๐Ÿ“ฆ
Website Builder

Website Builder Privacy Policy

๐Ÿ“… Effective Date: September 21, 2026 โ€ข Version 1.0.2 โ€ข Compliant with Google Play & Apple App Store Guidelines

Welcome to Website Builder ("we", "our", or "us"), provided by ShanApps. Website Builder is a multi-platform mobile application and web suite designed to help merchants, small business owners, artisans, and entrepreneurs build, manage, and publish instant WhatsApp-connected digital storefronts, catalog products, accept appointment bookings, and manage customer orders with zero transaction commissions.

Your privacy and trust are paramount to us. This Privacy Policy details the exact types of information we collect, how and why that data is processed, the specific device permissions our application requires, our strict compliance standards for Google Play Developer Policies and Apple App Store Review Guidelines, and how you can access, export, or delete your data at any time.

1 Information We Collect

We collect only the data necessary to provide and secure our storefront builder services:

  • Account & Authentication Information: When you register or sign in via Google OAuth or Apple Sign-In, we receive your name, verified email address, and unique account identifier. We do not store your Google or Apple passwords.
  • Business & Storefront Information: Storefront names, business categories, taglines, business addresses, public WhatsApp contact numbers, social links (Instagram, Facebook), and brand colors.
  • Catalog & Content Data: Product names, descriptions, pricing, inventory stock status, product photos, and service appointment schedules uploaded by you.
  • Customer Orders & Inquiries: Customer contact details and order line items sent directly to your storefront. The application directs checkout inquiries to your official WhatsApp number via encrypted WhatsApp links (https://wa.me/).
  • Subscription & Purchase Tokens: When upgrading to multi-site plans (1 Website, 3 Websites, 5 Websites), we receive anonymized transaction IDs, product SKUs, and purchase tokens from Google Play Billing or Apple StoreKit to verify and activate your subscription entitlements.

2 Device Permissions & Explicit Purpose Disclosures

In strict compliance with Google Play Store User Data & Permission Guidelines and Apple App Store Guideline 5.1.1, The application requests only the minimum native device permissions required to perform user-initiated features. We never access your device hardware or sensors in the background.

๐Ÿ“ธ Photos & Media Storage (READ_MEDIA_IMAGES / NSPhotoLibraryUsageDescription)

Purpose: Required exclusively when you choose to upload product pictures, storefront logos, or promotional announcement banners.
Scope & Protection: We only access the specific image file selected by you via the system photo picker. We never read, scan, or index your private photo library or unrelated documents.

๐Ÿ”’ Biometric & Device Security (USE_BIOMETRIC / NSFaceIDUsageDescription)

Purpose: Used exclusively for on-device security verification before performing destructive actions (e.g. permanently deleting a storefront or business profile).
Scope & Protection: All biometric processing (Fingerprint, Touch ID, Face ID, or system PIN) occurs locally inside your device's hardware Secure Enclave / Keystore. The application never accesses, transmits, or stores raw biometric templates.

๐Ÿ“ฑ Hardware & Device Metadata (Android ID, IDFV, Hardware RAM, OS Version, Country Code)

Purpose: Captured during registration and authenticated sessions to secure your merchant workspace, enforce multi-tenant storefront isolation, detect automated bot abuse, and resolve regional localization.
Scope & Protection: Stored securely in your encrypted user profile. We do not sell or share device identifiers with third-party data brokers.

๐ŸŒ Internet & Network State (ACCESS_NETWORK_STATE / INTERNET)

Purpose: Required to synchronize your catalog with our cloud database (PocketBase), verify your annual subscription status, and open direct customer communication links via WhatsApp (wa.me).

3 Financial Information & In-App Purchases

Website Builder offers annual subscription tiers allowing merchants to publish and host 1, 3, or up to 5 live websites.

๐Ÿ›ก๏ธ Zero Direct Financial Data Collection: All subscription payments are processed exclusively through Google Play In-App Billing (on Android devices) and Apple App Store In-App Purchases (on iOS devices). We never receive, store, or process your credit card numbers, debit card details, CVVs, or bank account credentials.

We retain only cryptographic transaction receipts, product IDs (e.g., 1_site, 3_site, 5_site), and purchase expiration dates to manage your storefront quota and renew your site hosting privileges.

4 Third-Party Services & Integrations

We work with trusted third-party providers to deliver reliable, high-performance services:

Service Provider Purpose Data Shared
Google Play Billing / Apple StoreKit In-app subscription processing & entitlement management Transaction receipts, product SKUs (No payment card details)
PocketBase Cloud Database Encrypted merchant catalog, orders, and storefront hosting Account credentials, product listings, store settings
WhatsApp (Meta Platforms, Inc.) Direct customer ordering and appointment inquiry links Public business phone number, customer order text
Google Analytics / Meta Pixel Anonymous, aggregated performance metrics and website visits Aggregated page view counts, anonymized device OS
Cloudflare CDN Fast and secure global edge caching for public storefronts Standard HTTP request headers and IP addresses for DDoS protection

5 Data Security, Encryption & Storage

We employ industry-standard technical and organizational security controls to protect your data:

  • Encryption in Transit: 100% of data transmitted between the mobile app, public storefronts, and cloud servers is protected using Transport Layer Security (TLS 1.3 / HTTPS).
  • Encryption at Rest: Database storage and sensitive merchant tokens are encrypted with AES-256 standards.
  • Tenant Isolation: Every merchant's storefront, products, services, and orders are strictly isolated using scoped database rules.

6 Data Retention & Account Deletion (Google Play & Apple Compliant)

In full accordance with Google Play Store Data Safety Policy and Apple Guideline 5.1.1(v), you have the absolute right to request the permanent deletion of your account and all associated data at any time:

  • Instant Storefront Deletion: You can delete any individual storefront directly within the mobile app under Manage Storefronts โ†’ Delete (authenticated via biometrics).
  • Complete Account Deletion: You can permanently delete your account, business records, and customer logs directly within the app settings or by submitting an email to our Data Protection Team at website-builder.support@shanapps.dev.
  • Turnaround Time: Upon receiving your verified deletion request, all account data, products, orders, and uploaded images are permanently purged from our primary database within 7 business days.

7 Children's Privacy

Website Builder is intended exclusively for business owners, merchants, and individuals of legal age to operate a commercial storefront. We do not knowingly collect or solicit personal information from children under the age of 13 (or under 16 in the European Union). If we become aware that a child has provided us with personal information, we immediately delete such records.

8 Changes to This Privacy Policy

We may update our Privacy Policy periodically to reflect app improvements, platform policy updates, or legal requirements. When significant changes occur, we will notify you through an in-app notice or update the "Effective Date" at the top of this policy. We encourage you to review this page periodically.

9 Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: