Privacy Policy
Last updated August 24, 2026
Two different relationships
tooo.market sits in the middle of two groups of people, and the rules are different for each.
Merchants. If you run a store here, we decide how your account information is handled, and this policy describes that.
Shoppers. If you bought something from a store built on tooo.market, your information belongs to that merchant. They decide what happens to it; we only process it on their instructions. Requests about your data should go to the store you bought from — their contact details are on their site. If you reach us instead, we will pass it along.
What we collect from merchants
- Account details: name, email, password hash, phone if you give one.
- Store details: name, address, support contacts, branding.
- Billing details for your subscription.
- Security and audit records: sign-in times, IP addresses, and a log of admin actions.
- Support conversations.
What we store on a merchant’s behalf
Running a store means holding its customers’ data: names, email addresses, shipping and billing addresses, phone numbers, order history, and any notes the merchant adds.
We use it to run the store — showing order history, sending the emails the merchant has configured, calculating tax and shipping. We do not sell it, rent it, or use it to market anything of our own to a merchant’s customers.
Payment information
We never see or store full card numbers. Card details are entered directly into a payment field hosted by our payment provider and go straight to them. They never reach our servers, and there is no card number, expiry, or security code anywhere in our database.
What we keep is a reference to the payment (an identifier from the provider), the amount, the currency, and whether it succeeded — enough to show an order history and issue a refund, and nothing more.
Who we share with
We use a small number of service providers to run the platform: hosting, email delivery, and payment processing. Each of them gets only what they need to do their part. We do not sell personal information to anyone.
We will disclose information if the law requires it. If we are legally able to tell you first, we will.
Cookies
Storefronts set a small number of cookies that are needed to work at all: one to keep track of a shopping cart, one to keep a shopper signed in, and one to remember a chosen language. Merchant admin sessions use a signed session cookie.
A merchant may add their own analytics or advertising tags to their storefront. Those are the merchant’s, governed by the merchant’s own policy, and outside our control.
How long we keep things
Store data stays as long as the account is open. After an account closes we keep it for 30 days so it can be exported, then delete it; backups roll off on their own schedule after that.
Some records have to outlive the account — invoices and payment records, for tax and accounting.
Your choices
Merchants can view, correct, export, or delete their data from the admin, or ask us to do it. Marketing emails from us always have an unsubscribe link; service messages about your account and billing do not, because you need them.
Shoppers: contact the store you bought from. Merchants have tools in their admin to export or delete a customer’s record.
Security
Passwords are hashed, traffic is encrypted in transit, and each store’s data is isolated from every other store’s at the database layer. Admin actions are logged. No system is perfectly secure, but if a breach affects your data we will tell you.
Children
The service is not for children under 13, and we do not knowingly collect their information. If you believe we have, write to us and we will delete it.
Changes and contact
If we change this policy materially we will email merchants before it takes effect. Questions or requests: [email protected]