Privacy Policy
Last updated: 5 October 2026
2 Minute Store (2minutestore.com, “we”, “us”) is a platform that lets businesses in Pakistan create and run their own online store. This policy explains what information we collect, why, who we share it with, how long we keep it, and how you can have it deleted. It applies to the 2minutestore.com website, every store hosted on the platform, and the store owners’ admin panels.
1. Who this policy is about
- Store owners — businesses and their staff who sign up and run a store on 2 Minute Store.
- Shoppers — people who visit or buy from a store hosted on 2 Minute Store. Each store owner decides how they use their shoppers’ information; we process it on the store owner’s behalf to run the store.
2. Information we collect
From store owners
- Account and business details: name, business name, email, phone number, address, login credentials (passwords are stored only as secure hashes).
- Store content: products, prices, photos, settings, pages, banners and other content the owner adds.
- Plan and payment records: the plan chosen and payment confirmations submitted for manual approval. We do not store card numbers.
From shoppers (on behalf of the store)
- Order details: name, phone number, email (if given), delivery address, items ordered and payment method chosen.
- Optional account details if the shopper registers with a store, product reviews and review photos they choose to submit.
- Saved items (wishlist) and cart contents are kept in the shopper’s own browser.
Automatically
- Basic technical data needed to deliver and protect the service, such as IP address, browser type and pages requested (server and security logs).
- A session identifier stored in the browser to keep the shopping cart working.
- If a store owner adds their own Meta Pixel, TikTok Pixel or Google Analytics code to their store, those services collect data under the store owner’s account and the provider’s own policies.
3. Facebook and Instagram (Meta) data
Store owners can choose to connect their Facebook Page and the Instagram professional account linked to it, so they can publish product posts from their 2 Minute Store admin panel. This happens only when the store owner clicks “Connect Facebook & Instagram” and approves access in Facebook’s own login window.
When a store owner connects, we receive and store only:
- The ID and name of the Facebook Page they choose, and an access token for that Page.
- The ID and username of the Instagram professional account linked to that Page (if any).
- The IDs of posts the store owner publishes through 2 Minute Store, so the admin panel can show what was posted.
We use this data only to:
- show the store owner which Page and Instagram account are connected;
- publish the product posts that the store owner creates and approves (a picture and caption) to that Page and Instagram account, at the moment the owner presses “Post”.
We do not read private messages, friends lists or personal profile information; we do not post anything without the store owner’s action; we do not use Meta data for advertising, profiling or selling; and we do not share it with anyone except as needed to call Meta’s own APIs.
Permissions requested from Meta and why: pages_show_list (list the Pages you manage so you can choose one), pages_read_engagement(read basic Page details needed to publish), pages_manage_posts (publish your product posts to your Page), instagram_basic(read your linked Instagram account’s ID and username), instagram_content_publish (publish your product posts to Instagram).
4. TikTok and Google
Stores can give Google Merchant Center, Meta Commerce Manager or TikTok Catalog a public product-list link (product names, prices, photos and stock) so those services can show the store’s products. This list contains product information only — never shopper or account data. If a store owner connects TikTok, we ask TikTok for user.info.basic (the account name and picture, to show which account is connected) and video.upload (to send a video the owner made in our Ad Maker to their TikTok drafts when they press “Send to TikTok drafts”). We store only the TikTok account identifier, name, picture and the access tokens needed for this, and use them only for that purpose. The owner finishes and publishes the video in the TikTok app; we never post publicly on their behalf.
5. How we use information
- To create, host and operate stores, process orders and show order status to shoppers.
- To send service messages: order confirmations and alerts, review requests, password resets and account notices.
- To provide features the store owner turns on, such as product feeds, social posting and AI writing help.
- To keep the platform secure, prevent abuse and fix problems.
We do not sell personal information, and we do not use shoppers’ information for our own advertising.
6. Service providers we share data with
We use trusted providers that process data only to run the platform for us:
- Supabase (database and file storage, Singapore region), Render (application servers), Vercel (website hosting) and Cloudflare (network and security).
- Resend (sending emails).
- Anthropic (AI writing help): when a store owner asks for an AI-written caption, description or design suggestion, the relevant product or store details are sent to generate the text. Shopper data is not sent.
- Meta, Google and TikTok — only when the store owner connects or uses those services as described above.
- Courier companies — delivery details of an order, only when the store owner books a delivery.
We may also disclose information when required by law or to protect the rights and safety of users and the platform.
7. How long we keep data
- Facebook, Instagram and TikTok connection data: until the store owner disconnects (which deletes the stored tokens immediately), removes our app from their Facebook or TikTok settings, or closes their store.
- Store, order and account data: while the store is active, and afterwards for as long as needed for legal, tax and dispute purposes, then deleted.
- Server logs: kept for a limited period for security and troubleshooting.
8. Your choices and data deletion
- Store owners can disconnect Facebook, Instagram or TikTok at any time in their admin panel; the stored access tokens are deleted at once.
- You can ask us to access, correct or delete your information by emailing [email protected]. We reply within 30 days.
- Shoppers should contact the store they bought from; we will help the store owner handle the request.
- Full steps: Data deletion instructions.
9. Security
Data is sent over encrypted connections (HTTPS), stored with a provider that encrypts data at rest, and access is limited to what each part of the service needs. Passwords are stored as one-way hashes. No method of storage or transmission is completely secure, but we work to protect your information and to fix problems quickly.
10. Children
The platform is for businesses. It is not directed at children under 13, and we do not knowingly collect their information.
11. Changes
We may update this policy. The date at the top shows the latest version; important changes are announced on the platform.
Contact us
2 Minute Store
480-FF, Citi Housing, Gujranwala, Pakistan, Pakistan
Email: [email protected]
Phone / WhatsApp: +92 322 4786 225