Privacy Policy
Last updated August 5, 2026
Lakop is business software: a merchant signs up, connects their sales channels, and runs their inventory, orders and books in one place. This policy explains what we hold, why, and how to get it removed. It covers both the merchants who use Lakop and the buyers whose orders flow through it.
Who this covers
Merchants — the businesses with a Lakop workspace. You give us your details directly when you sign up.
Buyers — the customers of those businesses. We receive your details from the merchant's sales channel (eBay, Shopify, or their own storefront) so the merchant can fulfil and account for your order. The merchant is the controller of that data; Lakop processes it on their behalf.
What we collect
From merchants: name, business name, work email, and the workspace address you choose. If you take card payments through the built-in storefront, Stripe collects and holds the card details — Lakop never sees or stores a card number.
From connected channels: orders, line items, prices, taxes, shipping and payout records, plus the buyer name, email and shipping address attached to each order. We request only the permissions the features need, and you see the exact list on the channel's consent screen before you grant it.
Automatically: operational logs. Personal fields are redacted before a log line is written — access tokens, refresh tokens, emails, phone numbers and addresses do not reach our logging system in readable form.
Why we hold it
To run the service the merchant asked for: importing orders, keeping one stock figure accurate across channels, posting the accounting entries, producing invoices and shipping documents, and reconciling marketplace payouts. We do not sell data, and we do not use buyer data to advertise to anyone.
Who we share it with
Only the parties needed to deliver the service: the sales channels you connect (to read your orders and push your stock and tracking back), Stripe (payments and payouts), and our email and SMS providers (order confirmations, shipping notices, invoice reminders).
Each merchant's data is isolated at the database level, not merely by application code. One workspace cannot read another's records.
How long we keep it
For as long as the workspace is active, and afterwards only where a law requires it — accounting records in particular have statutory retention periods. Ledger entries and stock movements are append-only by design: a correction is a new reversing entry, never an edit or a deletion, because a book that can be silently rewritten is not a book.
Deletion and access requests
Buyers: ask the merchant you bought from. Lakop gives every merchant a one-click anonymize that clears your name, email, phone and address while leaving the financial record intact, and an export of everything held about you.
eBay account closures are handled automatically. When eBay notifies us that a user closed their account, we verify the notification's signature and scrub that buyer's personal details from every workspace that received their orders, without anyone having to act.
Merchants: email us to close a workspace and have its data removed, subject to the retention above.
Security
Channel access tokens and other third-party secrets are encrypted before they are stored. Access inside a workspace is controlled by role, with financial data behind its own permission, and every change is written to an append-only audit trail. Traffic is served over HTTPS.
Contact
Questions, access requests or deletion requests: privacy@shopbuylow.com.