Privacy Policy

Last updated: October 1, 2026

CartProof (“CartProof”, “we”, “us”) is a Shopify app that displays social-proof and urgency badges — recent purchases, sales and cart counts, live visitor counts, low-stock alerts, promotions, popups, and an AI hesitation assistant — on a merchant’s storefront. This policy explains what personal data we process, why, and the choices available to merchants and their customers.

For personal data we process on behalf of a Shopify merchant, the merchant is the data controller and CartProof acts as a data processor. That processing is also governed by our Data Processing Addendum.

Operator: CartProof (operated from India)  ·  Contact: hello@getcartproof.com

1. Data we process

Merchant / store data. Store domain, Shopify access tokens, app settings, selected plan, and product/theme/locale metadata read via the Shopify Admin API — used to authenticate the app, render and configure badges, and operate billing. We never sell this data.

Customer & visitor data (processed for the merchant). We deliberately collect the minimum needed:

DataSourceWhy
Customer first name & city (and province/country)Order data (read_orders + the orders/create webhook)To display recent-purchase social proof, e.g. “Aria from Sydney”.
Order product, quantity, order ID, timestampOrder dataTo compute sales counts, bestseller rank, and trending badges.
Email and/or phone + consent flagSubmitted by a shopper through a CartProof popup or promotion-bar opt-in formTo capture marketing subscribers and, where enabled, sync them to the merchant’s Shopify customers.
A random per-browser visitor ID, page path, cart product handlesOur storefront scriptTo count live viewers and “in-cart” counts, run cart-countdown timers, and detect hesitation. Not the Shopify customer ID; not linked to a named individual.
Engagement events (impressions, clicks, add-to-cart, buy-now, detected hesitation concern)Our storefront scriptAggregate analytics shown to the merchant.

We do not collect last names, full street addresses, payment details, passwords, or government IDs. We do not use cookies to track individuals across unrelated sites, and we do not sell, rent, or share personal data for advertising.

2. How we use personal data

Only for the purposes above — providing the app’s functionality and the merchant’s own analytics. We do not use it for automated decisions that produce legal or similarly significant effects.

3. Consent

Where a shopper submits their email/phone through a popup or promotion bar, we record their consent and honour opt-outs. Order-derived data is processed under the merchant’s storefront privacy terms and consent settings.

4. Sharing & subprocessors

We share personal data only with the infrastructure providers needed to run the service, each bound by data-protection obligations: Shopify (platform and APIs) and reputable cloud hosting and database providers that encrypt data in transit and at rest. We do not sell personal data or share it with advertisers or data brokers.

5. Retention

6. Security

7. Data subject rights & Shopify compliance webhooks

We support Shopify’s mandatory privacy webhooks:

Customers should direct access/deletion requests to the merchant (the controller); merchants may also contact us at hello@getcartproof.com.

8. International transfers

Data may be processed in or outside India. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.

9. Children

The app is not directed to children and we do not knowingly collect their data.

10. Changes

We may update this policy; material changes will be reflected by the “Last updated” date and, where appropriate, communicated to merchants.

11. Contact

CartProof — hello@getcartproof.com