Privacy Policy

DRAFT — for lawyer review. Not in effect. This catalog is still sample data.

BotSKU collects the buyer’s name, email, and shipping address when an order is paid, the seller’s email and Stripe Connect account id, and the messages sent about that order. Payment card data is collected by Stripe, not by BotSKU. The order receipt is opened with an unguessable token. The public order page and the agent status tool mask the name, email, and street.

Request logs store the path, status, timing, and user agent. The client IP is truncated and stored only as a salted hash. Raw log rows are deleted after 30 days. Admin tools require a token sent as a header or an HttpOnly cookie, never a query-string secret. Webhook bodies, card numbers, and the admin token are not written to the request log.

Order records, the seller ledger, and mail copies are kept so BotSKU can ship, refund, and pay sellers. They are not sold. The sample catalog’s products, prices, and sellers are fictional and must not be treated as a real consumer profile.