Skip to content

Last updated September 17, 2026

Privacy policy

BC Authentication provides Google sign-in for participating BigCommerce stores. This policy explains how the app handles information when merchants configure it and shoppers use it.

Information used for sign-in

With your authorization, Google provides your account identifier, verified email address, and available first and last name. We use this information to verify your identity, create a customer account when appropriate, or sign you into a previously connected account in the participating store. We do not receive your Google password or request access to your Gmail, Google Drive, contacts, or payment information.

What we store

The app stores a connection between your Google identity and the store’s BigCommerce customer ID. Identity identifiers and email addresses used for matching are stored as hashes. Temporary sign-in records contain security values, timestamps, and, when profile completion is needed, encrypted profile details. The store retains customer names, email addresses, and other customer records in BigCommerce. For merchants, we store the store identifier, installation permissions, encrypted BigCommerce access token, settings, and the identifiers and temporary sessions needed to verify authorized staff access. Service infrastructure may process IP addresses and request metadata for operation, troubleshooting, and abuse prevention.

Sharing and service providers

Google handles Google authentication. Customer information is shared with the participating merchant’s BigCommerce store to provide account access. Vercel hosts the application and Convex provides its backend data storage. These providers process information to operate the service. We do not sell Google user data, use it for advertising, or use it to train AI models.

Cookies and retention

A temporary, secure sign-in cookie binds a login attempt to your browser. Sign-in attempts expire after ten minutes and are removed by a scheduled cleanup. Account connections are retained to support later sign-ins until disconnected or removed in response to a verified request. Uninstalling or disabling the app prevents new app sign-ins; it does not delete the merchant’s BigCommerce customer records. Infrastructure logs and backups follow the providers’ retention processes.

Your choices and requests

You may use the store’s ordinary sign-in instead, cancel Google authorization, or remove this app’s access from your Google Account. Removing Google authorization does not itself delete a store account or the app’s account connection. Contact the merchant about its customer records. For access, correction, disconnection, or deletion requests concerning this app, contact radovan@rashos.com. We may need to verify your identity and the relevant store before acting.

Contact and changes

BC Authentication support: radovan@rashos.com. Updates to this policy will appear here with a revised date. A participating store’s privacy policy separately governs its customer accounts, purchases, and marketing.

Contact privacy support