Last updated: February 8, 2026
This Privacy Policy describes how Aeolian CMS ("Aeolian," "we," "us," or "our") collects, uses, stores, and protects personal information through the Aeolian CMS platform ("Platform"), including the application hosted at admin.aeoliancms.com and all associated services.
The Platform operates as a multi-tenant e-commerce and content management system. This policy covers data practices for both Merchants (store operators) and Customers (end users of Merchant storefronts).
By using the Platform, you consent to the data practices described in this policy.
We act as a data controller for information we collect directly from Merchants, including account information, store configurations, and usage data.
We act as a data processor for Customer data that Merchants collect through their storefronts. Merchants are the data controllers for their Customer data and are responsible for lawful collection and processing.
Merchants are responsible for publishing their own privacy policies on their storefronts, obtaining necessary consents from Customers, and complying with all applicable data protection laws for the data they collect.
When you create an account, we collect the following through our third-party authentication provider:
When you create and configure stores, we collect:
We store content you create on the Platform, including:
When Customers interact with Merchant storefronts, the following data may be collected and stored on the Platform:
Full payment card details (card numbers, CVV, expiration dates) are never stored on our servers. Payment processing is handled entirely by PCI-DSS compliant third-party payment processors. We store only:
When Merchants invite team members, we collect:
We use the information we collect for the following purposes:
Data is stored on secure, professionally managed cloud infrastructure. We use industry-standard security practices including:
Each store on the Platform operates as an isolated tenant. Data belonging to one store is not accessible to other stores. Access controls ensure that only authorized users with appropriate permissions can access store data.
Uploaded files (images, videos, audio) are stored on third-party cloud object storage. Files are validated for type, size, and content before storage. We do not scan uploaded files for content beyond format validation.
We retain your data for as long as your account is active or as needed to provide services. Store data is retained while the store exists on the Platform, including deactivated stores (to allow reactivation).
When you delete content (products, pages, customers, etc.), the data is removed from our active databases. Some data may persist in backups for a limited retention period.
Upon account closure, we retain certain data as required by law (e.g., transaction records for tax and accounting purposes) or for legitimate business interests (e.g., fraud prevention). All other data is deleted within a reasonable timeframe.
Certain operations (such as changes to store variables and configurations) are logged with timestamps and user identifiers for audit purposes. These logs are retained for the lifetime of the store.
Depending on your jurisdiction, you may have the following rights regarding your personal information:
You have the right to request a copy of the personal information we hold about you.
You have the right to request correction of inaccurate personal information. You can update most information directly through the Platform.
You have the right to request deletion of your personal information, subject to legal retention requirements. Merchants can delete Customer data through the Platform's management tools.
You have the right to receive your data in a structured, commonly used format. The Platform provides export tools for products, content, and configuration data.
You have the right to object to processing of your personal information in certain circumstances.
You have the right to request restriction of processing of your personal information in certain circumstances.
To exercise any of these rights, please contact us at the email address provided below. We will respond to your request within the timeframe required by applicable law (typically 30 days).
If you are a Customer of a Merchant store and wish to exercise your rights regarding data collected by that Merchant, please contact the Merchant directly. Merchants are the data controllers for Customer data collected through their storefronts.
Your data may be processed and stored in countries other than your country of residence. Where personal information is transferred outside of Australia, we take reasonable steps to ensure that the overseas recipient handles your information in accordance with the Australian Privacy Principles (APPs) and applicable data protection laws, including through standard contractual clauses or other approved transfer mechanisms.
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us and we will take steps to remove such information.
In the event of a data breach that is likely to result in serious harm to affected individuals, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). Where applicable, we will also notify relevant authorities in other jurisdictions as required by law.
Notification will include the nature of the breach, the data affected, and steps taken to address the breach.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform with a revised "Last updated" date. Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy.
Aeolian CMS is an Australian entity and complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Under the APPs:
For complaints or inquiries regarding your privacy, please contact us at the email address below. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
If you are located in the European Economic Area, our legal bases for processing your personal information include:
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal. You also have the right to lodge a complaint with your local data protection authority.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
support@aeoliancms.com