Checkout, delivery and dispute handling on Stripe Connect Direct charges · seller is merchant of record

Legal

Privacy Policy

Last updated 7 September 2026

This describes what Faerra genuinely collects, who it goes to, and what you can make us do about it. Faerra is operated by Faerra LLC, a Delaware limited liability company, at 2810 N Church St, PMB 411821, Wilmington, DE 19802-4447. Questions and requests: privacy@faerra.com. Security problems: security@faerra.com.


Who holds what

There are two relationships here and they are not the same.

For sellers — the people with Faerra accounts — we decide what we collect and why. We are the controller.

For buyers — the people who purchase from a seller — the seller decides. They are the merchant of record; we process buyer data on their instructions to run the checkout, the delivery and the records. We are the processor, they are the controller. If you bought something and want your data removed, ask the seller you bought from; if you cannot reach them, ask us and we will help, and we will pass the request to them.

Where we are the processor, the seller's own privacy notice governs what happens to buyer data beyond what we do with it. We cannot answer for a seller's choices; we can tell you what we did.

One honest caveat: we set the retention periods below, we chose the providers below, and we decided that IP addresses are worth keeping as chargeback evidence. Those are our decisions, made once for every seller, and a regulator could reasonably call us a joint controller with sellers for that narrow set of choices rather than a pure processor. We have written this the way the relationship actually works rather than the way that is most convenient to claim.

What we collect from sellers

  • Your email address and password (stored hashed, never in readable form).
  • Your business name, store details and any custom domain you verify.
  • Your Stripe account identifier. We never see your bank details — Stripe does.
  • The products, prices and files you upload.
  • Credentials for integrations you connect, encrypted at rest and never shown back to you.
  • A record of significant actions on your account — refunds, deletions, settings changes — kept so that “who did that, and when” has an answer.
  • Technical logs from your use of the service: IP address, browser and device type, pages requested, timestamps, and errors.
  • Billing details for your Faerra plan, where your plan carries a subscription price. The card itself goes to Stripe, not to us.
  • Anything you send us in a support message.

What we collect about buyers

Collected on the seller's behalf, to complete and support the purchase:

  • Email address, and the billing address Stripe collects at checkout, which usually includes a name.
  • What was bought, for how much, in what currency, and its status.
  • The IP address the purchase was made from. Kept because it is the single strongest piece of evidence in a chargeback, where the alternative is the seller losing money to a claim they did not make.
  • Download records — time, IP address, browser, bytes transferred, and whether the download completed. This is what enforces per-file limits and what proves delivery when a purchase is disputed.
  • Licence key activations, where a seller sells licence keys.
  • A Discord user id, only if the buyer connects Discord to receive a role.
  • A copy of every email we send them, including its content, kept so a seller can answer “did they get it” and so a dispute can be evidenced.

We do not collect card numbers. Those go from the buyer's browser to Stripe and never touch our servers.

We do not knowingly collect special-category data — health, biometrics, religion, politics, union membership, sex life — and nothing in the product asks for it. If a seller puts it in a product field or a support message, that is the seller's doing, and they should stop.

Why, and on what legal basis

If you are in the EEA or the UK, the GDPR requires us to say which lawful basis each use rests on.

For seller data, where we are the controller:

What we doWhyBasis (GDPR Art. 6)
Run your account, host your products, deliver your purchasesTo provide the service you signed up forContract, Art. 6(1)(b)
Charge your plan, take our application feeSameContract, Art. 6(1)(b)
Account action logs, technical logs, and security measures generallyAccountability, and keeping accounts from being taken overLegitimate interests, Art. 6(1)(f)
Service and security emails to youTo operate the accountContract, Art. 6(1)(b)
Keep our own accounting and tax recordsTax and accounting lawLegal obligation, Art. 6(1)(c)
Marketing email to sellers, where we send itTo tell you about the productConsent, Art. 6(1)(a), withdrawable at any time

For buyer data, we are the processor. The lawful basis is the seller's to establish, not ours, and we process under Art. 28 on their instructions. Where a seller asks us what basis their own use most likely rests on, the honest answer for the transaction records is contract, and for the IP addresses and download logs kept as dispute evidence it is the seller's legitimate interest in not losing money to a claim they did not make, weighed against a buyer's limited expectation of privacy in the record of a purchase they chose to make. That is a view, not a determination we can make for them.

Where we rely on legitimate interests, you can object. Write to us and we will actually consider it rather than reciting the paragraph back at you.

Who else sees it

Our processors, and only for what they do:

  • Stripe — payments, payouts, tax calculation, disputes.
  • Microsoft — sending email, through the Graph API.
  • Discord — only where a seller delivers a Discord role, and only the buyer's Discord id and the server involved.

Those three are our complete set of sub-processors. We will give sellers notice before we add one.

Faerra runs on infrastructure we operate ourselves, in the central United States. There is no third-party hosting provider holding your database or your files, which means one fewer company with a copy of your data and one fewer contract between you and it. It also means the security below is ours to get right rather than a vendor's, and we would rather say that plainly than let a well-known logo do the reassuring.

Separately, and not as our processors: anything the seller connects — Zapier, Mailchimp, Kit, Flodesk, or their own webhook endpoint. If a seller switches one on, buyer email addresses and order details go there because the seller told us to send them. What happens next is governed by that service and by the seller, not by us, and we have no contract with it.

We will also disclose data where we are legally required to — a valid subpoena, court order, or law-enforcement demand we cannot lawfully refuse — and to our professional advisers under confidentiality. If we are legally allowed to tell you first, we will.

If we are ever acquired or merged, data moves with the business, and we will tell sellers before it does.

We do not sell data. We do not share it for cross-context behavioural advertising. We do not use buyer data to advertise anything. There is no advertising network and no third-party analytics vendor in the list above, and that is the whole list.

Where Faerra is offered, and where the data goes

Faerra is not currently offered in the European Economic Area or the United Kingdom. Sellers established there cannot open accounts, and the checkout does not accept buyers located there. We intend to open both markets once the representative appointments and transfer arrangements they require are in place. This policy will change before that happens, not after.

Everything else runs from the United States, on infrastructure we operate ourselves in the central US. If you are outside the United States, using Faerra means your data is processed here.

The GDPR material below — the legal bases, the rights, the response deadlines — stays in this policy for two reasons. We are building to that standard for when those markets open, and a geographic block is a control rather than a guarantee. Where any of it gives you more than the law where you live requires, take the more generous reading.

How long we keep it

  • Order records, download events and sent emails: while the seller's account is open, and afterwards for 7 years, because chargebacks arrive months after a sale, tax authorities look back years, and evidence deleted early is a case already lost. Where the same IP address appears both in an order or download record and in a technical log, the order record governs and the log copy is deleted on the log schedule.
  • Seller account data: while the account is open, then deleted within 14 days of closure, apart from what the line above requires us to keep.
  • Technical logs: 30 days.
  • Account action logs: 7 years.
  • Support messages: 5 years.
  • Backups: overwritten on a rolling 30-day cycle, so deleted data can persist in a backup for up to 30 days before it is gone.

A buyer's magic-link tokens are stored hashed and expire. Discord access tokens are used once, for the join, and never stored.

How we protect it

Passwords are hashed and never stored in readable form. Integration credentials are encrypted at rest and are never shown back to you, including to you. Traffic runs over TLS. Access to production data is limited to the people who need it and is logged. Product files are served through signed, expiring links rather than public URLs, so a product file cannot be reached by guessing an address.

No system is perfectly secure, and we are not going to claim otherwise. If we suffer a breach affecting seller data, we will notify affected sellers without undue delay and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware. If a breach affects buyer data, we are the processor: we will notify the affected sellers without undue delay so they can meet their own 72-hour obligation, and we will help them do it.

If you find a security problem, write to security@faerra.com.

Your rights

Depending on where you live, you may have the right to:

  • Know and access what we hold about you, and get a copy.
  • Correct anything inaccurate.
  • Delete it.
  • Take it elsewhere in a portable, machine-readable format.
  • Object to processing based on legitimate interests, or restrict it while a dispute is resolved.
  • Withdraw consent at any time, where consent is what we relied on. Withdrawing does not undo what was lawful before.
  • Not be discriminated against for exercising any of this.

Write to privacy@faerra.com. We will verify that the request comes from you — usually by asking you to send it from the account email, or by asking a buyer for the order details — and answer within 45 days, extendable once by a further 45 days where the law allows and we tell you why. If you are in the EEA or the UK, we will answer within one month, extendable by two further months for complex requests, and we will tell you inside the first month if we need the extension.

Some of it we cannot delete on request — a completed sale is a financial record, and removing it would break the seller's books and our tax obligations. We will say so rather than quietly ignore the request.

You can authorise an agent to make a request for you; we will ask for proof of that authority.

If you are in the EEA or the UK and you are not satisfied with how we handled it, you can complain to your local supervisory authority, or to the UK Information Commissioner's Office. We would rather you came to us first, but that is your right and not our permission to give.

If you are in California

The CCPA, as amended by the CPRA, requires some specific statements. Over the past 12 months we have collected these categories of personal information:

Category (Cal. Civ. Code 1798.140) What that is here Where it comes from Why Disclosed for a business purpose to
IdentifiersEmail address, IP address, account id, Stripe account id, Discord user idYou, or the buyer at checkoutRun accounts, deliver purchases, evidence disputesStripe, Microsoft, Discord
Customer records (1798.80)Billing address, and the name in it, from Stripe at checkoutStripeComplete the saleStripe
Commercial informationProducts bought, prices, order status, licence activationsGenerated by the transactionFulfil and record salesStripe
Internet or network activityDownload records, browser and device type, pages requested, error logsGenerated by your useEnforce limits, prove delivery, securityNobody. These stay on our own infrastructure.
Sensitive personal informationAccount log-in credentials — your email address in combination with your passwordYouTo let you sign in. Nothing else.Nobody.
InferencesNone. We do not build profiles.
Geolocation, biometrics, health, precise locationNone collected.

We use sensitive personal information only to authenticate you and secure your account — a use that falls within the exemptions in 1798.121(d), so no “Limit the Use of My Sensitive Personal Information” link is required, and there is nothing further to limit.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past 12 months — including of anyone under 16. There is therefore no “Do Not Sell or Share My Personal Information” mechanism, because there is nothing to opt out of.

Where a seller's own connected integration receives buyer data, that transfer happens on the seller's instruction. Whether it counts as a sale or share is the seller's question to answer under their own policy, not ours.

California residents have the rights listed in the section above — know, access, delete, correct, portability, non-discrimination — and may exercise them at privacy@faerra.com.

If you are in another US state

Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws give residents rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and profiling with legal effects. We do none of those three, so there is nothing to opt out of. Use privacy@faerra.com for the rest. Where a state gives you a right to appeal a refused request, tell us and we will review it and respond in writing within the period that state allows.

Children

Faerra accounts are for people 18 and over. We do not knowingly collect personal information from children under 13. Whether a seller's product is suitable for a younger buyer is the seller's responsibility, and a seller selling to children has obligations of their own under COPPA and its equivalents. If you believe a child has given us data, write to privacy@faerra.com and we will delete it.

Automated decisions

We do not make decisions about you by automated means alone that produce legal or similarly significant effects. No account is suspended or closed without a person deciding.

Cookies

CookiePurposeType
Seller sessionKeeps you signed in to your accountStrictly necessary
Order portal sessionKeeps a buyer's order-portal session openStrictly necessary
CSRF tokenProtects forms from cross-site request forgeryStrictly necessary

All of them are strictly necessary. There is no advertising, no third-party analytics, and no tracking across sites on Faerra, which is why there is no consent banner — there is nothing to consent to. If that changes, the banner arrives before the cookies do.

For sellers: your obligations, and the DPA

Where you sell through Faerra, you are the controller of your buyers' data and we are your processor. That means you need your own privacy notice for your buyers, and you need a lawful basis for what you do with their data after we hand it over — including anything you push into Mailchimp, Kit, Flodesk, Zapier or your own webhook. Section 3 of the Terms of Service makes that a contractual obligation, not just a suggestion.

If your own obligations require a data processing agreement with us, ask at privacy@faerra.com and we will provide one. Our sub-processors are the three named in “Who else sees it” above; the services you connect yourself are not sub-processors of ours, and you are responsible for the contracts with them.

Changes and contact

If this changes materially we will email sellers at least 30 days before it takes effect, and post the new version with a new date. Buyers are covered by the version in force when they bought.

Questions, requests and complaints: privacy@faerra.com, or Faerra LLC, 2810 N Church St, PMB 411821, Wilmington, DE 19802-4447.

See also the Terms of Service.