Your customers’ data.
Plainly, what we do with it.

StoreFleet is software that retail stores use to talk to their own customers. A store connects the tools it already runs on, and StoreFleet helps its staff send the right message at the right time.

That means there are two different people this policy has to be honest with. The store, which is our customer. And the store's customers, whose information passes through our software because the store put it there.

Last updated September 9, 2026

Who decides what, and who is responsible

The store decides who to contact, what to say, and why. We carry that out. In data protection terms the store is the controller and StoreFleet is the processor acting on its instructions.

This matters if you are a customer of a store that uses StoreFleet. Your relationship is with that store. It holds your information, it decided to message you, and it is the right first place to take a question or a request about your data. We help stores answer those requests and we will act on one passed to us, but we do not decide on our own what a store does with its customer list.

What information StoreFleet holds

Only what the software needs to do the job the store asked for. It comes from the systems the store connects, not from anywhere we go looking.

  • Contact details: name, phone number, email address, and a social handle when the store already has one.
  • Purchase history from the store's commerce platform: orders, order value, items, sizes and brands bought, and the date of the last purchase.
  • Messages between the store and its customer, so staff can see the conversation they are replying to. Whether the full text of an inbound message is kept is a per-store setting, and it is off unless the store turns it on.
  • A record of every message the store sends through us: who it went to, when, on which line, whether it was delivered, and which staff member or automation sent it.
  • Consent and opt-out state: whether someone agreed to be contacted and whether they have since asked to stop.
  • Photos and files a customer sends in, when the store uses the features that accept them.
  • Ordinary service records: who on the store's team logged in and what they changed, plus error and performance logs.

Why we hold it

To provide the product the store is paying for, and for nothing else.

  • To send the messages a store asks us to send, and to show its staff the conversation.
  • To decide who a message is appropriate for, which is what the purchase history is for.
  • To keep the store on the right side of the rules that govern business messaging: consent, quiet hours in the recipient's own time zone, sending limits, and honoring an opt-out.
  • To show the store what happened: what was sent, what was delivered, what it led to.
  • To keep the service running, secure and correct, and to fix it when it breaks.

What we never do

This section is short on purpose, because these are the questions owners actually ask.

  • We do not sell customer data. Not to anyone, in any form.
  • We do not share one store's data with another store. Every record belongs to exactly one store and is walled off from the rest.
  • We do not use one store's customer data to build a product for a different store.
  • We do not buy contact lists, and we do not message people a store did not bring to us.
  • We do not use customer data for advertising, our own or anyone else's.

Who else touches it

Running this software means using other companies. We use them to do a specific job, they are bound to protect the data, and they may not use it for their own purposes.

The current list of these providers is available to any store on request, and we will tell a store before we add one that handles customer data.

  • Cloud hosting and the database that stores a store's records.
  • The messaging providers that carry a text or a direct message to the recipient.
  • The store's own connected systems, such as its commerce platform and its customer relationship tools, which the store already controls.
  • AI providers that help draft a suggested message. A draft is shown to a person unless the store has explicitly turned on automatic sending for that feature.
  • Error monitoring and analytics that tell us when the software is failing.
  • Legal requests. If we are compelled by law to hand something over, we will, and we will tell the affected store unless we are forbidden from doing so.

How the AI part works

StoreFleet drafts messages. Drafting means the software writes a suggestion and, by default, a person at the store reads it and decides whether to send it.

A store can turn on automatic sending for a specific feature, and some do. That is the store's decision, it is recorded, and it can be switched back off at any time. Even then the same consent, quiet hours, sending limits and opt-out checks run on every message.

Drafting uses the store's own catalog and that customer's own history. We do not train a shared model on one store's customers.

How long we keep it

Contact and purchase records last as long as the store is a customer and stays connected, because that is what the product runs on.

Message content has a per-store retention setting. When a store sets one, a scheduled job removes content older than that limit without being asked again.

When a store leaves, its data is removed on request and otherwise on our ordinary schedule. Backups age out on their own cycle, so a record can survive a short time in a backup after it is gone from the live system.

Asking to be deleted, and what actually happens

If you are a customer of a store that uses StoreFleet, ask that store. It can make the request for you, and it is the one who knows which account you are.

Deletion here is not a single button that hides a row. Every table in our database is classified in advance for what a deletion has to do to it, and a build fails if a new table ships without that classification. Ninety eight tables and six file stores are covered.

Depending on the table, that means the identifying columns are cleared in place, or the row is removed outright, or the record is one that carries no personal information and is left alone. Free text is swept for the person's identifiers as well, so a name inside a note goes too.

Two honest limits. Very short identifiers inside free text can survive a sweep, because removing every four letter string would destroy the surrounding record. And a deleted contact leaves a marker behind so that the same person cannot be silently re-added and messaged again, which is a protection rather than a leftover.

Stopping messages

Reply STOP to any text and the block is recorded and applies everywhere, not only to the conversation you replied to. Staff cannot override it by hand, and an automation cannot route around it.

We also read the opt-out state held in the store's own connected systems, so an opt-out recorded somewhere else still reaches us. Clearing an opt-out is never automatic; it takes a deliberate human action.

Security

Data is encrypted in transit and at rest. Credentials are held in a secrets vault rather than in configuration files. Access to production is limited to the people who need it and is logged.

Each store's data is separated at the database level, and that separation is enforced by the database itself rather than by remembering to filter a query.

No system is perfect. If we discover a breach that affects a store's data we will tell that store promptly and tell it what we know.

Children

StoreFleet is business software and is not directed at children. We do not knowingly hold information about anyone under 13. If you believe we do, contact us and we will remove it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects how a store's customer data is handled, we will tell the store rather than relying on it to notice.

Contact

Questions about this policy, or a request about your data, go to jake@storefleet.com.

If you are the customer of a store that uses StoreFleet, that store can usually resolve it faster, because it holds the account you are asking about. We will still help.

Running a store and want the longer version of how the messaging rules work? The FAQ covers consent, co-pilot versus autopilot, and what stays yours.