The short version
- We collect what you give us when you book a call, start a module or email us, plus the basic server logs every website keeps.
- We use it to reply to you and to run our business. We don’t sell it, and we don’t put you on a marketing list without asking.
- This site sets no advertising or analytics cookies.
- When we run a store for a client, their customers’ data belongs to the client. We handle it only on their instructions.
- You can ask us what we hold about you, and ask us to correct or delete it.
This summary is here to help. The full text below is what applies.
1. Who we are, and our two roles
This policy is from [legal entity name], which operates as RunMyStore (“RunMyStore”, “we”, “us”). We build and run ecommerce operations for other brands: storefronts, search and content, email and SMS, wholesale pipelines, fulfillment and reporting.
That work puts us in two different positions, and the rules are different for each:
- Our own website and business. When you visit runmystore.com, apply for a build, or talk to us as a prospective or current client, we decide how your information is used. We are the “controller” (or “business”) for that information. Sections 2 to 5 and 9 to 16 cover this.
- Work we do for clients. When we operate a client’s store, mailing list, CRM or fulfillment, we handle their customers’ information on the client’s behalf and on their instructions. The client is the controller; we are their “processor” (or “service provider”). Sections 6 to 8 cover this.
If you bought from, or applied for a wholesale account with, a brand we work for, that brand’s privacy policy is the one that applies to you. See section 6 for how to make a request.
2. What we collect on this site
Information you give us
- Booking a call uses a third-party scheduling service, which collects your name, email and the time you pick under its own privacy policy, and passes the booking to us.
- Starting a module uses a third-party checkout. The payment provider handles your card details under its own policy; we receive your name, email, business name and what you bought — never your full card number.
- Emailing or messaging us gives us whatever you send, along with your address or number.
If you contact us by WhatsApp, email or phone instead, we receive whatever you send, along with your number or address. WhatsApp is operated by Meta, and its own privacy policy applies to your use of it.
Once you become a client we also hold the business records any supplier holds: contracts, invoices, billing contacts and our working correspondence with your team.
Information collected automatically
Like every website, the servers that deliver this site record standard technical logs: IP address, browser and device type, the pages requested and when. We use these to keep the site secure and working. We do not use them to build a profile of you.
Cookies and tracking
This site does not set advertising cookies, does not use analytics or session-recording scripts, and does not load third-party trackers. Our fonts are served from our own domain rather than a third-party font service. If we ever add analytics, we will update this policy first and, where the law requires it, ask for your consent before anything is set.
What we ask you not to send
We never ask for passwords, payment card numbers, government ID numbers or health information through this site. Please don’t send them. Access to client systems is always granted by invitation, never by sharing a password.
3. How we use it
| Purpose | Legal basis (where GDPR / UK GDPR applies) |
|---|---|
| Replying to an enquiry and arranging a call | Steps taken at your request before entering a contract |
| Running the modules you subscribe to, billing and supporting you | Performance of our contract with you |
| Keeping the site secure, preventing spam and abuse | Our legitimate interest in a safe, working website |
| Keeping financial and tax records | Legal obligation |
| Sending you marketing, if you have opted in | Your consent, which you can withdraw at any time |
We do not make decisions about you using solely automated processing that has legal or similarly significant effects.
4. What we don’t do
- We do not sell personal information, and we have not done so in the past 12 months.
- We do not share personal information for cross-context behavioral advertising.
- We do not add you to a marketing list because you booked a call or emailed us. An enquiry gets a reply, not a campaign.
- We do not use your enquiry to enrich or resell a profile of you.
- We do not use one client’s data for the benefit of another client.
6. Data we handle for our clients
Running a client’s commerce stack means working inside their systems. Depending on the engagement that can include:
- store customer and order records (names, contact details, order history, shipping addresses);
- email and SMS subscriber lists, including consent status and engagement history;
- wholesale applicants and accounts held in the client’s CRM: business name, contact people, license or resale details supplied on the wholesale form, quotes, orders and the record of calls, texts and emails;
- accounting and inventory records connected to those orders;
- the result of age or identity checks the client is required to perform. We do not ask to receive or keep copies of ID documents.
For all of this, the following always applies:
- The client owns it. Customer lists, order data and wholesale accounts are the client’s, during the engagement and after it.
- We act on instructions. We use client data only to deliver the services in our written agreement with that client, and for no purpose of our own.
- Access by invitation. We work through named user accounts the client grants and can revoke. We do not take shared passwords. We ask for the least access the work needs.
- Payment data stays with the processor. Card details are handled by the client’s payment processor. We are not the merchant of record and do not store card numbers.
- Subprocessors. The tools in a client’s stack (their store platform, CRM, email service and so on) are usually the client’s own accounts. Where we bring a tool of ours, we tell the client first.
- At the end. When a module or engagement ends — including one cancelled inside its first 30 days — we remove our access, and return or delete client data in our possession as the agreement directs.
- Incidents. If we become aware of a security incident affecting client data in our care, we notify that client without undue delay so they can meet their own obligations.
We sign a data processing agreement with any client who needs one. If you are a customer of one of our clients and want to access, correct or delete your information, contact that brand directly. If you send the request to us, we will pass it to them and help them respond.
7. Fulfillment and shipping data
Where we store and ship a client’s products, we receive the information needed to get an order to the door: recipient name, delivery address, phone or email for delivery updates, order contents, and any age or signature requirement on the shipment.
- We use it to pick, pack, ship and track the order, to handle returns and delivery problems, and to keep the shipping records the law and carriers require.
- We share it with the carrier delivering the parcel and the shipping software that produces the label. Carriers handle it under their own privacy policies.
- We do not contact recipients for marketing, and we do not reuse a client’s shipping data for any other client or for ourselves.
- Packing and shipping records are kept only as long as the client agreement, carrier claims windows and applicable record-keeping rules require.
8. AI assistants
Our Customer Service module answers a client’s customer email and chat with an assistant trained on that client’s products, policies and voice, with a human escalation path. Other modules use the same assistant to write and sort. If you are a customer of one of our clients, your messages to that brand may be answered this way.
For Lead Engine we find businesses that fit a client’s category using public sources — company websites, directories and business listings — and pass the business, a contact role and a reason for fit to the client. We don’t scrape personal social-media profiles or buy consumer lists. If you were identified this way and would rather not be, email us and we will remove you from future lists for every client.
- An assistant built for a client works from that client’s data and is available to that client’s team. It is not shared with, or used to inform work for, any other client.
- We do not use client data to train models of our own.
- These assistants run on third-party AI services. We choose business-grade services and settings under which the provider does not use the content to train its general models, and we tell the client which provider is used.
- Assistants are a tool for the client’s staff. They are not used to make automated decisions about individual consumers.
9. Calls, texts and email
If you give us a phone number, we may call or message you about your application or your account. We do not send marketing texts unless you have separately and expressly opted in. You can reply STOP to any text to end messages, and every marketing email we send includes an unsubscribe link. Message and data rates may apply. We do not share mobile opt-in data or consent with third parties for their marketing.
10. How long we keep it
- Enquiries that don’t become a subscription: up to 24 months after our last contact, then deleted — or sooner if you ask.
- Client business records: for the life of the engagement and as long afterwards as tax, accounting and legal rules require (typically up to seven years for financial records).
- Client data we process: only for the engagement, then returned or deleted as described in section 6.
- Server logs: for a short period set by our hosting provider, generally no more than 90 days.
11. How we protect it
We use measures appropriate to a business of our size and the data involved: encrypted connections to this site, named accounts with multi-factor authentication where the tool supports it, least-privilege access, prompt removal of access when someone leaves a project, and confidentiality obligations for everyone who works with us. No system is perfectly secure, and we won’t pretend otherwise. If a breach affects your information, we will notify you and the relevant authorities as the law requires.
12. Your rights
Depending on where you live, you may have the right to:
- know what personal information we hold about you and get a copy of it;
- have inaccurate information corrected;
- have your information deleted;
- object to or restrict certain uses, and withdraw consent you have given;
- receive your information in a portable format;
- opt out of the sale or sharing of personal information and of targeted advertising — though we do neither;
- appeal a decision we make about your request, and complain to your data protection authority or state attorney general.
To make a request, email [privacy contact email]. We will confirm it is really you before acting, which may mean asking you to reply from the address we hold. We respond within 30 days (or 45 where state law allows), and we’ll tell you if we need longer. We will never treat you differently for exercising these rights. An authorized agent can make a request for you with written permission.
We honor these rights for everyone as far as we reasonably can, not only where a law such as the GDPR, UK GDPR, or a US state privacy law such as the CCPA compels it.
13. International transfers
We are based in the United States and our service providers are mainly located there. If you contact us from elsewhere, your information will be processed in the US, where privacy laws may differ from yours. Where the law requires a safeguard for that transfer, such as standard contractual clauses, we rely on one.
14. Children
This site is for businesses. It is not directed to anyone under 18, and we do not knowingly collect information from them. If you believe a minor has sent us information, contact us and we will delete it.
15. Changes to this policy
If we change how we handle personal information, we will update this page and the date at the top before the change takes effect. If a change is significant and we have your contact details, we will tell you directly.
16. Contact
[legal entity name]
[mailing address]
[privacy contact email]
See also our Terms of Use.