Privacy policy

Last updated 31 July 2026

This policy covers Cart Craft Studio: Slide Cart (the “app”), a Shopify app published by Cart Craft Studio, a sole proprietorship based in California, United States. It explains what the app reads, what it stores, and for how long.

The short version. The app stores no shopper data at all. The only thing in our database is the authentication session for your shop. Your settings live in Shopify metafields on your own store, not on our servers.

What we store

Our database holds exactly one kind of record: the OAuth session that lets the app talk to your store. Each session contains

  • your shop’s .myshopify.com domain;
  • the access token and refresh token Shopify issued for the app, and their expiry;
  • the access scopes you granted.

That is the whole record, and there is exactly one of them per installed shop. It is updated in place whenever the access token is refreshed, so nothing accumulates over time.

No personal data is stored at all — not about your customers, and not about you or your staff. The app requests offline access only, so it never receives or records the name, email address or user ID of whoever installed or configured it. We hold no names, email addresses, payment details or contact information of any kind.

What we read but don’t store

Orders

The Insights page and the suggested-threshold feature read your recent orders through Shopify’s Admin API using the read_orders scope. Those orders are aggregated in memory to produce the figures shown on the page and then discarded — nothing derived from them is written to our database or sent anywhere else. Closing the page ends the only copy that ever existed.

Products

The read_products scope is used only so you can pick a gift product and upsell variants. We store the IDs you choose in your own store’s metafields, not on our servers.

Where your settings live

Every setting you configure — thresholds, the chosen gift, upsell variants, accent colour, message overrides — is written to metafields on your Shopify store. They belong to you and they stay in your Shopify account. The storefront drawer reads them directly from Shopify through Liquid, so the settings never travel through our servers to reach your shoppers.

What runs on your storefront

The drawer is JavaScript and CSS served from Shopify’s CDN as part of a theme app extension. It contains no analytics, no tracking pixels, no third-party scripts and no calls to any server we control. It talks only to your own store’s cart endpoints.

When a shopper interacts with a feature, the drawer records that on the cart itself — a _cart_suite_gift line-item property on an auto-added gift, and cart attributes noting which upsells were added and whether the free-shipping bar was crossed. These are stored by Shopify in your own cart and order records, which is how the Insights page can attribute revenue. They contain no personal information about the shopper.

Sub-processors

We use the following third parties to run the app. Each has access only to the session data described above.

  • Render (privacy policy) — runs the application server and hosts the PostgreSQL database holding sessions.

That is the entire list. There is no analytics provider, no error-tracking service, no email platform and no advertising network attached to this app.

Shopify itself is not a sub-processor here: it is the source of the data, and its own privacy terms govern your store.

Retention and deletion

  • When you uninstall, Shopify sends an app/uninstalled webhook and we delete every session for your shop.
  • On a shop redaction request (shop/redact, which Shopify sends 48 hours after uninstall), we delete any session records that remain.
  • On a customer data request or redaction request (customers/data_request, customers/redact), we have nothing to return or erase, because we hold no shopper data. We acknowledge these webhooks as Shopify requires.
  • Settings stored in your metafields are yours; delete them from your Shopify admin at any time.

California

Cart Craft Studio is based in California. Where the California Consumer Privacy Act applies to data reached through this app, we act as a service provider to the merchant, processing on their documented instructions and for no other purpose.

We do not sell or share personal information as those terms are defined by the CCPA, and we never have. We do not use merchant or shopper data for advertising, for cross-context behavioural profiling, or to train any model. We do not retain, use or disclose it outside the direct business purpose of providing the app’s features.

Your rights

Depending on where you are, you may have the right to access, correct, export or erase the personal data we hold about you, and to object to or restrict our processing of it. Since the only personal data we hold is merchant staff session data, uninstalling the app satisfies most of these requests immediately. For anything else, write to support@cartcraftstudio.com and we’ll respond within 30 days.

Security

All traffic to the app is served over TLS. Access tokens are stored in a database that is not publicly reachable. We request the narrowest set of Shopify access scopes the app’s features actually need, and no more.

Changes to this policy

If we change how the app handles data, we’ll update this page and change the date at the top. Material changes affecting merchants will also be sent to the email address on your Shopify account.

Contact

Questions about this policy, or about your data: support@cartcraftstudio.com. For help using the app, see Support.