CartStar Privacy Policy

Last updated 10 August 2026

CartStar is a Shopify app operated by Appify Market ("we", "us"), United States of America. This policy explains what data the app handles, why, and for how long.

Our role

When a merchant installs CartStar, that merchant is the controller of their customers' personal data and we are a processor acting on their instructions. We process data only to provide the app to that merchant. We do not use one merchant's data to serve another, and we do not sell data.

What we collect from a merchant's store

DataWhy
Store domain, name, currency, country, planTo identify the installation and format money correctly
Shopify access tokensTo call the Shopify API on the merchant's behalf
Product catalogue: title, handle, vendor, type, tags, image URL, variants, prices, availability, publication statusTo choose which products to recommend and render them in the cart
Order line items: order id, line item id, product id, variant id, quantity, price, order dateTo rank products by what actually sells, and to attribute purchases the app influenced
Shopify customer idSolely to group order lines by purchaser, so the app can answer "customers who bought this also bought". Never displayed, never exported.
Cart settings the merchant configuresTo render the cart as configured

We do not collect customer names, email addresses, phone numbers, or shipping or billing addresses. Shopify's order webhooks deliver those fields, but the app does not read them. This is a deliberate design decision and is enforced in the code: the order payload type declares only line items and the customer id.

What we collect from shoppers

When a shopper opens a cart on a store using CartStar, the app may record that a product recommendation was shown, clicked, or added to the cart. Each record holds the product id, the type of interaction, and a random session identifier stored in the browser's sessionStorage, which is discarded when the browser tab closes.

This identifier is not linked to a name, an email address, or any account, and is not used to track anyone across other websites. There is no advertising, no profiling, and no third-party analytics or tracking script.

Why we process it

We use the data for nothing else.

Who we share it with

We do not sell data or share it for advertising. We use these sub-processors to run the service:

ProviderPurposeLocation
ShopifyThe platform the app runs onGlobal
VercelApplication hostingUnited States
NeonDatabase hostingUnited States

We may also disclose data where required by law.

How long we keep it

When Shopify sends a customer redaction request, we clear the stored customer id from that store's order lines, which unlinks those records from the person.

Security

Requests from shoppers

If you shopped on a store that uses CartStar and want to know what is held about you or want it deleted, contact that store. As a processor we act on the merchant's instruction, and Shopify's data request and redaction flows reach us automatically. You can also write to us at the address below and we will assist the merchant in responding.

International transfers

Data is processed in the United States. If you are located elsewhere, your data will be transferred to and processed there.

Children

CartStar is a business tool sold to merchants and is not directed at children.

Changes

If we change this policy we will update the date at the top. Material changes affecting merchants will be communicated to them directly.

Contact

Appify Market, United States of America
rbisaidev@gmail.com