This is a policy template for a merchant and its customers, not a sales contract between Aster and visitors to this website.
Store policies are templates for merchants to adapt and review against their actual seller, products and sales markets.
1. Controller and scope
This draft applies to store example, for which example determines the purposes and means of customer-data processing; address example, privacy@example.com, telephone example. Aster provides technical processing on merchant instructions. PSPs, carriers and others may be independent controllers where they determine their own purposes. The privacy lead, local representative or DPO, if required and actually appointed, is example. Actual merchant identity must be completed before launch rather than replaced with the Platform’s identity.
2. Data and sources
We propose processing your name, email, telephone, shipping and billing addresses, order items, amounts and currencies, returns and support information. We may receive PSP transaction references, tokens and status, carrier fulfillment details, necessary login and security records, and browsing data enabled by your choices. Sources include you, recipient information you supply and relevant providers. Full PANs, CVVs, passwords and unrelated sensitive information must not enter store forms or support; secure payment fields are operated by the actual PSP.
3. Purposes and bases
Necessary data is used to accept and fulfill orders, deliver, provide after-sales service and refund, normally on contractual necessity where that legal framework applies. Tax, accounting and product-safety retention follow legal duties. Proportionate fraud prevention, security and claims protection may rely on assessed legitimate interests where permitted. Marketing, optional tracking and other consent-required purposes use separate choices. Missing a necessary address or payment confirmation may prevent fulfillment; refusal of marketing does not prevent purchase. Actual bases must be checked against the merchant’s operations and target markets.
4. Providers and disclosure
Data is disclosed only as necessary for these purposes to Aster, actual PSP example, carrier example, email provider example, approved AI provider example, and necessary advisers or authorities. Actual roles, countries, data scope and policy links must be recorded, with changes assessed before use. The default is no sale of personal information, no sharing for cross-context advertising and no use of conversations or orders to train general-purpose models. Different actual arrangements require prior review and accurate notice rather than retaining a false default statement.
5. Transfers and retention
Processing, provider establishment and remote-access regions are example. For restricted international transfers, we first establish an applicable mechanism and explain how to obtain safeguard information. A global CDN does not automatically mean data remains only in one country. Retention is example for accounts, example for orders and tax records, example for support conversations, example for fraud and security records, and example for consent evidence. Each requires an actual period or clear criterion and justification, followed by deletion or proper anonymization with specific backup and legal-retention arrangements.
6. Your rights and choices
Depending on applicable law, you may contact privacy@example.com for access, correction, deletion, restriction, a portable copy, objection or withdrawal of consent, and complain to competent authority example. We use proportionate verification and respond within applicable periods without using an order dispute or unpaid amount to deny legal requests. Deletion may be limited by tax, product-safety or litigation retention, with scope and basis explained. Unsubscribing from marketing or withdrawing Cookie consent does not itself cancel an order.
7. Fraud signals, AI and human review
We may analyze order and necessary device signals for anomalies and use an identified AI assistant to explain approved policies. AI risk scores alone do not finally deny statutory refunds or determine significant merchant decisions; you may request human review, express your view and correct errors. An independent PSP may conduct its own verification and decisions, with its contact or policy provided. Support may access only what is needed for the issue and must not reveal recipient addresses or other customers’ data without appropriate verification.
8. Children, security and updates
Whether the store targets children is example; selling children’s products does not itself authorize collection of children’s personal data. Age or guardian authorization requires necessary and proportionate mechanisms rather than a general-terms assertion. We implement verified access, encryption and incident measures that must match actual practice. Material notice changes are disclosed in advance, with fresh consent where required, and do not retrospectively rewrite agreed purposes. Draft version: draft-2026-10-10. Operative date: example.