StoreMingle Privacy Policy
Last Modified: September 16, 2026 · Effective: September 16, 2026
Celavii Software Inc (d/b/a StoreMingle) — 800 Progress Center Ct, Suite 500, Lawrenceville, GA 30043, USA — is the controller of the personal information described here.
This policy covers storemingle.com and the StoreMingle mobile apps (together, the
"Services"). Terms used here have the meanings given in our
Terms of Service.
StoreMingle is a business-to-business service. Most information we hold is about businesses and the people who represent them at work. Where that information identifies an individual, this policy applies to it.
1. The short version
| What | The honest answer |
|---|---|
| Do you record live video? | No. We transmit it and do not store it, except transiently as part of transmitting it. But live text chat is stored, and a still preview image of a broadcaster is captured while they are on air. |
| Who sees me when I go on air? | Depends which seat you are in. A buyer brought on air: the host business sees and hears you, everyone else only hears you. A vendor broadcasting, or crew put on the program: everyone watching sees and hears you. In all three cases your name, company and profile image are shown to everyone. See §4.2. |
| Do you sell my data? | No. We do not sell or share personal information for cross-context behavioural advertising. |
| Do you handle my money? | No. We accept no funds and take no commission. There is no payment card on file. |
| Who else gets my information? | Show organizers and vendors you interact with — including exports to their own systems. This is the widest disclosure in this policy; see §6. |
| Do you use AI on my data? | Yes, for specific features — including reading your verification documents, and summarising a live broadcast's booth chat when the vendor who hosted it asks. We never send live video or live audio. Your messages are not sent either, though that one is a setting rather than an absolute — see §7. |
| Can I delete my account? | Yes — every role, from within the app or on the web. See §9.1. Closing a seller account removes you, not the business you belong to (§9.1a). Some records survive because they are also another business's records, carrying your name as it appeared at the time. See §9. |
| Do you track what I watch? | Within a show, yes. We record how long you spend watching a vendor's live booth, against your account, and use it for show analytics and for features that depend on taking part (§6.1, §6.3). We also record that you asked to go on air. We do not track you across other companies' apps or websites. |
| Do you read my phone contacts? | Only when you run the contact-match feature, and only with the OS permission you grant. Phone numbers are sent, matched, and immediately discarded — we keep the date and a count, never the numbers. See §2. |
2. Information you give us
Account and business profile — name, work email, phone number, company name, job role, profile image, and your business's addresses and store locations.
Verification documents — business licence, tax registration or EIN document, resale certificate, and trade references. We do not ask for personal identity documents. See §5.
Content you publish — product listings and images, short-form video, live broadcasts, comments, reviews, and your storefront or booth content.
Communications — messages, quote requests, sample requests, and live booth chat.
Orders and quotes — what was requested, from whom, quantities, per-location allocations, and prices agreed.
Support and legal correspondence — what you send us and our replies.
Information given to us by someone else
Your account may have been created from a list an organizer or vendor uploaded, rather than by you. If so, we hold the business contact details they provided until you claim, correct or delete the record. Our Terms require the uploader to warrant it had the right to give us that information.
Because organizer imports are matched on email address alone, an upload by one organizer can add to or update the business contact details held on an existing record, including a record that was created through a different organizer. You can ask us to correct those details at any time under §11.
If you sign in with Apple or Google
You can create an account and sign in using Apple or Google instead of a password. If you do, that provider tells us your name and email address — and the provider learns that you use StoreMingle. Apple's Hide My Email, if you use it, means we receive a relay address rather than your real one, and we treat that relay as your email.
Google also sends us the web address of your Google profile photo, and where you have not set a picture on StoreMingle we show that one instead. Alongside these, Google sends an identifier it uses for your account and whether it treats your email address as verified.
We receive nothing else from either provider: no contacts, no calendar, no posts, no documents.
How you came to be here — the introduction record
Every account carries a permanent record of how it came to exist: whether it was created by the person themselves, by an organizer, by a vendor, by our staff, or by the platform during setup — and, where there was one, which business or person introduced you, and through which route (an invite, a shared link, a bulk upload, a self-signup).
This record is written once, when the account is created, and it is not erased when you delete your account — the account it points at goes, but the fact that an introduction happened survives, with no contact details attached. We keep it because it is the only answer to "why does this business have my details?", and that is a question both you and a regulator are entitled to ask.
Contacts you choose to match (mobile app)
The mobile app never reads your address book on its own. The "Find contacts" feature runs only when you open it, tap through its explanation screen, and then grant the operating system's contacts permission. On iOS 18 and later you can share only the contacts you select; on earlier versions the choice is all-or-nothing. If you decline, nothing is read and nothing is sent.
When you run a match:
- What leaves your device is the phone numbers from your contacts — nothing else. No names, no emails, no photos. Your contacts' names stay on your device, where the app uses them to label the invite list you see.
- Our server converts the numbers to a standard format and compares them against the account phone numbers of members who are discoverable by phone (§6.5). The numbers exist on our servers only while your request is being answered, and are then discarded. We do not store them, and we do not put them in our logs or error reports.
- What we keep is a record that you ran a match — the date and how many numbers you submitted. It contains none of the numbers. It is our evidence that the match was asked for.
- When you invite someone who is not a member, we do not store their number and we do not message them. The invite buttons on the results screen compose a message on your own device, in your own messaging apps, and nothing goes out unless you send it yourself.
You can revoke the contacts permission at any time in your device settings. There is nothing to ask us to delete afterwards, because the numbers were never kept.
3. Information we collect automatically
Device and connection — IP address, device and browser type, operating system, app version, and crash diagnostics.
Usage — pages and screens viewed, features used, and actions taken, so we can operate and improve the Services.
What you do inside a show. While you are in a show we record what you do there against your account: opening a booth, how long you watch a vendor's live stream, saving a product, requesting a quote, registering for a session and placing an order. We use it to show that show's organizer and its exhibiting vendors how their show performed (§6.1, §6.3), and, where the organizer is running a prize draw, to work out which prizes you have qualified for.
Prize draws. An organizer may run a prize draw on their show to encourage people to visit booths and talk to vendors. There is no entry fee and nothing to buy. Where you qualify we hold your entry for that prize, and if a draw picks you we tell you and tell the organizer. The organizer sponsors and runs the draw, publishes their own Official Rules on the prize board, and awards the prize; we handle no money for it. See Terms of Service §4(f).
What you search for — every search you run is recorded. We keep the text you typed, the structured reading our parser produced from it, how many results came back, and — if you then open one — which result you opened. The structured reading is more than keywords: it includes the category, the price ceiling, the price floor and the minimum order quantity our parser inferred from your words, so a search like "cases of sparkling water under $40, min 20" is stored both as you wrote it and as those figures.
This happens whether or not you are signed in. If you are not signed in, the searches are tied to your browser by a signed, http-only cookie holding the ids of your last 50 searches — that is what lets us match the result you opened to the search that produced it.
Two uses are worth naming, because one of them is visible to other people:
- Your own recent searches are shown back to you on the search screen.
- The suggestion chips are built from search text, including other buyers'. They blend the most-searched queries across the platform over the last seven days, queries run by buyers whose product interests overlap with yours, and categories from our catalogue. A chip is the query text itself, as it was typed. So a search you run may later appear to another buyer as a suggestion — never attributed to you or to your business, and never with your figures attached, but in your words.
How long we keep this, and what happens to it when you close your account, is in §8. The separate question of your search text reaching our AI provider is in §7.
Live viewer counts — while a broadcast is running we keep a set of viewer identifiers in temporary storage to count the unique viewers of that broadcast. This set expires automatically within 12 hours of the last activity on it.
Push tokens — if you enable notifications, a device push token so we can deliver them.
Cookies and similar technologies — strictly necessary cookies for sign-in, session and security, plus two first-party cookies that are not strictly necessary.
The first is an attribution cookie: if you arrive on an invite or share link, we remember for 30 days which link you came in on, so that when you create an account we can record who introduced you (see the introduction record in §2). It holds a referral code and nothing else, it is never sent to a third party, and clearing your cookies before you sign up removes it.
The second is the search cookie described above — the signed, http-only list of your last 50 searches, set only when you are not signed in, and used only to match the result you opened to the search that produced it.
Neither is sent to a third party. We do not use advertising cookies or third-party behavioural-advertising tags.
We also store a device identifier in your browser's local storage. It is a random value with nothing personal in it, created the first time you broadcast from a device, and it lets us tell your cameras apart so the right one goes live. It is not used to track you between sites or to build any profile.
What we deliberately do not collect
- We do not track you across other companies' apps or websites.
- We do not use session replay. Our error-monitoring tool is capable of recording screen sessions; that feature is not enabled.
4. Live video and audio
This section describes exactly what happens when you appear in a Live Session. Our Terms of Service §5 describes the same facts as contractual terms, and the two must always agree.
4.1 We do not record
When you go on air we capture your camera and microphone and transmit them live to other people in that booth. We do not record these streams and we do not store them, except on a strictly transient basis where that is a necessary part of transmitting them.
The application does not enable recording on any generally available broadcast path. A recording-capable broadcast mode exists in the code and is refused above the per-account setting, so it is not available to any account and no account setting reaches it.
Nor can recording survive into an ordinary broadcast. The booth's video channel is kept between broadcasts rather than rebuilt each time, so a setting made for one broadcast could outlive it. Every ordinary go-live now checks that channel and switches recording off before the stream starts, so a business that once used the recording-capable mode — or that had it withdrawn — does not carry it into a broadcast this section says is not recorded.
There is one broadcast mode in which a recording would exist, and it is switched off across the whole platform. It is meant for a business broadcasting from professional equipment rather than a phone, and in it recording is technically inseparable from playback — the video platform produces no live stream at all without it, so a broadcast made that way would be stored.
It is off for every account, and it is not a setting anyone here can turn on for you. It is disabled in our code above the per-account switch, so no member of our staff can enable it by flipping an account setting. No recordings of live rooms exist.
Two things have to be built before it can be switched on, and we have written the block so that it cannot be switched on without them: a rule that says how long such a recording is kept and a job that deletes it, and an on-screen notice telling everyone in the room that it is recording. If that ever changes, this section, §8 and Terms of Service §5 change with it in the same release.
4.2 Who sees you and who hears you are different questions
This subsection is about a buyer brought on air in a booth. A vendor broadcasting, and crew put on the program by the host, are seen and heard by everyone watching — see the three capacities set out in Terms of Service §5(a).
For a buyer on air:
- The business hosting the booth, and members of its team, can see and hear you.
- Everyone else watching the booth can hear you but cannot see you.
- Your name, your company name and your profile image are shown to everyone watching.
Your camera is delivered only to the host business. This is enforced by our servers rather than by the app: the set of streams a viewer is permitted to receive is computed server-side and never includes another participant's video.
Storefront live streams and scheduled show sessions are one-way — viewers are never on camera or microphone.
If you join a broadcast as crew. A business can invite someone to help run a live broadcast — operating cameras, cutting between them, appearing on the program. Accepting that invitation creates a membership record of you in that business, held under a system-generated placeholder address if you did not join through a full account, and it lasts until the business removes you. While you are on the program your camera and microphone go to everyone watching, not only to the host. Crew members can ask us to remove the record under §11.
4.3 What is kept, even though the stream is not
Three things are retained and are not covered by "we do not record":
- Live booth chat. Messages sent in a live booth are stored, together with the sender's account identifier and the display name shown at the time. Retention: see §8.
- Preview images. While a broadcast is live we automatically capture a still image of the broadcaster's camera roughly every ten seconds and use it as the live preview thumbnail. These images show only the person broadcasting — never a participant who has been brought on air. They are stored on publicly-readable infrastructure. They are removed when the broadcast ends — for booth broadcasts, by a job that runs every minute rather than at the moment the stream stops, so a frame may persist for up to a minute afterwards.
- A record that you asked to go on air, and when.
4.4 What we cannot control
Other participants may be able to capture what they see or hear using their own device or software. That is outside our control. It is prohibited by our Terms and we enforce against it when we learn of it, but no technical measure prevents it.
4.5 Your control and our legal basis
You can stop transmitting at any time by turning off your camera or microphone, or by leaving the seat. A host can mute you for the room and can undo that mute; a host cannot override a mute you set yourself. A host's mute withholds your audio from the audience — it does not switch off your device.
Our lawful basis for transmitting your camera and microphone is performance of our contract with you (GDPR Art. 6(1)(b)).
5. Verification documents
5.1 What happens to a document you upload
- It is stored in a private, access-restricted location. It is never published, shown on your profile, or made available to other users at large.
- We send it to an AI provider to extract the business details and flag possible tampering. An automated signal about the document's apparent authenticity is generated and shown to the human reviewer.
- A reviewer records a decision — StoreMingle staff, or the organizer of the show you are joining (§5.2).
What not to send us. We need documents about your business, not about you personally. Please do not upload anything showing a Social Security number, a driver's licence, a passport, or a date of birth — we do not need any of it and we do not ask for it. ⚠️ If you trade as a sole proprietor, read this twice: a sole proprietor's federal tax identification is often their SSN, and a W-9, an SS-4 or a state sales-tax registration can print it in full. If the document you were about to send shows one, black it out first, or send a different document. If you have already sent one, write to privacy@storemingle.com and we will remove it.
Automated processing disclosure. The authenticity signal feeds a decision about your access to the Services. In some cases that decision is made automatically: where the extracted details match what you told us and nothing is flagged, your account can be verified without a person looking at it. You can ask for a human to review any decision, and you can contest one, by writing to privacy@storemingle.com.
5.2 Who reviews your documents
Show organizers review your verification documents, not only StoreMingle staff. That review includes the extracted business details, your tax identification number, the authenticity analysis, and the ability to download the document itself through a time-limited link. See §6.2 — this is the disclosure most likely to surprise you, and it is why we state it separately here.
Which organizers. Any organizer who has attached you to one of their shows can open your verification record. That includes an organizer who added you by importing a contact list, and it does not require you to have asked to join, accepted an invitation, or done anything at all.
5.3 Verification carries across organizers
Being verified by one organizer grants you access to access-gated shows run by other organizers. Your verification status is held once on your account and read platform-wide. It is not held separately per organizer.
5.4 Retention
| Artifact | Kept for |
|---|---|
| The document file | 90 days after the verification decision is recorded, and never more than 12 months from upload. Undecided uploads are destroyed at 12 months. Deleting your account destroys them immediately (§9.2). |
| The details you typed (business name, tax ID, website, contact phone) | Kept while your account is open — they are part of your business profile. Erased immediately when you close your account (§9.2). |
| What was read out of the document (extracted details, field-by-field match scores, authenticity analysis) | Destroyed with the document: the per-document analysis in the same operation as each file, and the combined analysis once the last of your documents has been destroyed. Erased immediately on account closure (§9.2), whichever comes first. |
| The decision record (outcome, reviewer, date, document type and filename) | Life of your account plus 3 years, then destroyed. Pseudonymised. |
We keep the decision record to defend against fraud and legal claims (GDPR Art. 17(3)(e) on an Art. 6(1)(f) basis; CCPA §1798.105(d)(2)). We do not keep it for anti-money-laundering purposes — we handle no funds and no such obligation applies to us.
6. Who receives your information
6.1 Show organizers
An organizer whose show you join, or whose directory you are in, can:
- Export your business contact details to their own systems — company, contact name, email, phone, invite status, number of orders, and the names of their shows you are attached to. That last column lists every show of theirs you were added to, whether you joined it, were only invited, or never responded.
- If you have accepted an invitation from them, or registered for or applied to one of their shows, that export also carries your verification tier, your StoreMingle verification status, how you came to StoreMingle, and the number of stores you operate — and opening your record in their directory shows them each store by name, city and state.
- If you have not, those are withheld. An organizer who added you to a show, uploaded you in a spreadsheet, or invited you and heard nothing back sees only what they themselves supplied and what happened on their own shows. They are shown "not shared" rather than a blank or a zero, so nothing about you is inferred from the gap.
- See lead detail for their show: your email plus counts of messages, quotes, samples and orders, and order value, broken down per exhibiting vendor. The engagement score and hot/warm/cold label in that export are subject to the same rule as the tier above — they are withheld until you have accepted something from that organizer.
- Export order records including your company, contact details and per-store shipping addresses. These are not subject to the rule above: an order is the organizer's own record of a transaction with you, and they need the delivery details to fulfil it.
Withdrawing this. Leaving an organizer's directory (§9, and Data and privacy → Who can see your details in the app) moves you out of the accepted group, so the fields above stop being shared from that point on. It cannot un-send what was already exported.
Every export an organizer runs is recorded — who ran it, when, on how many records, and how many of those were withheld. The record holds counts and identifiers only, never a copy of what was exported.
Once exported, that information is under the organizer's own privacy policy and its own control. Every organizer is bound by our Data Processing Addendum — available on request, see Terms of Service §13 — which applies automatically and sets out what they may do with what they take.
An organizer cannot read the messages themselves — only how many there were.
6.2 Show organizers — verification records
An organizer opening your verification record receives all of it: your business name, tax identification number (EIN), website, any custom data you supplied, the full automated analysis including per-field match scores and authenticity flags, the result of our business-registry check including the raw response we received back, which provider ran it, and any failure code, and every document's filename with a time-limited download link.
Which organizers can open it is set out in §5.2 — it is wider than "the show you joined".
6.3 Vendors
A vendor whose booth you interact with can:
- See a lead list containing your name, company, an engagement score derived from your activity, a hot/warm/cold label, and a date labelled "Last Active" — which is really the date we last recalculated your score, not a date you did anything. The engagement score is profiling; you may object under §11. A vendor's lead list carries no email address and no phone number. The only way your contact details reach a vendor is an order they fulfil themselves — the next bullet.
- See order details. What a vendor sees depends on who fulfils the order. For a show order fulfilled by the organizer — the default for show orders — your email, phone, street address, postcode and store receiving phone are withheld from the vendor, who sees your company, contact name, verification tier, and the store's name, city, state and market. For vendor-fulfilled orders the vendor receives the delivery details it needs to ship. Every marketplace and storefront order is vendor-fulfilled by definition, so full delivery details always reach the vendor there — withholding is a show-order arrangement, not a platform-wide default.
- See who engaged with its short videos, by name. For each of its own shorts, a vendor can see which buyers liked, saved, commented on or shared it, your company and contact name against those actions, the text of your comment, and how many orders you have placed with that vendor. Saving or liking a vendor's video is visible to that vendor; it is not a private bookmark.
6.4 What your privacy settings do and do not control
Most of your settings control peer discovery — whether other members can find you, view your member profile, or reach you by phone-number match. Profile visibility, hide-from-search, order visibility, anonymous browsing and phone discoverability all work that way, and none of them restricts an organizer or a vendor.
One setting does. Share my contact details with organizers before I accept is on by default, and turning it off means an organizer who has added you to their directory sees no email address and no phone number for you — not in the directory, not in your record, not in any list they export — until you accept an invitation from them, register for one of their shows, or apply to one. From that point they see both, because you chose to deal with them and they have a show to run.
Two limits, stated here rather than left to be discovered:
- It never affects an order. A seller fulfilling your order receives the contact and delivery details they need to ship it, as §6.3 describes. A privacy setting that could stop your goods arriving would be a worse product and a worse promise.
- It is not needed for vendors. A vendor's lead list has never carried your email or phone (§6.3), so there is nothing there for this setting to withhold.
You will find it in the app under Me → Data and privacy, and on the web under Settings → Privacy.
6.5 Phone-number discovery
If you allow it, other members can find you by matching a phone number they already have. Buyers can be found either through the contact matching described in §2 or by someone typing a number into the add-contact form; vendor businesses can only be found through the bulk match in §2 — there is no look-up-a-vendor-by-number feature. A match shows them one display name (your contact name, or your company if you have not set one), your profile image, and whether you are a buyer or a seller; members you have blocked never find you this way. This setting is on by default, for buyers and for vendor businesses, and you can turn it off at any time — buyers under Privacy, vendors in the app's Settings. An account with no phone number on it never appears in these lookups. Vendors can remove their contact phone on their profile; buyers cannot yet remove their phone number themselves and can ask us instead (§11).
6.6 Service providers
We use service providers to run the Services. They process information on our instructions and may not use it for their own purposes, and each is required to protect it at least as well as this policy does.
| Type of provider | What they do for us |
|---|---|
| Hosting and database | Running the application, our database, sign-in, file storage, realtime messaging, and application logs |
| Live video | Delivering live video and audio, and hosting the short videos vendors publish |
| AI | AI features, including reading verification documents, and categorizing products and businesses, which includes vendor business names |
| Caching and rate limiting | Rate limiting, caching, and live viewer counts |
| Error reporting | Error and crash reports |
| Push notifications | Delivering push notifications through the push service your device or browser uses |
| Text messages | One-time confirmation codes you ask for, and text reminders if you turn them on. Text notifications are off unless you turn them on |
| Transactional email | |
| Address lookup | Suggesting addresses while you type one into an address field, and checking that an address you give us is complete and deliverable |
We do not send live video or live audio to any AI model provider — not to transcribe it, not to caption it, not to analyze it. No such capability exists in the Services.
Your messages are not sent — but that one is a setting rather than an absolute: a moderation capability that would scan message text exists in the code and is switched off in production (checked 2026-08-27). If we ever switch it on, this policy changes first.
Booth chat is sent, in one case. When the vendor who hosted a live broadcast asks for a summary of it, the booth chat from that broadcast goes to our AI provider to produce the summary, along with the deals and orders from the same session. It runs only when that vendor asks, only over that one session, and only that vendor's team sees the result.
6.7 Others
We may disclose information to comply with law or lawful requests, to enforce our Terms, to protect rights and safety, and in connection with a merger, acquisition or sale of assets (in which case we will tell you before your information becomes subject to a different policy).
6.8 We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.
7. AI features
We use AI to help draft product descriptions and business bios, to summarize show results, to categorize products, to interpret what you type into search, to answer your questions in a booth's AI assistant, and to read verification documents (§5).
What you type into search, and what you type to the booth assistant, is sent to our AI provider so it can be interpreted and answered. Treat the assistant as you would any other message you send through the Services: do not put anything in it you would not want handled by a third-party processor.
The written show recaps name buyers to our AI provider. After a show, a vendor or an organizer can generate a written recap of how it went. Producing one sends our AI provider:
- the names of the top buyers on that show, each with what they spent and how many orders they placed; and
- in the version an organizer generates for their own internal use, the names of buyers who registered for the show and did not order.
No contact details go with any of this — no email, no phone, no address — and no individual order lines. But your name, paired with what you spent, does leave the platform on this path, and so does the fact that you attended and bought nothing.
Our AI providers act as our processors — they handle the data we send on our instructions and are not permitted to use it for their own purposes.
We do not permit our AI providers to use your data to train their models.
We do not send live video or live audio to any AI provider. Booth chat is sent in one case only — a vendor asking for a summary of their own finished broadcast, described above.
Message content is not sent to any AI provider. An AI moderation capability exists in the code and is switched off.
8. How long we keep things
| Category | Retention |
|---|---|
| Account and business profile | While your account is open; then per §9 |
| Record that you accepted these terms | Kept as our evidence of the agreement, including after your account is closed. It holds who agreed, when, which version of each document, and which sign-up route you used. It holds no IP address and no device information |
| Verification documents | §5.4 |
| Orders, quotes and invoices | 7 years from the day the record was created — these are also the counterparty business's records. A weekly job deletes them: an order together with its lines, its history and the product reviews written against it, the quote requests behind it, and booth-booking invoices including the invoice PDF itself. Our own billing records — what a business paid us to host or take part in a show — are the company's books and are not covered by this row |
| Short videos a vendor publishes | Deleted automatically 14 days after posting — or 14 days after the show ends, for a short attached to a show. A daily job does the deleting, and this one really runs: the video is removed at our video provider, not merely hidden. One exception: a vendor can pin a short to their storefront, and a pinned short is kept until it is unpinned or deleted. None are pinned today |
| Buyer lists uploaded by an organizer | The uploaded file is never stored. We read the spreadsheet in memory, create the buyer records from it, and keep only those records — there is no copy of your file on our systems to retain or delete |
| Messages and conversations | While your account is open; the counterparty keeps its copy, including your name as it appeared when you sent it |
| Live booth chat | Kept as part of the record of the Live Session it was said in. Closing your account does not remove it, and it keeps your name as it appeared when you sent it |
| What you did inside a show, and any prize entry it earned (§3) | Kept as part of the record of that show. Closing your account does not remove it, and nothing deletes it on a timer |
| Live preview images | Removed when the broadcast ends; a scheduled job removes any that outlive it |
| Live viewer identifiers | Expire automatically within 12 hours of the last activity |
| Phone numbers submitted for contact matching | Discarded within the request — never written to the database or logs (§2) |
| Contact-match records (date and count only — no numbers) | Kept as our evidence that the match was consented to; after account deletion it links only to the anonymised shell in §9.5 |
| What you searched for, and what you opened from it (§3) | 12 months for the query text and the parsed intent, then deleted. The aggregate counts derived from it are kept indefinitely and are not tied to you. A daily job deletes the whole record rather than blanking the text: a record that old is outside every aggregate we compute, so keeping an emptied shell would preserve nothing and would still say which business searched and when |
| Error and crash reports | 30 days |
| Application logs | 1 day |
| Backups | 7 days of daily backups; see §9.3 |
9. Deleting your account
9.1 How
You can delete your account from within the app, or at storemingle.com/account-deletion. You do not need to contact support.
9.1a Closing a seller or organizer account
An account is the thing you sign in with, so closing one removes you — not the business you belong to. When you close a seller or organizer account:
- Your membership of every business is ended, and your sign-in is destroyed.
- The business itself continues, because it is not only yours. Its products, its orders and its history belong to it and to the businesses it has traded with, and if it has other members they keep working. If you were its only member, the contact details held against it were really yours, so those are cleared too, and the business is passed to our staff to wind down.
- We do not refuse. You are not asked to finish shipping orders or to end a live show first. If we made erasure conditional on winding down a business, a one-person business could never leave — so it is not conditional.
9.2 What happens, and when
- Immediately — your sign-in is revoked, your profile is removed from every surface, your contact details and profile image are erased, your privacy settings are deleted, any draft orders are cancelled so the businesses you were negotiating with are not left waiting, and your verification documents are deleted from storage — the business licences, tax certificates and resale permits themselves, not only the records pointing at them. Your remaining profile data goes in the same operation, not later: the business identifiers and tax details, any credit terms or account numbers held against you, notes a business wrote about you, the verification data we received about your business, your notification preferences, and your calendar-feed link. And the files you attached to messages are deleted from storage, with the references to them cleared.
- Backups — see §9.3.
9.3 Backups
Deleted information persists in encrypted daily backups for 7 days before ageing out. While it is there it is inert and restore-only — we do not use it and do not query it. We cannot surgically remove one person's records from a backup archive; the window is what makes the deletion complete.
9.4 What survives, and why
Deleting your buyer account does not erase a vendor's or an organizer's record of a completed wholesale transaction. Those records are retained as business records for 7 years. Your profile is anonymised, so the record no longer links to a live account — but the order carries the name and shipping details as they stood when it was placed, because that is what the other business's accounting record consists of.
The same applies to messages: the other business keeps its copy of what you sent it, showing your name as it appeared at the time, as it would keep an email.
This is deliberate. You are one party to a business transaction; the other party's accounting and legal records are not yours to erase.
9.5 What we still hold about you afterwards
An anonymised shell of your record remains so that those counterparty records stay coherent rather than pointing at nothing. It contains no name, no email, no phone, and no image.
10. Security
Access to production data is restricted and authenticated. Verification documents are held in a private bucket with row-level access rules. Data is encrypted in transit, and at rest by our infrastructure providers.
No service is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and the relevant regulators as the law requires.
To report a vulnerability, write to security@storemingle.com.
11. Your rights
11.1 Everyone
-
Access and portability — whatever kind of account you have, download everything we hold about it yourself, as a structured file, prepared while you wait. Buyers: Data and privacy in the app's settings, or your privacy settings on the web. Sellers and organizers: Settings on the web. Speakers: Me → Settings on the web.
A buyer's file carries your profile — including the fields we or an organizer recorded about you rather than ones you typed, such as an account note or a credit term — your locations, orders, conversations, follows, saved items, notification and privacy settings, verification record and our business-registry check on you with the raw response we received, your live booth and session chat, the record that you asked to go on air, your contact-match receipts (§2), your product reviews and video comments with any moderation outcome and the ground for it, your search history and what you opened from it (§3), the engagement scores in §6.1 and §6.3 with the breakdown behind them, and which organizer directories and shows hold your details.
A seller's or organizer's file carries your sign-in, every membership you hold and what it permits, and each record that names you as the person who acted — booths you staffed, broadcasts you started, order changes you made. Where you are an active owner of an organization, that organization's own records are included as well. Where you are a member but not an owner they are not: those are the company's records rather than any one colleague's, and the company's commercial reporting is exported from the surfaces that produce it.
A speaker's file carries your profile, the programmes you appear in, and your session chat.
What no file contains, and each one says so in its own first page: the bytes of uploaded files — they are listed by name, type and size, and you can ask us for copies; anything an organizer or vendor already exported into their own systems, which is then under their policy; and our server and security logs, which are not organised by account. If a category is large enough to be capped, the file names the cap and tells you where to ask for the rest rather than quietly returning less than it claims.
-
Correction — ask us, and for most fields that is the only way. What a buyer can change without asking is currently their profile picture and their discoverability settings; the name, company and phone held against a buyer account are corrected by us on request (and the phone, in particular, cannot be removed by the account holder — §6.5). Sellers and organizers can edit their own business profile directly.
-
Deletion — §9.
-
Object or restrict — including to the engagement scoring described in §6.3.
-
Complain — to us first, and to your data protection authority.
We do not charge for these and we do not discriminate against you for using them.
To exercise a right, use the in-app controls or write to privacy@storemingle.com. We respond within 30 days and will tell you if we need longer.
11.2 If you are in the EEA or UK
Legal bases:
| Purpose | Basis |
|---|---|
| Providing the Services, including transmitting live video and audio | Contract — Art. 6(1)(b) |
| Verifying that a business is a genuine wholesale participant | Legitimate interests — Art. 6(1)(f): preventing fraud and keeping a trade platform trustworthy |
| Security, abuse prevention, and defending legal claims | Legitimate interests — Art. 6(1)(f) |
| Transactional email and push notifications about your activity | Contract — Art. 6(1)(b) |
| Marketing email, where sent | Consent — Art. 6(1)(a), withdrawable at any time |
| Complying with law | Legal obligation — Art. 6(1)(c) |
You also have the right to withdraw consent, and to lodge a complaint with your supervisory authority.
11.3 If you are in California
You may request to know, delete, and correct; to opt out of sale or sharing (we do neither); and to limit the use of sensitive personal information. We do not use or disclose sensitive personal information for purposes beyond those permitted under §1798.121.
You may use an authorized agent. We verify requests against your account.
11.4 If you are elsewhere in the US
Residents of states with comprehensive privacy laws have comparable rights of access, correction, deletion, portability and appeal. If we deny a request you may appeal by replying to our decision; if the appeal is denied we will tell you how to contact your state Attorney General.
12. International transfers
We are based in the United States and our infrastructure is in the United States. If you use the Services from outside the US, your information is transferred to and processed in the US.
13. Children
The Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, write to privacy@storemingle.com.
14. Changes
We will post any change here and update the date at the top. Material changes follow the Terms of Service §21(d). If a change would let us use information we already hold in a materially different way than this policy described when we collected it, we will ask for your agreement before we apply the change to that information.
15. Contact
Celavii Software Inc (d/b/a StoreMingle) 800 Progress Center Ct, Suite 500, Lawrenceville, GA 30043, USA
| For | Write to |
|---|---|
| Privacy and data rights | privacy@storemingle.com |
| Security | security@storemingle.com |
| Support | support@storemingle.com |
We do not offer the Services in the European Economic Area or the United Kingdom, so no representative under GDPR Article 27 is appointed. If that changes, one is required before we begin offering there, and will be named here.