Information we collect
Account data can include names, work email addresses, company details, roles and security/audit information. Connected-channel data can include orders, refunds, taxes, shipping, discounts, payment methods, customer/contact details and source references needed to create accounting records. Xero connection data includes OAuth tokens, selected tenant details, chart-of-account information, tax rates, mappings, export references and responses.
Billing data includes the ClearCommerce plan, price, tax, billing dates, invoices, payment attempts and Stripe identifiers. ClearCommerce does not store full card numbers or card security codes; Stripe handles card entry and returns limited details such as card brand, expiry and last four digits. Website enquiries and technical logs may include the information supplied, source page, referral URL, campaign parameters, IP address and browser user agent.
How we use it
- To provide multi-tenant accounts and isolate each company’s data.
- To import ecommerce records, apply configured accounting treatment and export to Xero.
- To prevent duplicate exports, run retries, maintain sync history and investigate errors.
- To manage ClearCommerce subscriptions, invoices, renewals, payment failures and access.
- To send account, security, billing and service emails and respond to enquiries.
- To protect the service from abuse and meet legal, tax and record-keeping obligations.
Payment and email providers
Stripe processes card payments and stores payment credentials for future authorised charges. Brevo provides transactional email delivery. These providers receive only the information needed for their role and process it under their own security and privacy terms.
Security and retention
Store API credentials and Xero refresh tokens are intended to be encrypted, secrets are kept out of application logs, and tenant access is restricted. Records are retained for the period needed to provide the service, maintain accounting/audit history, resolve disputes and meet legal obligations. Subscription suspension does not automatically delete accounting history.
Lawful basis
Information is processed to take steps before entering a contract, perform the ClearCommerce service contract, meet legal obligations and pursue legitimate interests such as security, support, product reliability and fraud prevention. Optional marketing relies on consent where required.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw marketing consent. Some accounting, payment, security or audit records may need to be retained where law or legitimate claims require it.
Contact
Email privacy questions to info@clearcommerce.co.uk. Please do not include passwords, API keys, full card details or other secrets.
Last updated: 23 June 2026.
