Last updated: July 26, 2026
This Privacy Policy explains how Caldik collects, uses, discloses, stores, and protects personal information when you use the Services or interact with us. It should be read with the Terms of Service, Cookies Policy, and Data Processing Agreement.
1. Who we are and scope#
Caldik, ABN 84916006495, is responsible for the personal information described in this Policy. This Policy applies to Caldik’s websites, accounts, dashboard, APIs, hosted storefront infrastructure, checkout tools, support, communications, and related services.
Merchants operating storefronts are independently responsible for their customer-facing privacy practices. Their privacy notices may also apply when you buy from or interact with a storefront.
2. Information we collect#
Information you provide#
-
Account and profile information, such as name, email address, authentication methods, organisation details, and preferences.
-
Store and business information, including business identity, domains, team members, products, customer-support details, and configuration.
-
Billing and transaction information, such as plan, invoices, transaction references, billing address, tax information, payment status, and limited payment-method details supplied by a payment provider. Caldik does not need to store full card numbers when tokenised or hosted payment methods are used.
-
Content and files submitted to the Services, including storefront source, media, digital product files, product information, support messages, and feedback.
-
AI feature information, including prompts, instructions, conversation context, selected account or storefront context, generated text, code, designs, recommendations, feedback, and safety or quality signals.
-
Verification, compliance, dispute, or security information where required to protect the Services, meet provider requirements, or comply with law.
Information collected automatically#
-
Device and network data, including IP address, user agent, browser, operating system, language, approximate region, and identifiers.
-
Usage and event data, including pages, feature interactions, API and webhook activity, build and deployment logs, timestamps, errors, referrals, and diagnostic records.
-
Storefront analytics data, including visits, page views, referral source, campaign information, device and browser category, approximate region, product and checkout interactions, conversion events, and aggregated sales or performance measurements.
-
Security information, including authentication events, session identifiers, risk signals, access history, and suspected abuse or fraud indicators.
-
Automated review information, including content classifications, similarity signals, risk scores, policy indicators, moderation outcomes, reviewer actions, and appeals.
-
Cookie and similar-technology data described in the Cookies Policy.
Information from others#
-
Information from merchants when they use Caldik to process customer orders, fulfil products, provide support, or operate a storefront.
-
Information from identity and integration providers such as Google, Discord, and GitHub when you choose to connect them.
-
Information from Storrik, payment processors, acquiring partners, banks, blockchain networks, fraud-prevention services, and transaction counterparties when payment features are used.
-
Information from team members, referral sources, public records, compliance providers, and service providers where permitted by law.
3. How we use information#
-
Provide, operate, personalise, maintain, and support the Services.
-
Create accounts, authenticate users, manage teams and permissions, and operate connected integrations.
-
Process subscriptions, orders, transactions, billing, invoices, refunds, payouts, reconciliation, and related support.
-
Build, host, deploy, deliver, and back up storefront content and digital products.
-
Monitor performance, diagnose errors, improve features, and understand aggregate usage.
-
Measure storefront traffic and performance and display analytics, trends, conversion information, and operational insights to the merchant that operates the relevant storefront.
-
Provide Ask AI, AI-assisted website building, generated content or code, recommendations, search, support, and other AI-assisted functions requested by the user.
-
Automatically screen storefronts, content, products, deployments, accounts, and activity for potential acceptable-use, fraud, security, and prohibited-business concerns, and prioritise matters for review.
-
Protect accounts, prevent fraud and abuse, investigate incidents, enforce policies, and preserve platform integrity.
-
Communicate about service, security, billing, policy, support, and, where permitted, product news or marketing.
-
Comply with legal obligations, lawful requests, provider rules, and dispute-resolution requirements.
-
Establish, exercise, or defend legal claims and complete corporate transactions.
4. Legal bases for processing#
Depending on where you are located and the activity involved, we process personal information to perform a contract, take requested pre-contract steps, comply with law, pursue legitimate interests, protect vital interests, or with consent. Legitimate interests include operating and securing the Services, preventing abuse, supporting users, improving products, and managing business operations. Where consent is the basis, it may be withdrawn, without affecting earlier lawful processing.
5. When we disclose information#
We may disclose personal information to:
-
Infrastructure, hosting, storage, content-delivery, monitoring, communications, support, analytics, security, and professional-service providers.
-
AI model, inference, moderation, evaluation, and related technology providers used to supply an enabled AI feature or assist with platform safety.
-
Storrik and payment-related providers to connect accounts, process payments, manage transaction risk, reconcile activity, provide support, and meet legal or provider requirements.
-
Identity and integration providers when you enable or use an integration.
-
A merchant whose storefront you use, or to a customer where necessary to operate a merchant’s requested service.
-
Authorities, courts, regulators, advisers, or other parties where reasonably necessary to comply with law, respond to lawful process, protect rights and safety, investigate fraud or abuse, or resolve disputes.
-
Parties to a merger, financing, acquisition, reorganisation, sale, or transfer, subject to appropriate confidentiality and privacy safeguards.
-
Other recipients when you direct us or provide valid consent.
We do not sell personal information for money. If a law defines “sale” or “sharing” more broadly, we will provide any choices required by that law.
6. Storefront visitors and merchant analytics#
When you visit a Caldik-hosted storefront, Caldik may collect technical, usage, and commerce-event data so the storefront can operate and so the merchant can understand how its storefront performs. Depending on the merchant’s settings, this may include page views, referral source, approximate region, device and browser category, product views, cart actions, checkout progress, completed-order events, and aggregated revenue or conversion measurements.
Caldik presents this information to the merchant through its dashboard. We may also use aggregated or de-identified storefront analytics to maintain the Services, detect abuse, plan capacity, calculate platform-wide performance benchmarks, and improve features. We do not provide one merchant with another merchant’s identifiable customer or storefront analytics.
Merchants can opt out of Caldik storefront analytics or disable available analytics collection from the Caldik dashboard. Disabling analytics may stop future optional analytics collection but does not remove operational logs, security events, transaction records, or historical information that must be retained for billing, fraud prevention, legal compliance, or system integrity.
A storefront visitor may be offered cookie or analytics controls when the merchant has enabled Caldik’s storefront consent interface or another compatible consent tool. Available choices depend on the merchant’s configuration, visitor location, and the technologies in use. Strictly necessary processing may continue even when optional analytics is rejected.
The merchant is responsible for deciding whether analytics is enabled, configuring consent for its target regions, providing legally required notices, and ensuring any third-party tracking it installs has an appropriate legal basis. Caldik’s own processing for account security, platform operation, billing, fraud prevention, and legal compliance is governed by this Policy.
7. Caldik, Storrik, and payment data#
A Storrik account link is not required for the supported Storrik Crypto flow. A merchant may configure the feature in Caldik by supplying an xpub, public key, or destination wallet address. If the merchant separately uses a Storrik account or dashboard, information entered there is handled by Storrik under its own terms and privacy notice.
Caldik crypto integrations are powered by Storrik and operate wallet-to-wallet. Depending on the transaction, data may include an xpub or public key, derived or supplied wallet addresses, asset, amount, network, transaction identifiers, confirmations, timestamps, exchange-rate references, and order references. Neither Caldik nor Storrik receives or stores the merchant’s private key or recovery phrase through the standard flow.
Caldik and Storrik use public blockchain and transaction information to create payment instructions, monitor for matching transfers, update order state, prevent abuse, provide support, and reconcile technical events. Blockchain records are public or shared across network participants and may be immutable. Do not include unnecessary personal information in blockchain transaction fields.
Caldik and Storrik do not require platform identity verification for the standard non-custodial wallet-to-wallet feature. Information or verification may still be requested where required by law, sanctions obligations, security, fraud prevention, a supported network, or a separately enabled regulated service.
If you link Caldik and Storrik for another feature, information may move from either service to the other. This may include account identifiers, business details, contact information, connection status, transaction references, risk or compliance status, and support information needed to operate the linked services.
Card-processing providers may separately collect identity, business, payment, and verification information under their own privacy notices. Caldik receives only the information reasonably needed to operate and support the relevant feature.
8. Artificial intelligence and automated review#
Caldik uses AI to provide Ask AI in the dashboard, assist with website building, generate or transform content and code, make recommendations, improve search and support, and automate parts of acceptable-use and platform-safety review.
When you use an AI feature, Caldik may send the prompt, instructions, selected storefront or account context, attachments, and relevant conversation history to the model or provider needed to answer the request. Do not submit secrets, private keys, payment credentials, highly sensitive personal information, or content you are not authorised to use.
Caldik may use automated systems to identify content or activity that could violate the Acceptable Use Policy or Prohibited Businesses Policy. Signals may result in no action, a warning, additional checks, temporary technical limits, or referral to a human reviewer. Caldik does not intentionally use AI as the sole basis for a final decision that produces a material adverse account effect where human review is reasonably available or required by law.
You may request review of a material enforcement decision through support@caldik.com. AI output and risk indicators are probabilistic and may be wrong. Reviewers may consider additional context, merchant evidence, prior activity, security information, legal obligations, and provider requirements.
Unless a feature notice says otherwise, Caldik does not use merchant prompts, private storefront content, customer personal information, or AI outputs to train a general-purpose model for unrelated customers. We may use de-identified, aggregated, or permissioned feedback and safety data to evaluate and improve the Services.
9. EU data storage and international access#
All Caldik production data and customer data stored by Caldik is stored on infrastructure located in the European Union. Backups, databases, object storage, logs, and retained AI feature records controlled by Caldik are stored in the European Union.
Caldik requires subprocessors that persist covered service data on Caldik’s behalf to use European Union storage unless a merchant expressly enables a feature whose notice states a different location. Public blockchain records are distributed by the relevant network and are not stored exclusively or controlled by Caldik.
Authorised personnel and providers may remotely access or transiently process information from Australia, the European Union and European Economic Area, the United Kingdom, the United States, and other locations where support, security, AI, payment, or professional operations are performed. Remote access does not change the stated location of Caldik’s stored production data.
Privacy protections may differ between countries. Where required, we use contractual, organisational, and technical safeguards for international transfers and take reasonable steps regarding overseas recipients. A current non-public list of material providers and their processing locations may be requested by emailing support@caldik.com.
10. Security#
We use administrative, technical, and physical safeguards designed for the nature of the information and risks involved. Measures may include encryption in transit, encryption or hashing for selected stored information, access controls, network segmentation, audit logging, backups, monitoring, and incident response.
Some Caldik account modes may encrypt selected fields using credentials or recovery material controlled by the user. If Caldik does not possess the required recovery secret, we may be unable to restore that information. No system is completely secure, and you remain responsible for protecting credentials, devices, recovery phrases, and API secrets.
11. Retention#
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, backups, tax and accounting, disputes, fraud prevention, and legal obligations. Retention differs by record type, plan, account status, and applicable law.
When information is no longer required, we take reasonable steps to delete, de-identify, or isolate it, subject to backup cycles and legal holds. Public blockchain records cannot be deleted by Caldik.
Typical retention considerations include:
-
Account and subscription records for the life of the account and a reasonable period afterward.
-
Transaction, tax, invoice, refund, payout, and dispute records for the period required by financial, tax, anti-fraud, and legal obligations.
-
Security, access, API, build, deployment, and diagnostic logs for periods proportionate to security, troubleshooting, abuse prevention, and operational needs.
-
Storefront analytics for the period made available in the merchant’s plan or dashboard, followed by deletion, aggregation, or de-identification where appropriate.
-
Support and legal correspondence for as long as needed to resolve the matter and establish a record of the outcome.
-
Backups until they are overwritten or expire under ordinary backup cycles.
12. Your choices and rights#
Depending on applicable law, you may request access to, correction of, deletion of, restriction of, objection to, or portability of personal information, and may withdraw consent or complain about handling. Some information can be managed in account settings.
We may need to verify identity and authority before acting. Rights may be limited where an exception applies, another person’s rights would be affected, or retention is legally required. If Caldik processes storefront data only on a merchant’s instructions, we may refer your request to that merchant.
Merchants may change storefront analytics settings through the dashboard. Storefront visitors may use any controls displayed by the storefront and may also use browser privacy or cookie controls. These choices do not prevent processing that is strictly necessary to provide a requested transaction, secure the Services, prevent fraud, or comply with law.
13. De-identified and aggregated information#
We may create statistical, aggregated, or de-identified information that is not reasonably capable of identifying an individual. We may use and disclose that information for analytics, benchmarking, research, security, capacity planning, reporting, and service improvement. We do not attempt to re-identify information that has been properly de-identified unless needed to test or improve the de-identification method and permitted by law.
14. Marketing and communications#
You may opt out of marketing using the unsubscribe method in the message or account settings. We may still send transactional, operational, billing, security, and legal messages required for the Services.
15. Children#
The Services are intended for adults and businesses and are not directed to children. We do not knowingly permit a person under 18, or under the applicable age of legal majority, to operate a Caldik merchant account. If you believe a child has provided personal information contrary to this section, contact us.
16. Data incidents#
We maintain processes to assess and respond to suspected data incidents. Where required by applicable law, we will notify affected individuals and regulators of an eligible or reportable breach.
17. Complaints#
Send privacy requests or complaints to support@caldik.com. Include enough information to identify the issue and the account or interaction involved. We will investigate and respond within a reasonable period. If you are dissatisfied, you may have the right to contact the Office of the Australian Information Commissioner or another competent privacy authority.
18. Changes to this Policy#
We may update this Policy as the Services, providers, or law change. We will post the new version and update the date above. We will provide additional notice for material changes where reasonably practicable or legally required.
19. Contact#
Privacy contact: support@caldik.com.