap never exposes raw submissions, reply emails, account or store identity, anonymous browser identifiers, internal notes, or moderation reasons. Support identities are opaque hashes used only to prevent duplicate support and honor withdrawal.
Security
Controls include tenant authorization on every protected request, least-privilege staff permissions, encrypted provider credentials and actionable-email links, hash-only public tokens, session revocation, audit trails, rate limits, isolated preview resources, durable queues, backups and recovery procedures. No service can promise absolute security.
Requests and choices
Email horcrux@dropoutstudio.co with the subject “Privacy request”, the account or store involved, and the action requested. Depending on applicable law and context, requests may include access, correction, deletion, restriction, objection, portability or withdrawal of consent. We verify identity and authority, protect other people’s rights and immutable legal evidence, and explain any lawful limitation. Statutory right names, deadlines and appeal language follow current applicable law.
Children
Horcrux merchant accounts are for people able to form and administer a business agreement. Merchants must not knowingly use the platform to collect children’s information unlawfully. Contact us if information appears to have been submitted contrary to this requirement.
Automated decisions
Horcrux does not use an automated prohibited-commerce score to punish merchants and does not create a cross-store shopper blacklist or opaque fraud score. Signals require human review before compliance suspension. Store-local transparent checkout rules remain merchant-authored.
Changes and complaints
We publish revision and date information and require a fresh affirmative analytics grant after a relevant policy revision. Privacy complaints may be sent to horcrux@dropoutstudio.co.