Galactic Core
Sign in
Legal

Privacy Policy

Galactic Core is operated by TYBRITE TECHNOLOGIES LIMITED ("Tybrite", "we", "us"), trading as Tybrite Labs. This policy explains what personal information we handle, why, and what you and your customers can ask us to do with it.

Effective 27 July 2026

1.The two kinds of people in this policy

Galactic Core is used by businesses to sell to their customers, so personal information reaches us in two different ways — and our responsibilities differ in each case.

Merchants — the businesses using Galactic Core. If you sign up, run a store, or are invited onto a team, we handle your information as the party responsible for it. We decide what we collect and why, and this policy is our account of that.

Shoppers and buyers — your customers. When someone buys from a store running on Galactic Core, their information is handled on the merchant's instructions, for the merchant. The merchant decides what to collect and why; we process it to run their store. In data-protection terms, the merchant is the controller and we are their processor.

What this means practically: if you're a shopper and you want your data corrected or deleted, the store you bought from is the right first contact — they control it. Ask us and we'll help route the request, but we act on the merchant's instructions, not around them. Merchants: your own privacy notice to your customers is yours to publish, and this policy doesn't replace it.

2.What we collect

When you register and run a store

  • Account and business details — your name, email, phone, password (stored hashed, never in readable form), business name, the country and currency you sell in, your team members and their permissions.
  • Your business content — your products, prices, stock, orders, invoices, expenses, and bookkeeping records. Mostly not personal information, but your customer records are.
  • Billing details — your plan, billing period, invoices, and payment history. Your card details never reach us at all. You enter them directly with our payment provider on their own checkout page; we store no card number and no card details of any kind, and we hold only the record of which plan you're on and what has been invoiced and paid.
  • Support correspondence — the messages you send us and our replies.

Automatically, when you use the platform

  • Technical and usage data — IP address, browser and device type, pages and features used, timestamps, and referring page.
  • Diagnostics — error reports and performance traces when something breaks, so we can fix it.

Your customers' information, on your behalf

Name, email, phone, delivery and billing address, order history, and anything else the merchant chooses to collect at checkout or in a customer record. Also storefront analytics events — pages viewed, items added to a cart — collected first-party for the merchant's own reporting.

We don't collect special-category data (health, biometrics, political or religious beliefs, and the like) and we ask you not to put it into Galactic Core. We don't knowingly collect information from children.

3.Why we use it

We use personal information only for these purposes:

PurposeExamples
Running the platformSigning you in, provisioning your store, showing your catalog, processing the orders and payments you ask us to, keeping your books, producing your reports
Billing youTaking subscription payments, sending invoices and renewal notices, recovering unpaid fees
Supporting youAnswering your questions, investigating a problem in your account
Keeping it workingMonitoring availability, diagnosing faults, capacity planning, backups
Keeping it safeDetecting and preventing fraud, abuse, and unauthorised access; enforcing our terms
Improving itUnderstanding which features are used and where people get stuck, so we build the right things
Telling you thingsService notices, security alerts, billing notices, and — if you haven't opted out — occasional product news

We do not sell personal information, and we don't share it for cross-context behavioural advertising. We don't use your customer lists to market to your customers.

Our legal grounds (where the GDPR or a similar law applies): performing our contract with you; our legitimate interests in securing, supporting, and improving the platform; complying with legal obligations; and consent where we ask for it — which you can withdraw at any time. Where we act as a merchant's processor, the merchant is responsible for having a lawful basis for what they ask us to process.

4.Automated processing

Some features analyse your store's data to produce a result for you — search and product recommendations, sales and customer reporting, business-health scoring, and the assistant inside your dashboard. These operate on your own store's data to help you run it.

No automated decision produces a legal or similarly significant effect on an individual without a person involved. Where the platform proposes an action — a promotion, a price change — it is proposed as a draft for someone on your team to approve or reject.

5.Who we share it with

Service providers who help us run the platform. Hosting and infrastructure, email and SMS delivery, payment processing, error monitoring and analytics, and customer-support tooling. They get only what they need for their specific job, they act on our instructions, they're bound by confidentiality, and they may not use it for their own purposes.

Services you choose to connect. When you connect your payment processor, shipping carrier, accounting, email, or marketing tool, or a sales channel you sell on, we exchange the data that integration needs. You're choosing that sharing — it happens because you enabled it, it carries only what the integration requires, and once data reaches that service, its own privacy policy governs it.

Other merchants — only in a marketplace, and only what's necessary. If you sell on a marketplace running on Galactic Core, the marketplace operator sees the orders placed with you; if you operate one, you see the orders placed with your sellers. Sellers don't see each other's data.

Professional advisers, and authorities when we must. We disclose information where the law requires it, in response to a valid legal request, or to establish or defend a legal claim. We review every request, we don't hand over more than is asked for, and we'll tell you unless we're legally barred from doing so.

A buyer, if the business changes hands. If Tybrite is involved in a merger, acquisition, or sale of assets, information may transfer as part of it — under this policy, and we'll tell you before it happens.

6.Where it's held, and international transfers

Galactic Core runs on infrastructure in multiple regions, and some of our service providers operate outside your country — so your information may be transferred and stored across borders.

Where we transfer personal information out of the UK, the EEA, or another region with transfer restrictions, we rely on an appropriate safeguard — standard contractual clauses, an adequacy decision, or an equivalent mechanism — so the protection travels with the data.

7.How we protect it

  • Encrypted in transit and at rest.
  • Third-party credentials are encrypted in a dedicated secrets store — the keys you give us for your payment processor and other connected services are never stored in readable form, and they're never sent back to your browser.
  • Passwords are hashed, never stored in readable form. Not even we can read yours.
  • Access is scoped and least-privilege. Each store's data is isolated from every other store's at the database level, and enforced on every request. Our own staff access is restricted to those who need it for support or operations, and it's logged.
  • Role-based permissions inside your account — you control what each of your team members can see and do.
  • Regular backups, so your data survives a failure.

No system is perfectly secure. If a breach affects your personal information we'll notify you and the relevant regulator as the law requires, and without undue delay.

8.How long we keep it

We keep information for as long as your account is open, and after that only as long as we genuinely need it:

WhatHow long
Your account and store dataWhile your account is open
After you close your accountRetained for a limited period so you can export or reactivate, then deleted
Invoices, payments, and accounting recordsAs long as tax and company law requires, typically 7 years
Security and access logsA limited period for security investigation
Support correspondenceWhile it's useful for supporting you
Sandbox and test dataAutomatically deleted after 30 days

When a retention period ends, we delete the information or irreversibly anonymise it. Backups age out on their own schedule, so deletion can take a little longer to propagate there.

9.Your rights

Depending on where you are, you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct it if it's wrong;
  • delete it, where we don't have an overriding reason or legal duty to keep it;
  • export it in a portable format — you can do this yourself, any time, from your dashboard;
  • restrict or object to how we use it, including for our legitimate interests;
  • withdraw consent you gave us, without affecting what we did before you withdrew it;
  • not be discriminated against for exercising any of these rights.

How to ask: email privacy@tybritelabs.com. We'll respond within 30 days. We may need to verify who you are first — that's a protection for you, not an obstacle. It's free, unless a request is excessive or repetitive.

Shoppers: contact the store you bought from first — they control your information. If you come to us, we'll pass it to the merchant and support them in answering it.

If you're unhappy with how we've handled a request, tell us and we'll look again. You can also complain to your data-protection regulator — in Kenya, the Office of the Data Protection Commissioner; in the UK, the Information Commissioner's Office; in the EEA, your national authority.

10.Marketing, and how to stop it

We send service messages — security alerts, billing and renewal notices, and important changes to the platform — for as long as you have an account. These aren't marketing and you can't opt out of them while your account is open, because you need them.

Product news and onboarding emails are optional. Every one has a one-click unsubscribe, and you can turn them off in your notification settings. Unsubscribing from those never stops your service messages.

11.Cookies and similar technologies

We use cookies and local storage to keep you signed in, remember your preferences, keep your session secure, and understand how the platform is used so we can improve it.

We don't use advertising or cross-site tracking cookies on Galactic Core. Storefront analytics on a merchant's store are first-party and collected for that merchant's own reporting. You can clear or block cookies in your browser, but the ones that keep you signed in are necessary — block them and you won't be able to use your dashboard.

13.Changes to this policy

We'll update this policy when our practices or the law change. For material changes we'll give account owners at least 14 days' notice by email or in your dashboard, and we'll update the effective date at the top. Minor clarifications take effect when posted.

Your data, your call

Ask us what we hold, get a copy, or have it deleted — email privacy@tybritelabs.com and we'll reply within 30 days. You can also export everything yourself from your dashboard at any time, without asking us. See also the Terms of Service.
Also read