This policy explains how Cornerstone Rock Holdings handles personal information on the Hangerline platform — for boutique owners and staff (“Merchants”), and for the shoppers whose records merchants keep (“Merchant Customers”).
1. What we collect
From merchants
- Account data — your name, work email, boutique name, and a salted hash of your password (we never store the password itself).
- Business content — products, inventory counts and adjustment history, gift cards, loyalty members, staff records and settings you enter.
- Operational logs — an audit trail of significant account actions (imports, exports, integration changes) kept for your own accountability view, and integration activity logs.
- Usage analytics — first-party, cookieless event counts (page and feature usage with a short-lived session hint). No advertising trackers, no third-party analytics scripts.
About merchant customers
Merchants may store customer names, email addresses, phone numbers, loyalty balances and gift-card records. For that data the merchant is the controller and Cornerstone Rock Holdings is a processor acting on the merchant's instructions — see the Data Processing Terms.
2. What we deliberately never collect
- Card numbers. Stripe Terminal readers encrypt card data at tap or dip; it flows to Stripe, never to Hangerline servers.
- Identity documents, Social Security numbers, ownership details. Business verification happens inside Stripe's embedded onboarding components and goes directly to Stripe.
- Bank credentials. Payout accounts are added through Stripe's secure components — never on a Hangerline form.
- Third-party API secrets in the clear. Keys you paste for optional connections are stored server-side, shown back to you only masked (last four characters), and never echoed in full.
3. How we use information
- Operating the service you signed up for — nothing here is sold, rented, or used for advertising.
- Support: answering the messages you send us.
- Security: session management, abuse prevention and audit logging.
- Service communications about your account or material policy changes.
4. Where data lives
Application data is stored in Cloudflare D1 (SQLite) and served from Cloudflare's global edge network. The full processor list, and what each processor sees, is published openly on the Sub-processors page.
5. When data leaves the platform
- Stripe — payment, verification and payout data, under your own Stripe agreement.
- Connections you elect — if you connect Klaviyo, customer email addresses you choose to sync are sent to your Klaviyo account; if you connect Shippo, shipment addresses and parcel details are sent to your Shippo account; if you connect Twilio, recipient phone numbers and message text are sent to your Twilio account. Disconnecting stops all further sending.
- Legal process — if validly compelled, and with notice to you where lawful.
- We do not sell personal information and have not done so.
6. Cookies
One first-party session cookie, described plainly in the Cookie Policy. No advertising or cross-site tracking cookies.
7. Retention and deletion
Account and business data is retained while your account is active. On verified request to we delete your account data within 30 days, except records we must keep for legal, security or accounting reasons — which are retained only as long as required.
8. Your rights
You may access, correct, export or delete your data, and merchant customers may direct requests about their records to the boutique that holds them (we assist that merchant as processor). U.S. state privacy laws may grant additional rights; we honor verified requests regardless of state.