Privacy Policy

1. Who this covers

This policy applies to two groups of people:

For shoppers, the merchant whose app you are using is the business you are buying from. The merchant controls its customer relationship and its own privacy policy; we process shopper information on the merchant’s behalf to make the app work. Where a law such as the GDPR applies, the merchant is the controller of shopper data and we are its processor, except for the limited operational data described in section 3.

2. Information we collect from merchants

Account information

When you create an account we collect your email address and a password (stored by our authentication provider as a salted hash; we never see it). When you agree to pricing we record your name, email, the terms version you agreed to, and the time.

Store connection

When you connect your store (for example by installing our Shopify app) we receive an access token that lets us read your catalog, receive order and product updates, create checkouts, and — once you agree to pricing — add our fee to your platform bill. Tokens are encrypted at rest. We also receive your store’s name, domain, currency, plan, and contact email from the platform.

Catalog and orders

We keep a copy of your products, collections, images, and pages so the app can load quickly, and we receive orders, refunds, and cancellations by webhook so we can show sales in your dashboard and calculate our fee. Order records include the items purchased, totals, the shipping address, and a one-way hash of the customer’s email (which lets us count repeat customers without storing the address).

Developer accounts

To publish your app we ask you to invite our developer address into your Apple App Store Connect and Google Play Console accounts. We collect the team or developer identifiers needed to submit builds. We do not collect your Apple or Google passwords.

Usage

We log requests to our website and dashboard (IP address, browser, pages viewed, timestamps) to keep the service running and to diagnose problems.

3. Information we collect from shoppers

Merchant Apps are designed to hold as little about you as possible. Most of what you do stays on your device. Merchants may link this section as the privacy policy for their app; it describes exactly what the app sends to us.

We do not sell shopper data, we do not share it with advertising networks, and we do not track you across other companies’ apps or websites. Merchant Apps contain no third-party advertising SDKs.

4. Information from public storefronts

To show a merchant a preview of their app, we read information the store already publishes to anyone on the internet: its products, collections, navigation, logo, colors, and pages. We identify ourselves with a VendiNativeBot user agent, respect password-protected storefronts (we only analyze them when the merchant gives us the password), and keep the copy for a limited time if the merchant never activates (see retention). If you own a store that appears in a preview and would rather it did not, email us and we will remove it.

5. How we use information

We do not use merchant or shopper data to train machine-learning models, and we do not combine data across merchants except in aggregate statistics.

6. Who we share it with

We share information only with the providers that run our service, each bound by their own data-processing terms:

We may also disclose information if required by law or to protect the rights and safety of merchants, shoppers, or the public, and as part of a merger or acquisition (in which case this policy continues to apply to the transferred data).

7. How long we keep it

When a merchant uninstalls our Shopify app, Shopify sends us a deletion request 48 hours later; we honor it by deleting the store’s connection, orders, checkouts, installs, and campaigns.

8. Security

Data is encrypted in transit (TLS) and at rest. Store access tokens are additionally encrypted with a key held outside the database. Webhooks are verified by signature before we act on them. Access to production systems is limited to the people who operate the service. No system is perfectly secure; if we learn of a breach affecting your data we will notify affected merchants without undue delay and, where required, regulators.

9. Your rights and choices

Merchants

You can see and correct most of your information in the dashboard, disconnect your store at any time, and ask us to delete your account by emailing legal@vendinative.com. We respond within 30 days.

Shoppers

Turn off notifications in your device settings. Delete the app to clear everything stored on your device. For anything we hold — usage events tied to your install identifier, or an order copy — you can contact the merchant (they can request it from us) or contact us directly. We honor requests we receive from Shopify on a merchant’s behalf automatically: customer data requests produce an export of the orders we hold for that customer, and customer redaction requests strip the shipping address and customer identifier from those orders.

Depending on where you live

You may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to complain to a supervisory authority (EU/UK residents) or your state attorney general (US residents). We do not “sell” or “share” personal information as those terms are defined in the California Consumer Privacy Act, and we do not discriminate against anyone for exercising their rights.

10. Children

Our platform is for businesses and is not directed to children. Merchant Apps are storefronts for the merchant’s products and are not directed to children under 13 (or the age of digital consent where you live). We do not knowingly collect information from children; if you believe a child has provided us information, email us and we will delete it.

11. International transfers

We are based in the United States and our providers store data there. If you use the service from elsewhere, your information is transferred to the United States. For merchants in the EU, UK, or Switzerland we rely on our providers’ Standard Contractual Clauses and Data Privacy Framework certifications, and we will sign a data-processing agreement on request.

12. Changes to this policy

When we change this policy we update the effective date at the top. For material changes we email merchants at least 14 days before they take effect. Continued use after that date means you accept the updated policy.

13. Contact

CartSense LLC, doing business as VendiNative
legal@vendinative.com

See also our Terms of Service.