Last updated: September 1, 2026. This policy explains what MakersKnot collects, why, who else receives it, and what you can ask us to do about it.
MakersKnot is a platform that lets independent makers and craft sellers build and run their own online storefront. This policy applies to two groups:
For a maker’s own account, storefront, and subscription, MakersKnot is the data controller. For the personal information a shopper hands to a maker — an order, a delivery address, a message through the contact form — the maker is the controller and MakersKnot acts as their processor, handling that information to run the storefront on the maker’s behalf. A maker is responsible for how they use their own customers’ information, including any analytics or advertising tools they connect to their storefront. Makers who need a data processing agreement can request one at the address in the Contact section.
| Category | What we collect | Where it comes from |
|---|---|---|
| Maker account | Name, email address, password (hashed), and — if you sign in with Google — the basic profile Google returns | You, or Google at your direction |
| Shopper account | Name, email address, password (hashed), saved delivery address. Optional — checkout works as a guest | You |
| Storefront content | Shop name, craft type, product listings, pricing, inventory, shipping origin and rates, policies, social links, uploaded logos, favicons and product photos | You, or imported from Etsy at your direction |
| Orders | Order contents, delivery address, phone number, order total, and payment status. Card and bank details go straight to the payment processor and never reach us | The shopper, at checkout |
| Shipping | The delivery address and phone used to quote a shipping rate, buy postage, and track the parcel. Purchased labels are PDFs showing the sender and recipient address | Derived from the order |
| Storefront messages | Name, email address, subject, and message left through a storefront’s contact form | The sender |
| Billing (makers) | Subscription status and payment history for your MakersKnot plan. Stripe holds the card details | You, and Stripe |
| Sign-in security | A device identifier derived from your browser’s user-agent, with the user-agent string and first and last seen dates, kept per account so we can alert you when a new device signs in. It is kept for the life of the account and deliberately outlives individual sessions. We also record the IP address and device on each sign-in, and the IP and date on each acceptance of these terms | Your browser, at sign-in |
| Technical & log | IP address, browser and device type, operating system, pages viewed, timestamps, error and security logs, referring pages. IP addresses are also counted to rate-limit abuse of sign-in and verification | Automatically, as you use the service |
Please do not submit sensitive personal information through MakersKnot. We do not collect or ask for sensitive personal information as California law defines it — government ID numbers, financial account numbers, precise geolocation, racial or ethnic origin, health, biometric, or sexual-orientation data — and we do not use or disclose any for the purpose of inferring characteristics about you. MakersKnot is not designed to store regulated medical, financial, or legal records.
If you are in the UK or European Economic Area, the law requires us to name a legal basis for each purpose. These are ours:
| Purpose | Legal basis |
|---|---|
| Creating your account, generating and hosting your storefront, and providing support | Performance of a contract |
| Taking a shopper’s order, quoting shipping, buying postage, tracking parcels, and passing the order to the maker who has to make and ship it | Performance of a contract |
| Billing a maker’s MakersKnot subscription and paying makers out | Performance of a contract |
| Sending transactional email — verification, password reset, order confirmations, receipts, new-device alerts | Performance of a contract |
| Keeping accounts secure: recognising devices, rate-limiting abuse, detecting and preventing fraud | Legitimate interests — securing the service and its users |
| Troubleshooting, improving the platform, and improving the quality of our AI generation | Legitimate interests — operating and improving the service |
| Running our marketing partner programme and enforcing our Terms of Service | Legitimate interests — running the business fairly |
| Analytics and advertising cookies and pixels, and measuring our own advertising | Consent, where the law requires it |
| Keeping order, payment, and tax records | Legal obligation |
Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interests you can object — the Your rights section explains how.
We use the providers below to operate, secure, and support MakersKnot. Each processes information only as needed to provide its service to us, under its own terms and privacy policy. This list is everything we have connected — where a provider only receives information because a maker has chosen to switch a feature on, we have said so.
We also disclose information where the law requires it, to enforce our terms, to protect our rights or someone’s safety, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.
MakersKnot operates from the United States, and every provider in the Who else receives it section processes information there. If you are in the UK or European Economic Area, using MakersKnot means your information is transferred to the United States.
Those transfers are covered either by the provider’s certification under the EU–US Data Privacy Framework and its UK extension, or by the UK and European Commission’s Standard Contractual Clauses, together with the additional safeguards those clauses require. You can ask us which mechanism applies to a specific provider at the address in the Contact section.
We do not sell your personal information, and we never have. Nobody pays us for it.
We do “share” a limited amount of it, in the specific sense California law uses. There, “sharing” does not mean selling — it means letting a third party see what you did on our site so they can target advertising to you elsewhere. The Meta Pixel described in the Cookies, analytics & advertising section does that: it tells Meta which of our pages you viewed, and our Conversions API sends Meta a scrambled (one-way hashed) version of your email address so it can match a signup to an ad. Your actual email address is never sent. We share nothing else this way, and we do not share the contents of orders, storefront messages, or anything a shopper gives a maker.
The categories involved are online identifiers and browsing activity, plus a hashed email on conversion. The third parties are Meta and, where a maker has connected advertising tools of their own, whichever provider they chose.
We do not knowingly sell or share the personal information of anyone under 16.
We will not treat you differently for exercising any of this. Opting out does not change your price, your plan, or the service you get.
These are required for the service to work and cannot be turned off without breaking it.
On MakersKnot’s own pages we use Google Analytics to understand traffic, and the Meta Pixel with its server-side Conversions API to measure our advertising. Both may set cookies.
Our Google Analytics also runs on makers’ storefronts, so we can see traffic across the platform as a whole. Our Meta Pixel does not.
Makers can add their own tracking to their own storefront. A maker can save a Google Analytics measurement ID and a Meta Pixel ID in their settings, and when they do, those tags load for everyone who visits their shop and report to the maker’s own accounts. That is the maker’s decision and the maker’s data; we do not control what they do with it. If you are a maker and you switch these on, you are responsible for disclosing them to your own shoppers.
Global Privacy Control switches off every Pixel described here. It does not switch off analytics, because analytics reports to us about our own site rather than handing anyone your activity to advertise to you elsewhere; use your browser’s cookie controls or a tracker blocker for that. The ad-settings links in the Selling and sharing section cover what Meta and Google already hold.
MakersKnot uses AI to write and improve storefront text — shop copy, product descriptions, SEO text, image alt text — to detect which craft category a shop belongs to, to match spreadsheet columns when importing a catalogue, and to answer questions in the assistant on our marketing site. The provider is named in the Who else receives it section.
Everything AI produces here is a draft you can edit or discard. It writes marketing copy and organises a catalogue; it does not decide anything about you. We do not use AI to make automated decisions that produce legal or similarly significant effects — nothing about pricing, account approval, suspension, payouts, or eligibility is decided by a model. If that ever changes we will say so here before it does, and explain the logic and your right to a human review.
We use industry-standard practices to protect your information:
No system is completely secure. If a breach affects your information we will notify you, and the relevant regulator, as the law requires — within 72 hours of becoming aware of it where the UK or EU GDPR applies.
| What | How long |
|---|---|
| Account and storefront content | While the account is open. On deletion, the storefront goes offline immediately and personal information is deleted within 30 days |
| Order, payment, and tax records | Kept after account deletion for as long as tax and accounting law requires — generally up to seven years |
| Copyright (DMCA) notices | Kept indefinitely. A notice is evidence of the claim it makes, and the claimant’s name, address, phone, IP address, and user agent are part of that evidence; deleting any of it would undermine the record a dispute may later need |
| Terms of Service acceptance records | Kept indefinitely. The IP address, user agent, and timestamp are our proof of what was agreed to and when, which is what they are for |
| Sign-in sessions | Until they expire or you sign out, whichever comes first |
| Recognised devices | The life of the account |
| Abandoned checkouts | 14 days, then deleted automatically |
| Unfinished shops saved before signup | 7 days, then deleted automatically |
| Rate-limit counters | About 2 days |
| Storefront messages | Until the maker or we delete them |
| Error and security logs | Up to 12 months |
| Anonymised usage statistics | Indefinitely — these no longer identify anyone |
Information can survive these periods in encrypted backups until those cycle out, and in records we must keep for a legal claim, a dispute, or fraud prevention. Retained backup and log data is not used for any active purpose beyond security, fraud prevention, and legal compliance.
MakersKnot is not intended for anyone under 18, and we do not knowingly collect personal information from children. We do not knowingly sell or share the personal information of anyone under 16. If you believe a child has given us personal information — by creating an account or by checking out as a guest on a storefront — contact us at the address in the Contact section and we will investigate and delete it.
Depending on where you live, you have some or all of these rights:
Email [email protected] to exercise any of them. We respond within 30 days, or 45 where California law allows an extension and we tell you why. You may use an authorised agent; we will ask for proof of their authority.
We may need to verify your identity first, and we may decline or limit a request where the law permits or requires it — for example where it would interfere with a legal obligation, an ongoing dispute, fraud prevention, or another person’s rights, including a maker’s own order and tax records. If we decline, we will tell you why.
If your information sits on a maker’s storefront, that maker is the controller of it and is the right first stop. Contact them through their shop, or tell us and we will pass the request on and help them action it.
You can also complain to a regulator. In the UK that is the Information Commissioner’s Office; in the EEA it is your national data protection authority; in California it is the California Privacy Protection Agency or the Attorney General. We would rather you came to us first, but you do not have to.
Browsers vary in how they send “Do Not Track” signals and there is no agreed standard for honouring them, so we do not respond to Do Not Track. We do honour Global Privacy Control, which is the signal California law recognises; the Selling and sharing section says exactly what it turns off.
We update this policy as the product changes, and review it at least once a year. The date at the top of this page is the date of the current version, and it changes only when the policy does — that date is how you know whether anything has changed since you last read it. Continued use after a change takes effect constitutes acceptance.
For privacy questions, to exercise a right, or to request a data processing agreement:
[ENTITY LEGAL NAME]
[REGISTERED ADDRESS]