Privacy Policy
FlatCart (“we”, “the app”) is a Shopify app that adds a cart drawer and offers (tiered discounts, free gifts, upsells) to your store. This policy explains what data the app handles when you install it on your Shopify store.
The short version
- We store your configuration and anonymous daily counters. We do not store your customers’ names, emails, addresses, or payment details, ever.
- Order data is read only to count what FlatCart earned you, then discarded.
- Uninstall the app and everything is deleted within 48 hours, automatically.
Data we store about your store
- Your store’s
.myshopify.comdomain. - The drawer settings and offers you configure in the app.
- Your FlatCart plan and subscription status.
- Anonymous daily counters: drawer opens, upsell impressions and adds, gift unlocks, checkouts started and completed, and the revenue attributed to offers FlatCart itself added to a cart.
- The numeric ID of each order or refund we have already counted, so the same one is never counted twice.
- Your Shopify access token, so the app can talk to Shopify on your behalf.
Data we do not store
No customer names, emails, phone numbers, addresses, payment details, IP addresses, or cookies. The storefront drawer sends us event names only (“drawer opened”, “upsell added”), never who did it or what they bought. The checkout pixel does the same, and runs only where the shopper has consented to analytics.
Order data
When an order is placed we read its line items, prices and currency to work out whether FlatCart created any of that revenue. We keep the result as a counter and the order’s numeric ID. The rest of the order, including everything about the customer, is never written down.
Retention and deletion
Uninstalling FlatCart revokes our access tokens immediately. If you
reinstall within 48 hours, your settings and analytics are restored exactly
as they were. After 48 hours, all data for your store is permanently
deleted, both by our own scheduled job and in response to Shopify’s
shop/redact webhook, whichever comes first.
Because we hold no customer records, Shopify’s
customers/data_request and customers/redact
webhooks are acknowledged with nothing to return or erase.
Where data lives
The app’s server and database are hosted in the European Union. Error monitoring, when enabled, strips request bodies and cookies before an error is sent.
Sub-processors
| Who | What they process | Where |
|---|---|---|
| Shopify | The store data the app reads through Shopify’s APIs | Per Shopify’s own terms |
| Railway | Application hosting and the Postgres database | European Union |
| Sentry | Error reports, with request bodies and cookies removed | European Union |
Your rights
You can export or delete your data at any time by asking us, and uninstalling does it automatically. Our data processing addendum covers merchants who need one.
Contact
Questions about this policy or your data: support@flatcart.app.