Legal
Privacy Policy
VendiNative is a trade name of CartSense LLC (“VendiNative”, “we”, “us”). We turn e-commerce stores into native mobile apps. This policy explains what we collect, why, and what you can do about it — whether you are a merchant using our platform or a shopper using an app we built for a merchant.
1. Who this covers
This policy applies to two groups of people:
- Merchants — store owners and their staff who use vendinative.com to generate, activate, and manage a mobile app for their store.
- Shoppers — people who install and use a mobile app that we built and operate on behalf of a merchant (a “Merchant App”).
For shoppers, the merchant whose app you are using is the business you are buying from. The merchant controls its customer relationship and its own privacy policy; we process shopper information on the merchant’s behalf to make the app work. Where a law such as the GDPR applies, the merchant is the controller of shopper data and we are its processor, except for the limited operational data described in section 3.
2. Information we collect from merchants
Account information
When you create an account we collect your email address and a password (stored by our authentication provider as a salted hash; we never see it). When you agree to pricing we record your name, email, the terms version you agreed to, and the time.
Store connection
When you connect your store (for example by installing our Shopify app) we receive an access token that lets us read your catalog, receive order and product updates, create checkouts, and — once you agree to pricing — add our fee to your platform bill. Tokens are encrypted at rest. We also receive your store’s name, domain, currency, plan, and contact email from the platform.
Catalog and orders
We keep a copy of your products, collections, images, and pages so the app can load quickly, and we receive orders, refunds, and cancellations by webhook so we can show sales in your dashboard and calculate our fee. Order records include the items purchased, totals, the shipping address, and a one-way hash of the customer’s email (which lets us count repeat customers without storing the address).
Developer accounts
To publish your app we ask you to invite our developer address into your Apple App Store Connect and Google Play Console accounts. We collect the team or developer identifiers needed to submit builds. We do not collect your Apple or Google passwords.
Usage
We log requests to our website and dashboard (IP address, browser, pages viewed, timestamps) to keep the service running and to diagnose problems.
3. Information we collect from shoppers
Merchant Apps are designed to hold as little about you as possible. Most of what you do stays on your device. Merchants may link this section as the privacy policy for their app; it describes exactly what the app sends to us.
| Data | Where it lives | Why |
|---|---|---|
| Cart and favorites | On your device only | So the app remembers what you were looking at. Cleared when you delete the app. |
| Install identifier | Sent to us | A random ID generated when the app is first opened. It is not tied to your name, email, or advertising ID. We use it to count installs and to deliver push notifications you opted into. |
| Usage events | Sent to us | Which screens are viewed and which products are added to cart, together with the install identifier, app version, and platform (iOS or Android). This is how the merchant sees what is working in their app. We do not use it to build advertising profiles. |
| Push notification token | Sent to us, only if you allow notifications | Lets the merchant send you offers and updates through the app. Turn it off any time in your device settings. |
| Checkout and payment | The merchant’s commerce platform (for example Shopify) | When you check out, the app hands you to the platform’s secure checkout. Your name, address, and payment details are collected there under the merchant’s and the platform’s privacy policies. We never see your card number. |
| Order history | The merchant’s commerce platform; a copy with us | After a purchase the platform sends the merchant’s app (us) the order so it can appear in the merchant’s dashboard and, where supported, in the app’s order history. See retention for how long we keep it. |
We do not sell shopper data, we do not share it with advertising networks, and we do not track you across other companies’ apps or websites. Merchant Apps contain no third-party advertising SDKs.
4. Information from public storefronts
To show a merchant a preview of their app, we read information the store already publishes to anyone on the internet: its products, collections, navigation, logo, colors, and pages. We identify ourselves with a VendiNativeBot user agent, respect password-protected storefronts (we only analyze them when the merchant gives us the password), and keep the copy for a limited time if the merchant never activates (see retention). If you own a store that appears in a preview and would rather it did not, email us and we will remove it.
5. How we use information
- To generate, build, publish, and run the merchant’s app.
- To show merchants how their app is doing (installs, sessions, orders, revenue).
- To calculate and collect our fee through the merchant’s commerce platform billing.
- To send merchants service messages about their app — build status, store review results, security notices. These are not marketing.
- To deliver push notifications a shopper opted into, on the merchant’s behalf.
- To keep the service secure, prevent abuse, and comply with the law.
We do not use merchant or shopper data to train machine-learning models, and we do not combine data across merchants except in aggregate statistics.
6. Who we share it with
We share information only with the providers that run our service, each bound by their own data-processing terms:
| Provider | Purpose |
|---|---|
| Google Cloud / Firebase | Database, authentication, and hosting for the platform (United States). |
| Vercel | Hosting for vendinative.com and the API that Merchant Apps talk to. |
| Expo (EAS) | Building app binaries and relaying push notifications to Apple and Google. |
| Apple and Google | Distributing the app through the App Store and Google Play, and delivering push notifications. |
| Shopify and other commerce platforms | The merchant’s store, checkout, orders, and billing. The platform’s own privacy policy applies to what happens there. |
We may also disclose information if required by law or to protect the rights and safety of merchants, shoppers, or the public, and as part of a merger or acquisition (in which case this policy continues to apply to the transferred data).
7. How long we keep it
- Previews that are never activated — the store copy and preview are deleted after 90 days of inactivity.
- Active merchants — catalog and order data are kept for as long as the app is live, plus 30 days after the merchant disconnects or uninstalls, so a change of mind is not destructive.
- Financial records — order totals and fee calculations are kept for 7 years as required for tax and accounting, with customer details removed.
- Shopper usage events and install identifiers — 13 months.
- Push tokens — until notifications are turned off, the app is deleted, or the token is rejected by Apple or Google.
When a merchant uninstalls our Shopify app, Shopify sends us a deletion request 48 hours later; we honor it by deleting the store’s connection, orders, checkouts, installs, and campaigns.
8. Security
Data is encrypted in transit (TLS) and at rest. Store access tokens are additionally encrypted with a key held outside the database. Webhooks are verified by signature before we act on them. Access to production systems is limited to the people who operate the service. No system is perfectly secure; if we learn of a breach affecting your data we will notify affected merchants without undue delay and, where required, regulators.
9. Your rights and choices
Merchants
You can see and correct most of your information in the dashboard, disconnect your store at any time, and ask us to delete your account by emailing legal@vendinative.com. We respond within 30 days.
Shoppers
Turn off notifications in your device settings. Delete the app to clear everything stored on your device. For anything we hold — usage events tied to your install identifier, or an order copy — you can contact the merchant (they can request it from us) or contact us directly. We honor requests we receive from Shopify on a merchant’s behalf automatically: customer data requests produce an export of the orders we hold for that customer, and customer redaction requests strip the shipping address and customer identifier from those orders.
Depending on where you live
You may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to complain to a supervisory authority (EU/UK residents) or your state attorney general (US residents). We do not “sell” or “share” personal information as those terms are defined in the California Consumer Privacy Act, and we do not discriminate against anyone for exercising their rights.
10. Children
Our platform is for businesses and is not directed to children. Merchant Apps are storefronts for the merchant’s products and are not directed to children under 13 (or the age of digital consent where you live). We do not knowingly collect information from children; if you believe a child has provided us information, email us and we will delete it.
11. International transfers
We are based in the United States and our providers store data there. If you use the service from elsewhere, your information is transferred to the United States. For merchants in the EU, UK, or Switzerland we rely on our providers’ Standard Contractual Clauses and Data Privacy Framework certifications, and we will sign a data-processing agreement on request.
12. Changes to this policy
When we change this policy we update the effective date at the top. For material changes we email merchants at least 14 days before they take effect. Continued use after that date means you accept the updated policy.
13. Contact
CartSense LLC, doing business as VendiNative
legal@vendinative.com
See also our Terms of Service.