This document concerns Aster’s software service and its merchant customers. Store product sales remain the responsibility of the actual merchant.
1. Who we are and our roles
This draft notice is proposed for example, address example, contact privacy@example.com. For Platform visitors, merchant accounts, subscription billing and its own security operations, example acts as controller to the extent it determines processing purposes and means. Aster acts under the DPA as processor for store consumer, order and support data processed on merchant instructions; consumers should first contact their seller. Any required privacy lead, local representative, data protection officer and supervisory authority are example and must be completed after applicability is assessed, without implying an appointment that has not occurred.
2. Categories and sources
Proposed categories include name, work email, business details, login and role information, subscription billing details, PSP tokens and transaction references, support requests, IP and security events, and device or permitted usage information. Sources are the individual, authorized business administrators, PSPs and connected providers, and records created through service use. Full PANs, CVVs, account passwords, private keys and unnecessary sensitive information must not enter Platform forms or AI prompts. Actual collection fields must match the data inventory verified before publication.
3. Purposes and applicable legal bases
Processing necessary to establish and perform a service contract with an individual relies on contract necessity. Business-contact management, security, abuse prevention and service maintenance may rely on assessed legitimate interests where applicable. Invoicing and mandatory record retention rely on legal obligations. Optional marketing and tracking that legally require consent rely on separate consent. Refusing optional consent does not affect core service; missing necessary fields may prevent account creation or subscription. These bases apply where recognized by the relevant legal framework and require mapping for other jurisdictions.
4. Recipients, AI and secondary-use limits
Necessary data may be disclosed for these purposes to contracted infrastructure, transactional email, support and AI providers, and to PSPs, advisers or authorities acting under their own payment or legal responsibilities. Actual recipients and processing locations must appear in the published register, currently example. The proposed default is no sale of personal information, no sharing for cross-context advertising and no training of general-purpose models on merchant or consumer data. A proposed change requires prior assessment, disclosure and necessary authorization and cannot silently expand DPA instructions through an update notice.
5. Locations, transfers and retention
Primary processing, backup and remote-support locations are example and must account for both recipients and remote access. Restricted international transfers are enabled only after a lawful mechanism is established, such as applicable adequacy decisions, executed standard clauses with completed annexes and necessary supplementary measures. Active account records remain through the contract and export period; proposed deletion is within 30 days after that period for production data and within 90 days for rotating backups. Specific periods for invoices, security evidence and mandatory records are example and must have a legal and purpose-based justification rather than indefinite retention.
6. Rights and requests
Subject to applicable law, individuals may request access, correction, deletion, restriction, a portable copy, objection to certain processing and withdrawal of consent, and may complain to a competent authority. Requests go to privacy@example.com; verification requires only proportionate information and never a full payment card. Withdrawal does not affect previously lawful processing. The Platform responds within applicable statutory periods and cannot use a merchant billing dispute to refuse legal rights. Requests concerning merchant-controlled store data are promptly forwarded to the merchant and assisted under the DPA.
7. Automation, security and minors
Risk signals identify anomalies and assist human review; they do not alone determine final refusals with legal or similarly significant effects. Necessary immediate security restrictions must have an explanation and a human appeal path. Proposed safeguards include least privilege, encryption, logging and incident response; the operative notice must describe only implemented, verified measures. The Platform targets business operators and does not market to children. If it learns it collected children’s information improperly, it will restrict, delete or resolve it with a lawful guardian as applicable law requires.
8. Optional communications, updates and contact
Marketing emails must provide an unsubscribe option; billing, security and service notices must not impose marketing consent. Material privacy changes require clear advance notice and fresh consent where legally required. This draft version is draft-2026-10-10; the operative date is example. Privacy complaints: privacy@example.com. Postal address: example. Claims such as “GDPR compliant,” “PCI certified” or comparable certifications require independent evidence and do not arise merely from this document.