CartGain (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cart recovery platform for e-commerce businesses.
We design our practices to align with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDP Act, 2023), and other applicable data protection laws. Merchants remain responsible for their own compliance, including obtaining any customer consent the applicable law requires before sending messages.
Information We Collect
1. Personal Data
Account Information: Name, email address, phone number, company name, and password when you create an account.
Payment Information: Subscription and invoice records (payment processing is handled by Razorpay; payment card details are processed by Razorpay and are not stored by CartGain).
Communication Data: Messages you send us via support, chat, or email.
2. Business Data
Store Information: E-commerce platform details, store URL, and API credentials.
Customer Data: Abandoned cart information including customer names, emails, phone numbers, and cart contents.
Analytics Data: Recovery rates, conversion metrics, and campaign performance.
3. Automatically Collected Data
Functional Data: Basic identifiers needed to run the service (for example, IP address and browser/device details in standard server logs).
Session Data: Temporary session identifiers to keep you logged in.
Cookies: We use essential cookies for functionality (such as keeping you logged in). We do not run third-party advertising or analytics trackers that profile visitors.
How We Use Your Data
We process your data for the following purposes:
Data Minimization: We collect and process only the minimum personal data required to provide cart recovery value to merchants.
Service Delivery: To provide, maintain, and improve our cart recovery services.
Communication: To send recovery notifications via WhatsApp and email on your behalf (the corresponding providers are configured and activated before these channels go live).
Analytics: To track recovery performance and provide insights to merchants.
Security: To detect and prevent fraud, unauthorized access, and security incidents.
Legal Compliance: To comply with applicable laws and regulations.
Merchant Data Controls
We disclose to merchants which data we process and the purpose for each processing activity.
We limit the use of merchant and customer data to cart recovery, account administration, support, security, and legal compliance.
We maintain retention periods so personal data is not kept longer than needed.
We require merchants to accept our Terms of Service, Privacy Policy, and Data Processing Agreement before using the service.
Data Sharing and Third Parties
We share data with the following categories of third parties:
E-commerce Platform: Shopify, to sync cart, order, and discount data.
Communication Providers: WhatsApp Business API and Resend (Email) — activated as configured.
AI Services: OpenAI (GPT-4o / GPT-4o-mini) and, as a fallback, Groq (gpt-oss-120b) for AI-powered message generation — customer names and cart product details are processed to generate personalized recovery messages. Per OpenAI's published API data-usage policy, API inputs and outputs are not used for model training; the same applies to Groq for the OSS model used.
Payment Processors: Razorpay for subscription billing (once configured).
Cloud Infrastructure: Vercel and Supabase for hosting and database.
Legal Authorities: When required by law or to protect our rights.
Where sub-processor agreements are in place, third parties are bound by data processing terms and must comply with applicable data protection laws. CartGain maintains a sub-processor disclosure listing agreement status for each provider. See our Data Processing Agreement for details.
International Data Transfers
Your data may be transferred to and processed in countries other than your own. Where personal data is transferred out of your jurisdiction, we rely on available legal bases (such as the EU Standard Contractual Clauses offered by our providers, or the exemptions available under India's DPDP Act) and we contractually restrict how sub-processors use the data.
Data Retention
We retain your data for as long as your account is active or as needed to provide services. Applied retention limits:
Cart data: Customer contact details and cart contents are anonymized 90 days after abandonment.
Bargain sessions: AI negotiation sessions and messages are deleted 90 days after they start.
Access logs: Internal audit logs of data access are deleted after 180 days.
Verification tokens: Password-reset / verification tokens are deleted shortly after expiry.
Opt-out / suppression records: kept for as long as needed to honor your customers' choices.
Automated schedules enforce these limits on a daily basis. Data is either irreversibly deleted or anonymized so it can no longer identify a person.
Automated Decision-Making
CartGain's optional AI Bargain feature uses automated decision-making to negotiate product prices with customers. If enabled for your store, the AI may accept, counter, or reject a customer's offer and generate a discount code — decisions that determine the final purchase price.
Human override: You set a floor price, so the AI can never sell below the price you approve.
Customer opt-out: Customers are shown a clear “Skip AI, buy at full price” option that ends AI negotiation immediately and takes them to normal checkout.
Merchant control: You can disable the AI bargain system entirely at any time from your dashboard.
Your Data Protection Rights
Depending on your location, you have the following rights:
Access: Request a copy of your personal data.
Rectification: Correct inaccurate or incomplete data.
Erasure: Request deletion of your data (“right to be forgotten”).
Restriction: Limit how we process your data.
Data Portability: Receive your data in a structured, machine-readable format.
Objection: Object to certain processing activities.
Withdraw Consent: Withdraw consent at any time (where processing is consent-based).
Consent: You confirm that you have obtained explicit consent from your customers to receive WhatsApp and email messages on your behalf.
Opt-out: All messages include clear instructions to opt-out (e.g., an unsubscribe link or WhatsApp opt-out).
Message Frequency: Messages are sent based on cart abandonment events, not exceeding reasonable frequency.
Message & Data Rates: Standard messaging and data rates may apply to recipients.
Support: For help, recipients can contact your support team.
Data Security
We implement security measures including encryption in transit (TLS/SSL), app-level encryption of sensitive stored values (AES-256-GCM), access controls, rate limiting, audit logging of protected-data access, and provider-managed encryption for data at rest and backups. However, no system is 100% secure, and we cannot guarantee absolute security.
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or prominent notice on our website. Continued use after changes constitutes acceptance.
Contact Us
If you have questions about this Privacy Policy or our data practices: