Privacy Policy
Shoppa Dynamics ("Shoppa", "we", "us") operates the Shoppa platform, including our website, POS application, BackOffice dashboard, and Webstore hosting service. This Privacy Policy explains what data we collect when you use any part of the platform, how we use it, who we share it with, and what rights you have over it. If you have questions, contact us at privacy@shoppahq.com.
Data We Collect
We collect four categories of data. Account data: your name, email address, business name, business address, phone number, and billing information you provide when signing up. Business data: the products, inventory records, sales transactions, customer records, supplier records, purchase orders, and invoices you create while using the platform -- this is your data and you own it. Technical data: IP address, browser type, device information, operating system, session duration, pages visited, and other usage patterns collected automatically when you use the platform. Communication data: messages you send to our support team, emails you receive from us, and records of your interactions with our support channels.
Your Customers' Data
When you use Shoppa, you may store information about your own customers -- names, contact details, purchase history, and similar records. In that relationship, you are the data controller and we are the data processor. We process your customers' information only to provide the Shoppa service to you. We do not use your customers' data for our own marketing, analytics, or any other purpose. You are responsible for having appropriate privacy notices in place for your customers and for complying with the privacy laws that apply in your jurisdiction.
How We Use Your Data
We use your data to: provide and operate the Shoppa platform; route transactions to the payment processor you have selected; generate the analytics and business intelligence reports visible in your BackOffice dashboard; send you account communications such as receipts, billing notifications, and security alerts; send you marketing emails and product updates if you have opted in (you can unsubscribe at any time from any email we send); improve the platform by analyzing usage patterns in aggregate; detect and prevent fraud and unauthorized access; and comply with our legal obligations.
Who We Share Data With
We share data only as necessary to operate the service. Payment processors: when you complete a transaction, we pass the required data to the processor you have connected -- this may be Paystack, Flutterwave, or another processor you choose. Infrastructure providers: your data is hosted on DigitalOcean servers and our website runs on Vercel. Email: we use Resend to send transactional emails and newsletters. Analytics: we use PostHog to understand how merchants use the platform; PostHog receives anonymized usage data. Error tracking: we use Sentry to capture error reports so we can fix bugs; Sentry may receive technical details about errors but not your business data. We do not sell your data to anyone. We do not share your business data with other merchants. We do not share your data with advertisers.
Cookies and Tracking
We use cookies and similar technologies for three purposes. Essential cookies keep you logged in, remember your locale preference, and make the platform function correctly -- these cannot be disabled. Analytics cookies from PostHog help us understand how merchants navigate the platform so we can improve it; this data is anonymized. We do not set any advertising or third-party tracking cookies. If you want to disable analytics cookies, you can do so through your browser settings or by contacting us at privacy@shoppahq.com.
Data Security
We take reasonable measures to protect your data. All data is transmitted over encrypted HTTPS connections. Database access is restricted by role-based permissions and authenticated API calls use short-lived JWT tokens. We apply security updates regularly to our infrastructure. That said, no system is completely secure. If you discover a security concern, please contact us at privacy@shoppahq.com and we will investigate promptly.
Data Retention
We keep your account data for as long as your subscription is active and for 90 days after you request account deletion, to allow for re-activation and to comply with legal obligations. Your business data -- products, transactions, customers -- is available to export at any time. After account deletion, business data is permanently deleted within 90 days unless we are legally required to retain it longer. Technical log data is retained for up to 12 months. You can request a full export or deletion of your data at any time by contacting privacy@shoppahq.com.
International Data Transfers
Your data may be stored and processed in the United States, where our DigitalOcean infrastructure is located. Transferring your data to the United States is necessary for us to provide the service. We take steps to ensure that transfers comply with applicable data protection laws, including the Nigeria Data Protection Regulation (NDPR) and other relevant African data protection frameworks.
Children's Privacy
Shoppa is a business platform intended for use by adults. We do not knowingly collect personal information from anyone under 18 years of age. If you believe we have inadvertently collected data from a minor, contact us at privacy@shoppahq.com and we will delete it.
Changes to This Policy
We may update this Privacy Policy when we change how we handle data or when laws require it. For material changes, we will notify you by email at least 30 days before the changes take effect. The date at the top of this page shows when the policy was last updated. Continuing to use the platform after changes take effect means you accept the updated policy.
Contact Us
For privacy-related questions or to exercise your rights, contact us at privacy@shoppahq.com. For general inquiries, contact hello@shoppahq.com. You can also write to Shoppa Dynamics at our registered address.
Your Rights (Africa)
If you are based in an African country, including users in Nigeria covered by the Nigeria Data Protection Regulation (NDPR), you have the right to be informed about how your data is collected and used, access the personal data we hold about you, request correction of inaccurate data, request deletion of your data, and withdraw consent to processing where consent is the legal basis. To exercise any of these rights, contact us at privacy@shoppahq.com. We will respond within 30 days.