Privacy Policy

CartSync Pro — Last updated: February 9, 2026

1. Introduction

CartSync Pro ("we", "our", "the app") is a Shopify application that synchronizes customer shopping carts across devices. This privacy policy explains what data we collect, how we use it, and how we protect it.

2. Data We Collect

CartSync Pro collects and processes the following data:

We do not collect payment information, passwords, browsing history, personal addresses, or any data beyond what is necessary for cart synchronization.

3. How We Store Data

Cart data is stored exclusively in Shopify customer metafields (namespace: custom, key: custom_cart). This means:

4. Why We Use Customer Metafields

Metafields are used because cart synchronization requires associating cart contents with a specific logged-in customer. When a customer adds items on one device, the cart data must be retrievable on another device. Shopify customer metafields provide a secure, Shopify-native way to store this per-customer data without requiring external databases or third-party services.

5. Why We Access Customer Data

The app requests write_customers and read_products access scopes. Here is why each is needed:

6. Cart Helper — Customer Search

The Cart Helper is an admin-only tool that allows merchants to search for customers and manually manage their saved carts. Customer search is necessary so merchants can:

Customer search results only include name, email, and Shopify customer ID. This tool is accessible only to authenticated store administrators.

7. Client-Side Storage

The app uses browser localStorage and sessionStorage on the storefront for temporary operational data:

No personal or sensitive data is stored in client-side storage.

8. Data Sharing

We do not sell, share, or transfer customer data to any third parties. Cart data is only transmitted between the customer's browser and Shopify's servers via the app proxy (same-origin requests).

9. Data Retention

Cart data is retained in the customer metafield as long as the app is installed and the customer account exists. When a customer empties their cart, the metafield is updated to reflect an empty cart.

When the app is uninstalled, merchants can remove the custom.custom_cart metafield from customer records via Shopify admin. The app does not retain any data after uninstallation.

10. GDPR Compliance & Data Deletion

CartSync Pro complies with GDPR and applicable data protection regulations:

For data deletion requests, merchants or customers can contact us at the email address listed below.

11. Security

All data transmission uses HTTPS. Storefront API requests are routed through Shopify's App Proxy, which verifies HMAC signatures to prevent unauthorized access. Admin API requests require authenticated merchant sessions. Rate limiting is enforced on save operations (10 requests per minute per customer).

12. Contact

For privacy-related questions or data deletion requests, please contact us at:

Email: support@cartsyncpro.com

This privacy policy applies to the CartSync Pro Shopify application.