Last updated
Privacy Policy
This policy explains how CartTuck (“CartTuck”, “we”) handles personal information. It covers three groups of people: merchants who connect a Squarespace store to CartTuck, shoppers who upload files on those stores, and visitors to carttuck.com.
If you are a shopper: the store you bought from decides why and how your files are used, and CartTuck processes them on the store’s behalf. For questions or requests about your files, contact the store first. We will help the store respond, and you can also reach us at support@carttuck.com.
1. What we collect
From merchants, through Squarespace
When you connect a store, Squarespace shares data with us through its authorization process (OAuth) and API, limited to the access you approve:
- Store data: your Squarespace site ID, site name and domains; product IDs, names and page addresses.
- Order data, only for orders that include a CartTuck product or that a shopper asks to upload to: order ID and number, the customer’s email address, line items (product, quantity and form answers), payment state and order date.
- Access tokens that let us read your orders and products. We encrypt them at rest.
From merchants, directly
- Account and settings: the email address for notifications, product upload rules, and a Slack webhook address if you turn on Slack alerts.
- Billing: your plan and your Stripe customer and subscription IDs. Card details go directly to Stripe; we never see or store them.
- Support: anything you send us when you ask for help.
From shoppers, on behalf of merchants
- Uploaded files and details about them: file name, type, size, image dimensions, a checksum, and the results of automated checks such as print resolution. Files can contain personal information, for example a photo of a person.
- Post-checkout uploads: the order number and email address entered to find the order.
- Technical data: a one-way hash of the IP address, used for rate limiting and abuse prevention, and upload timestamps.
From website visitors
carttuck.com does not use advertising or tracking cookies. We may use Cloudflare Web Analytics, which counts page views without cookies and without tracking you across sites. Our hosting provider processes IP addresses and browser details in server logs to deliver the site and protect it from attacks.
2. How we use it
- To provide the Service: store files, match them to orders, show them in the dashboard, and send the emails you or your settings request (such as file-received notices and re-upload requests).
- To bill for paid plans and manage trials.
- To keep the Service secure: rate limiting, fraud and abuse prevention, and responding to abuse and copyright reports.
- To support you and send essential service messages, such as usage-limit and uninstall notices.
- To comply with the law.
We do not sell personal information, share it for cross-context behavioral advertising, use it for advertising, or use uploaded files to train machine-learning models.
3. Legal bases (EEA and UK)
For merchant data we rely on performing our contract with you, our legitimate interests in running and securing the Service, legal obligations, and consent where the law requires it. For shopper data we act as a processor: the merchant is the controller and decides the legal basis, and our Data Processing Addendum governs our processing.
4. Who we share it with
We use these subprocessors to run the Service:
| Provider | Purpose | Data |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage (R2), content delivery, security and logs | All Service data, including uploaded files |
| Stripe, Inc. | Subscription billing and payments | Merchant billing details |
| Resend | Sending transactional email | Recipient email addresses and email content |
We also share information:
- With Squarespace, only as needed to read your store’s orders and products and manage webhook subscriptions through its API.
- With Slack, if you turn on Slack alerts: order alert messages go to the webhook address you provide.
- When required by law, or to protect the rights, property or safety of our users, the public or us.
- In a business transfer, such as a merger or acquisition, subject to this policy.
5. How long we keep it
Uploaded files attached to an order are deleted automatically when the store’s plan retention ends, counted from when the file was attached:
| Plan | Files kept after attaching to an order |
|---|---|
| Free | 14 days |
| Maker | 60 days |
| Pro | 180 days |
| Studio | 1 year |
- Uploads never attached to an order are deleted after 7 days. Uploads that are started but never finished are removed within two days.
- Store, product and order records are kept while the store is connected.
- Uninstall: when you uninstall CartTuck from Squarespace, we stop collecting data from your store straight away and delete its files and data 30 days later.
- Billing records are kept for as long as tax and accounting laws require.
- Server logs are kept for a short period for security and troubleshooting.
6. Security
- All traffic is encrypted in transit with TLS. Files are stored encrypted at rest.
- Squarespace access tokens and webhook secrets are encrypted with AES-GCM using a key held separately from the database.
- Files are private. Download links are created only for a signed-in merchant, expire after 5 minutes, and are served from a separate domain that always downloads the file rather than displaying it.
- Uploads are limited to allowed file types, checked by their contents, and to the store’s own storage area.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as the law requires.
7. International transfers
We and our subprocessors process data in the United States and other countries. Where we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, or another valid transfer mechanism.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, and to object to or restrict some processing. Merchants can make requests to support@carttuck.com. Shoppers should contact the store they ordered from; if you contact us, we will pass your request to the store and help it respond. We won’t discriminate against you for exercising your rights. You can also complain to your local data protection authority.
9. Children
The Service is for businesses and is not directed at children under 16. Merchants must not use CartTuck to collect personal information from children in breach of the law.
10. Cookies
The CartTuck dashboard uses one strictly necessary, HttpOnly session cookie to keep you signed in. The marketing site sets no cookies, and the uploader on merchants’ stores does not set tracking cookies.
11. Changes
We will update this policy as the Service changes and show the date at the top. For material changes we will notify merchants by email or in the dashboard before they take effect.
Contact
Privacy questions and requests: support@carttuck.com.