Last updated: September 25, 2026
This policy is the data protection agreement between CartSuite and the merchant. Installing the app constitutes acceptance. It governs how CartSuite processes store data on the merchant's behalf, and it is available at this address at all times.
CartSuite is built to know as little as possible. We never read, request or store customer names, email addresses, phone numbers, shipping or billing addresses, IP addresses or payment details. We do not use any store data for advertising, marketing or profiling, and we never sell or share it.
When an order is created, Shopify sends us the order webhook. We read a fixed, minimal set of fields and discard the rest of the payload without writing it anywhere:
_cs_seen, _cs_goal, _cartsuite_assisted._cs_src and _cs_rule, which mark a line as coming from a recommendation, add-on, gift, bundle or the sticky cart.These values are added into daily totals immediately: orders per month, revenue added per feature, and units per product. The raw order is never written to disk, and no order can be reconstructed from what we keep.
Data is held in our application database, hosted on Railway, encrypted at rest by the provider and reached only over TLS. Webhooks are verified by HMAC signature. Your configuration is also written to a Shopify app-owned metafield so your storefront never calls our servers for it.
Nobody. We use no analytics, advertising or data-broker services. Our subprocessors are Railway, as the hosting provider, and Brevo, which delivers the setup emails and receives only the owner's email address and the message itself. Access to production is limited to the developer account, protected by two-factor authentication.
Aggregate counters and your configuration are kept for as long as the app is installed. On uninstall your configuration is deleted immediately, and Shopify removes the app-owned metafield automatically.
customers/data_request and customers/redact return without action, because we hold no customer data to return or erase.shop/redact erases everything we hold about the store, including the owner's contact details, email history, usage counters, campaigns, rules and aggregate metrics.If we become aware of a breach affecting store data, we notify the affected merchants and Shopify within 72 hours of detection.
If this policy changes we update the date above. Material changes are announced inside the app.
Questions or requests: info@esldekor.com