1. Who we are
Cartly is a commerce platform for Shopify merchants, available at joincartly.com. It is operated by Cartly from India. You can reach us at pratikr557@gmail.com.
This policy explains what personal data we collect, why, where it lives, who else touches it, and what you can do about it. It covers two groups of people: merchants who create a Cartly account, and merchants’ customers whose details a merchant uploads or connects so Cartly can work on the merchant’s behalf.
2. What we collect
Merchant account
When you sign in with Google or with a magic link, we store your email address and, if Google provides it, your name. We do not receive or store your Google password. We store the workspace you create, the settings you choose and the time of your sign-ins.
Business data you upload
Cartly works from Shopify CSV exports you choose to upload, and from integrations you connect. Depending on what you bring over, this includes:
- Products — titles, descriptions, variants, prices, inventory and images.
- Customers — names, email addresses, phone numbers, tags and order history.
- Orders — line items, amounts, shipping and billing addresses, and fulfilment status.
Integration credentials
To send WhatsApp messages through Waplify and to book shipments through Shiprocket, you give Cartly the API credentials for your own accounts with those services. We store these encrypted at rest and use them only to act on your instructions.
Usage logs
We keep operational logs of what Cartly did for you: which messages were queued and delivered, which shipments were created, which imports ran, and any errors. Our infrastructure also records standard request logs such as IP address, browser type and timestamps, which we use for security and debugging.
3. How we use it
- To run your workspace: importing your store data, showing your products, customers and orders, and keeping them in sync.
- To act on your behalf: sending WhatsApp messages to your customers, creating shipments and labels, and generating product copy or images when you ask for them.
- To keep the service secure: authenticating sign-ins, detecting abuse and diagnosing faults.
- To talk to you about your account, including service notices and changes to these documents.
- To tell you about Cartly features, only if you have opted in, and you can opt out at any time.
We do not sell personal data, and we do not use your customers’ data to advertise to them or to build profiles for anyone other than you.
4. Legal bases
Where a legal basis is required, we rely on:
- Performance of a contract — providing the service you signed up for, including processing the customer and order data you upload.
- Legitimate interest — keeping the service secure, preventing abuse, fixing bugs and understanding how Cartly is used, in ways that do not override your interests.
- Consent — sending you marketing about Cartly. You can withdraw consent at any time and it will not affect your use of the service.
5. Your customers’ data
For the customer, product and order data a merchant uploads, the merchant is the data controller and Cartly is the data processor. We process that data only to provide the service and only on the merchant’s instructions. The merchant is responsible for having a lawful basis to collect it and, in particular, for having the consent needed to message customers on WhatsApp.
The terms of that processing are set out in our Data Processing Addendum, which forms part of the agreement with every merchant.
If you are a customer of a Cartly merchant and want to know what a store holds about you, contact the store directly. If you write to us instead, we will pass your request to the merchant and help them respond.
6. Sub-processors
We use a small number of service providers to run Cartly. Each one receives only the data needed for its job.
| Provider | What it does | Data it handles | Location |
|---|---|---|---|
| Supabase | Database, authentication and file storage | All account and business data | Mumbai, India |
| Cloudflare | Hosting, edge network and scheduled jobs | Request data passing through the application | Global edge network |
| Sign-in with Google | Your email address and name at sign-in | Global | |
| Waplify | WhatsApp Business messaging | Customer phone numbers and message content | As per Waplify’s terms |
| Shiprocket | Shipping and courier booking | Order details and delivery addresses | India |
| OpenAI | Text and image generation in Studio | Product details you choose to generate from | United States |
We will update this list when a provider changes and, where the change materially affects your customers’ data, we will tell merchants by email before it takes effect.
7. Where data is stored
Your account and business data are stored in Supabase’s Mumbai (India) region. The Cartly application runs on Cloudflare’s global edge network, which means requests may be served from a data centre near you; the data itself remains in the Mumbai region unless you connect a service located elsewhere.
Data sent to Waplify, Shiprocket, Google or OpenAI is transferred to wherever those services operate, as described above. For merchants in the European Economic Area or United Kingdom, those transfers are covered by the providers’ standard contractual terms.
8. How long we keep it
- Raw CSV rows — the uploaded files and their unprocessed rows are deleted 90 days after import. The imported records (products, customers, orders) remain in your workspace.
- Account and workspace data — kept until you delete your account, or until we delete a workspace that has been inactive for a long period after giving notice.
- Integration credentials — deleted immediately when you disconnect an integration or delete your account.
- Usage and request logs — kept for up to 90 days for security and debugging, then deleted or anonymised.
- Backups — our database provider keeps short-rotation backups; deleted data drops out of them as they rotate.
9. Your rights
Whatever your location, you can:
- Access and export your data — from Settings in your workspace, or by emailing us.
- Correct anything that is wrong.
- Delete your account and everything in it — from Settings, or by emailing us. We complete deletion within 30 days.
- Object to processing based on legitimate interest, and withdraw consent for marketing at any time.
- Complain to your local data protection authority if you think we have got something wrong. We would rather you told us first so we can fix it.
Requests go to pratikr557@gmail.com. We will answer within 30 days and may ask you to confirm you own the account.
10. India DPDP Act and GDPR
India
Cartly is based in India and follows the Digital Personal Data Protection Act, 2023. For merchant account data we are the Data Fiduciary; for customer data uploaded by merchants, the merchant is the Data Fiduciary and Cartly is a Data Processor. You may exercise your rights under the Act, including access, correction, erasure and grievance redressal, by writing to the contact address above. If you are not satisfied with our response you may approach the Data Protection Board of India.
European Economic Area and United Kingdom
If you are in the EEA or UK, the GDPR or UK GDPR applies. The legal bases we rely on are listed in section 4. We do not currently have a representative in the EU or UK; contact us directly. Transfers outside the EEA and UK rely on standard contractual clauses or the equivalent measures offered by each provider.
12. Security
All traffic to Cartly is encrypted in transit. Integration credentials are encrypted at rest. Access to production systems is limited to the people who operate Cartly. We keep our dependencies up to date and review changes before they ship.
Cartly is a small, early-stage service. We have not yet undergone a third-party security audit or certification, and we do not claim one. If you find a security problem, please tell us at pratikr557@gmail.com.
13. Children
Cartly is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If a merchant uploads customer records that include a child’s data, the merchant is responsible for having the required consent.
14. Changes to this policy
We will update this policy as Cartly grows. Small changes will simply be published here with a new effective date. If a change affects what we collect or how we use it in a way you would care about, we will email account holders before it takes effect.
15. Contact
Cartly
Email: pratikr557@gmail.com
Web: joincartly.com