LemonStandSign in

Privacy Policy

Last updated 11 August 2026

This Privacy Policy explains how LemonStand (“we”, “us”) handles personal data when you use our marketing site, seller dashboard, or a storefront hosted on LemonStand. It is written for users in Singapore and is intended to align with the Personal Data Protection Act 2012 (PDPA).

Who we are

LemonStand. LemonStand provides software that lets sellers run PayNow-ready storefronts. Sellers control their own catalogue, pricing, and order handling.

Important:When you buy from a LemonStand storefront, you are buying from that seller — not from LemonStand. The seller decides how to use your order details for fulfilment, refunds, and support. LemonStand processes buyer order data on the seller's behalf to operate the platform.

Data we collect

Sellers (account holders)

  • Account: name and email from Google sign-in, user ID, and session tokens managed by Supabase Auth.
  • Store: store name, slug, vibe/theme, product catalogue, fulfilment settings, and PayNow proxy details you enter.
  • Billing: Stripe customer ID, subscription ID, plan, subscription status, and current billing period end. Card details are held by Stripe only — LemonStand does not store card numbers.
  • Push alerts (optional): browser push subscription endpoints if you enable seller notifications.

Buyers (storefront visitors)

  • Checkout: name, mobile number, email, delivery address (if required), order notes, cart contents, and fulfilment choices.
  • Orders: order reference, line items, totals, payment status, and order status updates visible on the public order page.

Buyers do not create LemonStand accounts. There is no buyer login.

Technical data

  • IP address, browser/device type, and request logs — used for security, rate limiting, and reliability (via Cloudflare and our application logs).
  • Cookies and local storage:Supabase auth cookies (sellers only); an optional short-lived cookie when a store owner previews their storefront; and browser local storage for your cart and fulfilment choices on a seller's storefront. We do not use analytics or advertising cookies.

Internal staff and sales previews

LemonStand staff who use the internal Admin console sign in with Google. We store staff email, role, and activity related to prospect stores, showcase demos, and sales preview links. Prospect business contact details entered in Admin are used for sales follow-up only.

How we use data

  • Provide, maintain, and improve the LemonStand service
  • Create, display, and manage orders for sellers and buyers
  • Generate PayNow QR codes with the amount and reference shown on the order page
  • Bill sellers for LemonStand subscriptions via Stripe
  • Send optional push alerts to sellers who enable them
  • Prevent abuse, secure accounts, and troubleshoot issues

We do not sell personal data. We do not use buyer data for LemonStand marketing unless a separate consent is obtained (we do not do this today).

PayNow payments

PayNow is a bank-to-bank transfer. LemonStand generates a QR code locally using EMVCo standards and the seller's PayNow proxy details. LemonStand does not receive, hold, or process buyer payment funds. Banks involved in PayNow are not LemonStand subprocessors — they have their own privacy terms.

Who we share data with

  • Sellers: receive buyer order details for stores they operate.
  • Subprocessors that help us run the platform:
    • SupabaseAuthentication, database, and image storage. Privacy policy
    • CloudflareApplication hosting, CDN, and security (including IP-based rate limiting). Privacy policy
    • StripeSeller subscription billing only (not buyer PayNow payments). Privacy policy
    • GoogleSign-in via Google OAuth (email and basic profile for authentication). Privacy policy
  • Web Push delivery (when sellers enable alerts): push endpoints may be delivered via:
  • Legal requirements: we may disclose information if required by law or to protect rights, safety, and security.

International transfers

Our infrastructure providers (including Supabase and Cloudflare) may store or process personal data in Singapore and in other countries where they operate. Where data is transferred overseas, we rely on appropriate safeguards offered by our providers and applicable law.

Retention and deletion

  • Seller accounts: kept while your account and store are active. LemonStand does not currently offer self-service Google account deletion — contact us to request account removal.
  • Close shop: sellers can close their shop from Settings. After closure, store data enters a 30-day grace period, then is permanently deleted (including products, orders, and the store slug). Cancel your Stripe subscription separately before closing if billing is active.
  • Completed orders: retained while the store is active to support fulfilment records. Purged when the store is permanently deleted after the grace period.
  • Abandoned checkout UI: unpaid orders may be hidden from seller dashboards after about 7 days but are not automatically deleted from the database until store purge.
  • Buyer requests: buyers should contact the seller for order-specific requests (refunds, corrections). For platform questions, contact us below.

Security

We use industry-standard safeguards including encrypted transport (HTTPS), access controls, and hosted infrastructure with reputable providers. No method of transmission or storage is perfectly secure.

Your rights (PDPA)

Subject to applicable law, you may request access to, correction of, or withdrawal of consent for your personal data. Some requests may be limited where we need to retain data for legal or operational reasons (for example, active orders or billing records).

We have not formally appointed a Data Protection Officer. For privacy enquiries or to exercise your rights, contact us at support@lemonstand.net.

Children

LemonStand is not directed at children under 13. Do not use the service if you are under 13.

Changes

We may update this Policy. The “Last updated” date on this page will change when we do. Continued use after an update means you accept the revised Policy.

Contact

Privacy questions: support@lemonstand.net · General support: support@lemonstand.net

← Back to LemonStand