CARTO privacy policy
Last updated: September 17, 2026
Who we are
CARTO is a Shopify app by Jamak Lab that adds a customizable cart drawer with upsells and a free-shipping progress bar to a merchant's online store. Contact and support: hello@jamaklab.com.
What we collect from merchants
- Store identifier (myshopify domain).
- An access token issued by Shopify so the app can read products and write its own app metafield.
- The drawer configuration you create (colors, texts, feature toggles, upsell products).
- Your subscription plan status as reported by Shopify, if you are on a paid plan.
What we collect from your customers
Nothing that identifies them. The cart drawer runs on your storefront and talks directly to Shopify's cart. CARTO records only aggregated, anonymous usage events (drawer opened, upsell added, discount applied, checkout clicked) with no customer identifiers, e-mail, IP address or cart contents. CARTO does not set cookies.
How we use data
Only to provide the app: rendering your drawer, showing usage counts in your dashboard and supporting you. We do not sell data or use it for advertising.
Where data is stored
On servers operated by Railway (United States). Data is transmitted over TLS and access is limited to the CARTO team for support and operations.
Retention and deletion
- When you uninstall CARTO, Shopify tokens are revoked immediately.
- All remaining store data is deleted within 48 hours of uninstall, when Shopify sends the shop/redact request.
- You can request earlier deletion at any time by e-mailing support.
GDPR and CCPA
CARTO honours Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact). Because we hold no customer-level data, data requests return no records and redaction requests have nothing to remove. Merchants may exercise their rights of access, correction and deletion by e-mailing support.
Changes
We will update this page and the "last updated" date if our practices change.