Legal
Privacy Policy
How this document differs from our Terms and Conditions: our Terms govern the commercial relationship between Agentic Cart and merchants. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have.
1. Who we are
Data controller: Creativity Insight UK Ltd, a company incorporated in England and Wales. Registered address: 26 Mauratania Way, Brooklands, MK10 7HL.
Contact: support@agentic-cart.com
Website: app.agentic-cart.com
We operate app.agentic-cart.com, an AI-powered operational platform for direct-to-consumer Shopify merchants. We are the data controller for data we collect about you (merchants and their team members) and a data processor when we handle personal data on your behalf (your customers' order data).
2. What data we collect and why
2.1 Merchant and team member data
When you install Agentic Cart and use the Service, we collect:
| Data | Source | Why we collect it |
|---|---|---|
| Shopify user ID (shopify_user_id) | Shopify OAuth | Identifies you uniquely across sessions. Your primary account identifier in our system. |
| Name | Shopify OAuth | Displayed in the dashboard greeting and used in email communications. |
| Email address | Shopify OAuth | Notifications, trial reminders, billing alerts, and security alerts. Required for team invitations. |
| Shopify store domain | Shopify OAuth | Identifies your store. Used to scope all data and permissions to the correct store. |
| Account owner flag (account_owner) | Shopify OAuth | Determines whether you are the store owner and can complete onboarding. |
| Role (Owner, Approver, Viewer) | Set by store owner | Controls what you can see and do within the Service. |
| Notification preferences | Set by you in Settings | Controls which emails you receive from us. |
| IP address | Inferred from requests | Rate limiting and security monitoring. Stored in FailedAccessAttempt records where relevant. |
| Login timestamps | System-generated | Stored in the audit log for security purposes. |
2.2 Store operational data
To power the Supply Readiness Agent, we access and store the following data from your Shopify store:
| Data | Source | Why we collect it |
|---|---|---|
| Product names, SKU identifiers, variant details | Shopify GraphQL Admin API | Populate the SKU selector and identify monitored products. |
| Inventory quantities per variant | Shopify GraphQL Admin API | Calculate current stock levels for each monitored SKU. |
| Order history — units sold, revenue, SKU ID, order date, and is_new_customer flag (boolean — derived, not a customer identifier) — 90-day rolling window | Shopify GraphQL Admin API | Calculate Daily Run Rate (DRR) for reorder recommendations. SKU-level aggregates only. |
| Shopify order IDs | Shopify GraphQL Admin API | Enable compliance with customers/redact GDPR webhooks. Not used for any other purpose. |
| Store plan and configuration | Shopify GraphQL Admin API | Understand store context for the Risk Profile. |
What we do NOT collect from your store
We do not collect or store: customer names, customer email addresses, customer postal addresses, customer phone numbers, payment card details, or any customer personally identifiable information beyond what is inherent in an order ID. The Supply Readiness Agent works entirely on inventory and aggregate sales velocity data.
We do not currently access advertising platform data (Meta Ads, Google Ads, TikTok Ads). These integrations are planned for a future release and will require your explicit separate authorisation when available.
2.3 Technical and usage data
| Data | Purpose |
|---|---|
| JWT session tokens (in httpOnly cookie) | Authenticates your session. Expires after 60 minutes. Stored only in your browser. |
| OAuth state nonces | Prevents CSRF during Shopify authentication. Redis, 5-minute TTL. Deleted after use. |
| Audit log entries | Records state-changing actions for security and accountability. Append-only. |
| FailedAccessAttempt records | Store ID, user ID, timestamp, and IP when access is denied. Rate limiting and owner notification. |
| AgentRun records | When agents ran, SKUs evaluated, recommendations created. Operational monitoring. |
3. How we collect data
- Shopify OAuth: when you install and authenticate, Shopify passes your identity to us.
- Shopify GraphQL Admin API: our sync worker reads product, inventory, and order data nightly after onboarding.
- You directly: Risk Profile, team invitations, notification preferences, Recommendations.
- Automatically: IP addresses, request timestamps, and error logs when you use the Service.
4. Legal bases for processing
| Processing activity | Legal basis | Explanation |
|---|---|---|
| Account creation, onboarding, authentication | Contract (Art. 6(1)(b)) | Necessary to provide the Service. |
| Nightly Shopify data sync | Contract (Art. 6(1)(b)) | The Service cannot function without reading your store data. |
| Generating and storing Recommendations | Contract (Art. 6(1)(b)) | Core deliverable of the Service. |
| Trial expiry and billing notifications | Contract (Art. 6(1)(b)) | Manage the commercial relationship. |
| Audit logging and security monitoring | Legitimate interests (Art. 6(1)(f)) | Maintain security and integrity of the Service. |
| Rate limiting and failed access records | Legitimate interests (Art. 6(1)(f)) | Protect merchants and the platform from unauthorised access. |
| Responding to GDPR data subject requests | Legal obligation (Art. 6(1)(c)) | Required by law and Shopify platform rules. |
| Improving Agent accuracy from rejection feedback | Legitimate interests (Art. 6(1)(f)) | Structured rejection reason codes only — no personal data. |
5. How we use your data
- To provide the Service — account, Supply Readiness Agent, Recommendations, subscription.
- To communicate — trial reminders, payment failure alerts, security notifications, product updates.
- To secure the Service — rate limiting, HMAC verification, audit logging.
- To improve the Service — structured rejection reason codes (not personal data).
- To comply with legal obligations — GDPR requests and Shopify compliance webhooks.
What we never do: We do not sell your data. We do not use Store Data to train general-purpose AI models accessible by other customers. We do not serve advertising. We do not share your data except as described in Section 6.
6. Who we share data with
| Recipient | Data shared | Purpose | Safeguard |
|---|---|---|---|
| Shopify Inc. | Store domain, OAuth tokens, billing events | App distribution, OAuth, Shopify Billing API | Shopify Partner Programme Agreement |
| Vercel (current MVP) | Frontend code and request logs | Hosting app.agentic-cart.com | Vercel DPA |
| Railway (current MVP) | Backend logs, environment variables | Hosting backend API | Railway DPA |
| Supabase (current MVP) | All Store Data and user data | Database hosting (EU region) | Supabase DPA, EU region |
| Google Cloud Platform (future) | All Store Data on migration | Production infrastructure (europe-west2, London) | GCP DPA, UK region |
| Shopify (GDPR webhooks) | Order IDs on redaction requests | Customer data deletion requests | Mandatory legal obligation |
We do not share your data with advertising networks, data brokers, analytics companies, or any other third party not listed above.
7. International transfers
Store Data is currently stored in the European Union (Supabase, EU region). We are migrating to Google Cloud Platform in europe-west2 (London, United Kingdom). Shopify Inc. operates globally; OAuth and billing flows are subject to Shopify's Privacy Policy and transfer safeguards including standard contractual clauses under UK GDPR.
8. How long we keep data
| Data | Retention period | Reason |
|---|---|---|
| Account data (AppUser, StoreMember) | Active subscription + 90 days after termination | Reinstallation and post-termination disputes. |
| Store operational data | Order rows: 90 days rolling from order date (automatic cron deletion). Other data: subscription + 30 days after termination. | Minimise data footprint; sufficient history for DRR calculations. |
| Audit log entries | 3 years from creation | Security, compliance, dispute resolution. |
| FailedAccessAttempt records | 90 days | Security monitoring. |
| AgentRun records | 12 months | Operational monitoring. |
| OAuth state nonces | 5 minutes (Redis TTL) | Single-use security tokens. |
| Session tokens (JWT cookies) | 60 minutes | Browser only — not stored in our database. |
| Shopify order IDs (GDPR) | Until redacted via customers/redact, then deleted within 30 days | Shopify GDPR compliance. |
| Email addresses for notifications | Until account deleted or you unsubscribe | Transactional emails only. |
9. Security
- Short-lived JWTs (60 minutes) in httpOnly Secure SameSite=Strict cookies.
- HTTPS for all connections; SSL between services and database.
- Encryption at rest; secrets in encrypted vaults.
- HMAC verification on all Shopify OAuth callbacks and webhooks.
- Rate limiting: three failed attempts in one hour triggers a 24-hour block.
- Immutable audit logging for all state-changing actions.
- Server-side role enforcement on every API request.
If you believe your account has been compromised, contact support@agentic-cart.com immediately.
10. Your rights
| Right | What it means | How to exercise it |
|---|---|---|
| Access | Copy of personal data we hold about you | Email support@agentic-cart.com — response within 30 days. |
| Rectification | Correction of inaccurate data | Email support@agentic-cart.com or update in Settings. |
| Erasure | Deletion of your personal data | Email support@agentic-cart.com or remove the app from Shopify Admin. |
| Restriction | Stop processing in certain circumstances | Email support@agentic-cart.com with details. |
| Portability | Structured, machine-readable export | Email support@agentic-cart.com — JSON or CSV export. |
| Object | Object to legitimate-interests processing | Email support@agentic-cart.com — response within 30 days. |
Right to complain: UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
11. Merchant customers — your responsibilities
- You are the data controller for your customers' personal data.
- We are the data processor acting on your behalf.
- Ensure your customers know third-party apps may process their data.
- customers/redact: we delete relevant order records within 30 days.
- customers/data_request: we locate order rows matching webhook order IDs. If matches exist, we provide a CSV export of SKU-level analytics (order ID, SKU, units, revenue, order date, is_new_customer) to you as store owner — not directly to end customers.
12. Cookies
| Cookie | Type | Purpose | Expiry |
|---|---|---|---|
| session | Strictly necessary — httpOnly Secure SameSite=Strict | JWT authentication token | 60 minutes (sliding window) |
| csrf_token | Strictly necessary | CSRF protection | Session |
We do not use advertising, tracking, or analytics cookies. No third-party cookies are set by the Service. See also our Cookie Policy.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email and by updating the effective date at the top of this page. The current version is always available at app.agentic-cart.com/legal/privacy.
14. Contact and complaints
Email: support@agentic-cart.com
Website: app.agentic-cart.com
Registered address: Creativity Insight UK Ltd, 26 Mauratania Way, Brooklands, MK10 7HL