Privacy policy
Last updated: September 23, 2026
This policy explains what Checkout Page does with personal data. Checkout Page is operated by Checkout Page Technologies, Inc., 8 The Green #21601, Dover, DE 19901, United States. You can reach us at support@checkoutpage.com, or at security@checkoutpage.com for anything about data protection.
The two roles we play
For sellers and visitors, we are the controller. When you create an account, pay for a plan, contact support or browse this website, we decide what data we collect and why. That processing is what this policy covers.
For your buyers, we are a processor. When someone buys through your checkout, we handle their data on your instructions, not our own. You decide what to collect and what to tell them, and our Data Processing Addendum governs that work. If you bought something through a Checkout Page checkout and want to know what happens to your data, ask the business you bought from. They can reach us if they need help answering.
What we collect about you
What you give us. Your name and email address, your password or the Google account you sign in with, your store settings and branding, your billing details, and whatever you write to us in a support conversation.
What we collect as you use the product. The pages you open in the dashboard and the features you use, your IP address, browser and device, and error reports when something breaks.
What we get from elsewhere. When you connect Stripe, we receive your business profile and account status from them. When you connect an integration, we receive what that service sends us. We do not buy personal data.
Why we use it, and on what basis
- To run the service you signed up for. Creating your account, showing your dashboard, sending your orders and running your checkouts. Legal basis: performance of our contract with you.
- To bill you and keep the records a business has to keep. Legal basis: contract, and our legal obligations.
- To support you, including looking into a problem you report. Legal basis: contract, and our legitimate interest in running a service people can get help with.
- To keep the service safe, to spot fraud and abuse, and to fix errors. Legal basis: our legitimate interest in a service that works and is not abused.
- To improve the product by measuring which features get used. Legal basis: our legitimate interest in building the right things.
- To send you product and marketing email. Legal basis: your consent where it is required, otherwise our legitimate interest in telling customers about the product they use. Every message has an unsubscribe link.
Cookies, analytics and advertising
Some cookies are needed to keep you signed in and to keep checkouts working. The rest come from three kinds of tool, all of which record page views, IP address and device details:
- Analytics, to understand how the product and this website are used: Google Analytics, PostHog and Mixpanel. Legal basis: our legitimate interest in improving what we build.
- Advertising and conversion measurement, to see which ads bring people here and to reach visitors again elsewhere: Google Ads, Meta Pixel and LinkedIn Insight Tag. These providers may combine what they receive with the data they already hold about you. Legal basis: your consent where it is required, otherwise our legitimate interest in advertising the product.
- Affiliate attribution, to credit the partner who referred you: Rewardful. Legal basis: our legitimate interest in running a referral programme.
You can clear or block cookies in your browser, opt out of Google Analytics with their browser add-on, and adjust ad settings with Google, Meta and LinkedIn directly. Blocking the essential cookies will break signing in and checkout.
We do not run session replay on checkout pages. In the seller dashboard, replay masks all text and input fields.
Who else sees it
We use other companies to run Checkout Page, such as hosting, email delivery, error monitoring, analytics and support tools. Each one is listed on our subprocessors page, with what it does, where it runs and what data it sees. They may only use the data to provide their service to us.
We also share personal data when:
- you tell us to, for example by connecting an integration;
- the law requires it, or we need it to establish or defend a legal claim, or to protect someone's safety;
- our business is sold or merged, in which case the buyer takes on this policy for the data they receive.
We do not sell personal data.
Where it is stored
Our application and database run in the United States, and some of the services we use store data in the EU or globally. The subprocessors page names the location for each one.
For the data this policy covers, we are the exporter. Where a provider processes it outside the EEA, the UK or Switzerland in a country without an adequacy decision, our agreement with that provider includes the European Commission's Standard Contractual Clauses, with the UK Addendum or the Swiss adaptations where they apply. Email security@checkoutpage.com if you want to see the safeguards that cover a particular provider.
Transfers of your buyers' data, where you are the exporter and we are your processor, are covered separately by our Data Processing Addendum.
How long we keep it
- Your account data stays while your account is open. When you delete a store, we delete its data within 30 days. When you close your account, we delete or anonymise what is left, apart from records we have to keep, such as invoices for tax.
- Backups expire within 3 months, so a copy can survive in a backup for that long after deletion.
- Web server logs are kept for about 30 days.
- Support conversations stay while your account is open, so we can see the history of a problem, and go when the account closes. We keep one longer only if it relates to a dispute that is still open.
- Analytics and advertising data is kept for different periods by each tool. Website analytics events go after 2 months and the visitor record after 14 months. Session recordings of the dashboard go after 30 days. Product analytics events go after 5 years, and the profile they belong to stays until we delete it.
Your rights
Under the GDPR, the UK GDPR and Swiss law you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent, you can withdraw it at any time.
Much of this is in your own hands: you can edit your account, export your data and delete a store from the dashboard. For anything else, email security@checkoutpage.com and we will answer within one month.
If you think we have got it wrong, you can complain to your data protection authority. In Finland that is the Office of the Data Protection Ombudsman, and each EU country, the UK and Switzerland have their own.
How we protect it
Card details never reach our servers, data is encrypted in transit and at rest in our database and file storage, and access to production systems is limited to the people who need it. Our security page explains this in full, including what happens if there is a breach.
Children
Checkout Page accounts are for businesses, so we do not knowingly collect a child's data for our own purposes.
Sellers sometimes do, for example when a parent registers a child for a class. The seller decides what to ask for and is responsible for any consent needed, and we only process it for them. Contact the business you booked with if you have a question about their data.
Changes to this policy
When we change this policy, we update the date at the top. If a change matters to you, for example a new purpose for using your data, we will tell you by email or in the product before it takes effect.