Privacy Policy
Last Revised: July 27, 2026
1. Introduction
Welcome to aiministores.com (the “Website”). The Website and all AI Mini Stores products and services (collectively, the “Services”) are controlled and operated by AICommerce Group - FZCO (“we,” “us,” or “our”). We know how much people value their privacy online, and this Privacy Policy explains how we handle the personal information collected through this Website.
Please review this Privacy Policy before using the Website or submitting any personal information. By using the Website, you accept the practices described here. We may update these practices from time to time; any changes will be posted on this page, and we encourage you to review this Policy on each visit so you always understand how information you provide will be used. If you are a California resident, please also read the “California Residents” section below, which describes additional rights available to you.
2. Information We Collect
A. Information You Provide Directly
You can browse and use much of the Services without identifying yourself. To use certain features, however, you may be asked to supply Personal Information — for example when you create an account, publish content, make a purchase, or complete an online form. Depending on the feature, this may include:
- Personal details, such as your name and country of residence;
- Contact information, such as your email address and mailing address;
- Account details, such as your username, unique user ID, and password;
- Payment information, such as credit card or bank details; and
- Certain mobile-device features, such as contacts, calendar, or photo gallery, where you enable them.
You may choose not to provide Personal Information, but some features of the Services may then be unavailable to you. If you are unsure which information is required, you are welcome to contact us.
B. Information from Other Sources
We may also obtain Personal Information about you from sources other than the Services, including public databases, social media platforms, third-party data providers, and our joint marketing partners. Information from these sources may include demographic details (such as age and gender), device information (such as IP address), location (such as city and state), and online behavioral data (such as social media activity, page views, and search results and links).
C. Non-Personally Identifiable Information
We collect various kinds of non-identifying and aggregated information to improve your experience, measure site activity, and plan improvements. For example, we may use session and persistent cookies, session logs, web beacons, GIF/pixel tags, banner ads, third-party analytics tools (such as Google Analytics), third-party retargeting networks that show you our ads on other websites, and third-party networks that deliver user-requested emails (such as refer-a-friend messages).
To maintain service quality and analyze product performance, we may also gather connection data — including the timing and size of packets sent over the Internet during a session — used solely to ensure the best possible experience with our products.
We continuously improve our websites and products using third-party web analytics tools. We want to know how visitors use our websites, tools, and applications — what they like and dislike, and where they run into problems. Our products and applications use analytics to understand feature-usage patterns, enhance your experience, and offer usage tips and guidance. In the course of normal business operations, this usage data may be linked to personal information we hold about individual users. We own this data and do not share individual-level usage data with third parties.
We may also run voluntary surveys collecting demographic information, used on an aggregate basis for internal market research, presentations to advertisers, and joint product-development research with outside companies. This helps us focus our products and personalize the services offered to each user.
3. How We Use Your Information
We need to collect and use certain Personal Information in order to make the Services available to you or to meet a legal obligation; if you do not provide requested information, we may be unable to deliver the requested products or services. Information we collect may be used to:
- Create and manage user accounts;
- Fulfill and manage orders and deliver products or services;
- Improve our products, services, and user experience;
- Send administrative information;
- Send marketing and promotional communications;
- Respond to inquiries and provide support;
- Request user feedback;
- Post customer testimonials (with consent);
- Deliver targeted advertising;
- Administer prize draws and competitions;
- Enforce our terms, conditions, and policies;
- Protect against abuse and malicious users;
- Respond to legal requests and prevent harm; and
- Run and operate the Services generally.
4. Legal Bases for Processing
How we process your Personal Information depends on how you interact with the Services, where you are located, and which of the following applies: (i) you have consented to processing for one or more specific purposes (note that this basis does not apply where processing is governed by the California Consumer Privacy Act or European data protection law); (ii) processing is necessary to perform an agreement with you or to take pre-contractual steps; (iii) processing is necessary to comply with a legal obligation; (iv) processing relates to a task carried out in the public interest or under official authority vested in us; or (v) processing is necessary for legitimate interests pursued by us or a third party.
Under some laws we may process personal information until you object (by opting out), without relying on consent or another legal basis. We are always happy to clarify which legal basis applies to a given processing activity, including whether providing Personal Information is a statutory or contractual requirement or necessary to enter into a contract.
In accordance with the General Data Protection Regulation (GDPR), we process personal data only where a lawful purpose exists — including consent, performance of a contract, compliance with a legal obligation, or our legitimate business interests. Where sensitive personal data is processed, additional conditions are met. Within that framework, we use your personal information to: deliver products and services you request; validate compliance with our terms and conditions; improve content and gather feedback; contact you when necessary about your use of the Website or our products; and handle the limited sharing situations described in Section 6.
5. Communications
By submitting your email address on this Website, you agree to receive email from us. You can leave any of our email lists at any time using the opt-out link or unsubscribe option included in each message. We only email people who have authorized contact — directly or through a third party — and we do not send unsolicited commercial email. By submitting your email address, you also permit us to use it for custom-audience targeting on platforms such as Facebook, where we show tailored advertising to people who have opted in to hear from us.
Telephone
By submitting your telephone contact information on this Website and/or registering for a product or service offered here, you agree that this act constitutes a purchase, an inquiry, and/or an application for purposes of the Amended Telemarketing Sales Rule (ATSR), 16 CFR § 310 et seq., and applicable state and local “do not call” regulations, and we retain the right to contact you by telephone in accordance with the ATSR and applicable state rules. We adhere to TCPA guidelines and provide clear ways to manage your communication preferences, including opting out of further communications.
Credit Pre-Qualification
By providing your contact information, you also provide written instruction authorizing AICommerce Group - FZCO and its affiliates to obtain your personal credit profile or related information from credit reporting agencies under the FCRA, solely to perform a credit pre-qualification using only your name, phone number, and email. This is a soft inquiry and will not affect your credit score in any way. Where applicable, any credit-related inquiry made in connection with our services is a soft pull only.
6. When We Share Information
Partners. We occasionally provide services or sell products jointly with other businesses. For these co-branded offerings, where a third party participates in your transaction, we may share or jointly collect related customer information with that third party. The co-branded registration page will identify who is collecting or receiving the information and whose privacy statement governs, so you know at signup exactly how your information will be used. If you registered through a partnership and opt out of promotional updates, we will also pass your email address to that partner — as required by the CAN-SPAM Act — so they can stop sending messages on our behalf.
Affiliated entities. We may share or jointly collect information with our parent entity and its wholly owned subsidiaries and affiliated divisions. This helps us make your customer experience more seamless — improving marketing targeting, streamlining processes, and consolidating backend systems.
Business transfers. If we are ever sold to or acquired by a third party, your information would transfer as part of the business being sold.
Testimonials. With your consent, we may post your testimonial together with your name. To update or remove a testimonial, contact us using the details in the “Contacting Us” section.
7. Cookies, Analytics, and Online Tracking
Cookies are small text files stored by your browser that remember your preferences and let us enhance your experience on the Website. Third-party retargeting networks may also use cookies to display our advertisements to you on other sites; you can learn how to opt out of a third-party vendor's cookies at the Network Advertising Initiative opt-out page.
Emails and newsletters we send may use web beacons or pixel tags to gather delivery metrics that improve the reading experience — such as open counts, whether a message was forwarded or printed, the device type used, and the general location (city, state, county) associated with the IP address.
Our site includes social media features (sometimes called an “Open ID”), such as Facebook and Twitter buttons. These features may collect your IP address and the page you are visiting, and may set a cookie so the feature functions properly. They can also authenticate your identity and offer to share certain personal information with us — such as your name and email — to pre-fill our signup form, and may let you post your activity on our website to your profile. Your interactions with these features are governed by the privacy policy of the company providing them. We may track aggregate data such as the number of visits using an Open ID, items “liked” on this Website, or items shared to third-party social sites.
Other parties — such as advertising partners and analytics companies — may collect information about your online activity across different websites over time, including identifiers used to tailor the ads served to your device. Because there is not yet a common standard for interpreting browser-based “Do Not Track” signals beyond cookies, we do not currently respond to undefined “Do Not Track” signals.
Most browsers can be configured to refuse cookies. Be aware, however, that disabling cookies may prevent access to some functions or services on our Website or on the web-hosted software that runs on it.
8. AI Mini Stores Suite — TikTok Application
This Privacy Policy also covers the “AI Mini Stores Suite” TikTok application (the “App”). When you connect your TikTok account through the App, we may access your basic profile information and publish advertising campaigns on your behalf. We access only the permissions you explicitly authorize (user info, video upload, and video publish). We do not access your TikTok analytics or ad-account data, and we do not sell your TikTok account data to third parties.
9. Third Parties We Link To
We do not control, and are not responsible for, the actions of third parties we may promote or link to from this Website. We take pride in recommending quality companies, but we have no control over their conduct, the content they provide, or their privacy practices. While we are not liable for their actions, we welcome your feedback about your experiences with any third party we work with, so we can improve our service to all customers.
10. Children's Privacy
We do not knowingly collect personally identifiable information from anyone under 18 years of age. If your minor child has provided us with such information, contact us using the details in the “Contacting Us” section and we will make reasonable efforts to remove your child's information from our records.
11. IP Addresses
We may use your IP address to help prevent fraud, diagnose problems with our servers, gather broad demographic information, and offer you products and services.
12. Data Security
All information collected from you is stored in a technically and physically secure environment. Employees, contractors, and vendors who access personally identifiable information while providing services for us are required to keep it confidential. We use SSL encryption to protect sensitive information online and take every reasonable measure to protect user information offline as well. That said, no Internet transmission can be guaranteed 100% secure — so while we work hard to protect your information, we cannot ensure or warrant the security of information you transmit to us, and you do so at your own risk.
13. Reviewing and Updating Your Information
To review or change your personal information, visit your account profile page, where you can access and update the personal information and account history we have on file. If you need help reviewing or updating your information, email us at support@aiministores.com; we will respond to review requests within 30 days.
14. California Residents
If you live in California, the California Civil Code gives you the right to ask companies doing business in California for a list of all third parties to which they disclosed Personal Information for direct marketing purposes during the preceding year. Alternatively, if a company's privacy policy offers an opt-out (“unsubscribe”) or opt-in choice for third-party use of your Personal Information for marketing, the company may instead tell you how to exercise that choice.
This Website qualifies for the alternative: we maintain a comprehensive Privacy Policy and explain how you may opt out of (or in to) third-party use of your Personal Information for direct marketing. We are therefore not required to keep or disclose a list of third parties that received Personal Information for marketing purposes in the preceding year.
If you are a California resident and want information about exercising your third-party disclosure choices, email our Privacy Administrator at support@aiministores.com, indicating whether you prefer our response by email or postal mail. Requests must include “Your California Privacy Rights” in the subject line and clearly within the request itself, along with your name, street address, city, state, and zip code (the zip code is for our recordkeeping). We do not accept these requests by telephone, postal mail, or fax, and we are not responsible for requests that are mislabeled, sent improperly, or incomplete.
15. Changes to This Policy
We may modify this Privacy Policy at any time, but we will give prominent advance notice of any material change — for example by posting a notice through the Services or on our websites, or by emailing you — so you can review the change and decide whether to continue using the Services.
16. Severability
If any part of this Privacy Policy is held invalid or unenforceable, that part will be construed consistently with applicable law to reflect the parties' original intent as closely as possible, and the remainder will stay in full force and effect.
17. Contacting Us
If you have questions about this Privacy Policy or our practices, email us at support@aiministores.com. We aim to pair excellent products with equally excellent customer service.
AICommerce Group - FZCO
IFZA Business Park, 56411-001, Dubai Digital Park
Dubai Silicon Oasis, Dubai, United Arab Emirates
Data Protection Addendum (GDPR)
Addendum last updated: July 27, 2026
The EU General Data Protection Regulation (GDPR) governs how organizations doing business with individuals or entities located in European Union nations — including AICommerce Group - FZCO — must collect, handle, and store personal information. These rules apply whether data is stored electronically, on paper, or otherwise. To comply, personal information must be collected and used fairly, stored safely, and not disclosed unlawfully.
The GDPR rests on core principles requiring that personal data be: processed fairly and lawfully; obtained only for specific, lawful purposes; adequate, relevant, and not excessive; accurate and kept up to date; held no longer than necessary; processed in accordance with data subjects' rights; protected appropriately; and not transferred outside the European Economic Area (EEA) unless the destination ensures an adequate level of protection.
This Data Protection Addendum (the “Addendum”) is entered into between AICommerce Group - FZCO (operating as AI Mini Stores, “AI Mini Stores”) and the customer agreeing to it (the “Customer”). It takes effect on the Addendum Effective Date (defined below) and replaces any previously applicable data protection addendum.
If you accept this Addendum on behalf of the Customer or an affiliate, you represent and warrant that you have read and understood it, that you have full legal authority to bind yourself or the applicable entity, and that you agree to it on behalf of the party you represent. If you lack that authority, do not sign, accept, or opt in.
A. Purpose
This Addendum sets out the terms that apply to AI Mini Stores' processing of the Customer's Personal Data under the privacy arrangements executed between AI Mini Stores and the Customer (the “Agreement”).
B. Definitions
Terms defined by the GDPR:
- “Addendum Effective Date” — the date the Customer clicked to accept or opt in to this Addendum.
- “Adequate Country” — a country deemed adequate by the European Commission under Article 25(6) of Directive 95/46/EC or Article 45 of the GDPR.
- “Data Subject” — the identified or identifiable person who is the subject of Personal Data.
- “Personal Data” — any information in the Customer Data relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to factors specific to their physical, physiological, mental, economic, cultural, or social identity.
- “Processing” — as defined by applicable EU Data Protection Law; “process,” “processes,” and “processed” are interpreted accordingly.
- “Data Controller” — the party that determines the purposes and means of Processing Personal Data.
- “Data Processor” — the party that Processes Personal Data on behalf of, or under instruction from, the Data Controller.
- “Data Transfer Mechanism” — an alternative data-export solution for lawfully transferring Customer Data outside the EEA, as recognized under EU Data Protection Law.
- “Data Protection Laws” — with respect to a party, all privacy, data protection, information-security, and related laws and regulations applicable to that party, including EU Data Protection Law where applicable.
- “Data Protection Authority” — the competent body charged with enforcing applicable Data Protection Law in a jurisdiction.
- “EEA” — the European Economic Area, the United Kingdom, and Switzerland.
- “EU Data Protection Law” — prior to May 25, 2018, European Union Directive 95/46/EC; on and after that date, European Union Regulation 2016/679 (the “GDPR”).
- “Written instructions” — the Data Controller's instructions for Processing Customer Data, consisting of the terms of the Agreement and this Addendum, Processing the Data Controller enables through the Service, and other reasonable written instructions consistent with the Agreement.
- “Model Contracts” — the Standard Contractual Clauses for Processors approved by the European Commission under Decision 2010/87/EU, in the form made accessible within the AI Mini Stores workspace.
- “Security Incident” — any unauthorized or unlawful confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data in the Data Processor's control.
- “Subprocessor” — any Third Party engaged by the Data Processor or its affiliates to process Customer Data pursuant to the Agreement or this Addendum.
- “Third Party” — any natural or legal person, public authority, agency, or other body other than the Data Subject, Data Controller, Data Processor, Subprocessors, or persons who, under the direct authority of the Data Controller or Data Processor, are authorized to Process the data.
Terms defined by AI Mini Stores with respect to the GDPR:
- “Data Subjects” include the individuals about whom data is provided to AI Mini Stores via the Services by, or at the direction of, the Customer.
- “Subject Matter of Processing” — the Customer Data.
- “Duration of Processing” — until termination of the Agreement, plus the period from expiry of the Agreement until AI Mini Stores deletes all Customer Data in accordance with this Addendum.
- “Nature and Purpose of Processing” — providing the Service to the Customer and performing AI Mini Stores' obligations under the Agreement (including this Addendum), or as the parties otherwise agree.
- “Categories of Data” — data relating to individuals provided to AI Mini Stores when Customers sign up, log in, use the product, interact with the website, and interact with ads.
- “Security Measures” — the commercially reasonable technical and organizational measures AI Mini Stores agrees to use, designed to prevent unauthorized access, use, alteration, or disclosure of the Service or Customer Data.
Other capitalized terms not defined here have the meanings given in the Agreement.
C. Scope and Applicability
The GDPR applies to the processing of personal data in the context of the activities of the establishment of a Controller or Processor in the EU. This Addendum applies where, and to the extent that, AI Mini Stores processes Customer Data that originates from the EEA — or that is otherwise subject to EU Data Protection Law — on behalf of the Customer in the course of providing the Service under the Agreement.
D. Roles and Scope of Processing
Under this Addendum, the Customer acts as Data Controller and AI Mini Stores acts as Data Processor, and each party is subject to applicable Data Protection Laws in carrying out its responsibilities. The Customer retains all ownership rights in the Customer Data as set out in the Agreement. Except as expressly authorized by the Customer in writing or as instructed by the Customer, AI Mini Stores has no right, directly or indirectly, to sell, rent, lease, combine, display, perform, modify, transfer, or disclose the Customer Data or any derivative work of it. AI Mini Stores acts only in accordance with the Customer's instructions regarding Processing, except where prohibited by applicable Data Protection Laws.
Additional instructions falling outside the scope of the Agreement require the parties' prior written agreement, including agreement on any additional fees payable by the Customer. The Customer acknowledges that AI Mini Stores may use aggregated anonymous data as detailed in the Agreement. AI Mini Stores will not disclose Customer Data to any Third Party except in compliance with the Customer's instructions or a legal obligation to disclose; where disclosure is legally required, AI Mini Stores will inform the Customer in writing beforehand, to the extent Data Protection Laws permit. For clarity, nothing in this Addendum limits AI Mini Stores from transmitting Customer Data (including Personal Data) as instructed by the Customer through the Service.
E. Subprocessing
AI Mini Stores' obligations under this Addendum extend to its employees, agents, and Subprocessors who may access Personal Data. The Customer authorizes AI Mini Stores to use Subprocessors (including cloud infrastructure providers) to Process Personal Data, provided that AI Mini Stores (a) enters into a written agreement with each Subprocessor imposing data protection obligations substantially similar to this Addendum, and (b) remains liable for compliance with this Addendum and for any acts or omissions of a Subprocessor that cause AI Mini Stores to breach its obligations. Information about Subprocessors — including their functions and locations — is available on request and may be updated from time to time in accordance with this Addendum. When engaging a new Subprocessor, AI Mini Stores will notify the Customer by email or in-app notification at least one week before the new Subprocessor processes any Customer Data.
F. Security
AI Mini Stores will implement and maintain appropriate technical and organizational security measures to protect Personal Data from Security Incidents and to preserve its security and confidentiality, in accordance with AI Mini Stores' security standards. The Customer is responsible for reviewing the security information AI Mini Stores makes available and independently determining whether the Service meets the Customer's requirements and legal obligations under Data Protection Laws. The Customer acknowledges that the Security Measures are subject to technical progress and that AI Mini Stores may update or modify them from time to time, provided such changes do not degrade the overall security of the Service the Customer purchased. AI Mini Stores will ensure that anyone authorized to process Personal Data — including staff, agents, and Subprocessors — is bound by an appropriate contractual or statutory duty of confidentiality.
G. Security Incidents
Upon becoming aware of a confirmed Security Incident, AI Mini Stores will notify the Customer without undue delay in accordance with the Security Measures — except where notice is prohibited by Data Protection Laws, and subject to delays requested by law enforcement or reasonably needed to investigate or remediate the matter first. Each notice will include: the extent to which Personal Data has been, or is reasonably believed to have been, used, accessed, acquired, or disclosed; a description of what happened, including the incident date and discovery date, if known; the known scope of the incident; and a description of AI Mini Stores' response, including mitigation steps taken. AI Mini Stores will take reasonable measures to mitigate the harmful effects of any Security Incident and prevent further unauthorized access or disclosure.
H. International Transfers
Subject to this section, AI Mini Stores may store and process Customer Data anywhere in the world where AI Mini Stores, its affiliates, or its Subprocessors maintain data-processing operations. Where AI Mini Stores processes Personal Data protected by the GDPR and/or originating from the EEA in the United States or another non-EEA country not designated as an Adequate Country, the parties will sign the Model Contracts, with AI Mini Stores as “data importer” and the Customer as “data exporter” (even if the Customer is located outside the EEA). If AI Mini Stores adopts an alternative transfer mechanism, that mechanism applies instead of the Model Contracts — but only to the extent it covers the territories to which Personal Data is transferred.
I. Regulatory Compliance and Data Subject Requests
At the Customer's request and expense, AI Mini Stores will reasonably assist the Customer in meeting its obligations to regulatory authorities, including Data Protection Authorities. AI Mini Stores will also (at the Customer's expense) reasonably assist the Customer in responding to individuals' requests concerning their rights of access, rectification, erasure, restriction, portability, and objection. If such a request is made directly to AI Mini Stores, AI Mini Stores will not respond without the Customer's prior authorization unless required by Data Protection Laws.
J. Reviews of Data Processing
At the Customer's request, AI Mini Stores will provide written responses to all reasonable requests for information relevant to its Processing of Personal Data under this Addendum — including responses to security and audit questionnaires — solely to the extent necessary to confirm AI Mini Stores' compliance. Such information will be provided within thirty (30) days of the written request, unless the Customer's regulators require a shorter period. Except as expressly required by Data Protection Laws, any review under this section will: occur no more than once per year, during AI Mini Stores' normal business hours and without interfering with standard operations; be subject to AI Mini Stores' reasonable confidentiality and security constraints; be conducted at the Customer's expense; and not extend to information, systems, or facilities of AI Mini Stores' other customers or its third-party infrastructure providers. Information provided under this section is AI Mini Stores' Confidential Information under the Agreement.
K. Return or Deletion of Data
Within ninety (90) days after the Customer's request at termination or expiration of the Agreement, AI Mini Stores will delete or return — at the Customer's choice — all Personal Data from its systems, and will, on request, provide written confirmation within a reasonable period that its deletion or destruction obligations have been fulfilled. Notwithstanding the foregoing, the Customer understands that AI Mini Stores may retain Customer Data where required by Data Protection Laws, in which case that data remains subject to this Addendum.
L. Further Cooperation
Where required by Data Protection Laws, AI Mini Stores will provide relevant Data Protection Authorities with information about its Processing of Personal Data, and will maintain — and renew where necessary — required registrations during the term of this Addendum, notifying the Customer immediately of any change in status by email or in-app notification. To the extent required under Data Protection Laws, AI Mini Stores will (at the Customer's expense) provide reasonably requested information about the Service, or prior consultations with Data Protection Authorities, to enable the Customer to carry out data protection impact assessments.
M. Term, Precedence, and Governing Law
This Addendum forms part of the Agreement; except as expressly set out here, the Agreement remains unchanged and in full force. If this Addendum conflicts with the Agreement, this Addendum prevails to the extent of the conflict in connection with the Processing of the Customer's Personal Data. All activities under this Addendum — including Processing of Customer Data — remain subject to the limitations of liability in the Agreement. This Addendum is governed by the governing-law and jurisdiction provisions of the Agreement unless applicable Data Protection Laws require otherwise. This Addendum and the Model Contracts terminate automatically upon expiration or termination of the Agreement.