Last updated: July 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CartGain (“Processor,” “we,” “us”) and the merchant (“Controller,” “you”) using the CartGain platform. This DPA sets out the terms relating to the processing of personal data by CartGain on behalf of the merchant, to facilitate compliance with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDP Act, 2023), and other applicable data protection laws.
Categories of Data Subjects:
Customers of the Controller who abandon their shopping carts on the Controller's e-commerce store.
Categories of Personal Data:
Nature and Purpose of Processing:
Automated sending of cart recovery notifications via email, WhatsApp, and push-style web alerts to encourage customers to complete their purchases.
Duration of Processing:
For the duration of the Controller's active subscription. Upon uninstall or termination, store-scoped data is purged and the data subject's personal data is procedurally deleted or anonymized within a reasonable window. Residual copies that may remain in hosting-provider backups are purged in line with the provider's own backup retention schedule.
CartGain shall:
The Controller shall:
The Controller authorizes CartGain to engage the following sub-processors:
| Sub-processor | Service | Data Location |
|---|---|---|
| Supabase (PostgreSQL) | Database hosting | Data region as selected in the Supabase project dashboard |
| Vercel | Application hosting & CDN | Global (multi-region) edge |
| Resend | Email delivery | US / EU (Resend processing) |
| Meta (WhatsApp Cloud API) | WhatsApp message delivery | Global (Meta processing) |
| Razorpay | Payment processing | India (Razorpay processing) |
| OpenAI | AI-powered message generation (GPT-4o / GPT-4o-mini) | US (OpenAI processing) |
| Groq | AI fallback inference (gpt-oss-120b) | US (Groq processing) |
| Upstash (Redis) | Job queue & caching | Data region as selected in the Upstash project dashboard |
CartGain will notify the Controller of any changes to sub-processors and the Controller may object within 14 days.
CartGain implements the following technical and organizational security measures:
Encryption
Data encrypted in transit via TLS. API keys and sensitive tokens stored encrypted in the database (AES-256-GCM). Customer passwords hashed with bcrypt (cost 12).
Access Control
Principle of least privilege, OAuth-based access to store data, access tokens stored encrypted, and audit logging of sensitive data access.
Monitoring
Application logging, Shopify webhook signature verification, and audit logging for access to sensitive personal data.
Backups
Backups are managed by the hosting provider; the provider retention window applies to stored backups.
Employee Access
Personnel with access to personal data are bound by confidentiality obligations. [DETAIL PER INTERNAL POLICY]
Incident Response
Documented incident response plan with a 72-hour merchant notification commitment (see CartGain Incident Response Policy).
In the event of a personal data breach, CartGain will:
CartGain shall assist the Controller in responding to data subject requests, including:
Controllers can exercise these rights by contacting support@cart-gain.com. We will respond within 30 days.
This DPA is governed by the laws of India. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution provisions in the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.
Data Protection / Privacy: support@cart-gain.com
Legal / DPA Inquiries: support@cart-gain.com
Grievance Officer: support@cart-gain.com
Address: Street No. 3, Line Par, Shanker Garden, Bahadurgarh, Haryana - 124507
© 2026 CartGain. All rights reserved.