Wexido
ProductFor SellersMarketplacePricing
Legal

Privacy Policy

Last updated 10 September 2026|Effective 10 September 2026

How Wexido collects, uses, shares and protects personal information across accounts, storefronts, orders, bookings and communications — and the choices you have over it.

On this page

  1. Introduction
  2. Information Wexido collects
  3. Information collected by stores
  4. How Wexido uses information
  5. Email communications
  6. Email consent and anti-spam
  7. Email deliverability and reputation
  8. Service providers
  9. Data sharing
  10. Data retention
  11. Security
  12. Cookies and analytics
  13. Your choices and rights
  14. Children’s privacy
  15. International processing
  16. Changes to this policy

Introduction

Wexido is a commerce platform. Sellers, creators and businesses use it to open a storefront, sell physical and digital products, take bookings, run subscriptions, accept orders, manage their customers, and send messages to the people who buy from them. Shoppers use it to browse those storefronts and to buy.

This policy explains what personal information we collect when you use Wexido, why we collect it, who we share it with, and the choices you have. It applies to the Wexido website, the storefronts hosted on Wexido (including stores served on their own custom domains), our email and notification systems, and the seller dashboard.

It does not apply to what an individual store does with customer data outside Wexido, or to third-party websites and services a store may link to. Those are governed by that store’s or that service’s own policies.

[LEGAL REVIEW REQUIRED: identify the legal entity that operates Wexido — its registered name, registered address, company registration details, and the name of the data controller or privacy contact where a jurisdiction requires one.]

Information Wexido collects

What we hold about you depends on how you use Wexido — as a visitor, as a customer of a store, or as a seller running one.

Account and profile information

Name, username, email address, phone number, password (stored only as a hash), profile photo and bio, display preferences such as theme, language and currency, and the sign-in methods you connect.

Store information

Store name, handle, description, logo, banner and other brand assets, product and service listings, pricing, inventory, policies, connected domains, and the settings you configure in the dashboard.

Customer and order information

Order and cart contents, order status and history, buyer and recipient names, delivery and billing addresses, contact details, shipping and tracking information, invoices and receipts, messages exchanged about an order, and returns or dispute records.

Booking and subscription information

Appointment and slot selections, attendee or participant details you provide, schedules and reschedules, cancellations, membership and subscription status, renewal dates, and entitlement or access records for digital and paid content.

Contact and subscriber information

For people who join a store’s or Wexido’s mailing list: email address, any name or other fields captured at sign-up, list membership, and the consent record described below.

Payment-related metadata

Payments are handled by third-party payment processors. We receive and store transaction metadata — amount, currency, payment status, processor reference identifiers, the payment method type, and the last digits of a card where the processor supplies them. We do not store full card numbers or card security codes. Payout-related identifiers submitted by sellers are handled in order to enable payouts.

Device, browser and network information

IP address, browser and device type, operating system, screen and viewport characteristics, language, time zone, referring page, and identifiers stored in cookies or local storage.

Usage and activity logs

Pages and storefronts viewed, actions taken (such as creating a listing, publishing a store or placing an order), sign-in and session events, security events such as new-device sign-ins, timestamps, and error and diagnostic logs.

Analytics

Aggregate and event-level product analytics about how the platform and individual storefronts are used, including performance measurements.

Support communications

Messages you send us, the contents of contact forms, and the records needed to answer and follow up on a request.

Email engagement data, where enabled

Delivery outcomes for messages we send on behalf of Wexido or a store — deliveries, bounces, complaints, rejects, delivery delays and rendering failures — and, where engagement tracking is enabled for a message, opens and link clicks.

Consent and opt-in records

Where a person opts in to marketing email, we record the opt-in source, the timestamp, the IP address and user agent seen at opt-in where available, the confirmation of a double opt-in where used, and the current consent status including any later unsubscribe.

Information collected by stores

Every Wexido store is run by an independent seller. When you buy from a store, subscribe to it, book with it, or sign up to its mailing list, the information you provide is available to that store’s owner and the people they authorise — because they need it to fulfil the order, deliver the booking, or answer your questions.

Wexido provides the software. The store owner decides what they ask for and how they use it, and is responsible for handling customer information lawfully, including honouring their own published policies and any privacy notice they show at checkout or at sign-up. A store may publish its own privacy policy on its storefront; where it does, that policy governs the store’s own use of the data.

If you want a store to correct or delete information you gave it, contact the store directly. You can also contact us using the details at the end of this policy and we will help you reach them.

How Wexido uses information

We use the information described above to:

  • run the platform — host storefronts, show listings, and keep carts, orders, bookings and subscriptions working;
  • create and authenticate accounts, keep sessions signed in, and verify identity when you sign in from a new device;
  • process orders and payments through our payment processors, and issue invoices and receipts;
  • send transactional and service messages you need in order to use the service;
  • send marketing messages that you, or a store’s subscribers, have asked to receive;
  • detect, investigate and prevent fraud, abuse, spam and prohibited activity;
  • keep the service secure — rate limiting, abuse detection, audit logs and incident response;
  • measure and analyse how the platform is used so we can fix problems and improve it;
  • provide support and respond to your requests;
  • build, test and improve features; and
  • meet legal, tax, accounting and regulatory obligations, and enforce our terms.

Email communications

Wexido separates two kinds of email, and treats them differently.

Transactional and service email

These messages are triggered by something you or a store’s customer did, or by something you need to know in order to keep using the service: account verification, password reset, sign-in and security notifications, order confirmations, payment and payout notifications, booking confirmations and updates, subscription and renewal notices, delivery of digital purchases, and important service or policy notices.

Marketing email

Newsletters, campaigns, promotions and store announcements. Marketing messages are sent only to recipients with applicable consent — see the next section.

Every marketing message includes a way to unsubscribe: an unsubscribe link in the message, and the List-Unsubscribe headers that let a mail client offer one-click unsubscribe (RFC 8058). An unsubscribe is honoured for the applicable list or sender.

Unsubscribing from marketing email does not necessarily stop transactional and service messages. If you still hold an account, or have an open order, booking or subscription, we and the relevant store may still need to send you operational messages about it. To stop those, close the account or resolve the underlying transaction.

Email consent and anti-spam

Contacts enter Wexido’s marketing system only through Wexido or storefront consent flows. Wexido does not support and does not permit purchased, rented, scraped, harvested or otherwise third-party-sourced mailing lists.

Specifically:

  • marketing recipients must have given appropriate consent to receive marketing from the sender;
  • double opt-in is enabled by default, so a subscriber confirms their address before marketing is sent to it;
  • we record the opt-in source, timestamp, IP address, user agent and consent status where applicable, so a consent claim can be checked;
  • stores may only send marketing mail to recipients who consented to hear from that store; and
  • importing addresses obtained from a list vendor, a scrape, a directory, another party’s customer list, or any other source without direct consent is prohibited.

Wexido may require proof of consent, may decline to send, and may restrict, suspend or remove email functionality for a store that abuses it. The full rules are in the email and anti-spam section of our Terms of Service.

Email deliverability and reputation

To keep email working for the people who want it — and to stop sending to people who do not — our email infrastructure processes the signals that mail providers return to us. These include deliveries, hard and soft bounces, spam complaints, rejects, delivery delays, rendering failures, subscription and unsubscribe events, and (where engagement tracking is enabled) opens and clicks.

We act on those signals:

  • an address that hard-bounces is treated as permanently invalid and is suppressed from future sending;
  • a spam complaint stops applicable marketing to that recipient;
  • an unsubscribe stops applicable marketing to that recipient; and
  • sending reputation is monitored at the store level, and a store’s sending may be throttled, restricted or suspended where it puts recipients or deliverability at risk.

Suppression is a protective measure. It exists so that an address which bounced, complained or opted out does not keep receiving unwanted mail.

Service providers

We use third-party providers to run the service. They process personal information on our behalf, for the purposes we set, in the following categories:

  • Cloud infrastructure and hosting — servers, databases, networking and application hosting.
  • Email delivery — sending transactional and marketing email and returning delivery, bounce and complaint events. This includes Amazon Simple Email Service (Amazon SES).
  • Payment processing — taking payments, handling refunds and enabling payouts.
  • Storage and content delivery — object storage and CDN delivery for images, media and files.
  • Analytics and performance monitoring — usage measurement, error reporting and performance metrics.
  • Support and communications — handling support requests and sending notifications.
  • Security and anti-abuse — bot and abuse protection, including verification challenges on sign-up and sign-in.

Naming a provider here describes who processes data for us. It is not a statement about that provider’s certifications, and it is not an endorsement of Wexido by that provider.

[LEGAL REVIEW REQUIRED: confirm the final provider list and, where a jurisdiction requires it, publish the specific sub-processor list and the contractual basis for each transfer. Do not assert compliance standards or certifications that have not been verified.]

Data sharing

We share personal information only in these situations:

  • With service providers, in the categories listed above, to run the platform on our instructions.
  • Between a store and its customer, to complete a transaction — a seller receives the order, contact and delivery details needed to fulfil it; a customer receives the store details needed to contact the seller.
  • With payment processors, to take payment and to handle refunds, chargebacks and disputes.
  • With delivery and logistics partners a seller uses, where a physical order has to be shipped.
  • Where the law requires it — in response to valid legal process, or where we are legally obliged to disclose.
  • To protect people and the service — to investigate fraud, abuse, security incidents or threats to the rights and safety of users or the public, and to enforce our terms.
  • In a business transfer — if Wexido is involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction, subject to this policy or a successor policy.
  • With your direction — when you ask us to share, or connect a third-party integration yourself.

Wexido does not sell personal data. We do not rent or trade personal information, and we do not make customer or subscriber lists available to other stores or to third parties for their own marketing.

Data retention

We keep personal information for as long as we need it for the purpose it was collected for, and then delete or de-identify it. How long that is depends on the record:

  • Account and store data — while the account or store exists, and for a limited period afterwards to allow recovery and to close out obligations.
  • Orders, payments, invoices and payouts — for as long as required to complete the transaction and to meet accounting, tax and legal obligations.
  • Bookings and subscriptions — while active, and afterwards as part of the transaction record.
  • Security, audit and abuse logs — for the period needed to investigate incidents and prevent recurrence.
  • Support communications — for as long as needed to resolve the matter and handle any follow-up.
  • Consent, unsubscribe and suppression records — retained on an ongoing basis. A suppression entry is the record that stops us sending to an address that bounced, complained or opted out; deleting it would allow the unwanted mail to resume, so we keep the minimum needed for that purpose.

[LEGAL REVIEW REQUIRED: specific retention periods. State a defined period per category only where it has been confirmed against the applicable accounting, tax and data-protection obligations — do not publish an estimate.]

Security

We use reasonable technical and organisational measures to protect personal information. These include encryption of traffic in transit, hashed password storage, opaque server-side session credentials held in httpOnly cookies, scoped access to private files through short-lived signed links, access controls and least-privilege internal access, abuse and bot protection, and logging and monitoring of security-relevant events.

No online service can be completely secure, and we do not claim otherwise. You also play a part: use a strong, unique password, keep your sign-in details to yourself, and tell us promptly if you think your account has been accessed without your permission.

Cookies and analytics

We use cookies and similar browser storage to keep you signed in, remember your preferences (such as theme and display currency), keep a cart together across pages, protect against abuse, and measure how the service is used.

Broadly, they fall into three groups:

  • Necessary — sign-in sessions, security and fraud protection, cart and checkout state. The service does not work without these.
  • Preferences — remembering choices you have made so you do not have to set them again.
  • Analytics and marketing — measuring usage and, where a store enables it, measuring campaign performance.

Storefronts may present their own cookie choices, and where optional analytics or marketing cookies are used you can accept or decline them. You can also clear or block cookies in your browser settings — blocking necessary cookies will stop sign-in and checkout from working.

Your choices and rights

  • Update your details — edit your name, contact details, photo and preferences in your account settings.
  • Email preferences — manage which marketing messages you receive from your account settings, or unsubscribe from any marketing message using the link it contains.
  • Unsubscribe — an unsubscribe applies to the applicable marketing from that sender. Transactional and service messages tied to an active account, order, booking or subscription may continue.
  • Cookie choices — accept or decline optional cookies where they are offered, and manage cookies in your browser.
  • Access, correction and deletion — you can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Where a store holds the data as its own customer record, we will pass the request to the store and help where we can.
  • Close your account — you can ask us to close your account and delete your profile.

Some information cannot be deleted on request — records we must keep for accounting, tax, fraud-prevention or legal reasons, and suppression entries that exist to stop unwanted email. We will tell you if that applies to your request.

To make a request, use the contact details at the end of this policy. We may need to verify your identity before acting, so that we do not disclose someone else’s data.

[LEGAL REVIEW REQUIRED: statutory rights, response deadlines, the legal bases for processing, and any supervisory-authority or grievance-officer disclosure required in the jurisdictions Wexido operates in.]

Children’s privacy

Wexido is built for businesses, creators and shoppers, and is not directed at children. Accounts are intended for people who can enter a binding contract in their jurisdiction, and we do not knowingly collect personal information from children.

If you believe a child has given us personal information, contact us and we will delete it and close any associated account.

[LEGAL REVIEW REQUIRED: the minimum age to hold an account, and any parental consent requirements applicable in the jurisdictions Wexido serves.]

International processing

Wexido is delivered from cloud infrastructure and content-delivery networks that operate in multiple countries, and our service providers — including our email delivery, storage and analytics providers — may process data in a country other than the one you are in. Where that happens, we take steps intended to keep the information protected to the standard described in this policy.

[LEGAL REVIEW REQUIRED: processing and storage locations, and the transfer mechanism relied on for cross-border transfers in each applicable jurisdiction.]

Changes to this policy

We may update this policy as the product, our providers or the law change. When we do, we will change the “Last updated” date at the top of this page. If a change materially affects how we handle your personal information, we will give notice in the product or by email before it takes effect, where that is appropriate.

Continuing to use Wexido after an update takes effect means the updated policy applies to you.

Wexido

Contact us about privacy

Questions about this policy, or a request about your personal information? Get in touch and tell us what you need — we will route it to the right place.

Email
support@wexido.com
Contact form
wexido.com/contact
Related
Terms of Service

[LEGAL REVIEW REQUIRED: registered legal entity name and postal address for legal and privacy notices, plus any dedicated privacy or grievance contact required by law. Only the support email address above is verified in the project.]

Wexido

One store for everything you sell — products, services, events, memberships and digital goods.

Important Links

Platform FeaturesPricing PlansExplore MarketplaceSeller SolutionsHelp & FAQContact Us

Connect & Share

X (Twitter)InstagramYouTubeLinkedIn
Share on X ↗Share on LinkedIn ↗

Subscribe for news

© 2026 Wexido

Terms & Conditions·Privacy Policy

Wexido