Overview
This Privacy Policy explains how Cartful collects, uses, and handles information when merchants install or use the Cartful app and when Cartful processes store and cart data through Shopify.
Cartful is designed to help Shopify merchants create a more branded, conversion-focused cart experience with merchandising controls, market targeting, and cart-specific analytics.
Information we process
Cartful processes the store, cart, analytics, billing, and limited order-related information needed to provide the service.
- Store and account information such as shop domain, installation status, authentication session details, and billing status.
- Cart configuration data such as widget settings, design settings, layout configuration, translation settings, and market targeting rules.
- Cart analytics and event data such as cart sessions, cart opens, checkout clicks, funnel activity, and related attribution data.
- Order and billing-related information such as order identifiers, totals, currency, timestamps, and normalized line item information used for attribution, reporting, and billing workflows.
- Communications and support information when merchants contact Cartful directly.
How we use information
- To provide, maintain, and improve the Cartful app and related storefront functionality.
- To store cart layouts, widget settings, and design configuration for merchant carts.
- To calculate cart-specific analytics such as revenue, orders, conversion rate, funnel metrics, and upsell performance.
- To manage billing, subscriptions, trials, promotions, and service eligibility.
- To troubleshoot issues, respond to support requests, and protect the security and reliability of the service.
- To comply with legal, regulatory, and Shopify platform requirements.
How information is shared
Cartful does not sell merchant or customer personal data. We may share information with service providers and infrastructure partners that help us operate the service, with Shopify when required to provide app functionality, and when disclosure is required by law or to protect the service and its users.
Data minimization
Cartful is designed to limit the amount of order and customer-related data it stores. Cartful does not maintain customer profiles as a standalone dataset and does not retain full raw Shopify order webhook payloads as part of its normal order analytics storage.
Retention and deletion
Cartful applies retention periods so data is not kept longer than needed for product, analytics, billing, and compliance workflows.
Current standard retention windows are 12 months for cart events, 12 months for cart sessions after inactivity, and 24 months for order analytics records.
If a merchant uninstalls Cartful, store data may be retained for a limited period so that an accidental reinstall can restore the prior state. When Cartful receives Shopify's shop redact request, store data associated with that shop is deleted from Cartful's systems.
Shopify privacy requests
Cartful responds to Shopify privacy and compliance workflows, including requests related to customer data and shop deletion.
Where Shopify provides order references for privacy workflows, Cartful handles those requests against the limited analytics and order records it stores, including deleting matching order analytics records when required.
Security
Cartful uses commercially reasonable administrative, technical, and organizational measures to protect information processed through the service. No system can be guaranteed to be completely secure, but we work to limit access, use secure transport, and reduce unauthorized access risk.
Contact
If you have questions about this Privacy Policy or Cartful's handling of data, contact team@cartful.ca.
