Privacy notice
Last updated: 1 October 2026
anyshop collects only what it needs to run the waitlist and seller accounts on anyshop.io, and to deliver what buyers purchase from the stores on it: your email, a hashed network fingerprint for security, what you add to your store, and what you buy. We do not sell data, show ads, or use analytics or tracking cookies.
Who we are
Anyshop LLC, 1603 Capitol Avenue, Suite 413, #4213, Cheyenne, WY 82001, United States, runs anyshop.io and decides how the data described here is used. For anything about your data, write to support@anyshop.io. A person reads every message, and we answer within one month.
This notice covers the anyshop.io website, the waitlist, seller accounts, and buying from a store on anyshop. Each store is run by an independent seller, who is responsible for their buyers' data; the section When you buy from a store on anyshop, below, explains what that means.
What we collect
We never store your IP address itself: where we need to recognise repeat requests, we keep a keyed hash of it that cannot be turned back into the address.
| Data | When we get it | Why | Legal basis | How long we keep it |
|---|---|---|---|---|
| Your email address | You join the waitlist | To invite you to the beta. That is the only email we send from the waitlist | Your consent, which you can withdraw at any time | Until you create an account or ask us to delete it, at most 24 months |
| Hashed network fingerprint | You join the waitlist or sign in | To stop automated sign-ups and password-guessing attacks | Our legitimate interest in keeping the service secure | At most 30 days, except in the security log below |
| Account details: email, sign-in sessions (device and browser type, hashed network fingerprint), passkey public keys, and your two-factor secret and backup codes, stored encrypted | You create a seller account | To let you sign in and to protect your account | Our contract with you | While your account is open. Sessions end when you sign out or after 7 days |
| Store details: store name, address, category, and everything you add to your store | You set up and run a store | To run your store | Our contract with you | While your account is open, then deleted within 30 days of closing it, except records the law requires us to keep |
| Security log: account actions such as sign-in changes and new API keys, with a hashed network fingerprint | You use the dashboard | To keep a record for security and for resolving disputes | Our legitimate interest | 24 months |
| Abuse reports: what you report about a store, and your email if you choose to give it | You use Report this store | To investigate and act on the report, and to reply to you. The seller never sees it | Our legitimate interest in keeping stores safe | The report: 24 months after we close it. Your email: deleted when we close the report; only a keyed hash of it stays, to spot repeated reports |
| Server logs: technical details of each request | Every visit | To run the site and fix problems | Our legitimate interest | Up to 30 days, at our hosting provider |
We do not sell your data, share it for advertising, or combine it with data from other sources. anyshop is for businesses and adults, and we do not knowingly collect data from anyone under 16.
Who helps us
Three providers process data on our behalf, under written agreements that let them use it only to provide their service to us.
| Provider | What they do for us | Where the data is |
|---|---|---|
| Vercel Inc. | Hosts the website and runs our servers | Our servers run in Frankfurt, Germany. Requests pass through Vercel's global network. Vercel is based in the United States |
| Neon | Runs our database | Frankfurt, Germany |
| Resend | Sends sign-in, waitlist and order emails | Sent from Ireland. Resend is based in the United States |
Anyshop LLC is a United States company. If you are in the EU or the UK, the GDPR or the UK GDPR still applies to how we handle your data, and our servers, database and email sending all run in the EU. Our fonts and scripts are served from anyshop.io itself, so visiting the site sends nothing to any other company.
Cookies
We only use cookies that the service cannot work without, so we do not ask for consent to them. There are no analytics, advertising or tracking cookies, and the waitlist page sets none at all.
| Cookie | What it does | How long it lasts |
|---|---|---|
| anyshop.session_token | Keeps you signed in to your seller account | Until you sign out, at most 7 days |
| anyshop.two_factor | Holds a sign-in while you enter your two-factor code | 10 minutes |
| anyshop.better-auth-passkey | Holds a passkey sign-in while your device confirms it | 5 minutes |
| anyshop.store | Remembers which of your stores the dashboard shows | 1 year |
| __Secure-anyshop_order | Keeps your order open on the device where you opened its link | Up to 24 hours |
| __Secure-anyshop_orders | Keeps a Find my order list open | 15 minutes |
| __Secure-anyshop_download | Lets one download start after you choose it | 2 minutes |
When you buy from a store on anyshop
Each store is run by an independent seller, who is responsible for your data as the seller of what you buy. anyshop handles it on the seller's behalf to run the checkout and deliver your purchase, and uses it for nothing else.
| Data | Why | How long it is kept |
|---|---|---|
| Your email address | To send your purchase, receipt and order link | Paid orders: 3 years from the order date, or 30 days after the store closes if that is sooner. Checkouts that were never paid: 30 days. A checkout the buyer already sent a crypto payment for (to the seller's wallet, or through NOWPayments) is kept like a paid order: 3 years |
| What you bought, the keys and files delivered, and when you opened them | To deliver your purchase, let you find it again, and sort out problems | With the order |
| License keys and their device activations | So the software you bought can check its license, and its device limit keeps working | As long as the store exists (without the buyer's details after 3 years) |
| Country and device type | To spot fraud and to support the seller if a payment is disputed | With the order |
| Your IP address, stored encrypted | Only as evidence if a payment is disputed, when it goes to the payment provider with the seller's answer | 120 days, then deleted |
| Blocklist matches: if a seller or anyshop blocks an email, email domain, network or country after fraud or abuse, we keep a keyed hash of it, never the email or IP address itself | To stop fraud and abuse at checkout, including across stores when anyshop confirms fraud | Until the block is removed |
| Once-per-email coupons: if you used a coupon a store allows once per email, a keyed hash of your email (never the address itself) | So the same email cannot use that coupon again | As long as the coupon exists |
| Order messages to the seller's own systems (webhooks): your email and what you bought | Only when the seller connects their own server, so it can deliver or record your purchase | Our copy: 30 days, so a failed send can be retried, then deleted |
| Details a seller brings from another platform: your email, name, licenses and devices, and marketing consent with its date | So the seller can keep serving you after moving their store to anyshop. Only a consent you already gave comes over; an import never subscribes you | Until the seller deletes it, or 30 days after the store closes |
Your payment details go to the payment provider you choose, such as PayPal, NOWPayments or the seller's own crypto wallet, under that provider's privacy notice; anyshop never sees your card or account details. NOWPayments receives the coins for the seller and holds them until it pays the seller; we send it only the order's price, a short description of what you bought and our reference for the payment, never your email or IP address. If you pay with crypto and have not paid within 10 minutes, we email you a link to your payment page once, so you can pay from another device. Opening the link to your order sets a cookie that keeps your order open on that device, listed under Cookies above. Data that is deleted can remain in our encrypted backups for up to 30 days.
To use your rights over an order, contact the seller through the link on your order page, or write to support@anyshop.io and we pass your request to the seller within 5 working days.
Your rights
Email support@anyshop.io from the address you used with us, and we will act within one month, free of charge. You can ask us to:
- show you the data we hold about you, and give you a copy in a portable format
- correct anything that is wrong
- delete your data, including removing you from the waitlist
- stop or limit how we use it, or object to a use based on our legitimate interest
- withdraw your consent, which does not affect what we did before you withdrew it
If you are unhappy with how we handled your data, you can complain to the data protection authority in the country where you live or work.
Changes to this notice
When we change how we use data, we update this page and the date at the top. If you are on the waitlist or have an account, we email you before a change that affects you takes effect.