Terms of Service →Copyright →
Legal

Privacy Policy

Last updated: September 1, 2026. This policy explains what MakersKnot collects, why, who else receives it, and what you can ask us to do about it.

This document is not final. The company operating MakersKnot as the data controller named in the Contact section has not been identified yet. Email [email protected] if you need the controller’s details before then.

1. Who this covers

MakersKnot is a platform that lets independent makers and craft sellers build and run their own online storefront. This policy applies to two groups:

  • Makers — people who create a MakersKnot account to build, host, and manage a storefront.
  • Shoppers — people who visit a MakersKnot-powered storefront, buy from it as a guest, contact a maker through it, or create an optional account on it.
We do not sell your personal information. We do share limited information for advertising — the Selling and sharing section explains exactly what that means and how to stop it.

Who is responsible for what

For a maker’s own account, storefront, and subscription, MakersKnot is the data controller. For the personal information a shopper hands to a maker — an order, a delivery address, a message through the contact form — the maker is the controller and MakersKnot acts as their processor, handling that information to run the storefront on the maker’s behalf. A maker is responsible for how they use their own customers’ information, including any analytics or advertising tools they connect to their storefront. Makers who need a data processing agreement can request one at the address in the Contact section.

2. Information we collect

CategoryWhat we collectWhere it comes from
Maker accountName, email address, password (hashed), and — if you sign in with Google — the basic profile Google returnsYou, or Google at your direction
Shopper accountName, email address, password (hashed), saved delivery address. Optional — checkout works as a guestYou
Storefront contentShop name, craft type, product listings, pricing, inventory, shipping origin and rates, policies, social links, uploaded logos, favicons and product photosYou, or imported from Etsy at your direction
OrdersOrder contents, delivery address, phone number, order total, and payment status. Card and bank details go straight to the payment processor and never reach usThe shopper, at checkout
ShippingThe delivery address and phone used to quote a shipping rate, buy postage, and track the parcel. Purchased labels are PDFs showing the sender and recipient addressDerived from the order
Storefront messagesName, email address, subject, and message left through a storefront’s contact formThe sender
Billing (makers)Subscription status and payment history for your MakersKnot plan. Stripe holds the card detailsYou, and Stripe
Sign-in securityA device identifier derived from your browser’s user-agent, with the user-agent string and first and last seen dates, kept per account so we can alert you when a new device signs in. It is kept for the life of the account and deliberately outlives individual sessions. We also record the IP address and device on each sign-in, and the IP and date on each acceptance of these termsYour browser, at sign-in
Technical & logIP address, browser and device type, operating system, pages viewed, timestamps, error and security logs, referring pages. IP addresses are also counted to rate-limit abuse of sign-in and verificationAutomatically, as you use the service

Please do not submit sensitive personal information through MakersKnot. We do not collect or ask for sensitive personal information as California law defines it — government ID numbers, financial account numbers, precise geolocation, racial or ethnic origin, health, biometric, or sexual-orientation data — and we do not use or disclose any for the purpose of inferring characteristics about you. MakersKnot is not designed to store regulated medical, financial, or legal records.

3. Why we use it, and our legal basis

If you are in the UK or European Economic Area, the law requires us to name a legal basis for each purpose. These are ours:

PurposeLegal basis
Creating your account, generating and hosting your storefront, and providing supportPerformance of a contract
Taking a shopper’s order, quoting shipping, buying postage, tracking parcels, and passing the order to the maker who has to make and ship itPerformance of a contract
Billing a maker’s MakersKnot subscription and paying makers outPerformance of a contract
Sending transactional email — verification, password reset, order confirmations, receipts, new-device alertsPerformance of a contract
Keeping accounts secure: recognising devices, rate-limiting abuse, detecting and preventing fraudLegitimate interests — securing the service and its users
Troubleshooting, improving the platform, and improving the quality of our AI generationLegitimate interests — operating and improving the service
Running our marketing partner programme and enforcing our Terms of ServiceLegitimate interests — running the business fairly
Analytics and advertising cookies and pixels, and measuring our own advertisingConsent, where the law requires it
Keeping order, payment, and tax recordsLegal obligation

Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interests you can object — the Your rights section explains how.

4. Who else receives it

We use the providers below to operate, secure, and support MakersKnot. Each processes information only as needed to provide its service to us, under its own terms and privacy policy. This list is everything we have connected — where a provider only receives information because a maker has chosen to switch a feature on, we have said so.

  • MongoDB Atlas — the database everything above is stored in, encrypted at rest and in transit.
  • Hosting provider — runs the application. Not yet finalized; we will name it here once selected.
  • Cloudflare — two roles. Its edge network sits in front of makers’ custom domains and therefore sees storefront requests; and its object storage holds uploaded product photos, logos, and favicons, plus a separate private store for purchased shipping labels.
  • Stripe — bills a maker’s MakersKnot subscription, and, through Stripe Connect, takes payment on a maker’s storefront and pays the maker out.
  • PayPal — an alternative processor a maker can connect to take payment on their storefront. Whichever processor a maker connects receives the shopper’s payment details directly. MakersKnot never receives or stores full card or bank account numbers.
  • EasyPost — quotes live shipping rates, buys postage, and tracks parcels. It receives the recipient’s name, address, and phone number, and returns the label.
  • Anthropic — the AI provider behind storefront copy, product descriptions, SEO text, image alt text, craft-category detection, and spreadsheet column matching. Storefront information and uploaded content are sent for these purposes. We do not send payment card numbers or passwords to AI providers.
  • Google — optional sign-in for maker and shopper accounts; Google Analytics (see the Cookies, analytics & advertising section); Search Console, which receives storefront URLs so shops can be indexed; and Google Calendar, only where a maker connects a calendar.
  • Meta — the Meta Pixel and its server-side Conversions API, used to measure our own advertising. See the Selling and sharing and Cookies, analytics & advertising sections.
  • Resend and Brevo — send our transactional email. They receive the recipient’s address and the message.
  • Unsplash — supplies licensed stock photography makers can search and add to a storefront.
  • Etsy — where a maker connects their Etsy shop, imports their existing listings through Etsy’s own authorization.
  • NameSilo — registers and manages a custom domain where a maker buys or connects one. Domain registration requires registrant contact details.
  • Bing Webmaster Tools and IndexNow — receive storefront URLs so shops can be indexed.
  • Brave Search — receives shop details when we look up comparable shops to inform storefront generation.

We also disclose information where the law requires it, to enforce our terms, to protect our rights or someone’s safety, and to a buyer or successor if the business is sold — in which case this policy continues to apply until you are told otherwise.

5. Where your information goes

MakersKnot operates from the United States, and every provider in the Who else receives it section processes information there. If you are in the UK or European Economic Area, using MakersKnot means your information is transferred to the United States.

Those transfers are covered either by the provider’s certification under the EU–US Data Privacy Framework and its UK extension, or by the UK and European Commission’s Standard Contractual Clauses, together with the additional safeguards those clauses require. You can ask us which mechanism applies to a specific provider at the address in the Contact section.

6. Selling and sharing

We do not sell your personal information, and we never have. Nobody pays us for it.

We do “share” a limited amount of it, in the specific sense California law uses. There, “sharing” does not mean selling — it means letting a third party see what you did on our site so they can target advertising to you elsewhere. The Meta Pixel described in the Cookies, analytics & advertising section does that: it tells Meta which of our pages you viewed, and our Conversions API sends Meta a scrambled (one-way hashed) version of your email address so it can match a signup to an ad. Your actual email address is never sent. We share nothing else this way, and we do not share the contents of orders, storefront messages, or anything a shopper gives a maker.

The categories involved are online identifiers and browsing activity, plus a hashed email on conversion. The third parties are Meta and, where a maker has connected advertising tools of their own, whichever provider they chose.

How to stop it

  • Turn off advertising cookies in your browser, or use a tracker-blocking extension. This stops the Pixel loading.
  • Turn on Global Privacy Control in your browser. We read it on every page you request, and it switches the Meta Pixel off: ours, and any a maker has added to their own shop. If you create an account while it is on, we also never send the conversion event for that account, so no hashed email of yours reaches Meta.
  • If you already have an account, turn it off yourself under Studio → Account → Privacy. It takes effect the moment you check the box, for any future payment, and you can turn it back on the same way.
  • Adjust Meta’s ad preferences and Google’s ads settings on your own accounts.
  • Or email us at [email protected] with “Do Not Share” in the subject and we will action it.

We do not knowingly sell or share the personal information of anyone under 16.

We will not treat you differently for exercising any of this. Opting out does not change your price, your plan, or the service you get.

7. Cookies, analytics & advertising

Cookies we need

  • Session cookie — keeps you signed in. HttpOnly and Secure, and it lasts your session unless you chose to be remembered.
  • Preference cookies — remember settings such as a cart in progress.

These are required for the service to work and cannot be turned off without breaking it.

Analytics and advertising

On MakersKnot’s own pages we use Google Analytics to understand traffic, and the Meta Pixel with its server-side Conversions API to measure our advertising. Both may set cookies.

Our Google Analytics also runs on makers’ storefronts, so we can see traffic across the platform as a whole. Our Meta Pixel does not.

Makers can add their own tracking to their own storefront. A maker can save a Google Analytics measurement ID and a Meta Pixel ID in their settings, and when they do, those tags load for everyone who visits their shop and report to the maker’s own accounts. That is the maker’s decision and the maker’s data; we do not control what they do with it. If you are a maker and you switch these on, you are responsible for disclosing them to your own shoppers.

Global Privacy Control switches off every Pixel described here. It does not switch off analytics, because analytics reports to us about our own site rather than handing anyone your activity to advertise to you elsewhere; use your browser’s cookie controls or a tracker blocker for that. The ad-settings links in the Selling and sharing section cover what Meta and Google already hold.

8. How we use AI

MakersKnot uses AI to write and improve storefront text — shop copy, product descriptions, SEO text, image alt text — to detect which craft category a shop belongs to, to match spreadsheet columns when importing a catalogue, and to answer questions in the assistant on our marketing site. The provider is named in the Who else receives it section.

Everything AI produces here is a draft you can edit or discard. It writes marketing copy and organises a catalogue; it does not decide anything about you. We do not use AI to make automated decisions that produce legal or similarly significant effects — nothing about pricing, account approval, suspension, payouts, or eligibility is decided by a model. If that ever changes we will say so here before it does, and explain the logic and your right to a human review.

9. Security

We use industry-standard practices to protect your information:

  • HTTPS/TLS encryption for everything in transit, and encryption at rest in the database
  • Argon2id password hashing — we never store plain-text passwords, and cannot recover one for you
  • Signed session tokens with expiry and server-side revocation, so signing out ends a session immediately
  • Alerts when your account is used from a device we have not seen before
  • Automatic redaction of passwords, tokens, and card fields before anything is written to our logs
  • Rate limiting on sign-in, verification, and other sensitive endpoints
  • Access controls and periodic security review

No system is completely secure. If a breach affects your information we will notify you, and the relevant regulator, as the law requires — within 72 hours of becoming aware of it where the UK or EU GDPR applies.

10. How long we keep it

WhatHow long
Account and storefront contentWhile the account is open. On deletion, the storefront goes offline immediately and personal information is deleted within 30 days
Order, payment, and tax recordsKept after account deletion for as long as tax and accounting law requires — generally up to seven years
Copyright (DMCA) noticesKept indefinitely. A notice is evidence of the claim it makes, and the claimant’s name, address, phone, IP address, and user agent are part of that evidence; deleting any of it would undermine the record a dispute may later need
Terms of Service acceptance recordsKept indefinitely. The IP address, user agent, and timestamp are our proof of what was agreed to and when, which is what they are for
Sign-in sessionsUntil they expire or you sign out, whichever comes first
Recognised devicesThe life of the account
Abandoned checkouts14 days, then deleted automatically
Unfinished shops saved before signup7 days, then deleted automatically
Rate-limit countersAbout 2 days
Storefront messagesUntil the maker or we delete them
Error and security logsUp to 12 months
Anonymised usage statisticsIndefinitely — these no longer identify anyone

Information can survive these periods in encrypted backups until those cycle out, and in records we must keep for a legal claim, a dispute, or fraud prevention. Retained backup and log data is not used for any active purpose beyond security, fraud prevention, and legal compliance.

11. Children

MakersKnot is not intended for anyone under 18, and we do not knowingly collect personal information from children. We do not knowingly sell or share the personal information of anyone under 16. If you believe a child has given us personal information — by creating an account or by checking out as a guest on a storefront — contact us at the address in the Contact section and we will investigate and delete it.

12. Your rights

Depending on where you live, you have some or all of these rights:

  • Know and access — what we hold about you, where it came from, why we have it, and who received it, in a copy you can keep
  • Correct — fix anything inaccurate
  • Delete — have your account and personal information removed
  • Portability — get your storefront, catalogue, or order data in a machine-readable format
  • Restrict — have us pause processing while a dispute or an accuracy question is resolved
  • Object — to processing we base on legitimate interests, including direct marketing
  • Withdraw consent — at any time, where consent is what we relied on. This does not undo what was done beforehand
  • Opt out of sharing — see the Selling and sharing section
  • Non-discrimination — we will not degrade your service or change your price because you exercised a right

Email [email protected] to exercise any of them. We respond within 30 days, or 45 where California law allows an extension and we tell you why. You may use an authorised agent; we will ask for proof of their authority.

We may need to verify your identity first, and we may decline or limit a request where the law permits or requires it — for example where it would interfere with a legal obligation, an ongoing dispute, fraud prevention, or another person’s rights, including a maker’s own order and tax records. If we decline, we will tell you why.

If your information sits on a maker’s storefront, that maker is the controller of it and is the right first stop. Contact them through their shop, or tell us and we will pass the request on and help them action it.

You can also complain to a regulator. In the UK that is the Information Commissioner’s Office; in the EEA it is your national data protection authority; in California it is the California Privacy Protection Agency or the Attorney General. We would rather you came to us first, but you do not have to.

13. Do Not Track

Browsers vary in how they send “Do Not Track” signals and there is no agreed standard for honouring them, so we do not respond to Do Not Track. We do honour Global Privacy Control, which is the signal California law recognises; the Selling and sharing section says exactly what it turns off.

14. Changes to this policy

We update this policy as the product changes, and review it at least once a year. The date at the top of this page is the date of the current version, and it changes only when the policy does — that date is how you know whether anything has changed since you last read it. Continued use after a change takes effect constitutes acceptance.

15. Contact

For privacy questions, to exercise a right, or to request a data processing agreement:

[email protected]

[ENTITY LEGAL NAME]
[REGISTERED ADDRESS]

© 2026 MakersKnot. All rights reserved.

Terms of Service →Copyright →