Legal
Privacy Policy
How this document differs from our Terms and Conditions: our Terms govern the commercial relationship between Agentic Cart and merchants. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have.
1. Who we are
Data controller: Creativity Insight UK Ltd, a company incorporated in England and Wales. Registered address: 26 Mauratania Way, Brooklands, MK10 7HL.
Contact: support@agentic-cart.com
Website: app.agentic-cart.com
We operate app.agentic-cart.com, an AI-powered operational platform for direct-to-consumer Shopify merchants. We are the data controller for data we collect about you (merchants and their team members) and a data processor when we handle personal data on your behalf (your customers' order data).
2. What data we collect and why
2.1 Merchant and team member data
When you install Agentic Cart and use the Service, we collect:
| Data | Source | Why we collect it |
|---|---|---|
| Shopify user ID (shopify_user_id) | Shopify OAuth | Identifies you uniquely across sessions. Your primary account identifier in our system. |
| Name | Shopify OAuth | Displayed in the dashboard greeting and used in email communications. |
| Email address | Shopify OAuth | Notifications, trial reminders, billing alerts, and security alerts. Required for team invitations. |
| Shopify store domain | Shopify OAuth | Identifies your store. Used to scope all data and permissions to the correct store. |
| Account owner flag (account_owner) | Shopify OAuth | Determines whether you are the store owner and can complete onboarding. |
| Role (Owner, Approver, Viewer) | Set by store owner | Store-scoped permissions for dashboards and recommendations. Some older tenant-scoped admin APIs treat anyone who is not the store Owner as a member (read-only), even if their store role is Approver. |
| Notification preferences | Set by you in Settings | Controls which emails you receive from us. |
| IP address | Inferred from requests | Rate limiting and security monitoring. Stored in FailedAccessAttempt records where relevant. |
| Login timestamps | System-generated | Stored in the audit log for security purposes. |
2.2 Store operational data
To power the Supply Readiness Agent, we access and store the following data from your Shopify store:
| Data | Source | Why we collect it |
|---|---|---|
| Product names, SKU identifiers, variant details | Shopify GraphQL Admin API | Populate the SKU selector and identify monitored products. |
| Inventory quantities per variant | Shopify GraphQL Admin API | Calculate current stock levels for each monitored SKU. |
| Order history — units sold, revenue, SKU ID, order date, and is_new_customer flag (boolean — derived, not a customer identifier) — 90-day rolling window | Shopify GraphQL Admin API | Calculate Daily Run Rate (DRR) for reorder recommendations. SKU-level aggregates only. |
| Shopify order IDs | Shopify GraphQL Admin API | Enable compliance with customers/redact GDPR webhooks. Not used for any other purpose. |
| Store plan and configuration | Shopify GraphQL Admin API | Understand store context for the Risk Profile. |
What we do NOT collect from your store
We do not collect or store: customer names, customer email addresses, customer postal addresses, customer phone numbers, payment card details, or any customer personally identifiable information beyond what is inherent in an order ID. The Supply Readiness Agent works entirely on inventory and aggregate sales velocity data.
With your explicit OAuth authorisation (Growth plan) we may connect Meta Ads and/or Google Ads to read advertising performance metrics for the ad account you select. See Section 2.4 for details. We do not access TikTok Ads. You can disconnect these integrations at any time in Settings → Integrations. For Meta platform data-deletion requests, use Facebook's app removal / deletion flow; status is available at /legal/data-deletion/status with the confirmation code Meta provides.
2.4 Advertising platform data (Growth plan, optional)
If you connect Meta or Google Ads, we store OAuth credentials and account identifiers needed to sync read-only ad performance data. We do not collect end-customer PII from ad platforms.
| Data | Source | Why we collect it |
|---|---|---|
| Meta access token, Facebook app-scoped user ID, selected ad account ID | Meta OAuth (ads_read) | Authenticate and read ad spend metrics for the account you choose. |
| Meta ad account names and IDs | Meta Marketing API | Display the account picker and attribute spend to your store. |
| Google Ads refresh token, selected customer ID, manager (login) customer ID when applicable | Google OAuth (adwords scope) | Authenticate and read campaign spend for the customer account you choose. |
| Google Ads customer account names and IDs | Google Ads API | Display the account picker and attribute spend to your store. |
| Daily ad metrics (spend, impressions, clicks, conversions) by platform and date | Meta Insights / Google Ads API | Power dashboards and "ad spend at risk" analytics on monitored SKUs. |
| Meta data-deletion confirmation codes | Meta data-deletion callback | Provide status on deletion requests via our status page. |
2.3 Technical and usage data
| Data | Purpose |
|---|---|
| ac_pivot_auth cookie (httpOnly, Secure) | Shopify sign-in session for app.agentic-cart.com. 7-day sliding expiry. Stored in the browser only — not as a JWT session cookie. |
| OAuth state nonces | Prevents CSRF during Shopify, Meta, and Google OAuth. Stored in our database (oauth_state), 5-minute TTL, deleted after single use. |
| Audit log entries | Records state-changing actions for security and accountability. Append-only. |
| FailedAccessAttempt records | Store ID, user ID, timestamp, and IP when access is denied. Rate limiting and owner notification. |
| AgentRun records | When agents ran, SKUs evaluated, recommendations created. Operational monitoring. |
3. How we collect data
- Shopify OAuth: when you install and authenticate, Shopify passes your identity to us.
- Shopify GraphQL Admin API: our sync worker reads product, inventory, and order data nightly after onboarding.
- Meta Ads OAuth (Growth, optional): when you connect Meta, we receive tokens and ad account access you authorise.
- Google Ads OAuth (Growth, optional): when you connect Google Ads, we receive tokens and customer account access you authorise.
- You directly: Risk Profile, team invitations, notification preferences, Recommendations, ad account selection.
- Automatically: IP addresses, request timestamps, and error logs when you use the Service.
4. Legal bases for processing
| Processing activity | Legal basis | Explanation |
|---|---|---|
| Account creation, onboarding, authentication | Contract (Art. 6(1)(b)) | Necessary to provide the Service. |
| Nightly Shopify data sync | Contract (Art. 6(1)(b)) | The Service cannot function without reading your store data. |
| Meta / Google Ads sync (Growth, when connected) | Contract (Art. 6(1)(b)) | Optional feature you enable via OAuth to read ad performance for your selected account. |
| Generating and storing Recommendations | Contract (Art. 6(1)(b)) | Core deliverable of the Service. |
| Trial expiry and billing notifications | Contract (Art. 6(1)(b)) | Manage the commercial relationship. |
| Audit logging and security monitoring | Legitimate interests (Art. 6(1)(f)) | Maintain security and integrity of the Service. |
| Rate limiting and failed access records | Legitimate interests (Art. 6(1)(f)) | Protect merchants and the platform from unauthorised access. |
| Responding to GDPR data subject requests | Legal obligation (Art. 6(1)(c)) | Required by law and Shopify platform rules. |
| Improving Agent accuracy from rejection feedback | Legitimate interests (Art. 6(1)(f)) | Structured rejection reason codes only — no personal data. |
5. How we use your data
- To provide the Service — account, Supply Readiness Agent, Recommendations, subscription, and optional ad spend analytics on Growth.
- To communicate — trial reminders, payment failure alerts, security notifications, product updates.
- To secure the Service — rate limiting, HMAC verification, audit logging.
- To improve the Service — structured rejection reason codes (not personal data).
- To comply with legal obligations — GDPR requests and Shopify compliance webhooks.
What we never do: We do not sell your data. We do not use Store Data to train general-purpose AI models accessible by other customers. We do not serve advertising. We do not share your data except as described in Section 6.
6. Who we share data with
| Recipient | Data shared | Purpose | Safeguard |
|---|---|---|---|
| Shopify Inc. | Store domain, OAuth tokens, billing events | App distribution, OAuth, Shopify Billing API | Shopify Partner Programme Agreement |
| Vercel | Frontend code and HTTP request logs | Hosting app.agentic-cart.com (global edge; application origin is not the Store Data database) | Vercel DPA |
| Railway | API logs and environment variables | Hosting api.agentic-cart.com (not the Store Data database) | Railway DPA |
| Supabase | All Store Data and user data | PostgreSQL in London, United Kingdom (eu-west-2) | Supabase DPA, UK region |
| Resend | Recipient email address and message content | Transactional mail (trial, invite, uninstall, billing) | Resend DPA |
| Upstash (optional) | Job payloads and cache keys — no customer PII by design | Redis queue/cache only when configured | Upstash DPA (when used) |
| Google Gemini (optional) | Already-computed recommendation text, not raw customer records | Optional phrasing of agent copy when enabled | Google Cloud terms (when used) |
| Google Cloud Platform (intended, not current) | None today — planned lift-and-shift only | We intend to migrate to europe-west2 (London). Not in production yet. | GCP DPA, UK region (when used) |
| Meta Platforms, Inc. | OAuth tokens and API requests to read your authorised ad account metrics | Meta Ads integration (when you connect) | Meta Platform Terms and your OAuth consent |
| Google LLC | OAuth tokens and API requests to read your authorised Google Ads customer metrics | Google Ads integration (when you connect) | Google API Services User Data Policy and your OAuth consent |
| Shopify (GDPR webhooks) | Order IDs on redaction requests | Customer data deletion requests | Mandatory legal obligation |
We do not sell your data to advertising networks, data brokers, or analytics companies. When you connect Meta or Google Ads, we call those platforms' APIs using your authorised tokens solely to read metrics for your account — we do not share your Store Data with them for their own marketing purposes.
7. International transfers
Store Data is stored in Supabase in London, United Kingdom (eu-west-2). Vercel and Railway host the web app and API and may process request logs outside the UK/EEA. We intend to migrate compute to Google Cloud Platform in europe-west2 (London, United Kingdom). Shopify Inc. operates globally; OAuth and billing flows are subject to Shopify's Privacy Policy and transfer safeguards including standard contractual clauses under UK GDPR. Meta Platforms and Google operate globally; when you connect those integrations, ad metric API calls are subject to their respective privacy policies and transfer mechanisms.
8. How long we keep data
| Data | Retention period | Reason |
|---|---|---|
| Account data (AppUser, StoreMember) | Active subscription + 90 days after termination | Reinstallation and post-termination disputes. |
| Store operational data | Order rows: 90 days rolling from order date (automatic cron deletion). Other data: subscription + 30 days after termination. | Minimise data footprint; sufficient history for DRR calculations. |
| Audit log entries | 3 years from creation | Security, compliance, dispute resolution. |
| FailedAccessAttempt records | 90 days | Security monitoring. |
| AgentRun records | 12 months | Operational monitoring. |
| OAuth state nonces | 5 minutes (database TTL; deleted on use) | Single-use CSRF protection for OAuth flows. |
| Meta / Google OAuth credentials and account linkage | While the integration is connected; deleted on disconnect or Meta data-deletion callback | Required to sync ad metrics; removed when you revoke access. |
Aggregate ad spend metrics (ad_spend_daily) | While your subscription is active + 30 days after termination (same as other Store operational analytics), unless deleted earlier via shop/redact. After a Meta platform data-deletion request we disconnect and delete Meta OAuth credentials immediately; previously synced aggregate ad metrics for your store may be retained for this period but are no longer linked to your Facebook user ID. | Historical analytics for dashboards; minimised and tenant-scoped. |
| Meta data-deletion confirmation records | 12 months from request | Status lookup for Meta platform deletion requests. |
| Session cookie (ac_pivot_auth) | 7 days (sliding) | Browser only — not stored in our database. |
| Shopify order IDs (GDPR) | Until redacted via customers/redact, then deleted within 30 days | Shopify GDPR compliance. |
| Email addresses for notifications | Until account deleted or you unsubscribe | Transactional emails only. |
9. Security
- httpOnly Secure
ac_pivot_authcookie (7-day sliding session). - HTTPS for all connections; TLS between services and the database.
- Database disk encryption at rest (Supabase). Integration tokens are stored in the database, readable only by the backend service role — not application-level field encryption today.
- HMAC verification on all Shopify OAuth callbacks and webhooks.
- Rate limiting: three failed attempts in one hour triggers a 24-hour block.
- Immutable audit logging for all state-changing actions.
- Server-side role enforcement on every API request.
If you believe your account has been compromised, contact support@agentic-cart.com immediately.
10. Your rights
| Right | What it means | How to exercise it |
|---|---|---|
| Access | Copy of personal data we hold about you | Email support@agentic-cart.com — response within 30 days. |
| Rectification | Correction of inaccurate data | Email support@agentic-cart.com or update in Settings. |
| Erasure | Deletion of your personal data | Email support@agentic-cart.com or remove the app from Shopify Admin. |
| Restriction | Stop processing in certain circumstances | Email support@agentic-cart.com with details. |
| Portability | Structured, machine-readable export | Email support@agentic-cart.com — JSON or CSV export. |
| Object | Object to legitimate-interests processing | Email support@agentic-cart.com — response within 30 days. |
Right to complain: UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
11. Merchant customers — your responsibilities
- You are the data controller for your customers' personal data.
- We are the data processor acting on your behalf.
- Ensure your customers know third-party apps may process their data.
- customers/redact: we delete relevant order records within 30 days.
- customers/data_request: we persist the request, locate order rows matching webhook order IDs, and log the match count. We do not email a CSV automatically. Store owners can request a manual export at support@agentic-cart.com.
12. Cookies
| Cookie | Type | Purpose | Expiry |
|---|---|---|---|
| ac_pivot_auth | Strictly necessary — httpOnly Secure | Shopify sign-in session for app.agentic-cart.com | 7 days (sliding) |
We do not use advertising, tracking, or analytics cookies. No third-party cookies are set by the Service. See also our Cookie Policy.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email and by updating the effective date at the top of this page. The current version is always available at app.agentic-cart.com/legal/privacy.
14. Contact and complaints
Email: support@agentic-cart.com
Website: app.agentic-cart.com
Registered address: Creativity Insight UK Ltd, 26 Mauratania Way, Brooklands, MK10 7HL