CartStar Privacy Policy
CartStar is a Shopify app operated by Appify Market ("we", "us"), United States of America. This policy explains what data the app handles, why, and for how long.
Our role
When a merchant installs CartStar, that merchant is the controller of their customers' personal data and we are a processor acting on their instructions. We process data only to provide the app to that merchant. We do not use one merchant's data to serve another, and we do not sell data.
What we collect from a merchant's store
| Data | Why |
|---|---|
| Store domain, name, currency, country, plan | To identify the installation and format money correctly |
| Shopify access tokens | To call the Shopify API on the merchant's behalf |
| Product catalogue: title, handle, vendor, type, tags, image URL, variants, prices, availability, publication status | To choose which products to recommend and render them in the cart |
| Order line items: order id, line item id, product id, variant id, quantity, price, order date | To rank products by what actually sells, and to attribute purchases the app influenced |
| Shopify customer id | Solely to group order lines by purchaser, so the app can answer "customers who bought this also bought". Never displayed, never exported. |
| Cart settings the merchant configures | To render the cart as configured |
We do not collect customer names, email addresses, phone numbers, or shipping or billing addresses. Shopify's order webhooks deliver those fields, but the app does not read them. This is a deliberate design decision and is enforced in the code: the order payload type declares only line items and the customer id.
What we collect from shoppers
When a shopper opens a cart on a store using CartStar, the app may record that a product recommendation was shown, clicked, or added to the cart. Each record holds the product id, the type of interaction, and a random session identifier stored in the browser's sessionStorage, which is discarded when the browser tab closes.
This identifier is not linked to a name, an email address, or any account, and is not used to track anyone across other websites. There is no advertising, no profiling, and no third-party analytics or tracking script.
Why we process it
- Product recommendations — ranking products by sales, by what sells alongside what is in the cart, and by attributes.
- Reporting to the merchant — showing that merchant how their own cart performs: revenue attributed to the recommendation rail, and how many shoppers saw, clicked, added and bought.
We use the data for nothing else.
Who we share it with
We do not sell data or share it for advertising. We use these sub-processors to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Shopify | The platform the app runs on | Global |
| Vercel | Application hosting | United States |
| Neon | Database hosting | United States |
We may also disclose data where required by law.
How long we keep it
- Shopper interaction records — deleted automatically after 90 days.
- Order line items — kept while the app is installed, because the recommendation ranking is computed from them.
- Aggregated daily totals — counts and revenue totals with no customer identifier attached.
- Everything — deleted when the merchant uninstalls. Shopify sends a shop redaction request 48 hours after uninstall, and we delete the store's record and every row belonging to it.
When Shopify sends a customer redaction request, we clear the stored customer id from that store's order lines, which unlinks those records from the person.
Security
- All traffic is served over HTTPS.
- Data is encrypted at rest by our database provider, and connections to it require TLS.
- Every webhook is verified by HMAC signature before its contents are read.
- Every database query is scoped to a single store; there is no query path that spans merchants.
- Access to production systems is limited to the developer operating the app.
Requests from shoppers
If you shopped on a store that uses CartStar and want to know what is held about you or want it deleted, contact that store. As a processor we act on the merchant's instruction, and Shopify's data request and redaction flows reach us automatically. You can also write to us at the address below and we will assist the merchant in responding.
International transfers
Data is processed in the United States. If you are located elsewhere, your data will be transferred to and processed there.
Children
CartStar is a business tool sold to merchants and is not directed at children.
Changes
If we change this policy we will update the date at the top. Material changes affecting merchants will be communicated to them directly.
Contact
Appify Market, United States of America
rbisaidev@gmail.com