A consolidated reference mapping Storefront policies, controls, and customer responsibilities to common enterprise review areas.
Effective DateAugust 5, 2026
AudienceSecurity, Legal, Privacy, and Procurement Teams
Contacthello@storefrontworks.com
1. Purpose and Scope
This Compliance and Trust Matrix provides a high-level map of the policies, agreements, technical safeguards, and operational practices maintained by Storefront Labs, LLC (“Storefront”).
It is intended to support enterprise procurement, security review, privacy review, vendor due diligence, and contract administration. It does not create certifications, warranties, audit rights, or contractual obligations beyond those expressly stated in an executed agreement.
Reference document. The governing source for any commitment is the applicable signed Order, Terms of Use, or other executed agreement.
2. Governance and Contracting
Review Area
Storefront Position
Primary Documents
Core service terms
Use, fees, disclaimers, liability, arbitration, indemnification, and account rules are governed by Storefront’s master service terms and Orders.
Terms of Use; Subscription Billing, Payment, and Refund Policy
Customer data processing
Personal information is processed as described in the Privacy Policy and any privacy terms expressly included in an applicable Order.
Privacy Policy; applicable Order
3. Privacy and Data Protection
Control Area
Storefront Approach
Primary Documents
Privacy notices
Storefront describes controller and business-purpose processing through its Privacy Policy.
Privacy Policy
Processing obligations
Processing obligations may be addressed through applicable Orders, the Privacy Policy, security practices, and subprocessor disclosures.
Privacy Policy; Security Overview; Subprocessors
Retention and deletion
Data is retained for commercially reasonable periods based on service, legal, operational, security, and backup requirements.
Data Retention and Deletion Policy
Cookies and tracking
Cookie, analytics, advertising, consent, browser, and mobile controls are described separately.
Cookie Policy
Subprocessors
Representative providers are disclosed and may change subject to applicable contractual requirements.
Subprocessors
Children and sensitive settings
Customers are responsible for lawful authority, notices, consent, and configuration where the Services are used around children or regulated populations.
Privacy Policy; Acceptable Use Policy; Accessibility Statement
4. Security Controls
Control Family
Representative Practices
Primary Documents
Cloud infrastructure
Primary hosting on AWS with managed cloud services and logical access controls.
Security Overview and Trust Center; Security Overview
Encryption
Industry-standard encryption in transit and appropriate encryption at rest where supported.
Security Overview
Identity and access
Least privilege, unique accounts, role-based controls where practicable, credential protection, and access revocation.
Security Overview; Acceptable Use Policy
Monitoring and logging
Operational, authentication, integration, security, diagnostic, and abuse-related telemetry may be retained and reviewed.
Security Overview; Data Retention and Deletion Policy
Vulnerability management
Material vulnerabilities are assessed and addressed based on risk and available mitigations.
Good-faith security research may be reported through a coordinated disclosure process.
Vulnerability Disclosure Policy
5. Resilience and Availability
Area
Storefront Approach
Primary Documents
Availability
Storefront does not currently publish a contractual uptime target or service-credit program.
Terms of Use
Maintenance
Scheduled and emergency maintenance may occur.
Terms of Use
Backups
Backup, replication, archive, or recovery mechanisms are used according to system criticality and operational need.
Business Continuity and Disaster Recovery Policy; Security Overview
Continuity planning
Recovery methods may include alternate infrastructure, provider substitution, restoration, manual procedures, and prioritized recovery.
Business Continuity and Disaster Recovery Policy
Third-party dependencies
External cloud, telecommunications, AI, payment, mapping, and platform outages may affect service delivery.
Terms of Use
6. AI and Automation
Area
Storefront Approach
Primary Documents
AI transparency
AI features, provider dependencies, limitations, and customer review responsibilities are disclosed.
AI Transparency and Responsible AI Policy; AI and Automated Decision-Making Policy
Human oversight
Customers must review outputs and maintain meaningful human oversight for consequential uses.
AI Transparency and Responsible AI Policy; Acceptable Use Policy
Restricted uses
Storefront AI may not be used as the sole basis for specified high-risk, safety-critical, or regulated decisions.
AI and Automated Decision-Making Policy; Acceptable Use Policy
Third-party providers
Storefront uses Anthropic for AI functionality, subject to product configuration and provider terms.
AI Transparency and Responsible AI Policy; Subprocessors
7. Communications and Messaging
Area
Storefront Approach
Primary Documents
Electronic consent
Account, billing, service, legal, security, and operational notices may be delivered electronically.
Electronic Communications and Messaging Consent Policy
Commercial messaging
Customers must obtain required consent, honor opt-outs, maintain records, and comply with messaging laws.
Electronic Communications and Messaging Consent Policy; Acceptable Use Policy
Delivery limitations
Email, SMS, push, and in-app messages may be delayed, filtered, blocked, duplicated, or undelivered.
Electronic Communications and Messaging Consent Policy
Message storage
Messages may be stored for a reasonable period, but indefinite availability is not guaranteed.
Data Retention and Deletion Policy; Electronic Communications and Messaging Consent Policy
8. Hardware and Connected Devices
Area
Storefront Approach
Primary Documents
Limited warranty
Storefront-branded hardware is generally covered for defects in materials and workmanship for the stated warranty period.
Hardware Warranty and Connected Device Terms
Installation
Customers are responsible for safe, secure, code-compliant installation unless an Order states otherwise.
Hardware Warranty and Connected Device Terms
Connectivity
Hardware may depend on power, Wi-Fi, Bluetooth, cellular, GPS, NFC, UWB, local networks, and cloud services.
Hardware Warranty and Connected Device Terms
Firmware and updates
Storefront may deploy remote updates to maintain security, compatibility, reliability, or functionality.
Hardware Warranty and Connected Device Terms; Mobile Application EULA
Camera and audio privacy
Customers are responsible for lawful placement, signage, notices, consent, retention, and monitoring practices.
Hardware Warranty and Connected Device Terms; Acceptable Use Policy
9. Intellectual Property
Area
Storefront Approach
Primary Documents
Copyright complaints
Storefront maintains a notice and counter-notice process for copyright claims.
Copyright and DMCA Policy
Trademark use
Storefront marks may be used only as permitted by written authorization and brand guidelines.
Trademark and Brand Usage Guidelines
Feedback
Feedback concerning Storefront products may be used, assigned, or licensed to Storefront as stated in applicable agreements.
Terms of Use
10. Regulatory and Trade Compliance
Area
Storefront Approach
Primary Documents
Government requests
Requests are reviewed for validity, scope, jurisdiction, notice restrictions, and legal sufficiency.
Law Enforcement and Government Requests Policy
Export and sanctions
Storefront may screen, restrict, suspend, or terminate service to comply with export controls and sanctions.
Export Control and Sanctions Compliance Policy
Accessibility
Storefront works toward accessible digital experiences and provides a channel for reporting barriers.
Accessibility Statement
Records and retention
Legal holds, investigations, disputes, audit, tax, security, and regulatory obligations may extend retention.
Data Retention and Deletion Policy
11. Customer Responsibilities
Storefront operates under a shared-responsibility model. Depending on the feature and deployment, customers are responsible for:
protecting credentials, accounts, devices, networks, and integrations;
configuring permissions and removing unauthorized users;
obtaining required notices, consent, and lawful bases;
reviewing published information, AI outputs, automations, and third-party updates;
maintaining independent copies of legally or operationally critical records;
complying with messaging, surveillance, privacy, employment, accessibility, and sector-specific laws;
maintaining local power, connectivity, hardware, and physical security; and
promptly reporting security, privacy, fraud, billing, and service issues.
12. Limitations and Verification
No certification implied. This matrix does not represent that Storefront holds SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or other certification unless Storefront separately confirms that status in writing.
Controls, products, providers, architecture, and policies may change as Storefront evolves. Certain technical details may be withheld where disclosure would create security, confidentiality, legal, or operational risk.
Enterprise customers may submit reasonable follow-up questions to Storefront, subject to confidentiality, relevance, available resources, and applicable agreements.
13. Contact Information
Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States