Scope
This policy explains how CartMotive processes information when a merchant installs or uses the CartMotive Shopify app and when the app's theme extensions run on that merchant's storefront. The merchant remains responsible for its own storefront privacy notices and consent configuration.
Information we process
- Store information, including the myshopify.com domain, store name, currency, timezone, installation state, and Shopify authentication sessions.
- Merchant-created campaign settings, selected product, variant and collection identifiers, storefront style settings, saved versions, and app-owned discount references.
- Subscription plan, status, billing interval, trial and billing period timestamps. Shopify processes payment details; CartMotive does not receive card details.
- Consent-permitted storefront events such as campaign impressions, clicks, add attempts, and successful adds, together with campaign, surface, currency, and permitted value fields.
CartMotive does not request Shopify customer, order, address, email, phone, checkout, or payment scopes. It does not store buyer names, email addresses, phone numbers, postal addresses, IP addresses, payment data, or raw browser identifiers.
How we use information
We use the information above to authenticate merchants, operate campaigns, publish theme-extension configuration, reconcile app-owned discounts, enforce plan limits, provide analytics, prevent abuse, respond to support requests, and maintain security and audit records.
CartMotive does not sell personal information and does not send storefront event data to advertising networks, session replay tools, external analytics services, CRMs, or email marketing platforms.
Consent and attribution
Storefront analytics events are accepted only when Shopify indicates that analytics consent is available. Requests are tenant-signed, origin-bound, schema-limited, time-bounded, rate-limited, and limited to 4 KB.
Order attribution is disabled unless the required Shopify approval and CartMotive deployment setting are both active. Where enabled, permitted correlation values are transformed with a keyed hash before storage and raw values are discarded.
Retention and deletion
Raw anonymous storefront events expire after 30 days. Daily aggregated analytics are retained for 30 days on Launch, 180 days on Growth, and 730 days on Scale. Campaigns may be soft-deleted so a merchant can recover configuration while the app remains installed.
On uninstall, CartMotive immediately disables storefront runtime, removes Shopify sessions, and stops paid access. Shopify privacy webhooks are used to process data requests and deletion. A verified shop deletion request removes the tenant record and its related app data.
Processors, security, and transfers
CartMotive uses Shopify to provide app authentication, APIs, extensions, and billing. Production application and database services run on DigitalOcean App Platform and DigitalOcean Managed Databases. Information may be processed in locations where these providers operate, subject to their contractual and security safeguards.
We use access controls, encrypted transport, secret management, tenant-scoped database operations, request validation, and minimized logs. No internet service can guarantee absolute security.
Your choices and contact
Merchants can pause or delete campaigns, disable theme app extensions, cancel a subscription, or uninstall the app. For access, correction, deletion, or privacy questions, contact [email protected]. Please include the store domain and do not send customer secrets or payment information.