Ellich legal
Privacy Notice
This Notice explains how Ellich collects, uses, discloses, retains, and protects personal information when it acts for its own account. A merchant may separately control guest, employee, and customer data entered into Ellich.
Effective and last updated: July 27, 2026
1. Roles and scope
Ellich acts as a business/controller for account registration, billing, security, product analytics, and direct communications. For store guest, employee, loyalty, order, and similar records submitted by a merchant, the merchant generally controls the purpose and Ellich processes the information for that merchant under the Data Processing Addendum. Contact the merchant first for requests concerning its records.
2. Information we collect
- Account and business details, including names, emails, phone numbers, roles, addresses, and verification data.
- Subscription, invoice, transaction, refund, chargeback, and payment-provider identifiers. Ellich does not intend to store raw card numbers.
- Orders, menus, products, inventory, staff operations, customer profiles, consent records, websites, and support content submitted through the service.
- Device, browser, network, IP-derived, log, security, authentication, crash, print, and diagnostic data.
- Communications, support requests, feedback, and optional marketing preferences.
3. How we use information
- Provide, secure, support, troubleshoot, and improve the service.
- Create accounts, provision tenants, process subscriptions, and operate integrations.
- Detect fraud, abuse, outages, unauthorized access, and payment or device risk.
- Comply with law, respond to valid legal process, and enforce agreements.
- Send transactional communications and, when chosen, product or marketing email.
- Produce aggregated or de-identified statistics that do not reasonably identify an individual.
4. How we disclose information
We disclose information to the merchant account that controls it; authorized users; infrastructure, security, support, payment, email/SMS, analytics, domain, delivery, and integration providers; professional advisers; authorities when legally required; and parties to a corporate transaction subject to appropriate safeguards. We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless a specific feature and legally required choice are presented.
5. Payment and connected services
Ellich currently uses Stripe for supported card processing, connected-account onboarding, identity and business verification, fraud and risk review, disputes, and payouts. When a merchant enables those services, Ellich may provide Stripe with business, representative, beneficial-owner, bank, device, transaction, refund, dispute, and related account information. Stripe also receives and processes information submitted directly through the embedded payment setup and payment interfaces.
Stripe processes this information under the Stripe Privacy Policy. Other connected services may independently collect and use information under their own notices. Enabling an integration directs Ellich to exchange the information necessary to operate it. Merchants should review and configure each provider's privacy, retention, and consent settings.
6. Retention
We retain information for as long as reasonably necessary to provide the service, maintain financial and audit records, resolve disputes, enforce agreements, meet legal obligations, and protect security. Retention varies by data type and merchant configuration. Backup and fraud-prevention records may remain for a limited period after deletion from active systems.
7. Security
We use access controls, encryption where appropriate, tenant scoping, logging, and operational safeguards designed for the sensitivity of the information. No system can guarantee absolute security. Account owners must protect credentials, devices, local networks, printer access, and staff permissions.
8. Choices and rights
Depending on location and relationship, individuals may have rights to access, correct, delete, obtain, or restrict certain information; object to or opt out of certain processing; and appeal a decision. We may verify identity and authority before responding. Authorized agents may be required to provide proof of authority. Marketing email can be stopped through its unsubscribe link. SMS consent can be revoked through supported reply keywords such as STOP or another reasonable method stated in the message.
9. Cookies and similar technology
Ellich uses cookies and local storage required for authentication, security, tenant routing, preferences, and reliable application operation. If non-essential analytics or advertising technologies are introduced where consent is required, an appropriate choice mechanism will be presented before they are activated. See the Cookie and Local Storage Notice for categories, provider use, duration, and browser controls.
10. Children
Ellich business accounts are not directed to children under 13, and we do not knowingly create business accounts for them. Merchants are responsible for ensuring that guest-facing programs involving minors comply with applicable law.
11. International processing
Information may be processed in the United States and other locations used by service providers. Where required, Ellich uses contractual or other recognized safeguards for cross-border transfers.
12. Updates and contact
We may update this Notice and will change the date above. Material changes will be communicated when required. Privacy requests and questions may be sent to privacy@ellich.com. Account and merchant-controlled requests should identify the relevant store or organization.