Privacy Policy
At ShopEase, your privacy is important to us. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform.
1. Information We Collect
We collect the following types of information:
- Account Information — Name, email address, and encrypted password when you register.
- Shipping Information — Address, phone number, city, state, and PIN code when you place an order or save an address.
- Order Information — Products purchased, order totals, payment method, and delivery status.
- Usage Information — Pages visited, search queries, and products viewed (stored locally on your device, not on our servers).
2. How We Use Your Information
- To process and deliver your orders
- To send order confirmation and delivery updates
- To manage your account and saved addresses
- To improve our products and shopping experience
- To prevent fraud and ensure platform security
- To respond to your support enquiries
3. Data Storage & Security
Your account data is stored in a secure MongoDB database hosted on MongoDB Atlas (cloud infrastructure with encryption at rest and in transit). Passwords are hashed using bcrypt and are never stored in plain text. We use JWT (JSON Web Tokens) for session management, which are stored as secure HTTP-only cookies.
4. What We Do NOT Do
- We do not sell your personal data to third parties.
- We do not share your email or phone number with advertisers.
- We do not track you across other websites.
- We do not store your payment card details (COD orders require no card information).
5. Cookies & Local Storage
We use essential cookies for authentication (NextAuth session token). We also use your browser's local storage to save preferences like theme (light/dark mode), wishlist items, and recently viewed products. This data stays on your device and is not sent to our servers.
6. Third-Party Services
We use the following third-party services:
- MongoDB Atlas — Database hosting (data stored in India/Asia region)
- Cloudinary — Product image hosting and delivery
- Resend — Order confirmation emails (if configured)
Each service has its own privacy policy. We only share the minimum data necessary for their function (e.g., your email for order confirmations).
7. Your Rights
You have the right to:
- Access your personal data (visible in your Account page)
- Update your name and email (Account > Edit Profile)
- Change your password (Account > Change Password)
- Delete your account — contact support@shopease.com to request account deletion
- Download your order history (Account > Orders > Invoice)
8. Data Retention
We retain your account data for as long as your account is active. Order records are kept for 2 years for legal and accounting purposes. If you request account deletion, your personal data will be removed within 30 days, though anonymized order records may be retained.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with the updated date. For significant changes, we will notify registered users via email.
10. Contact
For privacy-related questions or data requests, contact us at privacy@shopease.com.