Privacy Policy
Effective June 7, 2026
Palms Studio ("Palms Studio", "we", "us") operates a software platform that lets small businesses — flower shops, candle makers, gift boutiques, and other independent merchants — run their online storefronts, accept orders, manage deliveries, and communicate with customers. This Privacy Policy explains how we collect, use, and share personal information when you use our website, applications, or services (collectively, the "Service").
We act in two different roles: (a) as a controllerof personal information for the merchants who sign up to use Palms Studio ("Tenants"), and (b) as a processorof personal information that customers provide to those Tenants through storefronts we host. When you place an order on a Tenant’s storefront, the Tenant decides why your data is collected and how it is used; we process it on their behalf in accordance with our agreement with them.
1. Information We Collect
From Tenants and Tenant Staff
- Account information — name, email address, password, business name, business type (florist, candle maker, gift shop, etc.), business address, phone number.
- Payment account information — Stripe Connect account identifiers and onboarding status. We never see or store the bank account or full card details that a Tenant connects through Stripe.
- Configuration data — shop settings, products, pricing, hours, delivery zones, staff roster.
- Usage data — pages visited within the dashboard, actions taken, device and browser metadata.
From Customers of Tenants
- Contact information — name, email address, phone number, delivery address, gift recipient details.
- Order information — products ordered, delivery instructions, card messages, fulfillment dates.
- Payment information — collected directly by Stripe; we receive only a tokenized reference and the order total, never the card number or CVC.
- Communications preferences — whether you opted in to receive SMS updates about an order.
- Account information (if you sign in) — if you choose to create a customer account on a Tenant’s storefront, we store the email you signed in with and a session token. We do not store passwords (customer sign-in uses one-time magic links).
From Visitors to palmstudio.app
On our marketing website we collect standard server logs (IP address, user-agent, referrer, timestamp) and we may set first-party cookies to remember preferences and measure anonymous traffic patterns. We do not use third-party advertising cookies.
2. How We Use Information
- To provide the Service — process orders, route deliveries, send confirmations.
- To communicate with Tenants about their account, billing, support requests, and Service updates.
- To send transactional notifications (email and, with opt-in, SMS) to customers about the orders they place — see our SMS Terms.
- To prevent fraud, abuse, and security incidents.
- To comply with legal obligations and respond to lawful requests.
- To improve the Service through aggregate analytics. We do not sell personal information.
3. How We Share Information
With Tenants
When you place an order on a Tenant’s storefront, the Tenant receives the information needed to fulfill it (your name, contact details, delivery address, order contents, and any messages you included). The Tenant is the controller of that information once it reaches them and is responsible for how they use it.
With Service Providers
We rely on a small set of vetted vendors to operate the Service:
- Stripe, Inc. — payment processing and Stripe Connect for paying Tenants.
- Supabase, Inc. — database, authentication, and file storage.
- Vercel, Inc. — application hosting and content delivery.
- Resend — transactional email delivery.
- Twilio, Inc. — SMS delivery for opt-in transactional messages.
Each provider is bound by a data-processing agreement and may only use the information we share to perform the service they provide to us.
For Legal Reasons
We may disclose information to comply with a subpoena, court order, legal process, or government request, to enforce our agreements, or to protect the rights, property, and safety of Palms Studio, our Tenants, our Tenants’ customers, or the public.
In a Business Transfer
If Palms Studio is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of the transaction. We will notify Tenants and customers of material changes through our website or by direct communication before such a transfer.
4. Data Retention
We retain Tenant account data for as long as the account is active and for a reasonable period afterward to comply with tax, accounting, and legal obligations. Customer order data is retained for as long as the placing Tenant remains active on the Service, after which it may be deleted or anonymized. You can request deletion of your personal information at any time (see "Your Rights" below).
5. Your Rights
Depending on your jurisdiction, you may have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information.
- Withdraw consent for processing you previously consented to, including SMS opt-in.
- Object to or restrict certain processing.
- Receive a copy of your information in a portable format.
- Lodge a complaint with your local data protection authority.
Requests about information held on behalf of a Tenant should be directed to that Tenant first; we will assist them in responding. Requests about information we control directly can be sent to privacy@palmstudio.app.
6. Security
We use industry-standard safeguards — encryption in transit (TLS), encryption at rest, access controls, audit logging, and least-privilege provisioning — to protect personal information. No security system is perfect; if we learn of a breach that affects your information we will notify you in accordance with applicable law.
7. Cookies and Tracking
We use first-party cookies for essential functionality (authentication, cart state) and for limited analytics. We do not use third-party advertising or cross-site tracking cookies. You can disable cookies in your browser; some features of the Service may not work without them.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, please contact us and we will delete it.
9. International Users
The Service is operated from and primarily directed at the United States. If you access it from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Effective" date at the top of this page and, where appropriate, provide additional notice (such as an email to Tenants).
11. Contact
Questions about this Privacy Policy or our data practices can be sent to privacy@palmstudio.app.