A draft for review
Privacy
A plain-language account of what this storefront does in demo mode and what a live merchant implementation still needs to document.
Draft/demo notice. This is not legal advice or a merchant-approved privacy policy. Legal review, the responsible business identity, effective date, retention details, and final rights process are still pending before launch.
Demo behaviour
The demo keeps bag and wishlist activity in the browser's local storage so those choices can persist on this device. The selected shipping region used by the demo cart is also kept locally. These features do not require an account; clearing browser storage or using another device can remove or change the local state.
In demo mode, browsing and adding items to the bag does not create an order or collect payment. The storefront should not be treated as a live fulfilment or customer-record system.
Commerce data when connected
A live checkout and customer-account setup may handle information needed for commerce, such as a name, delivery address, checkout email, order details, account information, and payment status. Shopify, payment, delivery, and support services should receive only what the merchant-approved setup requires for its stated purpose.
The final policy must identify the responsible merchant, live service providers, purposes, retention, rights process, and any cross-border handling. Those details are not configured in this demo.
Contact & newsletter
The contact page has no active support form because no support email is configured. No contact message can be sent or stored by this storefront through that page.
The footer newsletter is optional but unavailable until a merchant-approved newsletter destination is configured. No newsletter subscription is created by this demo.
Payment proof
The demo payment-proof flow checks a selected JPEG, PNG, or WebP image in the browser and in the server request, then discards it. It does not look up an order, store the file, collect payment, or mark an order paid.
If the live workflow is configured, a receipt can be stored in private object storage for staff review and the related order remains pending until staff verifies the transfer. Access controls, retention, deletion, and processor terms for that workflow still need to be stated in the merchant-approved policy.
Accounts, cookies & choices
Customer Account sign-in is optional and configuration-dependent. If enabled, the server uses secure, HttpOnly session cookies to maintain the provider-backed sign-in; the account page does not ask for or keep a password in browser storage.
The final policy should explain access, correction, deletion, marketing preferences, cookies, account sessions, and the available contact route. This draft does not invent a legal entity, effective date, response promise, or privacy guarantee.
Questions
For the current support handoff, use Contact. For the storefront's current delivery and returns draft, see Shipping & returns. Legal approval remains pending.