Legal

Privacy Policy

Last updated: August 30, 2026

Overview

CartWatch is a Shopify app that helps merchants detect likely bot activity during checkout. This policy explains what data we collect, how we use it, and your rights as a merchant or end-customer.

Data We Collect

From Merchants (Shopify store owners)

  • Shopify store domain and OAuth access token (encrypted at rest) — used to read checkout data and tag customers.
  • App configuration preferences (e.g., auto-tag enabled, plan tier).
  • Credentials for optional third-party integrations (Klaviyo, Omnisend, Mailchimp and Drip OAuth tokens; a Brevo API key) — stored encrypted; used only to perform suppression actions on your behalf.
  • Product usage data for the CartWatch admin app — which pages you open and when your session is active, recorded against your store domain. Used only to understand how merchants use CartWatch and to improve it. This covers the merchant-facing app only; no end-customer or checkout data is included.

From Checkout Events (end-customers of merchant stores)

  • Email address provided during checkout — used for bot scoring and optional email validation (ZeroBounce, if configured by merchant).
  • Shipping and billing address — used for address intelligence signals to improve bot detection accuracy. The shipping address may be geocoded through Geoapify to check that it exists (see Sub-processors below).
  • Shopify checkout ID and customer ID — used to track detection events and apply customer tags.
  • Checkout metadata (timestamps, order amounts, cart contents) — used solely for bot scoring heuristics.

How We Use Data

  • Bot detection: Checkout data is analyzed against heuristic rules to determine whether a checkout exhibits bot-like patterns.
  • Customer tagging: When a checkout is flagged and the merchant has enabled auto-tagging, we apply the CARTWATCH_FLAGGED_BOT tag to the Shopify customer account via the Shopify Admin API.
  • Provider suppression: When integrated with Klaviyo, Omnisend, Mailchimp, Drip, or Brevo and suppression is enabled, we submit the flagged email address to the respective platform to unsubscribe or suppress the contact. In Mailchimp the contact is also archived, so it no longer counts toward the merchant's billing tier; in Brevo the contact is blocklisted for email and SMS.
  • Detection records: Detection results and processing logs are stored in Firebase Firestore under the merchant's namespace. Flagged checkouts are surfaced in the merchant's CartWatch dashboard; the underlying processing logs are retained for troubleshooting and service operation.
  • Service improvements: Aggregated, anonymized usage statistics may be used to improve detection accuracy.

We do not sell personal data to third parties, use checkout data for advertising, or share data between merchant accounts.

Legal Bases for Processing (GDPR)

Where the EU/UK General Data Protection Regulation applies, we process personal data under the following Article 6(1) legal bases:

  • Merchant account data (store domain, access tokens, app settings, connected provider credentials) — Article 6(1)(b), contractual necessity: this data is required to provide the CartWatch service the merchant has signed up for.
  • Billing and subscription dataArticle 6(1)(b), contractual necessity, and Article 6(1)(c), legal obligation, where retention is required for tax and accounting purposes.
  • Checkout and end-customer data (email address, shipping/billing address, checkout metadata) processed for bot detection and scoring — Article 6(1)(f), legitimate interests: the merchant's legitimate interest in preventing fraudulent and automated abuse of their store (fraud prevention is expressly recognized as a legitimate interest by GDPR Recital 47). CartWatch processes this data as a processor on the merchant's behalf; the merchant is the data controller for their customers' data.
  • Customer tagging and email suppression (applying bot tags in Shopify; suppressing flagged profiles and recording suppression events in Klaviyo, Omnisend, Mailchimp, Drip, or Brevo) — Article 6(1)(f), legitimate interests: fraud prevention and protecting the accuracy of the merchant's marketing audience, performed only on the merchant's configuration and instruction.
  • Support communicationsArticle 6(1)(b), contractual necessity, or Article 6(1)(f), legitimate interests, in responding to inquiries from prospective merchants.
  • Aggregated service-improvement statisticsArticle 6(1)(f), legitimate interests: improving detection accuracy. Data used for this purpose is aggregated and anonymized.
  • Data deletion and redaction (honoring Shopify shop/redact and customer redaction webhooks, and direct deletion requests) — Article 6(1)(c), legal obligation.

Third-Party Services (Sub-processors)

We use the following service providers to operate CartWatch. Each is engaged under a data processing agreement, is assessed for security and privacy before it receives any data, and is reviewed at least annually. We share only the minimum data each service requires.

Always active:

  • Google Cloud / Firebase — hosting, database, compute, and secret management for the entire service. All merchant and checkout data is stored here, in the United States.
  • Shopify — the platform CartWatch runs on. Checkout and order data reaches us from Shopify, and customer tags are written back to Shopify.
  • Resend — delivery of transactional and operational email to merchants (for example, detection notifications and service alerts). Merchant email addresses only; no end-customer data.
  • PostHog — product analytics for the merchant-facing app: page views and session activity recorded against your store domain. Merchant usage only; no end-customer or checkout data.
  • Geoapify (Geoapify GmbH, Germany) — geocoding of the checkout shipping address to check that the address exists, used as one bot-detection signal. Only the address components (street, city, region, postal code, country) are sent; no name, email, phone, or order details. Powered by Geoapify.
  • Help Scout — our support inbox and the in-app support chat. Receives your name, store domain, contact email address, and the content of your support messages, in the United States. Support replies may be drafted with AI assistance and are reviewed by our team.
  • OpenAI — bot-pattern analysis and drafting of support replies via the OpenAI API, in the United States. Receives annotated checkout fields (no payment data), the content of your support messages, and a summary of your account configuration. Credentials are never sent, and API data is not used to train OpenAI models.

Optional, activated only when a merchant connects them:

  • Klaviyo — email suppression for flagged contacts, via the merchant's connected Klaviyo account.
  • Omnisend — email suppression for flagged contacts, via the merchant's connected Omnisend account.
  • Mailchimp — email unsubscribe and archiving for flagged contacts, via the merchant's connected Mailchimp account.
  • Drip — email unsubscribe (from all mailings) for flagged subscribers, via the merchant's connected Drip account.
  • Brevo (Sendinblue SAS, France) — email and SMS blocklisting for flagged contacts, via an API key from the merchant's own Brevo account.

In each case the merchant authorizes CartWatch against the merchant's own provider account, and CartWatch acts only within the permissions the merchant granted. A merchant can revoke that authorization at any time, from CartWatch or from the provider, and we delete the stored credentials when they do.

Not currently in use:

  • ZeroBounce (email validation) is disabled in production. No checkout email addresses are sent to it. If we re-enable it, this policy will be updated first. Smarty (US address verification) was removed on 2026-09-10 and replaced by Geoapify, listed above.

Data Storage and Retention

Merchant and checkout data is stored in Google Firebase (Firestore), hosted in the United States. Checkout records and their associated processing logs are automatically deleted 90 days after they are created. When a merchant uninstalls CartWatch, Shopify access tokens and connected provider credentials are cleared immediately. Remaining store data is deleted after Shopify sends the mandatory shop/redact webhook (approximately 48 hours after uninstall), or sooner upon request.

Data Security

Sensitive credentials (Shopify access tokens, Klaviyo, Omnisend, Mailchimp, and Drip OAuth tokens, Brevo API keys) are encrypted before being written to Firestore. We use industry-standard AES encryption and do not store encryption keys alongside the data.

Your Rights

If you are a merchant using CartWatch, you may request deletion of your store's data at any time by uninstalling the app or contacting us at the address below.

If you are a customer of a Shopify store that uses CartWatch and you have questions about how your data was processed, please contact that store's owner directly. CartWatch processes checkout data on behalf of merchants and does not have a direct relationship with end-customers.

California Privacy Rights (CCPA/CPRA)

This section applies to California residents and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). Terms such as "personal information," "sell," "share," "business," and "service provider" have the meanings given to them in the CCPA.

Our role

For checkout and end-customer data, CartWatch acts as a service provider to the Shopify merchant, who is the business. We process that personal information only to perform the bot detection services set out in our agreement with the merchant. We do not retain, use, or disclose it for any other purpose, and we do not combine it with personal information received from other sources except as the CCPA permits a service provider to do. For merchant account data (the store owner's own contact, configuration, and billing details), CartWatch acts as a business.

Categories of personal information collected

In the preceding 12 months we have collected the following categories of personal information:

  • Identifiers — name, email address, postal address, phone number, IP address, Shopify customer and checkout identifiers, merchant store domain.
  • Customer records (Cal. Civ. Code § 1798.80) — name, address, and telephone number provided at checkout.
  • Commercial information — cart contents, order value, and checkout and order history.
  • Internet or other electronic network activity — checkout events observed by the CartWatch pixel, referring page, and user agent; and, for merchants, page views and session activity within the CartWatch admin app.
  • Geolocation data — coarse location (country and region) derived from IP address. We do not collect precise geolocation.
  • Inferences — the bot risk score and the detection reasons derived from the data above.

We do not collect sensitive personal information, biometric information, government identifiers such as Social Security numbers, payment card or financial account numbers (payment details are handled entirely by Shopify and never reach CartWatch), precise geolocation, characteristics of protected classifications, professional or employment information, education information, or audio, video, or similar recordings.

Sources, purposes, and disclosures

  • Sources: the merchant and the Shopify platform (webhooks and Admin API), the CartWatch pixel on the merchant's storefront, and email marketing providers the merchant has connected.
  • Business purposes: detecting and scoring likely bot checkouts; tagging flagged customers in Shopify; suppressing flagged contacts in a merchant's connected email provider; providing the merchant dashboard; security, debugging, and service maintenance; and improving detection accuracy using aggregated, anonymized statistics.
  • Disclosed for a business purpose: in the preceding 12 months we disclosed the categories listed above to the service providers named in "Third-Party Services (Sub-processors)," each of which is contractually restricted to processing the data on our instructions for those purposes only.

No sale or sharing of personal information

We do not sell personal information, and we have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not use or disclose personal information for targeted advertising of any kind. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age. Because we neither sell nor share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link; there is nothing to opt out of.

Your California rights

  • Right to know — to request the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties to whom we disclosed it.
  • Right to delete — to request deletion of personal information we have collected about you, subject to the exceptions the CCPA permits (for example, where retention is required to detect security incidents or fraudulent activity, or to comply with a legal obligation).
  • Right to correct — to request correction of inaccurate personal information we maintain about you.
  • Right to data portability — to receive the personal information you requested under the right to know in a readily usable format.
  • Right to opt out of sale or sharing — we do not sell or share personal information, so there is no sale or sharing to opt out of.
  • Right to limit the use of sensitive personal information — we do not collect sensitive personal information, so this right does not apply to our processing.
  • Right to non-discrimination — see below.

Non-discrimination

We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you a different price or rate, provide you a different level or quality of service, or suggest that you will receive a different price or quality of service, because you exercised your rights. We do not offer financial incentives in exchange for the retention or sale of personal information.

How to exercise your rights

Email us at support@vyntlabs.com with the subject line "California Privacy Request" and tell us which right you wish to exercise.

  • If you shopped at a store that uses CartWatch: the merchant is the business responsible for your data, so the fastest route is to contact that store directly. If you contact us instead, we will forward your request to the merchant and assist them in fulfilling it, as the CCPA requires of a service provider.
  • Verification: to protect your data, we will ask you to provide the email address used at checkout and the store you shopped at, so that we can match your request to our records. We use the information you provide only to verify and process the request.
  • Authorized agents: an agent may submit a request on your behalf if they provide written permission signed by you; we may also ask you to verify your identity with us directly.
  • Timing: we confirm receipt within 10 business days and respond substantively within 45 calendar days. If we need more time we will tell you, and we may extend by up to a further 45 days.
  • Cost: exercising these rights is free.

Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.

Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of CartWatch after changes are posted constitutes acceptance of the updated policy.

Contact

For privacy-related questions or data deletion requests, please contact:

CartWatch
Email: support@vyntlabs.com