Terms of Service

Last updated: October 1, 2026

These Terms govern a merchant’s use of the CartProof Shopify app (“the App”), operated by CartProof from India (“we”, “us”). By installing the App you agree to these Terms. Our handling of personal data is described in our Privacy Policy and in the Data Processing Addendum below.

Part A — Terms of Service

  1. License. We grant you a non-exclusive, non-transferable right to use the App on stores you control, subject to these Terms.
  2. The service. The App displays configurable social-proof, urgency, and marketing badges on your storefront and provides related analytics. Features may change over time.
  3. Acceptable use. You will not misuse the App, display false information you know to be untrue, reverse-engineer it, or use it to violate any law or Shopify policy. You are responsible for the accuracy and legality of content you configure and for your storefront’s own privacy disclosures.
  4. Fees & billing. Paid plans are billed through Shopify’s Billing API per the pricing shown in the App and on the App Store listing. Charges follow Shopify’s billing terms; taxes may apply.
  5. Data. Our handling of personal data is described in our Privacy Policy and the DPA in Part B.
  6. Availability & disclaimer. The App is provided “as is” without warranties of any kind. We do not guarantee uninterrupted or error-free operation.
  7. Limitation of liability. To the maximum extent permitted by law, our aggregate liability is limited to the fees you paid for the App in the three (3) months before the event giving rise to the claim. We are not liable for indirect or consequential damages.
  8. Termination. You may uninstall at any time. We may suspend or terminate access for breach of these Terms. On termination we delete your data as described in the DPA and Privacy Policy.
  9. Changes. We may update these Terms; continued use after changes constitutes acceptance.
  10. Governing law. These Terms are governed by the laws of India.
  11. Contact. hello@getcartproof.com

Part B — Data Processing Addendum (DPA)

This DPA forms part of the Terms and applies where we process personal data of your customers and site visitors on your behalf.

  1. Roles. You are the controller and CartProof is the processor of customer/visitor personal data. We process such data only on your documented instructions (your configuration and use of the App).
  2. Subject matter & duration. Processing lasts for the duration of your installation plus the retention/deletion periods in the Privacy Policy.
  3. Nature & purpose. Displaying social-proof and marketing badges, capturing opt-in subscribers, and providing engagement analytics.
  4. Data subjects. Your customers, prospective customers, and store visitors.
  5. Types of personal data. Customer first name and city/region (from orders); opt-in email and/or phone; pseudonymous visitor IDs and engagement events. We apply data minimisation and limit processing to these purposes.
  6. Confidentiality. Personnel authorised to process the data are bound by confidentiality and least-privilege access.
  7. Security. TLS in transit, encryption at rest, encrypted backups, access logging, strong authentication, and HMAC-verified webhooks.
  8. Subprocessors. You authorise the subprocessors listed in the Privacy Policy (cloud hosting, database, Shopify). We remain responsible for their compliance and will give notice of material changes.
  9. Data subject requests. We assist you in responding to access, deletion, and correction requests, including via Shopify’s customers/data_request and customers/redact webhooks.
  10. Personal data breach. We will notify you without undue delay and within 72 hours of becoming aware of a confirmed breach affecting your data.
  11. Deletion & return. On uninstall or written request we delete the relevant personal data (and honour Shopify’s shop/redact) except where retention is legally required.
  12. International transfers. Where data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses.
  13. Audits. On reasonable request we provide information necessary to demonstrate compliance with this DPA.