CartQuilt (“we,” “us,” or “our”) collects only the data needed to provide, protect, and improve the app. We do not sell personal information or use customer data to build advertising profiles.
1. Operator and contact details
CartQuilt is operated by Guangzhou Zhengjian Information Technology Co., Ltd. This is an app-owner-provided English rendering of 广州正简信息科技有限公司; it is not represented here as an independently verified official registry name.
Registered address as provided by the app owner: Room 2001, 20th Floor, Pazhou Commercial Plaza, Panlong New Street, Haizhu District, Guangzhou, Guangdong 51000, China. Privacy and security email: cartquilt@gmail.com. Urgent privacy or security phone: +1 213 876 0090.
2. Data we process
- Basic store information, such as the store domain, store name, currency, language, and time zone.
- App sessions and access tokens required to authenticate with Shopify and call authorized APIs, plus the authorized staff member’s Shopify user ID, name, email address, language, and account-role information.
- Offer rules created by merchants, product identifiers, display settings, schedules, and A/B test configurations.
- Anonymous widget impression, selection, and add-to-cart events, when permitted by the Shopify Customer Privacy API.
- If a merchant grants order access, Shopify order identifiers, discount amounts, currency, and the associated campaign used for offer attribution. We do not store customer names, email addresses, phone numbers, or postal addresses.
3. How we use data
We use data only to authenticate merchants, synchronize offers with product pages and checkout discounts, provide campaign analytics, troubleshoot issues, prevent abuse, and meet legal obligations.
4. Storefront analytics and local storage
Where analytics processing is permitted by region and consent status, CartQuilt may store a random anonymous identifier and A/B test assignment in the browser to provide a consistent experience. If a customer declines analytics processing, we do not store these analytics identifiers or send analytics events.
5. Sharing and service providers
We share data only as needed to provide the service with Shopify and service providers bound by contractual and security obligations. The production application, self-managed database, and encrypted backups are hosted in the Amazon Web Services (AWS) US East (N. Virginia) Region. We may also disclose necessary information when required by law or to protect lawful rights.
6. Retention, access, and deletion
Store settings and offer configurations are retained while a store uses CartQuilt. PURCHASE events used for offer-order attribution, including the Shopify Order GID, attributed value, currency, and offer identifier, are retained for no more than 180 days and removed by an automated cleanup task. After uninstall, we use Shopify’s mandatory privacy webhooks to delete the store’s sessions, settings, offers, and analytics data. Order identifiers covered by a customer deletion request are removed sooner.
When Shopify sends a customer data access request, we use only the order identifiers in that request to locate the corresponding minimal attribution records. The resulting report is made available to the authenticated merchant in CartQuilt’s Privacy requests page. The order GIDs needed for the request and the generated report are erased immediately after the merchant marks the request complete, and in all cases no later than 30 days after receipt. Audit metadata containing no customer identity—status, counts, and timestamps—may be retained. We do not write the customer name, email address, phone number, or postal address from an access-request payload to the application database or operational logs.
7. Security
We use reasonable safeguards, including least-privilege access, encryption in transit, encrypted EBS storage at rest, age-encrypted database backups, S3 server-side encryption, restricted production access, signed webhook verification, and regular dependency updates. No internet service can guarantee absolute security.
8. International processing
Data may be processed outside the merchant’s country or region. We require service providers to apply safeguards required by applicable law.
9. Your rights and how to contact us
Merchants and customers may request access to, correction of, or deletion of applicable data through the store owner or by emailing cartquilt@gmail.com. Customers should generally submit privacy requests first to the Shopify store where they made their purchase. For more help, visit our support page.
10. Policy updates
We may update this policy as our product, legal requirements, or security practices change. We will post the new update date on this page and notify merchants through reasonable means of material changes.