Back to home

Privacy Policy

Last updated: 26 March 2026

Cart Keeper (“we”, “our”, or “us”) is committed to protecting the privacy of Shopify merchants who use our app and the end-customers whose data is processed through it. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it.

By installing or using Cart Keeper, you agree to the practices described in this policy.

1. Information we collect

From merchants (you)

  • Shopify store URL and shop name
  • Email address associated with your Shopify account
  • Billing information (processed by Shopify — we never store card details)
  • App configuration settings (email sequences, templates, timing)

From your customers (on your behalf)

  • Customer name and email address
  • Cart contents (product names, quantities, prices)
  • Email engagement data (open and click events)
  • Checkout and order status (to stop emails after purchase)

We only collect customer data that is necessary to deliver the cart recovery service on your behalf. We act as a data processor for your customers' data; you remain the data controller.

2. How we use your information

  • To deliver and operate the Cart Keeper service
  • To send abandoned cart recovery emails on your behalf
  • To provide analytics and reporting within the app
  • To process billing and manage your subscription
  • To respond to support requests
  • To improve and develop the app

We do not sell, rent, or share your data or your customers' data with third parties for marketing purposes.

3. Data sharing and third parties

We use a limited number of trusted third-party services to operate Cart Keeper:

  • Shopify — our app runs within the Shopify platform and is subject to Shopify's own privacy practices.
  • Email delivery provider — we use a transactional email service to send recovery emails on your behalf. They process email addresses and message content only.
  • Hosting and infrastructure — our application runs on cloud infrastructure in the EU and US.

All third-party providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

4. Data retention

We retain merchant account data for as long as your Cart Keeper subscription is active, plus 30 days after cancellation to allow for reactivation. Customer email and cart data is retained for a rolling 12-month period, after which it is automatically deleted. You can request earlier deletion at any time.

5. Your customers' rights (GDPR & CAN-SPAM)

Cart Keeper is designed to help you stay compliant:

  • Every recovery email includes a one-click unsubscribe link. Unsubscribes are processed immediately and permanently.
  • Customers who unsubscribe are never emailed again, even if they abandon future carts.
  • You can delete a customer's data at any time from the Cart Keeper dashboard.
  • We support Shopify's mandatory GDPR webhooks for customer data requests and deletions.

6. Cookies and tracking

Cart Keeper uses cookies and similar tracking technologies within the Shopify admin to maintain your session and remember app preferences. Recovery emails may contain tracking pixels to record open and click events. These are standard industry practices and are disclosed in the emails we send on your behalf.

7. Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No method of transmission over the internet is 100% secure, but we take all reasonable steps to protect your data.

8. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Cart Keeper app at least 14 days before changes take effect. Your continued use of Cart Keeper after that date constitutes acceptance of the updated policy.

9. Contact us

If you have questions about this Privacy Policy, wish to exercise your rights, or want to report a concern, please contact us at info@cartkeeper.app.