Trust & Compliance
How we source, process, and protect ecommerce store data — and how you can control your information.
1. Data Sourcing Methodology
StoreCensus indexes publicly accessible ecommerce storefronts on Shopify and WooCommerce. Our crawler reads only information that is publicly visible to any web browser — store name, installed apps (detected via storefront signatures), theme, product count, and publicly listed contact information.
We do not access private store data, Shopify admin APIs, or any data behind authentication. Revenue estimates are heuristic approximations derived from publicly observable signals (traffic estimates, product count, pricing) and are clearly labeled as estimates throughout the platform.
For a detailed technical breakdown of our methodology, see our Data Methodology page.
2. GDPR & CCPA Stance
StoreCensus processes publicly available business contact information (store owner names, business email addresses, and phone numbers listed on public storefronts). Under GDPR, we rely on legitimate interests as our lawful basis for processing this data, as it relates to business-to-business commercial activity.
Under the California Consumer Privacy Act (CCPA), StoreCensus operates as a data broker. California residents may request deletion of their personal information using the opt-out process described below.
StoreCensus does not sell personal data of EU or UK data subjects to third parties without appropriate safeguards. Our platform users are responsible for ensuring their own use of exported data complies with applicable privacy laws.
3. Opt-Out & Data Removal
If you are a store owner and would like your store removed from the StoreCensus index, you can submit a removal request using our dedicated form:
Submit a data removal request →
We process removal requests within 30 days. Once processed, your store will be excluded from search results and future data exports. Existing exports already delivered to customers cannot be recalled, but your store will not appear in any new exports after removal.
4. Data Processing Agreement (DPA)
Enterprise and bulk data license customers who require a Data Processing Agreement (DPA) under GDPR Article 28 can request one by contacting our data team.
Our standard DPA covers:
- Subject matter and duration of processing
- Nature and purpose of processing
- Type of personal data and categories of data subjects
- Obligations and rights of the controller
- Sub-processor list and notification obligations
To request a DPA, contact us via the data licensing contact form.
5. Security
StoreCensus uses industry-standard security practices including encryption in transit (TLS 1.2+), encrypted storage for sensitive fields, and role-based access controls. We do not store payment card data — all billing is handled by Stripe.
Questions or concerns?
For privacy-related inquiries, data removal requests, or DPA requests, contact us at privacy@storecensus.com