cartly.Back to Cartly

PRIVACY POLICY

How Cartly handles your data.

Cartly holds two kinds of personal data: yours as a merchant, and your customers’ details that you upload so we can work on your behalf. This page says plainly what we keep, why, where it is, and how to get it out.

Effective 15 September 2026 · Cartly, operated from India · pratikr557@gmail.com

Contents

  1. 1Who we are
  2. 2What we collect
  3. 3How we use it
  4. 4Legal bases
  5. 5Your customers’ data
  6. 6Sub-processors
  7. 7Where data is stored
  8. 8How long we keep it
  9. 9Your rights
  10. 10India DPDP Act and GDPR
  11. 11Cookies
  12. 12Security
  13. 13Children
  14. 14Changes to this policy
  15. 15Contact

Other documents

Terms of ServiceData Processing Addendum

1. Who we are

Cartly is a commerce platform for Shopify merchants, available at joincartly.com. It is operated by Cartly from India. You can reach us at pratikr557@gmail.com.

This policy explains what personal data we collect, why, where it lives, who else touches it, and what you can do about it. It covers two groups of people: merchants who create a Cartly account, and merchants’ customers whose details a merchant uploads or connects so Cartly can work on the merchant’s behalf.

2. What we collect

Merchant account

When you sign in with Google or with a magic link, we store your email address and, if Google provides it, your name. We do not receive or store your Google password. We store the workspace you create, the settings you choose and the time of your sign-ins.

Business data you upload

Cartly works from Shopify CSV exports you choose to upload, and from integrations you connect. Depending on what you bring over, this includes:

  • Products — titles, descriptions, variants, prices, inventory and images.
  • Customers — names, email addresses, phone numbers, tags and order history.
  • Orders — line items, amounts, shipping and billing addresses, and fulfilment status.

Integration credentials

To send WhatsApp messages through Waplify and to book shipments through Shiprocket, you give Cartly the API credentials for your own accounts with those services. We store these encrypted at rest and use them only to act on your instructions.

Usage logs

We keep operational logs of what Cartly did for you: which messages were queued and delivered, which shipments were created, which imports ran, and any errors. Our infrastructure also records standard request logs such as IP address, browser type and timestamps, which we use for security and debugging.

3. How we use it

  • To run your workspace: importing your store data, showing your products, customers and orders, and keeping them in sync.
  • To act on your behalf: sending WhatsApp messages to your customers, creating shipments and labels, and generating product copy or images when you ask for them.
  • To keep the service secure: authenticating sign-ins, detecting abuse and diagnosing faults.
  • To talk to you about your account, including service notices and changes to these documents.
  • To tell you about Cartly features, only if you have opted in, and you can opt out at any time.

We do not sell personal data, and we do not use your customers’ data to advertise to them or to build profiles for anyone other than you.

4. Legal bases

Where a legal basis is required, we rely on:

  • Performance of a contract — providing the service you signed up for, including processing the customer and order data you upload.
  • Legitimate interest — keeping the service secure, preventing abuse, fixing bugs and understanding how Cartly is used, in ways that do not override your interests.
  • Consent — sending you marketing about Cartly. You can withdraw consent at any time and it will not affect your use of the service.

5. Your customers’ data

For the customer, product and order data a merchant uploads, the merchant is the data controller and Cartly is the data processor. We process that data only to provide the service and only on the merchant’s instructions. The merchant is responsible for having a lawful basis to collect it and, in particular, for having the consent needed to message customers on WhatsApp.

The terms of that processing are set out in our Data Processing Addendum, which forms part of the agreement with every merchant.

If you are a customer of a Cartly merchant and want to know what a store holds about you, contact the store directly. If you write to us instead, we will pass your request to the merchant and help them respond.

6. Sub-processors

We use a small number of service providers to run Cartly. Each one receives only the data needed for its job.

ProviderWhat it doesData it handlesLocation
SupabaseDatabase, authentication and file storageAll account and business dataMumbai, India
CloudflareHosting, edge network and scheduled jobsRequest data passing through the applicationGlobal edge network
GoogleSign-in with GoogleYour email address and name at sign-inGlobal
WaplifyWhatsApp Business messagingCustomer phone numbers and message contentAs per Waplify’s terms
ShiprocketShipping and courier bookingOrder details and delivery addressesIndia
OpenAIText and image generation in StudioProduct details you choose to generate fromUnited States

We will update this list when a provider changes and, where the change materially affects your customers’ data, we will tell merchants by email before it takes effect.

7. Where data is stored

Your account and business data are stored in Supabase’s Mumbai (India) region. The Cartly application runs on Cloudflare’s global edge network, which means requests may be served from a data centre near you; the data itself remains in the Mumbai region unless you connect a service located elsewhere.

Data sent to Waplify, Shiprocket, Google or OpenAI is transferred to wherever those services operate, as described above. For merchants in the European Economic Area or United Kingdom, those transfers are covered by the providers’ standard contractual terms.

8. How long we keep it

  • Raw CSV rows — the uploaded files and their unprocessed rows are deleted 90 days after import. The imported records (products, customers, orders) remain in your workspace.
  • Account and workspace data — kept until you delete your account, or until we delete a workspace that has been inactive for a long period after giving notice.
  • Integration credentials — deleted immediately when you disconnect an integration or delete your account.
  • Usage and request logs — kept for up to 90 days for security and debugging, then deleted or anonymised.
  • Backups — our database provider keeps short-rotation backups; deleted data drops out of them as they rotate.

9. Your rights

Whatever your location, you can:

  • Access and export your data — from Settings in your workspace, or by emailing us.
  • Correct anything that is wrong.
  • Delete your account and everything in it — from Settings, or by emailing us. We complete deletion within 30 days.
  • Object to processing based on legitimate interest, and withdraw consent for marketing at any time.
  • Complain to your local data protection authority if you think we have got something wrong. We would rather you told us first so we can fix it.

Requests go to pratikr557@gmail.com. We will answer within 30 days and may ask you to confirm you own the account.

10. India DPDP Act and GDPR

India

Cartly is based in India and follows the Digital Personal Data Protection Act, 2023. For merchant account data we are the Data Fiduciary; for customer data uploaded by merchants, the merchant is the Data Fiduciary and Cartly is a Data Processor. You may exercise your rights under the Act, including access, correction, erasure and grievance redressal, by writing to the contact address above. If you are not satisfied with our response you may approach the Data Protection Board of India.

European Economic Area and United Kingdom

If you are in the EEA or UK, the GDPR or UK GDPR applies. The legal bases we rely on are listed in section 4. We do not currently have a representative in the EU or UK; contact us directly. Transfers outside the EEA and UK rely on standard contractual clauses or the equivalent measures offered by each provider.

11. Cookies

Cartly uses only the cookies needed to keep you signed in: session cookies set by our authentication provider. We do not use advertising cookies, analytics cookies or third-party trackers on the marketing site or in the application. Because these cookies are strictly necessary, there is no cookie banner.

12. Security

All traffic to Cartly is encrypted in transit. Integration credentials are encrypted at rest. Access to production systems is limited to the people who operate Cartly. We keep our dependencies up to date and review changes before they ship.

Cartly is a small, early-stage service. We have not yet undergone a third-party security audit or certification, and we do not claim one. If you find a security problem, please tell us at pratikr557@gmail.com.

13. Children

Cartly is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If a merchant uploads customer records that include a child’s data, the merchant is responsible for having the required consent.

14. Changes to this policy

We will update this policy as Cartly grows. Small changes will simply be published here with a new effective date. If a change affects what we collect or how we use it in a way you would care about, we will email account holders before it takes effect.

15. Contact

Cartly
Email: pratikr557@gmail.com
Web: joincartly.com

Questions about this document? Write to pratikr557@gmail.com.

Privacy PolicyTerms of ServiceData Processing Addendum