Aster 平台与店铺协议全集

17 份双语草案 · 145 节条款 · 律师审阅版本

SaaS 服务条款

商户与平台的服务合同、职责边界、数据权利与终止安排。律师待审草案。

1. 草案状态与合同主体

本文件为按产品方案编写的待审草案,未由执业律师审核,不构成已生效合同或法律意见。拟由 example(注册编号 example,注册地址 example,注册地 example;以下称“Aster”或“平台”)向商业客户提供服务。正式上线前须填写全部 example 项、明确适用法并完成当地律师审查。网站:https://example.com;法律联系:legal@example.com。

2. 适用范围、资格与接受

服务面向为经营目的建站的企业及有行为能力的经营者。代表客户开通账号的人须有签约权限。正式合同仅在客户看到并主动接受明确版本的本条款及订单后成立;勾选框不得预先勾选。平台保留订单、条款版本、语言、接受时间及必要的接受记录,并向客户提供可保存的副本。浏览预览站不构成付费订阅。

3. 文件组成与优先顺序

正式签署的订单列明套餐、额度、计费周期、支持及任何附加服务。订阅政策、AUP、AI条款及适用的SLA构成合同组成部分。就个人数据处理而言DPA优先;已有效签署的跨境标准条款按其自身规则优先。经双方明确签署的特定约定优于一般条款,但不得减少强制性法律权利。隐私和Cookie告知说明处理活动,不能替代法定同意。

4. 平台与商户的角色

Aster提供建站、商品管理、订单编排、支付接口、售后和AI辅助软件。商户是其店铺商品和服务的卖方,负责商品合法性、价格、税务、配送、消费者权利和退款。Aster不作为店铺交易的 merchant of record,不代收或托管消费者货款,不提供银行账户、托管、资金担保或金融建议。各方的实际法定身份仍按真实业务活动认定,不能仅凭本条排除法定责任。

5. 账号、安全与权限

客户应提供准确的企业和联系资料、为管理员启用多因素认证、按工作职责分配权限并及时停用离职人员账号。客户负责其授权人员的使用行为;平台仍须履行自身安全义务。PSP密钥只能通过受保护的凭据配置进入系统,不得放入公开页面、AI提示词或客服对话。发现凭据泄露或异常访问时,双方应立即通过 security@example.com 配合隔离和调查。

6. 许可、内容与AI输出

在已付费期限内,平台授予客户非独占、不可转售的服务使用权,允许客户运营其获准店铺。客户保留其商品资料、商标、上传内容及业务数据的权利,并仅授权平台为提供、安全维护和支持服务处理这些资料。平台保留软件和通用组件权利。AI输出可能不具有独占性或可保护性;客户须核查来源、侵权风险及事实,不得将生成结果表述为平台或律师保证。

7. 支付、资金与退款权限

商户应与PSP直接签约并接收店铺结算;平台订阅通过平台自己的PSP账单单独收取。平台不收集或保存完整PAN或CVV。支付结果以经验证的PSP事件及对账结果为依据。退款执行须由商户授权员工逐笔审批,并在执行时核查已扣款或符合PSP退款条件的已结算金额、已退金额、处理中金额及币种;不得超过真实可退余额。PSP限制不免除商户另行履行法定退款的责任。

8. 服务提供、第三方与部署

订单应明确托管服务与自部署软件的实际范围。SaaS官网能够自行托管或部署在Cloudflare Workers,并不表示整套交易后台已可用同一方式部署,也不自动授予平台源码或生产系统自托管许可。第三方PSP、域名、物流、AI及分析服务可能适用另行条款和费用,须在启用前披露。平台对选择、配置和维护其分包服务应尽合理注意,不以第三方原因概括免除自身义务。

9. 费用、暂停与变更

费用和续订按订阅政策及结账确认执行;不得因使用量超过额度而自动产生未同意费用。重大功能缩减或价格调整应至少提前30日告知并在下一续订期生效,法律要求更长或再次同意的从其要求。对欠费、违规或安全风险,平台应采取必要且适度的措施;除紧急、违法或受限制情形外,应告知原因并提供合理整改机会。暂停不等于取得商户资金或无需处理消费者请求。

10. 保密、保证与责任

双方仅为履约使用对方非公开商业和技术信息,并使需要知悉的人员承担保密义务;依法披露时在允许范围内预先通知。平台承诺以合理技能和注意提供正式服务,但不承诺特定销量、SEO排名、无欺诈或AI永不出错。普通合同损害赔偿拟以引起索赔前12个月实付服务费为上限;保密、数据保护和知识产权索赔拟以该金额的两倍为上限,均须当地律师确认。欺诈、故意不当行为及法律不得限制的责任不受限;商户消费者义务不受上述平台合同上限影响。

11. 终止、数据导出与存续

客户可按订阅政策取消续订。发生重大违约且在书面通知后30日未纠正的,守约方可终止;不能补救的严重违法或安全风险可立即限制必要功能。正常终止后提供30日只读导出期,范围为商品、订单、客户、内容和许可允许导出的资源;之后按DPA删除。因平台无客户过错而提前结束已付服务的,应按未提供期间比例退款。应付费用、保密、已产生的权利、争议处理及法定保存义务按其性质存续。

12. 法律、争议与通知

拟适用法律:example;拟管辖法院或争议机构:example。这些字段未确定前不得作为最终管辖条款发布。双方先向 legal@example.com 提出争议并善意协商30日,但不妨碍紧急救济、法定期限或监管投诉。正式通知发送至订单约定地址或电子邮件。中英文应保持等效;不得因切换语言减少一方权利。若当地法要求某语言、法院或不可放弃救济,应优先适用该强制规定。

13. 第三方索赔与防御

对于第三方主张平台按约提供且未经客户改动的软件侵犯其知识产权的索赔,平台拟承担合理防御及依法或经同意和解确认的金额,并可取得继续使用权、修改为非侵权方案或终止受影响功能及退还未使用预付费。对于客户无权提供的内容、违法商品或故意滥用造成的第三方索赔,客户拟承担与其过错相称的防御责任。任何一方均须及时通知、合理配合、允许适当控制防御;未经受影响方同意不得承认其责任或施加非金钱义务。上述安排须结合责任上限、当地法和保险审定,不适用于转嫁另一方自身过错。

14. 一般条款与合同完整性

超出合理控制的事件影响履约时,受影响方应及时通知、减轻影响并恢复履约;不因此免除已到期付款、保密、数据保护或依法应作的退款。未经另一方同意,不得将合同转让给不能履行义务的主体;合法重组转让应提供通知并保障数据和既有权利。本合同不设合伙或代理关系。未立即行使权利不构成放弃。明确接受的合同文件构成相关服务的完整约定,但不排除欺诈、法定陈述责任或消费者强制保护。

订阅、续费、取消与退款政策

月付与年付、明示授权、取消入口和争议账单的拟议规则。律师待审草案。

1. 建议价格与适用范围

本政策只适用于Aster向商户收取的软件订阅费,不适用于店铺消费者订单。预览建议价以美元计:Launch每月39或每年390;Grow每月99或每年990;Scale每月249或每年2490。年付为一次支付12个月服务费,金额等于10个月月付价格,约节省16.67%,不是按月扣费。价格尚未构成可购买的正式报价;最终金额、税费及额度须在生产结账中确认。

2. 订阅确认与主动同意

扣款前页面须紧邻购买按钮显示套餐、当期总价、计费币种、税费、开始日、周期、续费金额与日期、是否自动续订,以及直接取消方式。自动续费须由客户通过未预勾选的独立授权控件主动同意,并保留证据。价格、周期或加购变化不能仅依赖已保存卡片授权;对依法需要重新同意的变更应重新获取同意。营销订阅同意与付费订阅授权分开。

3. 收费、额度与第三方费用

本方案不提供会自动转付费的免费试用,也不进行自动超额收费。达到额度时,应提示可选升级或暂停新增受限操作,保留已存在的订单、退款处理和数据访问所需能力。客户只有在看到新增费用并明确确认后才承担升级或加购费。PSP处理费、域名、配送、税务申报和客户单独接入服务的费用不包含在软件费内,须由实际供应商或订单逐项说明。

4. 续订与提醒

仅在已获得有效授权时,订阅按所选月度或年度周期续订。拟议服务承诺:年付至少提前30日和7日提醒,月付至少提前7日提醒,列明金额、日期及取消链接;如适用法律要求不同的时限或格式,则从其规定。续费涨价至少提前30日通知且不追溯当期;因通知时间不足无法合法应用新价时,应延期变更或取得有效同意。提醒失败应记录并提供处理途径。

5. 直接取消与效果

客户可在“工作区设置 → 账单 → 取消续订”完成线上取消,无需拨打电话、解释理由或先与Agent聊天。操作成功立即给出确认、终止日期及可保存回执。无法登录时可联系 billing@example.com 进行相称的身份核实后办理。取消在下次续费前提交即停止后续续费,现有已付服务通常持续至周期结束;删除支付方式或不使用服务不等于取消。撤回授权后不得再收取未获同意的后续款项。

6. 升降级及支付失败

升级前应展示按剩余天数计算的差价并要求确认;降级默认下期生效,不追溯扣减已付权益。付款失败应通知客户并提供更新方式,拟给予7日宽限期;未经授权不得更换收费商品或尝试其他未授权付款账户。宽限期结束可限制新增发布和AI额度,但应保留合理的取消、账单查询、既有售后及数据导出路径。为避免中断,客户须保持账单联系资料有效。

7. 退款及争议

除法定权利、重复或错误扣款、未经授权续费、未交付服务、平台过错或另行书面承诺外,因客户自愿停止使用所产生的当期费用不按比例退还。年付不是不可退款的绝对承诺;适用的强制退款权利优先。客户可向 billing@example.com 提供账单号申请人工复核,拟在5个工作日内答复。获准退款退回原支付方式;处理时点及PSP到账预估应分别通知,平台不以AI风险评分单独拒绝退款。

8. 税费、记录与规则状态

正式账单应列明开票主体 example、税号 example、税种与应税金额;依法需要含税标价的地区不得只在付款末步增加税费。账单币种以结账确认及发票为准,发卡行或换汇服务可能另行收费。自动续费规则按销售地、客户身份和有效法律核验;本政策未宣称2024年FTC click-to-cancel修正规则仍生效。主动作出续费选择和便捷取消是本方案的产品承诺,不能替代法域审查。

9. 套餐额度与AI credits

预览拟定Launch、Grow、Scale分别允许1、5、20个活动店铺(含草稿),1,000、10,000、100,000个活动SKU,以及2、10、30个团队席位,最终额度和计数范围须在购买前显示。AI credits按每个订阅月分别发放500、3,000、10,000,当月有效且不结转;年付也按月发放,不一次预发全年。额度应与套餐表及订单一致。拟议任务示例为短文或单项翻译1 credit、单商品内容包3 credits、单内容页5 credits、限定模板店铺初稿10 credits;这些示例只适用于预先列明的长度、输入、页面和模型范围,不代表无限内容。执行前显示最大消耗及范围;超出范围须先提供新估价并获得明确确认。失败任务返还预留额度,同一逻辑任务的自动重试不重复计费。主动选择不同内容的新任务应再次确认。额度没有现金价值,不自动购买补充包,也不因额度耗尽阻断法定售后。

平台隐私声明

平台自身账号、订阅、访问及安全数据的处理说明。律师待审草案。

1. 我们是谁及处理身份

本待审声明拟由 example(地址 example;privacy@example.com)发布。对于平台访问者、商户账号、订阅账单及自身安全管理,example在决定处理目的和方式的范围内作为控制者。对于受商户指示处理的店铺消费者、订单和客服数据,Aster按DPA作为处理者;消费者应首先联系实际卖方。需要指定的隐私负责人、当地代表或数据保护官及监管机关为 example,须完成适用性判断后填写,不能虚构任命。

2. 信息类别与来源

拟处理的信息包括姓名、工作邮箱、企业资料、登录和角色信息、订阅账单资料、PSP令牌及交易引用、支持请求、IP和安全事件、设备及经许可的访问数据。信息来自本人、获授权的企业管理员、PSP与接入供应商,以及使用服务时生成的记录。完整PAN、CVV、账户密码、私钥及不必要的敏感资料不得进入平台表单或AI提示。具体采集字段须与发布前数据清单逐项一致。

3. 目的及适用的法律依据

开通和履行个人作为当事方的服务合同,以履约所必要的处理为依据;企业联系人管理、安全防滥用和服务维护在适用情况下以经过利益衡量的合法利益为依据;开票和法定保存依法律义务处理。可选营销及依法需要同意的追踪以独立同意为依据。拒绝可选同意不影响基础服务;履约必要字段缺失可能导致无法创建账号或完成订阅。上述依据适用于认可该分类的法律体系,其他法域须另行映射。

4. 接收方、AI及禁止二次利用

为实现上述目的,必要数据可提供给受合同约束的基础设施、事务邮件、支持和AI供应商,以及独立履行付款或法律职责的PSP、顾问和机关。正式接收方和处理地点见发布后的清单,当前为 example。方案默认不出售个人信息、不以跨情境广告共享个人信息、不将商户或消费者数据用于训练通用模型;任何拟改变须事先重新评估、披露并获得必要授权,不能以更新通知默示扩大DPA指令。

5. 地点、跨境与保存

主要处理地、备份地及远程支持访问地为 example,须同时考虑接收方所在地和远程访问。受限制的跨境传输仅在确定合法机制后启用,例如适用的充分性决定、已签署并填妥附件的标准条款及必要补充措施。活跃账号资料保留至合同结束和导出期届满;拟议删除安排为导出期后30日删除生产数据、90日内轮替备份。发票、安全证据和法定留存的具体期限为 example,须给出法律及目的,不得无限期保留。

6. 权利与请求

按适用法律,个人可请求访问、更正、删除、限制、可携带副本、反对特定处理及撤回同意,并可向有权监管机关投诉。请求发送至 privacy@example.com;核实身份仅索取相称资料,不要求提供完整支付卡。撤回同意不影响撤回前合法处理。平台在适用法定期限内响应;不得把商户账单争议作为拒绝法定权利的理由。涉及店铺控制的数据,将及时转交商户并依DPA协助。

7. 自动化、安全与未成年人

风控信号用于识别异常和支持人工审查,不单独决定具有法律或类似重大影响的最终拒绝;必要的即时安全限制应可解释并提供人工申诉。拟采用权限最小化、加密、日志和事件响应措施,正式声明只描述已落实并验证的措施。平台面向商业经营者,不针对儿童营销;若得知收集了不应收集的儿童信息,将依适用法律限制、删除或联系合法监护人处理。

8. 可选通讯、变更和联系

营销邮件应提供退订;账单、安全及服务变更通知不混入强制营销同意。重大隐私变更应在生效前清晰告知,并在法律要求时重新获取同意。本草案版本为 draft-2026-10-10,正式生效日为 example。隐私投诉:privacy@example.com;邮寄地址:example。任何“GDPR compliant”“PCI certified”或类似认证声明,须另有真实证据,不因存在本文件而成立。

平台 Cookie 与类似技术政策

区分必要、偏好、统计和广告用途,并定义选择、撤回及登记要求。律师待审草案。

1. 范围与状态

本待审政策适用于 example 运营的 https://example.com 及明确列明的平台域名;联系 privacy@example.com。Cookie、localStorage、像素和指纹等都可能属于存储或访问信息的技术。不是所有机制都采集个人信息,也不是仅有第三方Cookie才受规则约束。生产上线前须扫描真实页面和供应商脚本,并填写本政策的技术清单;预览中的清单参数不表示供应商已经启用。

2. 必要功能

登录会话、购物或订阅流程安全、请求防伪及保存隐私选择可在满足具体适用豁免条件时运行。必要性按用户明确请求的功能判断,不能因为有商业价值就把统计或广告列为必要。必要项应尽量短期、限域并受适当安全属性保护;拒绝可选项目仍可使用不依赖这些项目的核心服务。

3. 偏好、统计与广告

语言、外观偏好和聚合统计须分别说明用途与保存期。方案默认可选统计、广告和跨站追踪为关闭,适用同意要求时在同意之前不得加载或发送请求。英国法律可能对特定统计或外观用途设有条件性豁免及简易反对要求;只有审核并满足所有条件时才可使用,不能据此豁免广告或套用到所有地区。当前方案不预设广告供应商。

4. 同意控件与撤回

首次需要作出选择时,应提供同样容易使用且显著程度相当的“接受可选项”“拒绝可选项”和分类设置。不得预勾选,不以继续浏览或关闭横幅代替有效同意,不将可选同意捆绑服务条款。页面底部持续保留“隐私选择”,允许随时撤回或更改;撤回后停止未来的相关处理并在可控范围内移除非必要存储,同时通知适用供应商。

5. 技术登记表

每个实际项目须在发布清单中列明:名称 example;设置方 example;域名 example.com;用途 example;类别 example;是否第一方 example;持续时间 example;关联接收方与国家 example;同意或豁免理由 example;撤回方式 example。名称相同但用途不同的项目应分开列明。不得把Cookie有效期当作服务端个人数据删除期限;二者均需说明。未识别或未批准的可选脚本不得上线。

6. 记录、第三方与浏览器设置

平台保存必要的选择版本、时间和范围,以证明选择并防止重复询问;不得把选择标识用于广告画像。嵌入内容和外部支付页面可能由独立主体管理,应在跳转或加载前解释其身份及政策。浏览器可删除或阻止存储,但可能影响登录等必要功能。适用地区要求识别通用退出信号时,平台应实现相应处理而不能仅依赖文字承诺。

7. 更新与联系

增加用途、供应商或实质改变保存期限前应更新技术登记,判断是否需要重新同意,并保留旧版本。重大变更在相关脚本启用前告知。版本 draft-2026-10-10;正式生效日 example。问题、清单副本及撤回协助请联系 privacy@example.com。本政策不替代各商户店铺自己的Cookie配置与告知。

数据处理协议与附件

商户控制者与平台处理者的约定,含处理说明、子处理者、安全及跨境安排。律师待审草案。

1. 当事方、范围与指令

本待审DPA拟由订单客户 example(“控制者”)与服务提供方 example(“处理者”)订立,并在双方有效接受后并入服务合同。“个人数据”“处理”“泄露”等按适用数据保护法律解释。处理者仅按控制者可证明的书面指令处理店铺个人数据,包括服务配置、获授权工单及本DPA;不能把消费者数据用于自有广告、出售、训练通用模型或其他独立目的。超出该角色的合法独立处理须单独告知并有自身依据。

2. 处理说明:对象与期限

处理对象为客户获准店铺的建站、商品展示、顾客账户、购物车、订单、履约、支付状态、退款、客服、反滥用及经合法配置的分析。处理性质包括收集、记录、组织、托管、检索、传输、受限自动分析、纠正、导出和删除。期限为服务期、30日导出期及本DPA允许的删除周期。店铺、处理区域及生效日期分别为 example;新增目的、特殊数据或新地区须先更新附件与授权。

3. 数据类别与数据主体

数据主体包括顾客、访客、收件人、商户管理员和客服联系人。允许类别为姓名、联系和地址资料、账号标识、订单商品与金额币种、履约信息、支付令牌和状态、退款记录、必要设备与安全日志、同意记录及支持对话。禁止提交完整PAN、CVV、密码、私钥、未经批准的健康、生物识别或其他特殊类别数据。默认服务不面向儿童;如商户业务不可避免涉及儿童或受保护数据,应另行完成合法性、必要性和加强措施评估后签署特定附件。

4. 控制者责任与违法指令

控制者负责合法来源、处理依据、准确告知、必要同意及向顾客履行义务,并仅发送必要资料。处理者认为指令违反适用数据保护法律时,应立即说明问题并暂停受影响指令直至澄清,不因此擅自改变处理目的。法律强制处理时,处理者在允许范围内预先说明法律要求。双方应指定有权限的联系人:控制者 example / privacy@example.com;处理者 example / privacy@example.com。

5. 保密与安全措施附件

处理者应确保可接触数据的人员受保密义务约束并接受与职责相称的培训。拟议最低措施为租户隔离、最小权限及管理员MFA、传输和静态加密、密钥分离、审计记录、备份与恢复演练、漏洞管理、变更审查及事件响应。具体算法、密钥托管、恢复目标、日志期限、隔离测试和责任人均为 example,须在签署前以已实施证据填妥。未经风险评估不得降低约定保护;本附件不是安全认证。

6. 子处理者登记与授权

采用一般书面授权模式时,控制者授权的是完整清单中实际列明的子处理者,不是任意供应商。每项须填:法定名称 example;服务 example(基础设施/邮件/AI/支持/监控);数据类别 example;所在及处理国家 example;跨境机制 example;安全附件 example。当前条目均为未选择占位,不能据此进行生产传输。处理者应与子处理者约定不低于本DPA的相关义务,并对其履行承担责任。

7. 子处理者变更与反对

新增或替换子处理者拟至少提前30日书面通知,说明用途、地点及保护措施。控制者可基于具体数据保护理由在通知期内反对,双方先采取替代供应商、限制功能或其他合理方案。未解决前不向该供应商传输受影响客户数据;若无合理替代,可终止受影响服务并按未用期间退还预付费。紧急安全替换须事先通知到可行程度并立即补齐说明,不能借紧急情形永久取消反对权。

8. 国际传输附件

数据出口方 example、进口方 example、目的地 example、远程访问地 example、监督机关 example及适用机制 example须逐项填写。对受欧盟限制的传输,如无适用充分性决定,应选择合适的有效标准条款模块、补齐附件及完成转移影响评估和必要补充措施;英国传输另行判断IDTA或UK Addendum等机制。仅引用“GDPR”“SCC”或本段不等于已签署跨境协议。若目的地保护无法维持,应暂停传输并就替代或删除达成指令。

9. 个人权利与合规协助

处理者收到与控制者数据有关的权利请求,应不无故拖延、拟在2个工作日内转交,不未经授权直接作实体决定。按处理性质和可用信息,协助控制者完成访问、更正、删除、限制、可携带及反对请求,并协助安全义务、DPIA及事先咨询。协助安排不得拖延适用法定期限。常规服务内协助包含在服务费中;确属额外范围的工作须事先约价,不能以收费争议阻断必要法定义务。

10. 个人数据泄露处理

处理者知悉涉及控制者数据的个人数据泄露后,应无不当延迟通知控制者,拟定首报目标为24小时,不等待完整调查。通知包括已知事件性质、影响类别和规模、可能后果、已采取措施及联系人,并分阶段更新。处理者应保存必要证据、配合补救,不未经授权代表控制者向数据主体或机关作通知,法律强制除外。24小时是待运营验证的拟议合同目标,不能混同控制者在特定法律下的监管报告时限。

11. 审计、记录与监管

处理者提供证明履行本DPA所需的信息,包括与客户数据相关的控制说明、评估和纠正记录。控制者或受保密约束的独立审计人可通常每年进行一次合理审计;泄露、重大不合规或监管要求时不受年度限制。事先安排、范围保护和合理费用不得实质阻碍法定检查,也不得暴露其他租户数据。双方合作回应合法监管要求;对第三方数据披露请求进行适当核验,并在允许时通知控制者。

12. 返还、删除与存续

服务结束后控制者可选择返还或删除;拟提供30日只读导出期,导出期满后30日内删除生产副本,并在同一导出期满日起90日内通过既定轮替删除或不可逆匿名化备份。备份不得用于其他目的,恢复时须重新应用删除清单。法律确需保留的部分应说明依据、类别、访问限制和期限,并在义务结束后删除。按请求提供删除确认。本DPA在仍有受其约束数据时继续有效,任何未填附件须在生产处理前完成。

可接受使用与禁售政策

商品、内容、营销及平台安全的边界和申诉程序。律师待审草案。

1. 适用责任

本待审政策适用于商户及其授权人员、上传内容、店铺和通过平台调用的自动化。商户须确认销售地、发货地及目的地允许经营有关商品,并获得许可、标签和产品安全文件。AI生成文案或平台未拦截上架不代表商品获批准。平台可设置比当地法律更严格且预先披露的经营限制;政策变化应合理通知并保护已产生的消费者权利。

2. 禁止商品与活动

不得销售非法、盗窃、假冒或侵犯权利商品;不得从事诈骗、洗钱、规避制裁、人口剥削或交易未经授权取得的数据。禁止恶意软件、盗号服务、伪造身份或证件、违法成人内容和涉及未成年人的性剥削内容。方案默认不支持武器、受控药物、赌博、无许可金融产品或其他需特殊监管审批的高风险业务;经明确书面批准且符合法律及PSP规则的例外须另订专项条款。

3. 受限与需要审核的品类

食品、保健品、化妆品、医疗相关产品、电池、儿童用品及其他受专门产品标准约束的品类须提交对应市场的证明及履约方案。不得发布未经证实的治疗、认证、环保或功效声明。适用的年龄限制、标签、召回、生产者或负责人资料应准确展示并保持更新。商户必须设置可执行的召回及顾客通知路径,不能把产品安全义务交由Agent自行判断。

4. 真实营销与评价

禁止伪造顾客评价、订单量、倒计时、库存稀缺、比较价格或独立背书;不得让AI伪装成真实购买者发表评价。折扣、赠品、订阅和推广合作必须说明重要条件及适用披露。不得发送未经允许的批量营销,购买非法邮件名单或通过误导性界面阻碍取消和退款。SEO内容应反映实际商品与服务,不以批量生成方式制作虚假品牌关联或欺骗页面。

5. 技术与数据滥用

禁止探测其他租户、绕过授权或额度、窃取凭据、投放恶意代码、滥用接口和以提示注入诱导泄露秘密。未经许可不得爬取个人资料或将客服、支付和订单数据导出至未批准工具。安全研究应通过 security@example.com 协调,避免破坏、真实消费者数据和持续访问;本草案不自动授予测试生产系统的权限。

6. 检测、措施与通知

平台可依据投诉、明确证据和适度的安全信号调查,采取限制单一商品、暂停高风险操作或限制账号等必要措施。除法律禁止、明显紧急或可能妨害调查外,应说明受影响内容、政策依据、措施范围及申诉路径。不能仅依据未经复核的生成式AI结论没收资产、拒绝消费者权利或作永久封禁。平台应保存必要证据,并控制数据访问和保存期限。

7. 申诉与纠正

商户可向 abuse@example.com 提交决定引用、合法经营证明及纠正措施,要求由未单独依赖原自动结果的人工复核。拟在5个工作日内确认收到,复杂事项给出进度。申诉不阻止必要的暂时安全措施,但通过核实后应及时恢复合规内容。平台应区别善意错误与重复或严重滥用,并在终止时提供依法允许的数据导出与客户售后处理安排。

AI 与自动化使用条款

Agent权限、审批、数据、人工监督及法律文档的控制。律师待审草案。

1. 功能与边界

本待审条款适用于建站、商品内容、翻译、SEO、客服及运营辅助Agent。AI根据用户输入、批准的知识库和获授权工具提供草稿、建议或限定操作;生成结果可能不准确、遗漏上下文或与他人输出类似。平台及Agent不提供专业法律、税务、医疗或投资意见,不能把本模板标为“已由专业律师编写或审定”。具体启用模型和数据处理安排须在供应商清单中确定。

2. 权限与指令层级

Agent只在商户明确授予的店铺、工具、操作和额度范围内工作;对网页、邮件、商品文件和客服消息中的内容应按不可信输入处理。外部文本不能覆盖平台安全规则、商户正式政策或权限控制。操作授权应由服务端验证,并可即时撤回;不能通过在提示词中写“允许退款”等话语绕过独立审批和支付权限。

3. 草稿、发布与敏感操作

商品文案、图片描述、翻译和SEO修改默认进入可预览草稿。商户审阅后才能发布影响公众展示、价格或促销的重要变更。退款、收款配置、结算账户、域名、数据批量删除、权限扩大和协议生效须分别获得明确批准;同意日常客服自动回复不构成这些操作的授权。批准须对应具体内容、金额或操作版本,内容发生变化须重新批准。

4. 退款与消费者权利

Agent可解释已批准的退款政策、收集必要事实、检索订单和起草退款请求,但每笔退款执行须经商户授权员工审批。系统执行前重新计算可退金额并防止重复退款,不能把AI预测当作资金事实。Agent不得最终拒绝法定撤回、缺陷救济、退款或人工复核;对期限即将届满、政策冲突或权益争议应立即转人工,记录请求的原始时间,避免因排队损害权利。

5. 法律文档及翻译

法律文档只能从受版本控制、按法域配置的律师待审模板形成草案;example字段及未确定选项应阻止正式发布。Agent不得自行修改法律结论、适用法律、法定期限、责任限制或消费者权利;这类变更须由商户获授权负责人和适当律师审查。翻译版本应对齐原版本和条款编号,并保留可追溯差异;语言切换不得替换成内容不同的协议。

6. 数据最小化和供应商

发送给模型的数据应限制为完成当前任务所需,并尽可能使用订单引用、脱敏字段或聚合信息。不得提交完整PAN、CVV、密码、私钥或无关个人信息。模型供应商、国家、日志保存和训练使用政策在上线前完成核查及DPA安排;默认禁止通用模型训练和跨租户检索。商户自带模型或插件须通过同样的接收方、权限和跨境审查。

7. 输出核验与记录

商户应检查商品事实、知识产权、文化语言、价格、库存、配送和广告声明。系统应记录必要的输入引用、知识版本、工具调用、审批、结果及撤回,敏感字段需脱敏并按限定周期保存。低风险变更应具备可回滚版本;资金等不可简单撤回操作必须使用专用流程,而不能用“重试一次”代替幂等和对账。

8. 披露、人工接管与停止

面向消费者的会话开始时须说明正在与AI客服交流,并提供可用的人工联系途径和实际服务时间。商户可暂停Agent、撤回工具或切换人工;停用不能抹去已收到的投诉或申请。发现越权、数据泄露、重复交易或明显错误时,平台应停止受影响任务并通知相关负责人。AI错误的责任仍按实际行为及法律分配,本条款不免除平台或商户自身过错责任。

服务等级与支持政策

明确拟议可用性目标、计量、支持窗口和服务抵扣边界。律师待审草案。

1. 草案及适用服务

以下为拟议SLA,须在监控、值班和合同验收后才可作为正式承诺。仅覆盖订单明确包含的由Aster运营的生产托管API和店铺服务,具体服务清单为 example;不自动覆盖预览官网、Beta功能或客户自行部署的系统。自部署支持范围和响应义务须单独约定。宣传页面不得把本草案目标展示为已经测得的历史可用性。

2. 月度目标与计算

拟议月度可用性目标为99.9%。可用性=(合格服务分钟数-受影响不可用分钟数)÷合格服务分钟数。不可用应以双方可核验的外部探测及服务记录识别核心读写或结账API不能成功处理有效请求的时间,测量点、探测频率和判定阈值为 example。账单期、租户和受影响组件分别计量,不得用静态首页可访问掩盖交易接口故障。

3. 维护和排除项

拟议计划维护应至少提前72小时通知,每月排除上限120分钟;超出上限计入不可用,紧急维护是否排除须按具体原因和合同处理。客户自身系统、未经授权修改、客户连接网络或独立PSP本身故障可在有证据的范围内排除;Aster选用的基础设施故障及Aster支付集成错误不得被概括归为“第三方”而全部排除。排除必须与受影响时段存在实际因果关系。

4. 支持等级与时段

拟议P1为核心交易广泛中断、数据隔离风险或重大安全事件,生产付费计划需24×7接收,首次响应目标1小时;P2为重要功能降级且有替代方式,工作时段首次响应4小时;P3为一般问题,2个工作日。实际工作时段、时区、节假日和套餐差异为 example,须上线前填明。响应是确认和开始调查,不是修复保证。支持邮箱 support@example.com;安全邮箱 security@example.com。

5. 服务抵扣

正式采用本方案时,月度可用性低于99.9%但不低于99%可申请受影响月服务费的5%抵扣;低于99%但不低于95%为10%;低于95%为25%,同一月份不累加。年付以年费除以12计算月费。申请应在该月结束后30日内发送至 support@example.com 并附受影响时间;平台自身监控已确认的,无需客户重复举证。抵扣不覆盖PSP费用,也不能减少法定赔偿或重大违约救济。

6. 事件沟通与恢复

平台应通过已约定状态页 https://example.com/status 和有效联系渠道通报重大事件、受影响功能和恢复进展;状态页只是占位,正式上线须可独立使用。恢复方案应覆盖数据完整性、未完成支付事件、重复提交和退款对账。备份频率、RPO、RTO及演练证据均为 example,不承诺未经验证的“零数据丢失”。涉及个人数据泄露时同时适用DPA,无需等待普通支持工单。

7. 持续不达标与变更

若连续两个月低于拟议目标,客户可要求书面改进计划;若连续三个月不达标且实质影响合同目的,可按正式合同终止受影响服务并要求未使用预付费按比例退款。SLA重大不利变更仅在提前通知后的下一续订期适用,不追溯已付期间。所有目标和服务抵扣须与订单一致;未签署或未验证的草案不构成生产可用性保证。

投诉、知识产权与内容处理程序

提供有证据的举报、通知、反通知、人工复核和消费者转介流程。律师待审草案。

1. 联系与职责

平台主体为 example,地址 example。一般投诉 support@example.com;侵权和法律通知 legal@example.com;违法或危险内容 abuse@example.com;隐私事项 privacy@example.com。店铺订单的卖方是商户,平台应帮助识别实际商户和传递请求,不将技术服务身份作为拒绝收到有关平台自身行为投诉的理由。本程序为律师待审草案,不能代替适用法律规定的专门机制。

2. 举报所需信息

举报应尽可能包含相关完整URL、店铺或订单引用、所投诉内容、具体理由、支持证据及可联系的姓名和邮箱。权利人投诉应说明权利类型、权属或代理权限以及被指侵权内容与受保护材料之间的关系。仅要求调查所必要的资料,不要求公开无关身份证或付款信息。匿名或信息不完整的紧急安全举报仍应按证据与风险评估。

3. 接收、调查与处置

拟在2个工作日内确认一般通知,危及人身安全、严重违法或凭据泄露事项尽快升级。审查应考虑明确证据、适用法律和政策,不把AI相似性分数当作侵权结论。必要时可限制特定内容或操作,并在允许范围内通知商户原因、范围、期限及申诉方式。对已移除内容保留受控证据,不继续向公众传播有害材料。

4. 知识产权反通知

商户认为错误移除时,可提交决定引用、内容原位置、拥有权利或获得许可的证据及善意解释。适用美国DMCA或其他法定反通知机制时,应由律师配置其签名、宣誓、管辖同意、送达、转交与恢复期限等要件,不能用本通用申诉替代。美国指定代理人姓名和登记信息均为 example;在实际完成登记之前不得声称已指定或具备安全港保护。

5. 人工复核与重复滥用

商户和举报人均可依据新的实质证据请求人工复核,复核人员不得仅重复自动结果。恶意伪造、反复骚扰或明显滥用通知机制可在适度通知后限制,但不能阻断善意投诉。对重复侵权或严重违法的账号,平台可依法和按合同终止;应区别涉嫌、确认和已推翻的记录,不把所有通知自动视为已证实侵权。

6. 消费者救济与外部渠道

消费者可同时联系商户、付款服务商、适用监管机关或有权争议机构,本程序不要求放弃拒付、诉讼或强制性救济,也不暂停法定期限。适用的ADR机构、登记信息和参加义务为 example,须按商户销售地及真实资格填写。不得链接或声称可使用已经停止服务的欧盟ODR平台;应使用仍有效且适用的当地投诉或ADR安排。

7. 隐私、证据与法律请求

处理投诉只使用必要个人数据,按隐私声明和有依据的期限保存。为使被投诉方答复可能需要转交投诉事实,但不应自动转交无关敏感信息或举报人隐私。执法和法院请求须核实权威、范围和合法性,并在允许时通知相关客户。拟议程序目标不缩短适用法律要求的处理时间或妨碍紧急救济,正式版本和生效日应明确记录。

店铺消费者销售条款

由真实卖方采用的消费者合同,覆盖下单、交付、数字内容及法定救济。律师待审模板。

1. 卖方与模板状态

本文件为供商户及当地律师审阅的模板,尚未生效。本店 example 由 example 经营;注册编号 example,注册地址 example,经营及投诉地址 example,电话 example,邮箱 support@example.com,网站 https://example.com,税号 example。结账页面必须显示实际卖方。Aster提供软件,通常不是本店商品卖方或收款托管方;您的销售合同与页面列明的商户成立,不影响任何主体因其实际行为承担的法定责任。

2. 商品信息与适用范围

本条款适用于商品页和结账页明确销售的实物商品,以及在明确启用并另行说明时销售的数字内容或服务。商品主要特征、规格、材料、尺寸、兼容性、限制、价格、库存及必要安全警示应在购买前展示。图片可存在合理的屏幕色差,但不能改变实际承诺的规格。商户不得仅依赖AI生成内容说明受监管商品、认证、功效或法定权利。

3. 下单、支付义务与合同确认

提交订单前,您可核对并纠正商品、数量、地址、配送及支付资料;最终按钮应明确表示下单产生付款义务。合同在本店发出明确接受订单的确认时成立,单纯“已收到请求”的通知应清楚区别。接受前应核查库存和价格,不得无期限保留接受权。若无法接受已收款订单,应及时说明并全额退还相关款项。我们提供可保存的订单、价格、协议版本和取消资料副本。

4. 价格、币种与支付

应付总额、交易币种、适用税费、运费及其他必要费用在付款前清楚列明;依法须含税显示的价格以含税方式显示。浏览时换算价只有在标明为估算时才是估算,订单接受后不因汇率变化追补商品价。银行卡及其他支付由结账所示PSP处理,卡号和CVV不得通过客服提交。未经明确同意不保存为后续收费授权,不自动增加商品、捐赠、保险或订阅。

5. 配送、风险与延迟

配送地区、发货窗口、预计送达、运费、追踪及进口安排在商品页、配送政策或结账中显示。除依法允许的特殊情况,运输风险在您或您指定的非承运人第三方实际接收商品时转移。若不能按承诺发货或交付,我们应及时说明新的合理日期和您可行使的取消、退款或其他权利,不把预计时间描述为保证。丢件、损坏或错发应联系 support@example.com;快递签收记录不当然推翻相反证据。

6. 撤回、退换与法定保障

您的适用撤回权、缺陷商品救济和其他消费者权利见退换货政策及强制性法律。符合条件的欧盟远程销售通常有14日撤回期,但起算点、商品例外和成员国实施须适当配置。法定缺陷权利不因商业退货期届满、包装打开或商户写有“最终销售”而自动消失。任何商业保修是对法定权利的补充;需要退货授权的内部流程不得阻碍及时提出法定请求。

7. 数字内容与服务分支

只有本店实际销售相关内容时才启用本条,并在购买前说明访问方式、许可、兼容性、功能、更新及使用限制。对适用的非实体载体付费数字内容,若希望在撤回期结束前开始提供,须取得您事先明确同意立即履行、对相应撤回权丧失的明确确认,并提供法定确认;仅下载或打开文件不能替代这些条件。服务提前履行、完成及按比例收费适用不同规则,须另行明确请求和披露,不能套用数字内容豁免。

8. 错误、风控与订单限制

发现明显定价错误、支付异常或缺货时,本店应进行人工核实并通知您,可提出更正后的新要约供您选择;不得擅自增加已确认应付金额。存在具体欺诈或法律风险可采取必要且相称的验证或暂时限制,但不得以国籍、残障等受保护特征作违法区别对待。AI风险评分不单独决定最终拒绝法定权利。未履行或依法取消的已收款订单应依适用期限退还。

9. 客服、隐私与AI

本店可能使用明确标识的AI客服辅助查询和提供已批准信息,您可转人工或联系 support@example.com;实际人工服务时间为 example。AI回答不更改已成立合同或法律权利,商户须纠正其错误。个人数据依本店隐私声明处理,非必要Cookie和营销依据独立选择。隐私声明的存在不表示您已同意全部数据用途,也不授权与合同无关的广告。

10. 责任、适用法与争议

本条款不排除因本店过错产生且依法不得排除的责任,不限制产品安全、缺陷、退款、人身损害或其他强制性消费者救济。拟定合同法律为 example,争议法院或机构为 example,须在发布前由律师确定;若适用法保护您惯常居所地的强制性权利,本条不得剥夺这些权利。您可联系本店、监管机关或有权ADR机构;无需先取得AI或平台许可才能寻求法定救济。

11. 版本、语言与变更

本模板版本为 draft-2026-10-10,正式生效日为 example。购买时接受的版本适用于该笔订单,后续政策变更不追溯降低既有权利。中英文及其他语言必须与同一审定版本对应;对消费者有约束力的信息应满足其适用语言要求。若某项条文不可执行,其他条文在法律允许的范围内继续适用,但不得以替代条款规避强制性保护。

店铺撤回、退换货与退款政策

区分法定撤回、瑕疵救济和商家自愿退货,保留人工处理及期限。律师待审模板。

1. 卖方与适用顺序

卖方 example;客服 support@example.com;退货地址 example;电话 example。本政策为待审模板,实际市场、品类、流程和地址须在营业前填妥。适用法律赋予的撤回、缺陷、未交付和其他救济优先;商户自愿退换安排只能增加权利,不能减少法定保护。AI、反欺诈标签、PSP技术限制或“最终销售”文案不能自行否定您的法定请求。

2. 欧盟适用分支:撤回期限

对受相关欧盟成员国消费者规则保护的合格远程实物交易,通常可在您或指定的非承运人第三方收到商品后14个日历日内通知撤回,无需说明原因。同一订单分批收到商品、分部件交付或定期交付的起算规则须按实际交易配置。服务及非实体载体数字内容通常自合同订立日起计算,相关例外见后文。未正确提供撤回告知可能延长法定期间,不能仍按正常期限拒绝。

3. 提交方式与在线撤回

您可通过 support@example.com、邮寄明确声明或适用的线上“撤回合同”入口 https://example.com/withdrawal 通知。提出撤回无需先取得退货编号,也不强制使用模板。适用在线撤回义务时,入口在撤回期内持续醒目可用,允许确认姓名、订单引用及回执地址,并通过明确的“确认撤回”按钮提交;随后无不当延迟提供含内容、日期和时间的可保存回执。只要及时提交,人工复核排队不改变提出日期。

4. 寄回、费用与商品处理

适用欧盟撤回规则时,除我们同意取回外,通常应在通知撤回后14日内寄回商品,寄出即符合相关寄回期限。只有在购买前依法告知且法律允许时,您才承担直接退货运费;无法通常邮寄的大件应预先说明合理估算成本。因检查商品性质、特征和功能所必要的处理不应被收费;超出必要检查造成的减值,只能在具备法律条件和证据时扣除。不能一概要求未开封或原包装作为法定撤回条件。

5. 退款范围与时间

适用欧盟撤回规则时,我们通常应自收到撤回通知起不超过14日退还已收款及标准交付费用;您自选的较贵配送增量可在法律允许时不退。除我们同意取回外,实物退款可依法暂缓至收到退货或您提供寄回证明之较早时点。退款使用原付款方式,除非您明确同意其他不增加费用的方式;不能强制改为店铺积分。其他法域及未交付退款按其适用期限处理,不能统一等待银行卡到账天数后才发起。

6. 商品例外与数字内容

定制商品、易腐商品和某些拆封后不适宜退还的卫生商品等,只有在法律规定的具体条件成立时才可排除无理由撤回,不影响缺陷权利。非实体载体付费数字内容的提前提供只有在事先明确同意、明确确认相应撤回权丧失、并提供所需合同确认等条件全部成立时才适用例外。服务需区分提前开始、履行完成与比例费用,分别取得所需请求和确认。所有例外须在购买前就适用商品说明,不能一概写“数字商品不退款”。

7. 瑕疵、损坏、错发和未交付

请尽快说明问题并提供合理可得的订单和情况资料;我们不得把拍摄开箱视频、保留所有包装或极短通知期作为一切救济的前提。根据适用法律和情况,可提供维修、更换、减价、取消或退款,并承担依法应由商户承担的必要费用。法定质量保障与无理由退货是不同制度,商业退货期限结束不代表缺陷权利失效。未交付应按配送政策处理,不能要求消费者仅自行向承运人索赔。

8. 自愿退换货安排

法定保护之外的自愿退货期为 example;适用品类 example;合理状态要求 example;直接运费安排 example;换货方式 example。商户未填妥并明确公布前,不得宣传额外“30天无条件退款”等承诺。已作出的更有利承诺应履行。换货缺货时,须与您商定退款或其他选择,不自动替换成更贵商品或要求补差价。

9. 内部审批、可退余额与失败

商户授权员工负责逐笔审批退款,AI只能辅助收集事实和起草。系统核验订单归属、交易币种、PSP允许退款的captured或settled金额、已成功及处理中退款,并阻止超额或重复请求;执行结果须对账确认。内部可退余额校验是资金安全措施,不是缩减法定应付金额的条款。若原渠道失败、已关闭或不足以完成应退款项,我们须及时协调合法且经您认可的替代处理,不将技术故障转嫁为您的权利丧失。

10. 人工复核与争议

若不同意处理结果,您可向 support@example.com 请求人工复核,提供已有订单引用即可开始,不必先与Agent反复交涉。我们拟在2个工作日确认收到并说明合理预计处理时间,但法定退款和撤回期限不因内部目标延长。您仍可向PSP、监管机关、法院或适用ADR机构寻求救济。存在拒付时我们可核对是否已经重复退款,但不以“有争议”为由无限期搁置法定责任。

11. 可选撤回声明

致 example(地址 example;support@example.com):我/我们现通知撤回关于以下商品或服务的合同。订单号:example;商品或服务:example;订购日期:example;收货日期(如适用):example;消费者姓名:example;地址:example;接收回执邮箱:example;日期:example。仅纸质提交需要在适用情况下签名。您也可使用其他明确表达撤回意思的方式;本示例须由当地律师核对是否需使用法定标准表格。

店铺隐私声明

由商户作为控制者告知消费者的用途、接收方、保存及权利。律师待审模板。

1. 控制者及适用范围

本待审声明适用于 example 店铺,由 example 决定顾客数据的处理目的和方式;地址 example,privacy@example.com,电话 example。Aster按商户指令提供技术处理服务;PSP、承运人等在自行决定处理用途时可能为独立控制者。隐私负责人、当地代表或DPO在适用且实际任命时为 example。正式上线须填妥真实身份,不得用平台的主体信息代替实际商户。

2. 数据与来源

我们拟处理您提供的姓名、邮箱、电话号码、收货和账单地址、订单商品、金额币种、退货及客服资料;还可能接收PSP返回的交易引用、令牌和状态、承运人履约信息、必要的登录和安全记录,以及按选择启用的浏览数据。来源包括您本人、您指定的收件人信息和相关服务商。完整PAN、CVV、密码或无关敏感资料不得发送到本店表单或客服;安全支付控件由实际PSP负责。

3. 用途及依据

我们为接受和履行订单、配送、提供售后及完成退款处理必要资料;在适用体系下通常依据合同必要性。税务、会计和产品安全保存依法律义务;适度的反欺诈、系统安全和权利维护在法律允许时以经评估的合法利益为依据。营销、可选追踪及其他依法需同意的用途取得独立选择。缺少必需的地址或支付确认可能无法履约;拒绝营销不影响购买。具体依据必须按商户经营和目标市场核对。

4. 服务商和数据共享

数据仅在实现上述目的所需范围内提供给Aster、实际PSP example、承运人 example、邮件服务 example、获批准的AI服务 example及必要专业顾问或机关。每方的作用、国家、数据范围及政策链接在实际清单中填写,供应商更换前评估合法性。默认不出售个人信息、不以跨情境广告方式共享、不将客服或订单用于训练通用模型。任何不同的真实商业安排都须先审查并准确告知,不得沿用不实的默认声明。

5. 国际传输和保存

处理地区、供应商所在地和远程访问地区为 example。涉及受限制跨境传输时,我们先确认适用机制并提供如何获取保障措施副本的信息,不能把使用全球CDN自动等同于数据仅在某国停留。账号资料期限 example,订单和税务资料 example,客服对话 example,风控及安全记录 example,同意证据 example。每项应填实际期限或清晰标准及法律理由;期限结束后删除或适当匿名化,并对备份和法定留存作具体安排。

6. 您的权利与选择

依适用法律,您可向 privacy@example.com 请求访问、更正、删除、限制、可携带副本、反对处理或撤回同意,并向有权机关 example 投诉。我们进行相称身份核验并在适用期限内答复,不把有争议的订单或未付费用作为拒绝法定请求的理由。删除可能受税务、产品安全或诉讼保存限制,但我们应解释范围和依据。退订营销或撤回Cookie同意不会自动取消订单。

7. 风控、AI及人工复核

我们可能分析订单及必要设备信号以识别异常,并通过标识为AI的客服解释已批准政策。AI风险评分不单独决定最终拒绝法定退款或具有重大影响的商户决定;您可请求人工审查、表达观点并纠正错误。独立PSP可能有自身安全验证和决定,应提供其联系或政策。客服应仅访问解决当前问题所需的订单,未经身份验证不得披露收件地址或其他顾客资料。

8. 儿童、安全和更新

本店是否面向儿童为 example;商品面向儿童不当然授权收集儿童个人数据。涉及年龄或监护人授权时应选择必要且相称的机制,不能仅靠一般条款确认。我们实施经验证的访问、加密和事件处理措施,具体清单须与现实一致。声明重大变化应预先告知并在需要时重新获取同意;不会追溯改变已约定的数据用途。草案版本 draft-2026-10-10;正式生效日 example。

店铺 Cookie 与隐私选择政策

购物必要存储、语言偏好、分析和广告的独立选择。律师待审模板。

1. 运营者与技术范围

本店由 example 运营,域名 https://example.com,privacy@example.com。本待审政策覆盖Cookie、浏览器存储、像素、设备标识及类似存取技术。商户应在正式发布前核对主题、插件、PSP、客服及分析脚本的实际行为,不因使用Aster模板而视为已完成技术合规。平台自己的官网Cookie政策不能代替本店的实际告知。

2. 购物与安全必要项

为提供您明确请求的购物车、结账、账号登录、请求安全和保存隐私选择,可能需要受适用豁免允许的存储。每项须证明必要性并设置与目的相称的持续时间。不能把广告归因、跨站跟踪或不必要指纹归为结账必要项。第三方PSP确需的安全技术应说明提供方及其角色,不得以“支付安全”授权所有附带营销。

3. 可选目的与初始状态

语言和展示偏好、流量统计、广告及再营销分别设置。方案默认关闭可选用途,在适用情况下取得同意才加载相关工具。特定国家允许的统计或外观豁免须满足全部条件并提供要求的反对方式,不能直接跨法域复制。当前广告及分析供应商为 example(未确认);未确定目的和依据的脚本不得先加载后补告知。

4. 同意、拒绝与再次选择

隐私面板提供易于理解、显著程度相当的接受、拒绝和分类设置,不预先勾选,不把沉默当同意。您可通过页脚“隐私选择”随时修改;拒绝不会阻止不需要可选追踪的购买。改变用途或加入新供应商时在需要的范围内再次询问,而不是把旧同意无限扩展。选择证据用于记录您的意愿,不作为广告标识。

5. 必须填写的技术清单

生产登记须对每个项目列明名称 example、提供方 example、域名 example.com、目的 example、类别 example、有效期 example、接收方和国家 example、依据 example及关闭方式 example;会话与持久存储应区分。由浏览器删除的Cookie可能对应已在服务端保存的数据,后者的期限和权利见隐私声明。商户须定期复扫,删除闲置或不再获准的项目。

6. 第三方页面与退出信号

跳转至支付、物流或社交网站后,对方可能按自己的政策处理数据,本店应清楚说明跳转而不伪装页面身份。适用法律要求响应通用退出信号时,应在实际系统识别并执行,且不能要求再次提供不必要的身份资料。浏览器删除或拦截可能影响必要功能,您仍可通过 privacy@example.com 获取相应帮助。

7. 变更与联系

草案版本 draft-2026-10-10,正式生效日 example。Cookie选择界面、技术清单和隐私声明须同步发布,不能只更新文字而保持旧脚本加载行为。重大变更在生效前告知,需要同意时先取得再执行。联系 privacy@example.com 或地址 example;本政策不构成关于GDPR、PECR或其他法律的认证声明。

店铺配送与履约政策

显示真实发货与送达承诺,明确延迟、丢损及进口处理。律师待审模板。

1. 商户、地区与商品类型

卖方 example;仓库或发货地 example;配送国家及限制 example;support@example.com。本待审政策只适用于实际启用的实物配送;数字内容的交付方式应在商品页单独说明。商户须在结账前限制无法履约的地址和品类,不能先收款再以未披露的地区限制拒绝服务。商品产地、发货地及商户注册地不得混淆。

2. 备货、发货与送达

订单处理时间 example,截单时间和时区 example,承运人 example,预计运输时间 example,适用工作日及节假日 example。发货是交给承运人,送达是顾客收到,两者应分别表示。预售或定制商品须说明可合理支持的日期和付款安排。商户不得仅根据AI预测承诺时效,结账确认应保留购买时显示的承诺。

3. 费用和拆单

运费、免邮条件、偏远地区费用及可选快递费在付款前明确列明。因商户原因拆单不得收取未获同意的额外运费;多个包裹应分别提供追踪并告知预计时间。消费者选择较贵配送方式应有主动操作和清楚价格,不预选附加保险或保价。依法发生退款时应按适用规则处理原始和退回运费。

4. 延迟与美国适用分支

若订单受美国FTC邮寄、互联网或电话订购商品规则约束,商户须有合理依据按承诺期限发货;未说明发货时间时,通常须能在收到完整订单后30日内发货,具体例外按规则处理。不能按时发货时,须在相关期限到期前提供合规延迟通知和取消、及时退款的选择;进一步或长期延迟的同意规则应逐项配置。本方案优先请求顾客明确选择,不把沉默普遍视为同意。

5. 欧盟交付及其他市场

在适用的欧盟消费者规则下,除双方另行约定外,通常应在合同成立后不迟于30日完成交付;违反约定交付义务时,额外合理期限、立即解除的例外及退款按当地实施规则适用。此处“交付”不同于美国上述“发货”规则。英国、印度和其他地区须按实际销售法律单独配置,不因使用本模板而自动采用欧盟或美国规则。

6. 丢失、损坏与地址问题

发生丢件、损坏或错送时,请联系 support@example.com,我们负责调查并提供依法适当的补救,不只要求您自行与快递协商。签收记录、照片和追踪用于核查,不自动构成最终证据。您可在发货前请求更正地址;若已发货,我们说明可行性及事先同意的实际费用。无人领取或地址错误不能当然允许保留全部款项,须按实际成本和消费者保护规则处理。

7. 海关、进口人与税费

跨境订单在购买前说明进口责任方 example、税费是否已含 example、清关费用 example、受限品类及必要收件资料。若由消费者支付进口税,应以明确可理解的方式说明可能费用和计价依据;不能把商户本应承担的费用在交付后转嫁。海关延迟应及时沟通,不能免除已承诺且依法承担的退款或消费者救济。

8. 记录与联系

商户保留订单承诺、延迟通知、消费者选择、追踪及退款记录,以处理争议并满足必要法律义务,不超期收集顾客信息。配送状态由实际承运事件及人工核验确认,AI客服不得编造已发货或已签收。版本 draft-2026-10-10;正式生效日 example;人工服务时间 example;联系 support@example.com。

店铺支付、税费与币种政策

交易币种、PSP、付款验证、退款及税费的消费者说明。律师待审模板。

1. 收款主体及服务商

商品卖方和收款商户为 example,账单描述符 example,支付服务商 example,PSP政策链接 https://example.com。上述均为占位,须替换为实际接入信息。Aster软件不托管本店消费者资金;商户接收其PSP结算。您为商品支付的款项与商户向Aster缴纳的SaaS订阅费是不同交易,不会因购买商品而订阅平台。

2. 总价与收费授权

付款前明确展示商品价、优惠、运费、适用税费及总额,并使用表示付款义务的确认操作。所有附加服务需主动选择,不通过预勾选收取额外费用。商品如为周期性订阅,必须另行清楚披露每期金额、周期、开始、续费、终止及取消路径并获取独立授权;本店普通商品订单不包含默示的周期收费。

3. 多币种及换算

可用交易币种 example。最终扣款币种和金额在结账、支付确认和订单中一致显示;浏览估算换算须注明来源或基准时间及其估算性质。不同币种的精度和舍入规则不得造成隐藏附加收费,总价须可核对。发卡行的换汇或境外交易费用由其规则决定,我们不能保证银行扣账的本币数额,但不得以此改变已确认的商户交易价。

4. 验证、扣款及订单状态

PSP或发卡行可能要求额外验证,例如3-D Secure或钱包确认。授权不一定等于最终扣款;商户应清楚区分待支付、已授权、已扣款和退款状态。支付完成页面不应成为唯一成功证据;后台使用经验证的事件与对账确认,页面异常时可凭订单号联系人工。重复点击不应导致重复收费;疑似重复款项应核查并及时纠正。

5. 支付数据与安全

完整卡号PAN、CVV和其他敏感验证数据由实际PSP的安全支付流程处理,商户和Aster不通过自身页面表单、日志、邮件或AI客服收集或保存这些数据。系统仅保留完成交易和售后所需的令牌、引用、支付方式摘要及状态。任何要求通过客服提供CVV、一次性验证码、密码或私钥的请求都不应被遵从;可联系 security@example.com 核实。

6. 退款与币种差异

退款按退换货政策由商户人工审核并通过已获授权流程执行,通常使用原支付方式和原交易币种。所退商户交易金额以您依法应得金额为准;银行换算时点不同可能导致本币差额,应由相应提供方说明,不能宣传为保证原本币到账。PSP显示已发起与银行实际入账应区分;银行预计到账时间为 example,须由实际PSP信息确认,法定发起或完成义务仍优先适用。

7. 税费和发票

适用税种、登记号、开票主体和价格是否含税应依据实际卖方、商品、顾客身份及销售地配置。销售税、VAT/GST、进口税和清关费不能混称为同一费用。您可按合法要求提供开票资料并联系 support@example.com 更正发票。平台计算工具或AI建议不构成税务裁定;商户负责核实登记、税率、免税和申报义务,不能将错误全部转嫁给消费者。

8. 争议与联系

无法识别账单、付款失败或怀疑未授权交易时,请联系 support@example.com 或您的支付机构。商户可要求必要订单证据但不要求完整卡号,不阻碍及时向银行提出争议。对已经通过另一渠道退还的同一款项应核对避免重复支付,但不得无限期冻结所有无关退款。版本 draft-2026-10-10,正式生效日 example;本政策须与真实PSP合同和消费者权利保持一致。

店铺 AI 客服告知

告诉顾客何时与AI交互、能做什么以及如何联系人工。律师待审模板。

1. 您正在与AI交流

本店 example 可使用AI客服协助查询商品、订单和售后。会话开始时将明确标识“AI客服”,不会冒充真实员工、律师或支付机构。商户 example 对其店铺客服运营负责;AI由Aster和商户批准的供应商提供。此告知为待审模板,正式上线时应与实际功能及数据流一致。

2. 可提供的帮助

AI可解释经商户审核的商品信息、配送及退换政策,在完成必要身份核验后查询您的订单,整理问题并起草售后申请。AI仅访问解决当前问题必要的资料,不应展示完整支付卡、其他顾客记录或不必要的收件信息。未得到实际订单或承运事件支持时,AI应明确表示无法确认,而不能编造退款完成或已经送达。

3. 人工处理与权限限制

每笔退款由商户授权员工审批;AI不能单独执行转账、改变收款账户或最终拒绝法定请求。涉及撤回、争议、产品安全、隐私权利、异常付款或重要承诺时,应提供人工复核。AI生成的说明不修改订单价格、已接受条款或法定保障。您不需要取得AI批准才能提出有效请求。

4. 联系人工与请求时间

您可在会话中选择“转人工”或直接联系 support@example.com,电话 example;人工服务时间及时区 example,通常响应目标 example。无需反复与AI交谈、提供不必要理由或支付额外费用。非工作时间也可提交申请并获得记录;法定通知时间以有效提交时间为准,不因等待人工接管而延后。

5. 数据和敏感信息

对话可能包含您提供的内容、订单引用和处理记录,按店铺隐私声明用于回答、交接和纠错。实际AI供应商 example、处理地区 example、对话保存期 example,应在上线前说明;默认不用于训练通用模型。不要发送密码、一次性验证码、PAN、CVV、私钥或无关敏感信息;误发时我们应限制使用并按程序处理,不将其转为模型知识。

6. 错误与纠正

AI可能误解问题或提供过期信息。发现不一致可引用对话向人工提出,我们应核查实际合同、政策和订单事实,并说明纠正措施。商户不能仅以“这是AI说的”为理由排除本应承担的责任。对法律解释存在不确定时,AI应转人工,不自行决定适用法、消费者期限或责任限制。

7. 选择与持续可达性

选择不用AI不影响您按相同实体政策购买、取消、投诉或申请退款;人工渠道应可用且不造成不合理障碍。AI停用或服务故障不会删除已提交的请求。版本 draft-2026-10-10;正式生效日 example;联系 support@example.com。任何语音录音、屏幕共享或新数据用途须另行说明并取得法律要求的选择或同意。

店铺可访问性声明

披露设计目标、真实评估状态、已知问题和辅助联系路径。待评估模板。

1. 运营者与承诺范围

example负责 https://example.com 的店铺体验,联系 accessibility@example.com,地址 example。我们计划使浏览、搜索、商品选择、结账、取消、退货和客服更易于不同能力的顾客使用。本模板是待评估草案,未作“完全符合”或第三方认证声明。正式发布须明确纳入范围的域名、应用、第三方流程和测试日期。

2. 设计目标与法律要求

拟采用WCAG 2.2 AA作为前端设计和测试目标,包括键盘操作、可见焦点、足够对比度、标签和错误说明、文本缩放及减少非必要动画。适用的法律标准、欧洲可访问性法实施要求、豁免与过渡条件须按商户规模、服务和目标地区实际评估。采用某个技术目标不能自动证明满足所有法律义务。

3. 评估状态和已知限制

评估方式 example;独立评估方 example;最后测试日期 example;浏览器及辅助技术 example;符合程度 example;已知障碍及受影响页面 example;负责人和修复期限 example。未测试应如实标注,不得用AI生成审计分数冒充人工测试结果。支付验证、Cookie弹窗、聊天窗口、动态购物车及移动端均应纳入验证,而非只检查首页。

4. 获取帮助和替代方式

遇到使用困难可联系 accessibility@example.com 或电话 example,并说明希望使用的联系形式、问题页面及障碍;不要求提供医疗诊断。我们拟在2个工作日确认收到,并提供合理的人工协助、可访问格式或替代流程。替代流程应维持商品价格和实体消费者权利,不要求您以不安全方式发送付款秘密,也不作为长期不修复网站的替代品。

5. 第三方和内容管理

我们应在选择PSP、客服工具和插件时检查可访问性,发现第三方障碍时与供应商协调并告知可行替代路径。商品图片替代文字、视频字幕、文档可读性及翻译由商户持续维护;Agent生成内容须复核。不得因为第三方组件存在就笼统排除对完整购买和售后流程的责任。

6. 反馈、升级与更新

若协助未能解决问题,您可向负责人 example 请求升级,并按适用法律联系监管或执行机关 example。每次重大主题、结账、语言或客服变更应重新验证相关流程,并更新已知问题和修复进度。声明版本 draft-2026-10-10,正式发布日期 example。本声明不会限制任何法定投诉或救济途径。

原始资料来源与审阅线索

  1. EU GDPR — Regulation (EU) 2016/679

    Primary text: roles, lawful processing, rights, processor contracts, security, breach and transfer provisions. Applicability and local implementation must be reviewed.

  2. EDPB Guidelines 07/2020 on controller and processor concepts

    Official interpretation of factual controller/processor roles; labels alone do not determine legal status.

  3. European Commission — Standard Contractual Clauses

    Official source for transfer clauses. A selected module and completed annexes must be executed; a draft DPA reference does not execute SCCs.

  4. EU Consumer Rights Directive 2011/83/EU

    Baseline text for distance-sale information, withdrawal, reimbursement, exceptions and delivery. Read with amendments and national implementing rules, not as a universal consumer code.

  5. Directive (EU) 2023/2673 — online withdrawal function

    Article 1 adds Article 11a to Directive 2011/83/EU; Article 2 provides application from 19 June 2026. Check relevant national transposition and eligible transactions.

  6. EU Regulation 2024/3228 — discontinuation of ODR platform

    The former EU ODR platform was discontinued and its regulation repealed with effect from 20 July 2025. Do not retain obsolete live-complaint links.

  7. FTC Mail, Internet, or Telephone Order Merchandise Rule

    Official rule summary distinguishing promised shipment and the usual 30-day default, delay consent and refund duties.

  8. 16 CFR Part 435 — current electronic CFR text

    Check detailed coverage, shipping-delay notices, exceptions and prompt-refund methods. Dispatch is not delivery; timelines are not universal across payment methods.

  9. FTC — Restore Online Shoppers’ Confidence Act

    Federal online consumer negative-option framework. Consumer applicability differs from a B2B merchant SaaS contract; state requirements need separate review.

  10. Federal Register 2026-02866 — Negative Option Rule revision

    Effective 12 February 2026, restores the pre-2024 Negative Option Rule following court vacatur; do not describe the 2024 click-to-cancel amendments as operative.

  11. FTC — March 2026 negative-option rulemaking notice

    The FTC announced a new advance notice on 11 March 2026. A proposal is not a final enforceable rule; recheck before launch.

  12. ICO — Guidance on storage and access technologies

    Final guidance updated 29 April 2026 following PECR changes. Covers cookies and similar technologies, conditional exceptions and practical consent.

  13. ICO — Storage and access technology exceptions

    Assess every condition for communications, necessity, statistical, appearance or emergency exceptions; do not infer a general advertising exception.

  14. ICO — Managing consent in practice

    Official operational guidance for clear choices, refusing, withdrawal and changed purposes.

  15. MeitY — Digital Personal Data Protection Rules, 2025 (final Gazette)

    Final Gazette G.S.R. 846(E), not the January 2025 draft. Rule 1 stages commencement. An India launch needs the Act commencement notification and any subsequent amendments checked alongside this text; do not assume all provisions are already applicable.

  16. European Commission — European Accessibility Act

    Official scope includes e-commerce. Assess national implementation, service scope, exemptions and evidence instead of blanket conformance claims.

  17. W3C — Web Content Accessibility Guidelines 2.2

    Primary technical standard. WCAG 2.2 AA is a proposed design target, not a completed audit or automatic finding of legal compliance.

© 2026 example · draft-2026-10-10

Aster Platform & Store Agreement Collection

17 bilingual drafts · 145 sections · Legal review edition

SaaS Terms of Service

The merchant–platform contract, allocation of responsibilities, data rights and termination. Draft for legal review.

1. Draft status and contracting parties

This document is a proposed draft based on the product design. It has not been reviewed by qualified counsel and is neither an operative agreement nor legal advice. The proposed provider is example, registration number example, registered address example, place of incorporation example ("Aster" or the "Platform"). All example fields, applicable law and local legal review must be completed before launch. Website: https://example.com. Legal contact: legal@example.com.

2. Scope, eligibility and acceptance

The service is intended for businesses and legally capable traders building stores for business purposes. A person opening an account for a customer must have authority to bind that customer. An operative contract is formed only after the customer is shown and affirmatively accepts a specified version of these terms and an order; acceptance boxes must not be preselected. The Platform retains the order, terms version, language, acceptance time and necessary evidence, and provides a retainable copy. Viewing the preview does not create a paid subscription.

3. Contract documents and precedence

The executed order identifies the plan, allowances, billing period, support and any add-ons. The billing policy, AUP, AI terms and applicable SLA form part of the contract. The DPA prevails for personal-data processing, and validly executed transfer clauses prevail as specified in those clauses. Express provisions signed by both parties take precedence over general terms without reducing mandatory rights. Privacy and Cookie notices describe processing and do not replace legally required consent.

4. Platform and merchant roles

Aster provides software for storefront creation, catalog management, order orchestration, payment integrations, after-sales operations and AI assistance. The merchant is the seller of its store’s goods and services and is responsible for lawful products, prices, taxes, delivery, consumer rights and refunds. Aster is not the merchant of record for store sales, does not collect or hold consumer sale proceeds, and does not provide bank accounts, escrow, fund guarantees or financial advice. Statutory roles depend on actual activities; this clause does not displace duties imposed by law.

5. Accounts, security and permissions

Customers must provide accurate business and contact details, enable multifactor authentication for administrators, assign permissions by role and promptly disable departed personnel. Customers are responsible for their authorized users, while the Platform remains responsible for its own security duties. PSP secrets must enter the system only through protected credential configuration and must not be placed in public pages, AI prompts or support conversations. The parties must promptly cooperate through security@example.com to contain and investigate compromised credentials or suspicious access.

6. License, content and AI output

During the paid term, the Platform grants a nonexclusive, nonresalable right to use the service to operate the customer’s permitted stores. Customers retain rights in their product information, marks, uploaded content and business data, and authorize processing only to provide, secure and support the service. The Platform retains its software and general components. AI output may not be exclusive or protectable; customers must assess sources, infringement risk and accuracy and may not represent generated output as guaranteed by the Platform or counsel.

7. Payments, funds and refund authority

Merchants contract directly with their PSP and receive store settlements; Platform subscriptions are billed separately through the Platform’s own PSP account. The Platform does not collect or retain full PANs or CVVs. Payment status is based on verified PSP events and reconciliation. Each refund requires approval by an authorized merchant employee and an execution-time check of captured amounts or settled amounts eligible under PSP rules, previous and pending refunds, and currency; it must not exceed the actual refundable balance. PSP restrictions do not relieve the merchant of a legal refund obligation.

8. Service delivery, third parties and deployment

The order must identify the actual scope of hosted services and any self-hosted software. The ability to host the SaaS marketing website independently or on Cloudflare Workers does not mean the entire commerce backend supports that deployment or automatically license the Platform source or production system for self-hosting. PSP, domain, logistics, AI and analytics providers may have separate terms and charges, disclosed before activation. The Platform must exercise reasonable care in selecting, configuring and maintaining its subcontracted services and cannot use third-party involvement to excuse all of its obligations.

9. Fees, suspension and changes

Charges and renewals follow the billing policy and checkout confirmation; excess usage must not generate unapproved automatic fees. Material feature reductions or price changes require at least 30 days’ advance notice and take effect at the next renewal, subject to longer notice or renewed consent required by law. For nonpayment, violations or security risks, the Platform must act proportionately and, except in urgent, unlawful or restricted circumstances, explain the reason and allow a reasonable opportunity to cure. Suspension does not authorize taking merchant funds or abandoning consumer requests.

10. Confidentiality, warranties and liability

Each party may use the other’s nonpublic commercial and technical information only to perform the contract and must bind need-to-know personnel to confidentiality; legally compelled disclosure requires advance notice where permitted. The Platform will provide production services with reasonable skill and care but does not guarantee sales, SEO rankings, absence of fraud or error-free AI. The proposed ordinary contractual damages cap is fees actually paid during the 12 months before the event giving rise to the claim; a proposed two-times cap applies to confidentiality, data-protection and intellectual-property claims, subject to local legal review. Fraud, intentional misconduct and liability that cannot lawfully be limited remain uncapped. These Platform caps do not limit merchants’ obligations to consumers.

11. Termination, export and survival

Customers may cancel renewal under the billing policy. A party may terminate for a material breach not cured within 30 days after written notice; irremediable serious illegality or security risks may justify immediate limits on affected functions. Normal termination includes a 30-day read-only export period for products, orders, customers, content and assets that their licenses permit to be exported, followed by deletion under the DPA. If the Platform ends prepaid service early without customer fault, it refunds the unused period proportionately. Accrued fees and rights, confidentiality, dispute provisions and statutory retention duties survive as appropriate.

12. Law, disputes and notices

Proposed governing law: example. Proposed court or dispute body: example. These fields must be resolved before publishing a final jurisdiction clause. Parties should first notify legal@example.com and seek a good-faith resolution for 30 days, without delaying urgent relief, statutory deadlines or regulatory complaints. Formal notices go to the addresses or emails agreed in the order. Chinese and English should be equivalent; switching language must not reduce rights. Mandatory language, jurisdiction and nonwaivable remedies required by local law prevail.

13. Third-party claims and defense

For a third-party claim that the Platform software, supplied as agreed and unmodified by the customer, infringes intellectual property, the Platform proposes to provide reasonable defense and pay amounts awarded or agreed in settlement. It may obtain continuing rights, provide a noninfringing modification or end affected functions with a refund of unused prepaid fees. Customers propose a proportionate defense obligation for claims arising from content they have no right to supply, unlawful products or intentional abuse. Parties must give prompt notice, cooperate reasonably and allow appropriate defense control; settlements may not admit the affected party’s liability or impose nonmonetary duties without consent. These arrangements require review against caps, local law and insurance and do not shift the other party’s own fault.

14. General provisions and entire agreement

If an event beyond reasonable control affects performance, the affected party must notify promptly, mitigate and resume performance. It does not excuse accrued payment, confidentiality, data-protection or legally required refund duties. The contract may not be assigned without the other party’s consent to an entity unable to perform; permitted restructuring assignments require notice and protection of data and accrued rights. No partnership or agency is created. Delay in exercising a right is not waiver. Expressly accepted contract documents form the entire service agreement without excluding fraud, statutory misrepresentation liability or mandatory consumer protection.

Subscription, Renewal, Cancellation and Refund Policy

Proposed rules for monthly and annual plans, affirmative authorization, cancellation and disputed charges. Draft for legal review.

1. Proposed pricing and scope

This policy applies only to Aster’s software subscription fees charged to merchants, not consumer orders placed with stores. Proposed preview prices in USD are Launch $39 monthly or $390 annually; Grow $99 monthly or $990 annually; and Scale $249 monthly or $2,490 annually. Annual billing is one payment for 12 months at the price of ten monthly payments, approximately 16.67% less, and is not billed monthly. These are proposed prices, not a live offer; production checkout must confirm the final amount, taxes and allowances.

2. Confirmation and affirmative consent

Before charging, the page must display beside the purchase action the plan, total current charge, currency, taxes, start date, period, renewal amount and date, whether renewal is automatic, and a direct cancellation method. Automatic renewal requires affirmative authorization through a separate, unselected control, with evidence retained. A saved payment method alone does not authorize changes in price, period or add-ons; fresh consent is obtained where required. Marketing consent is separate from paid-subscription authorization.

3. Billing, allowances and third-party costs

This proposal includes no free trial that converts to paid service and no automatic overage billing. When an allowance is reached, the service should offer an optional upgrade or pause new limited operations while preserving access needed for existing orders, refund handling and data. Customers incur upgrade or add-on fees only after seeing and expressly accepting them. PSP processing, domains, shipping, tax filing and separately connected services are not included in software fees and must be disclosed by the actual provider or order.

4. Renewal and reminders

Subscriptions renew on the selected monthly or annual cycle only with valid authorization. The proposed service commitment is annual reminders at least 30 and seven days before renewal and monthly reminders at least seven days before renewal, showing the amount, date and cancellation link; applicable legal timing and format requirements prevail. Renewal price increases require at least 30 days’ notice and do not apply retrospectively to the current term. If notice is insufficient, the change must be deferred or valid consent obtained. Failed reminders must be recorded and handled.

5. Direct cancellation and effect

Customers may cancel online through Workspace settings → Billing → Cancel renewal, without a phone call, a reason or prior interaction with an agent. Successful cancellation immediately shows confirmation, the service end date and a retainable receipt. Customers unable to sign in may contact billing@example.com and complete proportionate identity verification. Cancellation submitted before the next renewal stops future renewal; paid access normally continues to the end of the current term. Removing a payment method or ceasing use is not cancellation. No subsequent unauthorized charge may be made after authorization is withdrawn.

6. Plan changes and failed payments

Upgrades require a displayed, day-based prorated price and confirmation. Downgrades normally take effect next term without retroactively reducing paid entitlements. Failed payment triggers notice and a way to update the method, with a proposed seven-day grace period. The Platform must not substitute a different billed product or attempt another unauthorized payment account. After the grace period, new publishing and AI usage may be restricted, while reasonable cancellation, billing, existing after-sales and export paths remain available. Customers must keep billing contacts current.

7. Refunds and disputes

Current-term fees are generally not prorated merely because a customer voluntarily stops using the service, except for statutory rights, duplicate or erroneous charges, unauthorized renewal, undelivered service, Platform fault or another written commitment. Annual billing is not an absolute no-refund rule; mandatory refund rights prevail. Customers may request human review at billing@example.com with the invoice reference, with a proposed response within five business days. Approved refunds return to the original method; processing and expected PSP posting times are communicated separately. An AI risk score alone cannot determine refusal.

8. Taxes, records and rule status

Production invoices must identify the billing entity example, tax number example, tax type and taxable amount; tax-inclusive pricing required by local law must not be replaced with a last-step tax addition. Checkout confirmation and invoices determine the billing currency; issuers or conversion services may charge separately. Renewal rules must be checked against location, customer status and current law. This policy does not claim the FTC’s 2024 click-to-cancel amendments remain effective. Affirmative renewal choices and convenient cancellation are product commitments, not a substitute for jurisdictional review.

9. Plan allowances and AI credits

The proposed Launch, Grow and Scale plans allow respectively 1, 5 and 20 active stores including drafts, 1,000, 10,000 and 100,000 active SKUs, and 2, 10 and 30 team seats. Final allowances and counting scope must be shown before purchase. AI credits of 500, 3,000 and 10,000 respectively are issued each subscription month, expire for that month and do not roll over. Annual plans also receive credits monthly, not all in advance. Allowances must match the plan table and order. Proposed task examples are 1 credit for a short text or single-item translation, 3 for a single-product content pack, 5 for one content page, and 10 for an initial store draft within a limited template. These examples apply only to disclosed length, input, page and model limits, not unlimited content. Show maximum consumption and scope before execution; exceeding scope requires a new estimate and express confirmation first. Failed tasks release reserved credits and automatic retries of the same logical task are not charged again. A deliberately different new task requires confirmation. Credits have no cash value, do not trigger automatic top-ups and cannot block statutory after-sales rights when exhausted.

Platform Privacy Notice

How Platform account, subscription, website and security data would be handled. Draft for legal review.

1. Who we are and our roles

This draft notice is proposed for example, address example, contact privacy@example.com. For Platform visitors, merchant accounts, subscription billing and its own security operations, example acts as controller to the extent it determines processing purposes and means. Aster acts under the DPA as processor for store consumer, order and support data processed on merchant instructions; consumers should first contact their seller. Any required privacy lead, local representative, data protection officer and supervisory authority are example and must be completed after applicability is assessed, without implying an appointment that has not occurred.

2. Categories and sources

Proposed categories include name, work email, business details, login and role information, subscription billing details, PSP tokens and transaction references, support requests, IP and security events, and device or permitted usage information. Sources are the individual, authorized business administrators, PSPs and connected providers, and records created through service use. Full PANs, CVVs, account passwords, private keys and unnecessary sensitive information must not enter Platform forms or AI prompts. Actual collection fields must match the data inventory verified before publication.

3. Purposes and applicable legal bases

Processing necessary to establish and perform a service contract with an individual relies on contract necessity. Business-contact management, security, abuse prevention and service maintenance may rely on assessed legitimate interests where applicable. Invoicing and mandatory record retention rely on legal obligations. Optional marketing and tracking that legally require consent rely on separate consent. Refusing optional consent does not affect core service; missing necessary fields may prevent account creation or subscription. These bases apply where recognized by the relevant legal framework and require mapping for other jurisdictions.

4. Recipients, AI and secondary-use limits

Necessary data may be disclosed for these purposes to contracted infrastructure, transactional email, support and AI providers, and to PSPs, advisers or authorities acting under their own payment or legal responsibilities. Actual recipients and processing locations must appear in the published register, currently example. The proposed default is no sale of personal information, no sharing for cross-context advertising and no training of general-purpose models on merchant or consumer data. A proposed change requires prior assessment, disclosure and necessary authorization and cannot silently expand DPA instructions through an update notice.

5. Locations, transfers and retention

Primary processing, backup and remote-support locations are example and must account for both recipients and remote access. Restricted international transfers are enabled only after a lawful mechanism is established, such as applicable adequacy decisions, executed standard clauses with completed annexes and necessary supplementary measures. Active account records remain through the contract and export period; proposed deletion is within 30 days after that period for production data and within 90 days for rotating backups. Specific periods for invoices, security evidence and mandatory records are example and must have a legal and purpose-based justification rather than indefinite retention.

6. Rights and requests

Subject to applicable law, individuals may request access, correction, deletion, restriction, a portable copy, objection to certain processing and withdrawal of consent, and may complain to a competent authority. Requests go to privacy@example.com; verification requires only proportionate information and never a full payment card. Withdrawal does not affect previously lawful processing. The Platform responds within applicable statutory periods and cannot use a merchant billing dispute to refuse legal rights. Requests concerning merchant-controlled store data are promptly forwarded to the merchant and assisted under the DPA.

7. Automation, security and minors

Risk signals identify anomalies and assist human review; they do not alone determine final refusals with legal or similarly significant effects. Necessary immediate security restrictions must have an explanation and a human appeal path. Proposed safeguards include least privilege, encryption, logging and incident response; the operative notice must describe only implemented, verified measures. The Platform targets business operators and does not market to children. If it learns it collected children’s information improperly, it will restrict, delete or resolve it with a lawful guardian as applicable law requires.

8. Optional communications, updates and contact

Marketing emails must provide an unsubscribe option; billing, security and service notices must not impose marketing consent. Material privacy changes require clear advance notice and fresh consent where legally required. This draft version is draft-2026-10-10; the operative date is example. Privacy complaints: privacy@example.com. Postal address: example. Claims such as “GDPR compliant,” “PCI certified” or comparable certifications require independent evidence and do not arise merely from this document.

Platform Cookie and Similar Technologies Policy

Necessary, preference, statistics and advertising uses, choice controls and disclosure requirements. Draft for legal review.

1. Scope and status

This draft applies to https://example.com and specified Platform domains operated by example; contact privacy@example.com. Cookies, localStorage, pixels and fingerprinting can all store or access information. Not every mechanism processes personal data, and the rules are not limited to third-party cookies. Actual pages and provider scripts must be audited and the technology register completed before production launch. Placeholder register entries in the preview do not mean a provider is enabled.

2. Necessary functions

Login sessions, security for purchasing or subscription flows, request protection and storage of privacy choices may operate when the specific applicable exemption is met. Necessity is assessed against a function the user expressly requests; commercial value does not make analytics or advertising necessary. Necessary entries must use proportionate lifetimes, domain scope and security attributes. Core functions that do not depend on optional entries remain usable when optional entries are refused.

3. Preferences, statistics and advertising

Language or appearance preferences and aggregate statistics require separate purposes and lifetimes. Optional statistics, advertising and cross-site tracking are disabled by default in the proposal and must not load or send requests before consent when consent is required. UK law may provide conditional exceptions for specific statistical or appearance uses with a simple objection mechanism; these may be used only after every condition is assessed and met, not for advertising or automatically in all countries. No advertising provider is assumed in this proposal.

4. Consent controls and withdrawal

When choices are needed, equally usable and comparably prominent controls must allow accepting optional uses, refusing them and selecting categories. No preselected boxes, continued-browsing consent, dismissal-as-consent or bundling optional consent into service terms is allowed. A persistent Privacy choices link permits changes or withdrawal. Withdrawal stops future related processing and removes nonessential storage within the Platform’s control while notifying applicable providers.

5. Technology register

Every actual entry must list: name example; setter example; domain example.com; purpose example; category example; first-party status example; lifetime example; associated recipients and countries example; consent or exemption justification example; and withdrawal method example. Entries with the same name but different purposes require distinct disclosure. Cookie expiration is not the same as server-side personal-data deletion; both must be explained. Unidentified or unapproved optional scripts must not be released.

6. Records, third parties and browser controls

The Platform retains necessary choice version, time and scope to demonstrate preferences and avoid repeated requests; preference identifiers must not be reused for advertising profiles. Embedded content or external payment pages may be controlled independently and must be identified with their policies before navigation or loading. Browsers can remove or block storage, which may affect necessary functions such as login. Where local law requires universal opt-out signals to be recognized, the Platform must implement them rather than rely on a textual promise.

7. Updates and contact

Before adding a purpose or provider or materially changing a lifetime, update the register, assess whether renewed consent is necessary, and preserve the prior version. Material changes are disclosed before the related scripts run. Version: draft-2026-10-10. Operative date: example. Contact privacy@example.com for questions, a register copy or withdrawal assistance. This policy does not replace each merchant store’s own Cookie configuration and notice.

Data Processing Addendum and Schedules

Controller–processor terms with processing details, subprocessors, security and transfers. Draft for legal review.

1. Parties, scope and instructions

This draft DPA is proposed between order customer example (the “Controller”) and service provider example (the “Processor”) and becomes part of the service contract after valid acceptance by both parties. Personal data, processing and breach are interpreted under applicable data-protection law. The Processor processes store personal data only on demonstrable written instructions, including service settings, authorized tickets and this DPA. It may not use consumer data for its own advertising, sale, general-purpose model training or other independent purposes. Lawful independent processing outside this role requires separate notice and its own basis.

2. Processing description: subject and duration

The subject is the customer’s authorized stores: site generation, product presentation, customer accounts, carts, orders, fulfillment, payment status, refunds, support, abuse prevention and lawfully configured analytics. Operations include collection, recording, organization, hosting, retrieval, transmission, limited automated analysis, correction, export and deletion. Duration is the service term, a 30-day export period and the deletion periods permitted here. Stores, processing region and effective date are example. New purposes, special data or regions require prior updates to these schedules and authorization.

3. Data types and data subjects

Data subjects are customers, visitors, recipients, merchant administrators and support contacts. Permitted types are names, contact and address details, account identifiers, order items and amounts/currencies, fulfillment information, payment tokens and status, refund records, necessary device and security logs, consent records and support conversations. Full PANs, CVVs, passwords, private keys and unapproved health, biometric or other special-category data are prohibited. The default service does not target children; unavoidable children’s or protected data require a specific schedule after legality, necessity and enhanced safeguards are assessed.

4. Controller duties and unlawful instructions

The Controller is responsible for lawful sources and bases, accurate notices, necessary consent and duties to customers, and sends only necessary data. If the Processor considers an instruction contrary to applicable data-protection law, it must promptly explain the concern and pause the affected instruction pending clarification without inventing a new purpose. Where law compels processing, the Processor gives prior notice of the legal requirement where permitted. Authorized contacts must be designated: Controller example / privacy@example.com; Processor example / privacy@example.com.

5. Confidentiality and security schedule

The Processor ensures personnel with data access are bound to confidentiality and trained for their duties. Proposed minimum measures include tenant isolation, least privilege and administrator MFA, encryption in transit and at rest, separated keys, audit records, backups and restoration exercises, vulnerability management, change review and incident response. Algorithms, key custody, recovery targets, log lifetimes, isolation testing and owners are example and must be completed with implementation evidence before signature. Agreed protections must not be reduced without risk assessment. This schedule is not a security certification.

6. Subprocessor register and authorization

Where general written authorization is used, it authorizes the actual subprocessors identified in a complete register, not arbitrary providers. Each entry must state legal name example; service example (infrastructure/email/AI/support/monitoring); data types example; establishment and processing countries example; transfer mechanism example; and security schedule example. Current entries are unselected placeholders and do not authorize production transfers. The Processor must impose relevant obligations at least as protective as this DPA on subprocessors and remain responsible for their performance.

7. Changes and objections to subprocessors

Proposed additions or replacements require at least 30 days’ written notice of purpose, location and safeguards. The Controller may object during that period on specific data-protection grounds; the parties first consider an alternative provider, function restriction or other reasonable solution. Affected customer data must not be sent to the new provider while the objection is unresolved. If no reasonable alternative exists, the affected service may end with a refund of unused prepaid fees. Urgent security replacements require notice as far in advance as practicable and prompt details, without permanently eliminating objection rights.

8. International-transfer schedule

The data exporter example, importer example, destination example, remote-access locations example, authority example and mechanism example must each be completed. For restricted EU transfers without applicable adequacy, select an appropriate valid standard-clause module, complete its annexes, assess transfer risks and adopt necessary supplementary measures. UK transfers require a separate assessment of mechanisms such as the IDTA or UK Addendum. References to “GDPR,” “SCCs” or this paragraph do not execute a transfer agreement. If destination protections cannot be maintained, transfers must pause pending instructions for alternatives or deletion.

9. Individual rights and compliance assistance

Rights requests concerning Controller data must be forwarded without undue delay, with a proposed two-business-day forwarding target, and not substantively decided without authority. Considering processing nature and available information, the Processor assists access, correction, deletion, restriction, portability and objection requests, security duties, DPIAs and prior consultation. Assistance arrangements must not delay applicable statutory periods. Ordinary in-scope assistance is included in service fees; genuinely additional work requires an agreed price in advance and a fee dispute cannot block necessary legal duties.

10. Personal-data breach handling

On becoming aware of a personal-data breach affecting Controller data, the Processor notifies the Controller without undue delay, with a proposed initial target of 24 hours, without waiting for a complete investigation. The notice includes known nature, affected categories and scale, likely consequences, measures and a contact, followed by phased updates. The Processor preserves necessary evidence and cooperates in remediation, and does not notify individuals or authorities on the Controller’s behalf without authority unless legally compelled. The 24-hour target is a proposed contractual commitment requiring operational validation, distinct from regulatory deadlines applicable to controllers.

11. Audits, records and regulatory cooperation

The Processor supplies information needed to demonstrate this DPA’s performance, including relevant controls, assessments and remediation records. The Controller or a confidentiality-bound independent auditor may ordinarily conduct one reasonable audit annually; breaches, material noncompliance or regulatory requirements are not subject to that annual limit. Scheduling, scope safeguards and reasonable fees must not materially obstruct legally required inspection or expose other tenants’ data. Parties cooperate with lawful regulatory requirements. Third-party disclosure demands must be appropriately verified and notified to the Controller where permitted.

12. Return, deletion and survival

At service end, the Controller may choose return or deletion. The proposal provides a 30-day read-only export period, production-copy deletion within 30 days after that period, and backup deletion or irreversible anonymization through the documented rotation within 90 days of the same export-period end. Backups cannot be used for other purposes and restored copies must reapply deletion records. Legally necessary retention must identify its basis, categories, access restrictions and period, with deletion when that duty ends. Deletion confirmation is available on request. This DPA remains effective while covered data is retained; all incomplete schedules must be completed before production processing.

Acceptable Use and Restricted Products Policy

Limits for products, content, marketing and security, with a review process. Draft for legal review.

1. Scope and responsibility

This draft applies to merchants, authorized users, uploaded content, stores and automation invoked through the Platform. Merchants must verify that products may be sold in selling, dispatch and destination locations and obtain required permits, labels and safety documentation. AI-generated copy or an unblocked listing does not signify approval. The Platform may impose disclosed restrictions stricter than local law; changes require reasonable notice and protection of accrued consumer rights.

2. Prohibited products and activities

Illegal, stolen, counterfeit and rights-infringing goods are prohibited, as are fraud, money laundering, sanctions evasion, exploitation and trade in unlawfully obtained data. Malware, account-theft services, forged identities or documents, unlawful adult content and sexual exploitation of minors are prohibited. The default proposal does not support weapons, controlled drugs, gambling, unlicensed financial products or other high-risk activities needing special regulatory approval. Any expressly approved exception must be lawful, permitted by the PSP and covered by specific written terms.

3. Restricted categories requiring review

Food, supplements, cosmetics, health-related goods, batteries, children’s products and other specially regulated categories require market-specific evidence and fulfillment arrangements. Unsupported therapeutic, certification, environmental or performance claims are prohibited. Applicable age limits, labels, recalls and producer or responsible-person details must be displayed accurately and kept current. Merchants must maintain an actionable recall and customer-notification process and cannot delegate product-safety judgments to an agent alone.

4. Truthful marketing and reviews

Fabricated reviews, order counts, countdowns, stock scarcity, comparison prices and independent endorsements are prohibited; AI must not impersonate actual purchasers in reviews. Discounts, gifts, subscriptions and promotional relationships must disclose material conditions and required relationships. Unpermitted bulk marketing, unlawful mailing lists and deceptive interfaces obstructing cancellation or refunds are prohibited. SEO content must reflect actual products and services rather than mass-generated false brand affiliations or deceptive pages.

5. Technical and data abuse

Tenant probing, authorization or allowance bypass, credential theft, malicious code, API abuse and prompt injection intended to expose secrets are prohibited. Personal-data scraping or exporting support, payment or order data to unapproved tools is not allowed without authority. Security research should be coordinated through security@example.com and avoid damage, real consumer data and persistent access. This draft does not itself authorize testing production systems.

6. Detection, measures and notice

The Platform may investigate complaints, specific evidence and proportionate security signals and restrict an individual listing, a risky operation or an account where necessary. Unless prohibited by law, clearly urgent or prejudicial to an investigation, it explains the content affected, policy basis, measure scope and appeal route. An unreviewed generative-AI conclusion cannot justify asset confiscation, denial of consumer rights or a permanent ban. Necessary evidence is preserved with controlled access and retention.

7. Appeals and correction

Merchants may send the decision reference, evidence of lawful activity and corrective steps to abuse@example.com for human review that does not rely solely on the original automated result. The proposed acknowledgment target is five business days, with updates for complex matters. Appeals do not block necessary temporary safeguards, but verified lawful content should be restored promptly. Good-faith errors should be distinguished from repeated or serious abuse, with legally permitted export and customer after-sales arrangements on termination.

AI and Automation Terms

Agent permissions, approval, data, human oversight and legal-document controls. Draft for legal review.

1. Functions and boundaries

These draft terms cover site-building, catalog, translation, SEO, support and operational agents. AI produces drafts, suggestions or limited actions using user inputs, approved knowledge and authorized tools; output may be inaccurate, incomplete or similar to others’ output. Neither the Platform nor an agent provides professional legal, tax, medical or investment advice, and this template must not be presented as written or approved by qualified counsel. Enabled models and processing arrangements must be identified in the provider register.

2. Permissions and instruction hierarchy

Agents operate only within expressly granted stores, tools, actions and allowances. Content in web pages, emails, product files and support messages is untrusted input and cannot override Platform safeguards, formal merchant policies or access controls. Authorization must be enforced by the server and be revocable immediately; prompt text such as “refund allowed” cannot bypass separate approval or payment permissions.

3. Drafting, publishing and sensitive actions

Product copy, image descriptions, translations and SEO changes default to previewable drafts. Merchants review material public-content, price or promotion changes before publication. Refunds, payment configuration, settlement accounts, domains, bulk data deletion, expanded permissions and operative legal terms require specific approval. Authorizing routine automated support does not authorize these actions. Approval must identify the particular content, amount or action version and must be renewed if it changes.

4. Refunds and consumer rights

An agent may explain approved refund policy, collect necessary facts, retrieve orders and draft requests, but every executed refund requires approval by an authorized merchant employee. The system rechecks refundable funds and prevents duplicate refunds rather than treating predictions as payment facts. An agent must not finally deny statutory withdrawal, defect remedies, refunds or human review. Imminent deadlines, policy conflicts and rights disputes must escalate promptly with the original request time recorded so a queue does not prejudice rights.

5. Legal documents and translation

Legal documents may be drafted only from version-controlled, jurisdiction-configured templates awaiting legal review; example fields and unresolved options must block operative publication. Agents must not independently change legal conclusions, governing law, statutory periods, liability limits or consumer rights. Such changes require an authorized merchant decision-maker and appropriate legal review. Translations must align with the source version and clause numbering with traceable differences; changing language must not substitute a materially different agreement.

6. Data minimization and providers

Data sent to models must be limited to the current task, using order references, masked fields or aggregates where possible. Full PANs, CVVs, passwords, private keys and unrelated personal information are prohibited. Model providers, countries, logging and training policies require verification and DPA arrangements before launch, with general-purpose model training and cross-tenant retrieval disabled by default. Merchant-supplied models or plugins require the same recipient, permission and transfer review.

7. Output verification and records

Merchants must check product facts, intellectual property, language and cultural context, pricing, stock, delivery and advertising claims. The system records necessary input references, knowledge versions, tool calls, approvals, outcomes and reversals with sensitive fields masked and limited retention. Low-risk changes should be versioned for rollback; financial actions that cannot simply be reversed require dedicated processes rather than a retry used in place of idempotency and reconciliation.

8. Disclosure, human handoff and stopping

Consumer-facing conversations must identify the AI assistant at the start and provide an available human contact path and actual service hours. Merchants may pause agents, revoke tools or take over manually; disabling AI cannot erase complaints or requests already received. Suspected unauthorized action, data leakage, duplicate transactions or material errors require stopping the affected task and notifying the responsible people. Responsibility for AI errors remains based on actual conduct and law; these terms do not excuse either party’s own fault.

Service Levels and Support Policy

Proposed availability, measurement, support windows and service-credit rules. Draft for legal review.

1. Draft status and covered services

This is a proposed SLA that becomes an operative commitment only after monitoring, staffing and contractual validation. It covers only Aster-operated production hosted APIs and storefront services expressly included in the order; the service list is example. It does not automatically cover the preview website, beta functions or customer-operated deployments. Self-hosted support requires a separate scope and response agreement. Marketing must not portray proposed targets as measured historical availability.

2. Monthly target and calculation

The proposed monthly availability target is 99.9%. Availability equals eligible service minutes minus affected unavailable minutes, divided by eligible service minutes. Unavailability is determined from verifiable external probes and service records showing core read/write or checkout APIs cannot process valid requests; probe locations, frequency and thresholds are example. Measurement is by billing period, tenant and affected component. A reachable static homepage cannot conceal a failed transaction API.

3. Maintenance and exclusions

Proposed scheduled maintenance requires at least 72 hours’ notice and is excluded up to 120 minutes monthly; excess time counts as unavailable. Emergency-maintenance exclusions depend on cause and contract. Customer systems, unauthorized changes, customer connectivity or independent PSP failures may be excluded to the extent evidenced. Infrastructure selected by Aster and Aster payment-integration errors cannot be excluded wholesale as “third-party” events. Exclusions require an actual causal link to the affected interval.

4. Support severity and hours

Proposed P1 covers widespread core-transaction failure, data-isolation risk or major security incidents, with 24/7 intake for paid production plans and a one-hour first-response target. P2 is a significant degradation with a workaround and a four-business-hour target; P3 is a general issue with a two-business-day target. Actual hours, timezone, holidays and plan differences are example and must be specified before launch. Response means acknowledgment and investigation, not guaranteed resolution. Support: support@example.com. Security: security@example.com.

5. Service credits

If formally adopted, monthly availability below 99.9% but at least 99% qualifies for a credit of 5% of the affected monthly service fee; below 99% but at least 95% qualifies for 10%; below 95% qualifies for 25%, without stacking in a month. Annual fees are divided by 12 for this purpose. Claims are sent to support@example.com within 30 days after month-end with affected times; customers need not re-prove events confirmed by Platform monitoring. Credits exclude PSP fees and do not reduce statutory compensation or remedies for material breach.

6. Incident communication and recovery

The Platform communicates major incidents, affected functions and recovery progress through the agreed status page https://example.com/status and effective contacts; this is a placeholder that must be independently usable at launch. Recovery must address data integrity, incomplete payment events, repeated submissions and refund reconciliation. Backup frequency, RPO, RTO and exercise evidence are example, with no unverified “zero data loss” promise. Personal-data breaches also invoke the DPA without waiting for a normal support ticket.

7. Repeated failure and changes

Two consecutive months below the proposed target entitle the customer to request a written improvement plan. Three consecutive failures that materially frustrate the contract may permit termination of the affected service and a proportionate refund of unused prepaid fees under the executed agreement. Material adverse SLA changes apply only at the next renewal after advance notice, never retrospectively to paid periods. Targets and credits must match the order; an unsigned or unvalidated draft is not a production availability guarantee.

Complaints, Intellectual Property and Content Procedure

Evidence-based reports, notices, counter-notices, human review and consumer referrals. Draft for legal review.

1. Contacts and responsibilities

The Platform entity is example, address example. General complaints: support@example.com. IP and legal notices: legal@example.com. Unlawful or dangerous content: abuse@example.com. Privacy: privacy@example.com. The merchant is the seller for store orders; the Platform helps identify that merchant and route requests, while its technical role does not excuse refusing complaints about its own conduct. This is a draft for legal review and does not replace special procedures required by applicable law.

2. Information for a report

Reports should include the complete relevant URL, store or order reference, content at issue, specific grounds, evidence and a contact name and email where possible. Rights complaints should describe the right, ownership or authority to act and the relationship between the challenged content and protected material. Only necessary information is requested, not public disclosure of unrelated identity or payment documents. Urgent safety reports that are anonymous or incomplete should still be assessed based on evidence and risk.

3. Intake, investigation and action

The proposed acknowledgment target for ordinary notices is two business days, with prompt escalation for personal safety, serious illegality or credential leakage. Review considers evidence, law and policy rather than treating an AI similarity score as an infringement finding. Specific content or actions may be restricted where necessary, with merchant notice of reason, scope, duration and appeal where permitted. Controlled evidence may be retained after removal without continuing public distribution of harmful material.

4. Intellectual-property counter-notices

A merchant challenging removal may provide the decision reference, original location, ownership or licensing evidence and a good-faith explanation. Where the US DMCA or another statutory counter-notice mechanism applies, counsel must configure required signatures, declarations, jurisdiction consent, service, forwarding and reinstatement periods; this general appeal does not replace them. US designated-agent and registration details are example, and no designation or safe-harbor protection may be claimed before actual registration and qualification.

5. Human review and repeated abuse

Both merchants and reporters may request human review based on material new evidence; reviewers must not merely repeat automated results. Malicious fabrication, repeated harassment or clear procedural abuse may be restricted after proportionate notice without blocking good-faith complaints. Repeat infringement or serious illegality may justify lawful contractual termination. Alleged, confirmed and overturned records must be distinguished rather than every notice treated as proven infringement.

6. Consumer remedies and external routes

Consumers may contact the merchant, payment provider, relevant authority or competent dispute body. This process requires no waiver of chargebacks, court proceedings or mandatory remedies and does not pause statutory deadlines. Applicable ADR bodies, registration details and participation obligations are example and must match the merchant’s markets and actual status. The discontinued EU ODR platform must not be presented as an available channel; use applicable active local complaint or ADR arrangements.

7. Privacy, evidence and legal requests

Complaints use only necessary personal data retained under the privacy notice and justified periods. Allegations may need to be shared so the responding party can answer, but unrelated sensitive information or reporter details must not be forwarded automatically. Law-enforcement and court demands require verification of authority, scope and legality, with customer notice where permitted. Proposed procedural targets do not reduce legally required protections or obstruct urgent relief, and the operative version and date must be recorded.

Store Consumer Terms of Sale

A seller-adopted consumer contract covering orders, delivery, digital content and statutory remedies. Draft merchant template.

1. Seller and template status

This is a template for merchant and local-counsel review and is not yet operative. Store example is operated by example; registration number example, registered address example, trading and complaint address example, telephone example, email support@example.com, website https://example.com and tax number example. Checkout must identify the actual seller. Aster provides software and is ordinarily neither the product seller nor a custodian of sale proceeds. Your sales contract is with the identified merchant, without limiting any party’s statutory duties arising from its actual conduct.

2. Product information and scope

These terms cover physical products identified on product and checkout pages and digital content or services only when expressly enabled and explained. Key characteristics, specifications, materials, sizes, compatibility, restrictions, price, availability and required safety warnings must be shown before purchase. Reasonable screen-color variation does not change promised specifications. The merchant must not rely only on AI-generated statements for regulated products, certifications, performance claims or legal rights.

3. Ordering, payment obligation and confirmation

Before submitting an order, you can review and correct items, quantities, address, shipping and payment details; the final button must clearly indicate an obligation to pay. The contract forms when the store sends express acceptance, clearly distinguished from a mere request-received message. Availability and price must be checked before acceptance, without an indefinite acceptance option. If an already-paid order cannot be accepted, we promptly explain and return the relevant payment in full. We provide a retainable copy of the order, price, terms version and cancellation information.

4. Prices, currency and payment

The payable total, transaction currency, applicable tax, shipping and necessary charges are clearly disclosed before payment; prices include tax where required. A browsing conversion is only an estimate if labeled as such, and exchange movements do not increase an accepted product price. Cards and other payment methods are processed by the PSP shown at checkout; card numbers and CVVs must not be sent through support. No future-charge mandate is created without express consent, and products, donations, insurance or subscriptions are not added automatically.

5. Delivery, risk and delays

Delivery regions, dispatch windows, estimated arrival, charges, tracking and import arrangements are disclosed on product pages, in shipping policy or at checkout. Except for special cases permitted by law, transit risk passes when you or a noncarrier third party you designate takes physical possession. If promised dispatch or delivery cannot be met, we explain a reasonable new date and available cancellation, refund or other rights without describing estimates as guarantees. Contact support@example.com for loss, damage or wrong items; a carrier delivery scan does not automatically defeat contrary evidence.

6. Withdrawal, returns and statutory protection

Applicable withdrawal, defective-product and other consumer rights follow the returns policy and mandatory law. Eligible EU distance purchases generally have a 14-day withdrawal period, with the correct start event, product exceptions and national implementation configured. Statutory defect rights do not automatically disappear because a commercial return window ended, packaging was opened or a merchant wrote “final sale.” Commercial warranties supplement statutory rights. Internal return-authorization procedures must not prevent timely exercise of legal rights.

7. Digital-content and service branch

This clause is enabled only if the store actually sells the relevant content, with access, license, compatibility, functionality, updates and restrictions disclosed before purchase. For applicable paid digital content not supplied on a tangible medium, starting before the withdrawal period ends requires prior express consent to early performance, express acknowledgment of the resulting loss of the withdrawal right and the required confirmation. Downloading or opening a file alone does not replace these conditions. Early service performance, completion and proportionate charges have different rules requiring separate requests and disclosures; the digital-content exception cannot simply be reused.

8. Errors, fraud checks and order restrictions

Obvious price errors, payment anomalies or stock shortages require human verification and notice. We may offer a corrected new proposal for your choice but may not unilaterally increase an accepted total. Specific fraud or legal risks may justify necessary and proportionate verification or temporary restrictions, without unlawful discrimination based on protected characteristics such as nationality or disability. An AI risk score alone cannot finally deny statutory rights. Paid orders that are unfulfilled or lawfully canceled must be refunded within applicable periods.

9. Support, privacy and AI

The store may use an identified AI assistant to help with queries and approved information. You can request a person or contact support@example.com; actual human support hours are example. AI replies do not change an existing contract or legal rights, and the merchant must correct errors. Personal data follows the store privacy notice; optional Cookies and marketing depend on separate choices. The existence of a privacy notice does not mean you consent to every purpose or authorize unrelated advertising.

10. Liability, applicable law and disputes

These terms do not exclude liability for the store’s fault that cannot lawfully be excluded or restrict mandatory product-safety, defect, refund, personal-injury or other consumer remedies. Proposed contract law is example and court or dispute body example, to be determined by counsel before publication. Mandatory protections of your habitual residence preserved by applicable law cannot be removed by this clause. You may contact the store, regulators or competent ADR bodies without prior permission from AI or the Platform to exercise legal remedies.

11. Version, language and changes

Template version: draft-2026-10-10. Operative date: example. The version accepted for an order applies to that order, and later changes cannot retrospectively reduce accrued rights. Chinese, English and other languages must correspond to the same approved version and satisfy applicable consumer-language requirements. If a provision is unenforceable, the remainder applies to the extent lawful, without a substitute clause used to evade mandatory protection.

Store Withdrawal, Returns and Refund Policy

Statutory withdrawal, defect remedies and optional commercial returns, with human handling and deadlines. Draft merchant template.

1. Seller and order of application

Seller: example. Support: support@example.com. Return address: example. Telephone: example. This draft requires actual markets, categories, procedures and addresses before trading. Statutory withdrawal, defect, nondelivery and other remedies prevail. Voluntary commercial returns may add rights but cannot reduce legal protection. AI, fraud labels, PSP technical limits or “final sale” copy cannot themselves defeat your statutory request.

2. Applicable EU branch: withdrawal period

For eligible physical distance purchases protected by the relevant EU Member State’s consumer rules, you may normally notify withdrawal within 14 calendar days after you or a designated noncarrier third party receives the goods, without giving a reason. Split-item, multiple-part and regular-delivery start events must reflect the actual transaction. Services and digital content not supplied on a tangible medium normally run from contract formation, subject to the exceptions below. Failure to provide proper withdrawal information may extend the legal period; the normal deadline cannot then simply be used to refuse.

3. How to notify and withdraw online

Notify us by support@example.com, a clear postal statement or the applicable online Withdraw from contract function at https://example.com/withdrawal. No prior return number or mandatory form is needed. Where online-withdrawal duties apply, the function remains prominent and available throughout the period, lets you confirm your name, order reference and receipt address, and submits through a clear Confirm withdrawal action. We then provide a retainable receipt of its content, date and time without undue delay. Timely submission is not changed by a queue for human review.

4. Sending goods back, costs and handling

Under applicable EU withdrawal rules, goods normally must be sent back within 14 days after notification unless we offer collection, with timely dispatch satisfying the return deadline. You bear direct return shipping only when lawfully disclosed before purchase and permitted by law; bulky items not normally returnable by post require a prior reasonable cost estimate. Necessary handling to establish nature, characteristics and functioning is not charged. Diminished value from excess handling may be deducted only with the legal prerequisites and evidence. Unopened condition or original packaging cannot be a blanket condition of statutory withdrawal.

5. Refund scope and timing

Under applicable EU withdrawal rules, we normally reimburse payments and standard outbound delivery no later than 14 days after receiving the withdrawal notice; the increment for a more expensive delivery option you chose may be excluded where lawful. Unless we offer collection, a goods refund may be withheld as law permits until the earlier of receipt of the returned goods or your evidence of dispatch. Refunds use the original method unless you expressly agree to a no-cost alternative; store credit cannot be forced. Other jurisdictions and nondelivery refunds follow their own deadlines, without postponing initiation for the length of a bank’s posting estimate.

6. Product exceptions and digital content

Customized, perishable and certain unsealed hygiene goods are excluded from no-reason withdrawal only when the precise legal conditions apply, without affecting defect remedies. Early supply of paid digital content not on a tangible medium invokes an exception only when all requirements are met, including prior express consent, express acknowledgment of the resulting loss of withdrawal rights and required contract confirmation. Services require separate treatment of early start, completion and proportionate charges with the necessary requests and acknowledgments. Applicable exceptions must be disclosed before purchase; “all digital goods are nonrefundable” is not acceptable.

7. Defects, damage, wrong items and nondelivery

Please describe the issue promptly with reasonably available order and factual information. An unboxing video, every piece of packaging or an unusually short notice period cannot be imposed as a condition of all remedies. Depending on law and circumstances, repair, replacement, price reduction, cancellation or refund may apply, with the merchant paying necessary costs allocated to it by law. Statutory quality rights differ from no-reason returns; expiry of a commercial window does not end defect rights. Nondelivery follows the shipping policy and cannot require consumers to seek recourse only from the carrier.

8. Voluntary commercial returns

Any voluntary return period beyond legal protection is example; eligible categories example; reasonable condition requirements example; direct-shipping allocation example; exchange process example. Merchants must not advertise extra promises such as “30-day unconditional refunds” before completing and publishing those commitments. More favorable promises already made must be honored. If an exchange is unavailable, agree on a refund or another option rather than automatically substituting a more expensive item or demanding extra payment.

9. Internal approval, refundable funds and failures

An authorized merchant employee approves each refund; AI only assists fact gathering and drafting. The system verifies order ownership, currency, captured or settled amounts eligible under PSP rules, and successful and pending refunds, preventing excessive or duplicate requests and reconciling outcomes. Internal balance validation is a financial safeguard, not a reduction of the amount legally owed. If the original channel fails, closes or cannot complete a refund, we promptly coordinate a lawful alternative acceptable to you rather than treating technical failure as loss of your rights.

10. Human review and disputes

You may request human review at support@example.com using the existing order reference without repeatedly negotiating with an agent. We propose acknowledging within two business days and providing a reasonable estimated handling time, without extending legal refund or withdrawal periods. PSPs, regulators, courts and applicable ADR bodies remain available. Where a chargeback exists, we may check for duplicate reimbursement but cannot suspend legal responsibilities indefinitely merely because a dispute exists.

11. Optional withdrawal statement

To example (address example; support@example.com): I/we notify withdrawal from the contract for the following goods or services. Order reference: example; goods or services: example; order date: example; receipt date if applicable: example; consumer name: example; address: example; receipt email: example; date: example. A signature is required only where applicable to a paper submission. Any other clear withdrawal statement is also accepted. Local counsel must assess whether a statutory model form should be supplied.

Store Privacy Notice

Merchant-controller notice of consumer-data purposes, recipients, retention and rights. Draft merchant template.

1. Controller and scope

This draft applies to store example, for which example determines the purposes and means of customer-data processing; address example, privacy@example.com, telephone example. Aster provides technical processing on merchant instructions. PSPs, carriers and others may be independent controllers where they determine their own purposes. The privacy lead, local representative or DPO, if required and actually appointed, is example. Actual merchant identity must be completed before launch rather than replaced with the Platform’s identity.

2. Data and sources

We propose processing your name, email, telephone, shipping and billing addresses, order items, amounts and currencies, returns and support information. We may receive PSP transaction references, tokens and status, carrier fulfillment details, necessary login and security records, and browsing data enabled by your choices. Sources include you, recipient information you supply and relevant providers. Full PANs, CVVs, passwords and unrelated sensitive information must not enter store forms or support; secure payment fields are operated by the actual PSP.

3. Purposes and bases

Necessary data is used to accept and fulfill orders, deliver, provide after-sales service and refund, normally on contractual necessity where that legal framework applies. Tax, accounting and product-safety retention follow legal duties. Proportionate fraud prevention, security and claims protection may rely on assessed legitimate interests where permitted. Marketing, optional tracking and other consent-required purposes use separate choices. Missing a necessary address or payment confirmation may prevent fulfillment; refusal of marketing does not prevent purchase. Actual bases must be checked against the merchant’s operations and target markets.

4. Providers and disclosure

Data is disclosed only as necessary for these purposes to Aster, actual PSP example, carrier example, email provider example, approved AI provider example, and necessary advisers or authorities. Actual roles, countries, data scope and policy links must be recorded, with changes assessed before use. The default is no sale of personal information, no sharing for cross-context advertising and no use of conversations or orders to train general-purpose models. Different actual arrangements require prior review and accurate notice rather than retaining a false default statement.

5. Transfers and retention

Processing, provider establishment and remote-access regions are example. For restricted international transfers, we first establish an applicable mechanism and explain how to obtain safeguard information. A global CDN does not automatically mean data remains only in one country. Retention is example for accounts, example for orders and tax records, example for support conversations, example for fraud and security records, and example for consent evidence. Each requires an actual period or clear criterion and justification, followed by deletion or proper anonymization with specific backup and legal-retention arrangements.

6. Your rights and choices

Depending on applicable law, you may contact privacy@example.com for access, correction, deletion, restriction, a portable copy, objection or withdrawal of consent, and complain to competent authority example. We use proportionate verification and respond within applicable periods without using an order dispute or unpaid amount to deny legal requests. Deletion may be limited by tax, product-safety or litigation retention, with scope and basis explained. Unsubscribing from marketing or withdrawing Cookie consent does not itself cancel an order.

7. Fraud signals, AI and human review

We may analyze order and necessary device signals for anomalies and use an identified AI assistant to explain approved policies. AI risk scores alone do not finally deny statutory refunds or determine significant merchant decisions; you may request human review, express your view and correct errors. An independent PSP may conduct its own verification and decisions, with its contact or policy provided. Support may access only what is needed for the issue and must not reveal recipient addresses or other customers’ data without appropriate verification.

8. Children, security and updates

Whether the store targets children is example; selling children’s products does not itself authorize collection of children’s personal data. Age or guardian authorization requires necessary and proportionate mechanisms rather than a general-terms assertion. We implement verified access, encryption and incident measures that must match actual practice. Material notice changes are disclosed in advance, with fresh consent where required, and do not retrospectively rewrite agreed purposes. Draft version: draft-2026-10-10. Operative date: example.

Store Cookie and Privacy Choices Policy

Separate choices for shopping essentials, language preferences, analytics and advertising. Draft merchant template.

1. Operator and technologies

This store is operated by example at https://example.com; contact privacy@example.com. This draft covers cookies, browser storage, pixels, device identifiers and similar access technologies. Before publication the merchant must check actual theme, plugin, PSP, support and analytics scripts. Using an Aster template does not complete that assessment. The Platform marketing site’s Cookie policy cannot replace the store’s actual notice.

2. Shopping and security essentials

The cart, checkout, account sign-in, request security and storage of privacy choices you request may need storage permitted by an applicable exemption. Each entry requires a necessity assessment and proportionate lifetime. Ad attribution, cross-site tracking or unnecessary fingerprinting cannot be labeled checkout essentials. Necessary PSP security technology must identify the provider and its role; “payment security” does not authorize all associated marketing.

3. Optional purposes and initial state

Language and display preferences, traffic statistics, advertising and remarketing are configured separately. Optional purposes are disabled by default and related tools load only after consent where required. Country-specific statistics or appearance exceptions require all conditions and the required objection mechanism and cannot simply be copied across jurisdictions. Current advertising and analytics providers are example (unconfirmed); scripts with unresolved purposes or bases cannot load before disclosure is completed.

4. Accepting, refusing and changing choices

The privacy panel offers understandable, comparably prominent accept, refuse and category settings, without preselected choices or silence treated as consent. You may change preferences through the footer’s Privacy choices link. Refusal does not block purchases that do not require optional tracking. New purposes or providers trigger renewed choices as required instead of indefinite expansion of old consent. Preference evidence records your wishes rather than acting as an advertising identifier.

5. Required technology register

The production register must list each entry’s name example, provider example, domain example.com, purpose example, category example, lifetime example, recipients and countries example, basis example and disablement method example, distinguishing session and persistent storage. Deleting a browser cookie may not delete related server records, whose periods and rights follow the privacy notice. Merchants must rescan periodically and remove unused or no-longer-authorized entries.

6. Third-party pages and opt-out signals

After navigation to payment, shipping or social sites, those providers may process data under their own policies; the transition should be clear rather than disguising the page’s identity. Universal opt-out signals must be recognized and applied where required, without unnecessary repeated identification. Browser deletion or blocking may affect necessary functions, and assistance remains available at privacy@example.com.

7. Updates and contact

Draft version: draft-2026-10-10. Operative date: example. The choice interface, register and privacy notice must be released together; changing text while old scripts continue is insufficient. Material changes are notified in advance, with consent obtained before processing when necessary. Contact privacy@example.com or address example. This policy makes no certification claim under GDPR, PECR or any other law.

Store Shipping and Fulfillment Policy

Actual dispatch and delivery commitments, delays, loss, damage and import arrangements. Draft merchant template.

1. Merchant, regions and product types

Seller: example. Warehouse or dispatch location: example. Delivery countries and restrictions: example. Contact: support@example.com. This draft applies to enabled physical shipping; digital delivery must be separately explained on the product page. Unsupported destinations and categories must be identified before checkout rather than taking payment and invoking undisclosed restrictions. Product origin, dispatch location and merchant incorporation must not be confused.

2. Handling, dispatch and arrival

Order processing time is example, cutoff and timezone example, carrier example, estimated transit example, and business days and holidays example. Dispatch means handing goods to the carrier; delivery means customer receipt and must be stated separately. Preorders or customized goods require reasonably supported dates and payment arrangements. Merchants must not base delivery promises only on AI forecasts, and checkout confirmation retains the promise shown at purchase.

3. Charges and split shipments

Shipping charges, free-shipping conditions, remote-area charges and optional express costs are disclosed before payment. Merchant-initiated split shipments do not create unapproved extra charges; packages receive separate tracking and estimates. A more expensive service requires an active choice and clear price, without preselected insurance or protection. Refunds allocate original and return shipping under applicable rules.

4. Delays and the applicable US branch

For orders covered by the US FTC Mail, Internet, or Telephone Order Merchandise Rule, the merchant needs a reasonable basis for dispatch within the promised period. Without a stated dispatch time, the usual default is dispatch within 30 days after receipt of a properly completed order, subject to the rule’s specific exceptions. An inability to dispatch on time requires a compliant delay notice and cancellation with prompt-refund options before the applicable deadline. Further or extended-delay consent rules require specific configuration. The proposal prefers an express customer choice rather than treating silence as universal consent.

5. EU delivery and other markets

Under applicable EU consumer rules, delivery normally must occur no later than 30 days after contract formation unless otherwise agreed. Additional reasonable time, exceptions allowing immediate termination and refunds follow local implementing rules when delivery obligations are breached. “Delivery” here differs from “dispatch” under the US rule above. The UK, India and other markets require their own applicable-law configuration and do not automatically adopt EU or US rules through this template.

6. Loss, damage and address issues

For lost, damaged or misdelivered goods, contact support@example.com. We investigate and provide legally appropriate remedies rather than only requiring you to negotiate with the carrier. Delivery records, photos and tracking are evidence to assess, not automatic final proof. You may request an address correction before dispatch; after dispatch we explain feasibility and any actual fee agreed in advance. Noncollection or address error does not automatically justify retaining all payment; actual costs and consumer-protection rules govern.

7. Customs, importer and taxes

Before cross-border purchases, disclose importer responsibilities example, whether duties and taxes are included example, clearance charges example, restricted categories and necessary recipient data. Consumer-paid import charges require clear, understandable disclosure of possible costs and the calculation basis. Costs allocated to the merchant cannot be shifted after delivery. Customs delays require communication and do not remove promised or statutory refund and consumer remedies.

8. Records and contact

The merchant retains order promises, delay notices, customer choices, tracking and refund records to resolve disputes and meet necessary legal obligations without excessive retention. Status is based on actual carrier events and human verification, and the AI assistant must not fabricate dispatch or delivery. Version: draft-2026-10-10. Operative date: example. Human support hours: example. Contact: support@example.com.

Store Payment, Taxes and Currency Policy

Consumer information on transaction currency, PSPs, verification, refunds and taxes. Draft merchant template.

1. Payee and payment providers

The seller and payee merchant is example, statement descriptor example, PSP example, PSP policy link https://example.com. These placeholders must be replaced with the actual integration details. Aster software does not hold this store’s consumer funds; the merchant receives settlement from its PSP. Payment for goods is separate from the merchant’s SaaS subscription to Aster and does not enroll you in that subscription.

2. Total price and charge authorization

Before payment, item prices, discounts, shipping, applicable taxes and the total are displayed with a confirmation action indicating payment obligation. Add-ons require active choices, not preselected extra charges. If a product is a recurring subscription, its amount per period, frequency, start, renewal, term and cancellation path require separate clear disclosure and authorization. An ordinary product order does not contain an implied recurring-charge mandate.

3. Multiple currencies and conversion

Available transaction currencies are example. Final charge currency and amount are consistent across checkout, payment confirmation and order records. Browsing estimates identify their indicative nature and source or reference time. Currency precision and rounding must not conceal extra fees, and totals must be reconcilable. Issuer conversion and foreign-transaction fees follow issuer rules, so we cannot guarantee the bank’s domestic-currency debit, but this does not permit changing the accepted merchant transaction price.

4. Verification, capture and order status

The PSP or issuer may require additional verification such as 3-D Secure or wallet confirmation. Authorization does not necessarily mean capture, and the merchant must distinguish pending, authorized, captured and refunded states. A completion page is not the sole evidence of payment; verified events and reconciliation establish status. If a page fails, contact a person with the order reference. Repeated clicks must not cause duplicate billing, and suspected duplicates require prompt investigation and correction.

5. Payment data and security

Full PANs, CVVs and other sensitive authentication data are handled by the actual PSP’s secure payment flow, not collected or retained by the merchant or Aster through their own fields, logs, email or AI support. Systems retain only tokens, references, payment-method summaries and status needed for transactions and after-sales service. Do not comply with requests to send CVVs, one-time passcodes, passwords or private keys through support; contact security@example.com to verify.

6. Refunds and currency differences

Refunds are reviewed by the merchant and executed through an authorized process under the returns policy, normally to the original method in the original transaction currency. The merchant refund reflects the amount legally owed. Different bank conversion dates may create a domestic-currency difference that the relevant provider must explain, so identical domestic-currency posting cannot be promised. Refund initiation and actual bank posting are distinct. Estimated posting time is example, to be confirmed with the actual PSP, while statutory initiation or completion duties prevail.

7. Taxes and invoices

Tax type, registration, invoice issuer and tax-inclusive pricing must reflect the actual seller, product, customer status and market. Sales tax, VAT/GST, import duties and clearance fees are distinct. You may supply required invoice information and contact support@example.com for corrections. Platform calculations or AI suggestions are not tax rulings. The merchant verifies registrations, rates, exemptions and filings and cannot shift all consequences of its mistakes to consumers.

8. Disputes and contact

For an unrecognized charge, payment failure or suspected unauthorized transaction, contact support@example.com or your payment institution. The merchant may request necessary order evidence but not full card details and must not obstruct a timely bank dispute. Amounts already reimbursed elsewhere may be checked to prevent duplicate payment without indefinitely freezing unrelated refunds. Version: draft-2026-10-10. Operative date: example. This policy must align with actual PSP terms and consumer rights.

Store AI Support Notice

When customers interact with AI, what it can do and how to contact a person. Draft merchant template.

1. You are interacting with AI

Store example may use AI support for product, order and after-sales questions. The conversation is clearly labeled “AI assistant” at the start and does not impersonate an employee, lawyer or payment institution. Merchant example is responsible for its store’s support operation. AI is supplied through Aster and merchant-approved providers. This draft notice must match actual functions and data flows at launch.

2. Available help

AI may explain merchant-reviewed product, shipping and returns information, look up your order after necessary verification, organize an issue and draft an after-sales request. It accesses only information needed for the issue and must not show complete cards, other customers’ records or unnecessary recipient details. Without actual order or carrier evidence, it must say it cannot confirm rather than fabricate refund completion or delivery.

3. Human handling and limits

Every refund is approved by an authorized merchant employee. AI cannot alone transfer money, change a payout account or finally refuse legal requests. Withdrawal, disputes, product safety, privacy rights, payment anomalies and significant commitments must have human review. AI explanations do not change order prices, accepted terms or statutory protections. You do not need AI approval to submit a valid request.

4. Contacting a person and request timing

Choose Talk to a person in the conversation or contact support@example.com, telephone example. Human hours and timezone are example, and the usual response target is example. Repeated AI interaction, unnecessary explanations or an extra fee are not required. Requests can be submitted and recorded outside working hours, and legally effective notification is measured from valid submission rather than a later human handoff.

5. Data and sensitive information

Conversations may include your content, order references and handling records, used under the store privacy notice to answer, hand over and correct issues. Actual AI provider example, processing regions example and conversation retention example must be disclosed before launch. General-purpose model training is disabled by default. Do not send passwords, one-time codes, PANs, CVVs, private keys or unrelated sensitive information. Accidentally submitted secrets must be restricted and handled under procedure rather than added to model knowledge.

6. Errors and correction

AI may misunderstand or provide outdated information. You can refer a conversation to a person, and we check the actual contract, policy and order facts and explain corrections. The merchant cannot avoid responsibility merely because “AI said it.” Where legal interpretation is uncertain, AI must escalate rather than determine applicable law, consumer deadlines or liability limits itself.

7. Choice and continued access

Choosing not to use AI does not alter the substantive policies for buying, canceling, complaining or requesting refunds. Human channels must remain usable without unreasonable barriers. Disabling AI or a service outage does not erase submitted requests. Version: draft-2026-10-10. Operative date: example. Contact: support@example.com. Voice recording, screen sharing or new data purposes require separate disclosure and legally required choice or consent.

Store Accessibility Statement

Design targets, actual assessment status, known barriers and assistance channels. Draft assessment template.

1. Operator and scope

example is responsible for the store experience at https://example.com; contact accessibility@example.com, address example. We plan to make browsing, search, product selection, checkout, cancellation, returns and support usable by customers with different abilities. This is an unassessed draft, not a statement of full conformance or external certification. Production publication must identify covered domains, applications, third-party flows and testing dates.

2. Design target and legal requirements

The proposed frontend design and testing target is WCAG 2.2 AA, including keyboard operation, visible focus, sufficient contrast, labels and error explanations, text resizing and reduced nonessential motion. Applicable legal standards, European Accessibility Act implementation, exemptions and transitional conditions require assessment of merchant size, service and markets. Adopting a technical target does not automatically establish compliance with every legal duty.

3. Assessment status and known limits

Assessment method: example. Independent evaluator: example. Last test: example. Browsers and assistive technologies: example. Conformance status: example. Known barriers and pages: example. Owner and remediation date: example. Untested areas must be labeled honestly rather than presenting AI-generated audit scores as human test results. Payment verification, Cookie controls, chat, dynamic carts and mobile flows must be covered, not just the homepage.

4. Assistance and alternative access

For a barrier, contact accessibility@example.com or telephone example and describe your preferred contact format, page and issue; no medical diagnosis is required. We propose acknowledging within two business days and offering reasonable human assistance, accessible formats or an alternative process. Alternatives must preserve prices and substantive consumer rights, never require unsafe transmission of payment secrets, and do not replace long-term remediation of the website.

5. Third parties and content management

We assess accessibility when selecting PSPs, support tools and plugins, coordinate supplier fixes and explain workable alternatives when barriers arise. The merchant maintains product-image alternatives, captions, readable documents and translations, reviewing agent-generated content. Third-party components do not justify a blanket exclusion of responsibility for the complete purchase and after-sales experience.

6. Feedback, escalation and updates

If assistance does not resolve an issue, request escalation to responsible person example and contact relevant regulator or enforcement body example under applicable law. Material theme, checkout, language or support changes require revalidation of affected flows and updated known-issue and remediation information. Statement version: draft-2026-10-10. Operative publication date: example. This statement does not restrict legal complaint or remedy routes.

Primary sources & review context

  1. EU GDPR — Regulation (EU) 2016/679

    Primary text: roles, lawful processing, rights, processor contracts, security, breach and transfer provisions. Applicability and local implementation must be reviewed.

  2. EDPB Guidelines 07/2020 on controller and processor concepts

    Official interpretation of factual controller/processor roles; labels alone do not determine legal status.

  3. European Commission — Standard Contractual Clauses

    Official source for transfer clauses. A selected module and completed annexes must be executed; a draft DPA reference does not execute SCCs.

  4. EU Consumer Rights Directive 2011/83/EU

    Baseline text for distance-sale information, withdrawal, reimbursement, exceptions and delivery. Read with amendments and national implementing rules, not as a universal consumer code.

  5. Directive (EU) 2023/2673 — online withdrawal function

    Article 1 adds Article 11a to Directive 2011/83/EU; Article 2 provides application from 19 June 2026. Check relevant national transposition and eligible transactions.

  6. EU Regulation 2024/3228 — discontinuation of ODR platform

    The former EU ODR platform was discontinued and its regulation repealed with effect from 20 July 2025. Do not retain obsolete live-complaint links.

  7. FTC Mail, Internet, or Telephone Order Merchandise Rule

    Official rule summary distinguishing promised shipment and the usual 30-day default, delay consent and refund duties.

  8. 16 CFR Part 435 — current electronic CFR text

    Check detailed coverage, shipping-delay notices, exceptions and prompt-refund methods. Dispatch is not delivery; timelines are not universal across payment methods.

  9. FTC — Restore Online Shoppers’ Confidence Act

    Federal online consumer negative-option framework. Consumer applicability differs from a B2B merchant SaaS contract; state requirements need separate review.

  10. Federal Register 2026-02866 — Negative Option Rule revision

    Effective 12 February 2026, restores the pre-2024 Negative Option Rule following court vacatur; do not describe the 2024 click-to-cancel amendments as operative.

  11. FTC — March 2026 negative-option rulemaking notice

    The FTC announced a new advance notice on 11 March 2026. A proposal is not a final enforceable rule; recheck before launch.

  12. ICO — Guidance on storage and access technologies

    Final guidance updated 29 April 2026 following PECR changes. Covers cookies and similar technologies, conditional exceptions and practical consent.

  13. ICO — Storage and access technology exceptions

    Assess every condition for communications, necessity, statistical, appearance or emergency exceptions; do not infer a general advertising exception.

  14. ICO — Managing consent in practice

    Official operational guidance for clear choices, refusing, withdrawal and changed purposes.

  15. MeitY — Digital Personal Data Protection Rules, 2025 (final Gazette)

    Final Gazette G.S.R. 846(E), not the January 2025 draft. Rule 1 stages commencement. An India launch needs the Act commencement notification and any subsequent amendments checked alongside this text; do not assume all provisions are already applicable.

  16. European Commission — European Accessibility Act

    Official scope includes e-commerce. Assess national implementation, service scope, exemptions and evidence instead of blanket conformance claims.

  17. W3C — Web Content Accessibility Guidelines 2.2

    Primary technical standard. WCAG 2.2 AA is a proposed design target, not a completed audit or automatic finding of legal compliance.