Back to home

Privacy Policy

Effective date: August 3, 2026

This Privacy Policy explains how Prado Commerce collects, uses, stores, and protects information when merchants and their teams use the website, dashboard, APIs, and embedded cart experiences.

1. Scope of this policy

This policy applies to all Prado Commerce surfaces, including:

  • Public website pages such as home, pricing, privacy, terms, login, signup, and password reset.
  • Dashboard modules including stores, products, categories, orders, customers, and settings.
  • Settings features including store profile, currencies, payments, shipping, tax, security, and API access.
  • Storefront rendering routes by slug or mapped domain.
  • API routes used for authentication, catalog management, cart, checkout, uploads, and key management.
  • Embed scripts and storefront events that send data to platform APIs.

2. Information we collect

  • Account data: name, email, password hash, onboarding records, and account status metadata.
  • Authentication data: session cookies, session version values, login events, and security events.
  • Store data: store ID, store name, slug, domain settings, allowed frontend domains, and branding fields.
  • Catalog data: products, variants, categories, media URLs, pricing, and inventory attributes.
  • Customer data: customer profiles and related order history stored by the merchant.
  • Order data: cart contents, checkout context, order totals, status transitions, and fulfillment metadata.
  • Payment and tax configuration data: provider settings, tax preferences, and region-level rules.
  • Shipping configuration data: origin, zones, methods, and carrier integration states.
  • API access data: publishable keys, secret keys, key metadata, and revocation history.
  • Operational data: request logs, error traces, and performance telemetry needed for reliability and security.

3. How we use information

  • Provide dashboard and storefront functionality for merchant operations.
  • Authenticate users, enforce access control, and protect accounts from unauthorized use.
  • Process catalog, cart, and checkout workflows requested by merchants and storefront users.
  • Support configuration features for shipping, tax, payment, currency, and domain controls.
  • Issue, validate, and revoke API keys for integrations and headless storefront use cases.
  • Monitor platform performance, troubleshoot issues, and improve service reliability.

4. Cookies and sessions

Prado Commerce uses cookies and related session mechanisms to keep users signed in, protect secure routes, and support account-level controls such as changing passwords and signing out other devices.

5. API keys and integration safety

  • Publishable keys are intended for client-side or public integration contexts.
  • Secret keys are intended for trusted server-side environments only.
  • Merchants can create and revoke keys in Dashboard Settings under API access.
  • Allowed frontend domain controls are used to reduce misuse of browser-side integrations.

6. Data sharing and disclosures

Prado Commerce does not sell merchant data. Information may be shared only when required to:

  • Operate requested platform features through service providers.
  • Comply with legal obligations, lawful requests, or enforcement requirements.
  • Protect the rights, security, and integrity of Prado Commerce, merchants, and users.

7. Data retention

Data is retained for as long as needed to provide services, maintain legitimate business records, enforce security controls, and satisfy legal or contractual requirements.

8. Security practices

  • Access controls and authentication checks on protected dashboard and API routes.
  • Password change and active-session invalidation controls.
  • Key lifecycle management with creation and revocation endpoints.
  • Operational monitoring for platform stability and abnormal usage detection.

9. International use

Merchants may access Prado Commerce from multiple regions. By using the service, you understand that data may be processed in jurisdictions where our infrastructure or vendors operate.

10. Policy updates

This policy may be updated as platform features evolve, including updates to dashboard modules, API behavior, or security controls. Continued use of Prado Commerce after updates indicates acceptance of the revised policy.

11. Contact

For privacy questions or requests, contact: support@pradocommerce.com