SHOPLINE PRIVACY POLICY

Updated and Effective as of 26 June 2025

Overview

SHOPLINE aims to provide merchants (hereinafter referred to as "you" or “merchants") a “Software as a Service” platform (hereinafter referred to as “SHOPLINE” or the “Platform”) with all-in-one solutions for website building, leads generation, payments, logistics and other e-commerce related services.

When you visit our websites and use the Platform, we may collect and use personal information about you (including your employees and/or persons who act on your behalf). We may also collect and use personal information from your customers on your behalf under your entrustment if they visit or purchase on the SHOPLINE empowered store. We are fully aware of the importance of personal information to you and your customers (collectively the “Personal Data Subjects”) and we are committed to ensure integrity and security of the Platform.

This SHOPLINE Privacy Policy (hereinafter referred to as “Privacy Policy”) is formulated in accordance with the applicable law and regulations.
We hope that The Privacy Policy will help you to understand why, what and how we collect, use, store, share, transfer and disclose personal information in the process of providing SHOPLINE products/services, as well as the purpose, method, scope, and information security protection measures; how the Personal Data subject realizes the rights and methods of managing its personal information. You shall carefully read and thoroughly understand the Privacy Policy before using this platform, and use the relevant products and/or services of the platform after confirming your full understanding and consent. You shall immediately stop using this platform and any SHOPLINE services if you do not agree with any content of this policy. In order to help you read and understand, we set out key definitions in the appendix to this Privacy Policy. Please pay special attention to the following important notes:

This Privacy Policy will help you understand the following:

Overview

SHOPLINE aims to provide merchants (hereinafter referred to in this Privacy Policy as "you" or “merchants") with a “Software as a Service” platform (hereinafter referred to as “SHOPLINE” or the “Platform”) with all-in-one solutions for website building, leads generation, payments, logistics and other e-commerce related services.

When you visit our websites and/or use the Platform, we may collect and use personal information about you (including your employees and/or persons who act on your behalf). We may also collect and use personal information from your customers on your behalf under your entrustment if they visit or make a purchase on your SHOPLINE-enabled online store. We are fully aware of the importance of personal information to you and your customers (collectively the “Personal Data Subjects”) and we are committed to ensuring the integrity and security of the Platform.

This SHOPLINE Privacy Policy (hereinafter referred to as “Privacy Policy”) is formulated in accordance with the applicable law and regulations. We hope that the Privacy Policy will help you to understand why, what and how we collect, use, store, share, transfer and disclose personal information in the process of providing SHOPLINE products/services, as well as the purpose, nature, method, scope, and information security protection measures, and how the Personal Data subjects exercise their rights in relation to  manage their personal information. You should carefully read and thoroughly understand the Privacy Policy before using this Platform, or any other SHOPLINE services. In order to help you read and understand, we set out key definitions in the Section 9 at this Privacy Policy. Please pay special attention to the following important notes:

This Privacy Policy will help you understand the following:

SCHEDULE A. ADDITIONAL LOCATION SPECIFIC INFORMATION

SCHEDULE A
ADDITIONAL LOCATION SPECIFIC INFORMATION
UK and EEA Privacy Law Appendix

  • What is our legal basis for processing your personal information

    • We will only use your personal information when the law allows us to. In respect of each of the purposes for which we use your personal information, the UK GDPR requires us to ensure that we have a "legal basis" for that use. Most commonly, we will use your personal information in the following circumstances. We have set out our specific purposes and associated legal bases in more detail in table format above.

    • Where we need to perform a contract we are about to enter into or have entered into with you (“Performance of our contract with you”);

    • Where it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests ("Legitimate Interests"). More detail about the specific legitimate interests pursued in respect of each purpose we use your personal information for is set out in the table above;

    • Where we need to comply with a legal or regulatory obligation (“Compliance with a legal obligation”); and

    • Where we have your specific consent to carry out the processing for the purpose in question (“Consent”).

    Information we collect

    Legal basis

    Information you provide to us about you and your employees or authorised persons, such as your business name, email address, phone number, registration number, VAT number, and log-in password.

    • Legitimate Interests;

    • Performance of our contract with you;

    • Compliance with a legal obligation.

    Payment or billing information you provide us, such as your credit card number, debit card number or bank account number, and your billing records.

    • Performance of our contract with you;

    • Legitimate Interests;

    • Compliance with a legal obligation.

    Customer support communications that you send us in the event of encountering an issue.

    • Legitimate Interests

    We also collect the following via cookies or similar technologies: device information, including your (and those of your employees and authorised persons) frequently used personal devices, including the IP address, device model, device identification number, operating system, resolution, and telecom operator; and log information, including network diagnosis, lag information, click events, click records, browsing history on the Platform and potentially unsafe URLs (“Usage Data").

    • Legitimate Interests;

    • Performance of our contract with you;

    • Consent.

    We collect Usage Data and other information uploaded by you for analytics.

    • Compliance with a legal obligation;

    • Legitimate Interests.

    Processing of the personal information we hold about you as required or permitted by applicable law to comply with a legitimate disclosure request.

    • Compliance with a legal obligation;

    • Legitimate Interests.

    The personal information we hold about you. 

    • Legitimate Interests.

    Information your customers provide us about them, such as:
    - Information your customers provide at the time of member registration, such as their name, email address, phone number, and other information that you authorized to collect (such as birthday);

    - Information your customers provide at the time of checkout, such as their name, email address, phone number, delivery information, and payment information.

    Browsing history, behavior data, and device information that we collect through “cookies” or similar technologies, such as network connection, IP address, and details of how they browse the store.

    • Performance of our contract with you;

    • Legitimate Interests;

  • International transfers

    We may share your personal information within our group, which may involve transferring your personal information outside the EEA and/or UK.
    Some of our third-party partners are also based outside the EEA and/or UK so their processing of your personal information may involve a transfer of data outside the EEA and/or UK.
    Whenever we transfer your personal information out of the EEA and/or UK, we will ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

    • We will only transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information; or

    • We will take measures to comply with applicable data protection laws related to such transfers and use appropriate transfer solutions for any transfers of data outside the EEA and/or UK, such as the UK Standard Contractual Clauses.

  • How you exercise rights over your personal information

    You have the right to, at any time:

    • Request access to your personal information (commonly known as a data subject access request). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.

    • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

    • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal information to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

    • Object to processing of your personal information where we are relying on a Legitimate Interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal information for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

    • Request restriction of processing of your personal information. This enables you to ask us to suspend the processing of your personal information in the following scenarios:

      • If you want us to establish the data’s accuracy;

      • Where our use of the data is unlawful but you do not want us to erase it;

      • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; and

      • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

    • Request the transfer of your personal information to you or to a third party. We will provide to you, or a third party you have chosen, your personal information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

    • Withdraw consent at any time where we are relying on consent to process your personal information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

    • Make a complaint to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues – if you are unhappy about how we process your personal information, you can always file a complaint with the ICO at www.ico.org.uk. We would however appreciate the opportunity to resolve your concerns in the first instance before you contact the ICO.

  • Automated decision-making

    If we deploy automated technologies which give rise to automated decision-making about you, we will either: (1) have a human being involved in the process; or (2) use these technologies in ways that don’t have legal or similarly significant effects.

United States Privacy Law Appendix

  • How you exercise rights over your personal information

    You have the right to, at any time:

    • You have the right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about you.

    • You have the right to request that we delete certain personal information we have collected from you.

    • You have the right to correct inaccurate personal information that we maintain about you.

    • You have the right to opt-out of sale or sharing of personal information. We do not “sell” your personal information to third parties in exchange for money or other valuable consideration. We also may “share” your personal information, as described by the CCPA, for purposes of cross context behavioral advertising.

    • You have the right to opt-out of targeted advertising.

    • You may request to opt-out of profiling in furtherance of a decision that produces a legal or similarly legal effect, or request to learn about the logic involved in decision making processes.

    • You have the right to obtain your personal data and a list of third parties to which we have disclosed your personal data in a portable, and to the extent technically feasible, readily useable format, which you can use to transmit your data to another entity.

    • You have the right to request that we limit the use and disclosure of sensitive information necessary to perform the services requested. Once we have received and confirmed your request, we will limit the use and disclosure (and direct our service providers to limit thew use and disclosure) of your sensitive personal information, unless and exception applies. You also have the right to not receive discriminatory treatment for exercising this right.

    • You may appeal our decision to your request regarding your personal information. To do so, please contact us in any of the ways list above. We respond to all appeal requests as soon as we reasonably can, and no later than legally required.

    If you direct us not to sell/share your personal information, we will consider it a request pursuant to California’s “Shine the Light” law to stop sharing your personal information covered by that law with third parties for their direct marketing purposes. Please know that the privacy rights outlined above are subject to exceptions. We will confirm receipt of every request within 10 business days and respond to every request within 45 calendar days. We may extend that response time as appropriate, if permitted. We will not retaliate or discriminate against you for exercising any of these privacy rights.

    Requests to exercise privacy rights must be verified. This process may require us to request additional personal information from you in order to authenticate your identity. In certain circumstances, we may decline a request to exercise a privacy right, particularly where we are unable to verify your identity.

    You may designate an authorized agent to make a request on your behalf. An authorized agent must have written documentation of their authority to act on your behalf, such as receiving: (i) a power of attorney; or (ii) sufficient evidence to show that the individual has provided the authorized agent signed permission to act on their behalf, verified the individual’s own identity directly with us pursuant to the procedures above, and directly confirmed with us the individual provided the authorized agent permission to submit the request on their behalf.

  • Children’s Privacy

    Our services are not for children under the age of 13. We do not knowingly collect personal information from children under 13 years of age. Individuals under the age of 13 should only use our services with the permission and under the supervision of a parent or guardian. Individuals under the age of 13 should not attempt to provide us with any personal information. If you think we have received personal information from children under the age of 13, please contact us immediately.

  • California Privacy Law Appendix

    This appendix seeks to provide additional information to residents of California and supplements the information provided in the Privacy Policy. As discussed in the Privacy Policy in further detail, we “sell” and “share” any personal information as such terms are defined under California privacy law.

    To learn more about the categories of personal information we collect, how we collect it, why we collect it, with whom we share it, and how long we retain it, please see the items below. To submit a privacy request, please see the instructions provided in the Privacy Policy.

    Category

    What we collect

    How we collect it

    Why we collect it

    With whom we share it

    How long we retain it

    Identifiers

    Such as, name, email, phone number, birth date, log-in password, registration number and VAT number.

    For more information please see the  Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above.

    We retain personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law. For more information, please see the How we retain and protect personal information section of this privacy policy.

    Protected classification characteristics under California or federal law

    Any protected classification characteristics you voluntarily provide to us.
    For more information please see the  Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above

    We retain personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law. For more information, please see the How we retain and protect personal information section of this privacy policy.

    Commercial information

    Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above.

    We retain personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law. For more information please see the How we retain and protect personal information section of this privacy policy.

    Customer Records

    Bank account number, credit card number, debit card number, or any other financial information.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above

    We retain personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law.

    For more information please see the How we retain and protect personal information section of this privacy policy.

    Biometric information

    N/A

    N/A

    N/A

    N/A

    N/A

    Internet or other similar network activity

    Information on a customer’s interaction with our services including browsing history, behavior data and device information, such as IP address, device model, device identification number, operating system, resolution, and telecom operator; and log information, including network diagnosis, lag information, click events, click records, browsing history on the Platform and potentially unsafe URLs.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above

    We retain  personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law. For more information please see the How we retain and protect personal information section of this privacy policy.

    Geolocation data

    In some instances IP addresses are collected.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above

    We retain  personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law.

    For more information please see the How we retain and protect personal information section of this privacy policy.

    Sensory data (Audio, video, etc.)

    N/A

    N/A

    N/A

    N/A

    N/A

    Professional or employment-related information

    N/A

    N/A

    N/A

    N/A

    N/A

    Non-public education information

    N/A

    N/A

    N/A

    N/A

    N/A

    Inferences drawn from other personal information

    Information generated from your use of our services, such as usage and data analytics.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above.

    We retain  personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law.

    For more information please see the How we retain and protect personal information section of this privacy policy.

    Sensitive personal information

    Account log-in information, financial account, debit card, or credit card number in combination with any  access code, and precise geolocation.

    For more information please see the Information We Collect section of the Privacy Policy.

    Collected directly or indirectly through your use of the service or obtained from third parties.

    For more information please see the What we collect and how we use personal information section of the Privacy Policy.

    We collect this information for the purposes listed in the How we use such information section of this privacy policy.

    Shared with our affiliates, partners, social networking sites, service providers and payment processing companies as described in the When we share, transfer and disclose personal information section above.

    We retain personal information for such a period as necessary to achieve the purposes authorized by you and your customers or otherwise provided by law.

    For more information please see the How we retain and protect personal information section of this privacy policy.