Cartbeat
Home

Privacy Policy

Cartbeat · Last updated July 15, 2026 · info@cartbeat.app

Cartbeat (“we”, “us”) provides cart-recovery software for Shopify merchants. This policy explains what we collect, why, and how merchants and shoppers can exercise their rights. It applies to cartbeat.app and the Cartbeat Shopify app, including optional SMS / Comebacks messaging.

Who we are

Cartbeat operates at cartbeat.app. Contact: info@cartbeat.app.

Data we process

Merchant data (Shopify store owners): store domain, OAuth access tokens, shop profile (name, email, address), app settings, billing status, and operational logs.

Shopper data (your customers): abandoned checkout information Shopify sends us · typically email, first name, cart line items, cart total, currency, and checkout recovery URL. We use this only to send recovery emails and measure attribution on behalf of the merchant store.

SMS / Comebacks (when enabled): mobile phone number (E.164), SMS opt-in / messaging consent timestamp and source, opt-out and suppression timestamps, message content templates configured by the merchant, and delivery metadata (e.g. sent / delivered / failed). See our SMS Opt-In Policy for consent and TCPA details.

Email engagement: open and click timestamps on recovery messages we send.

How we use data

We do not use shopper mobile numbers or messaging consent to build third-party marketing lists, sell leads, or run promotional campaigns for unrelated brands.

SMS, mobile information & messaging consent (A2P / TCPA)

Required non-sharing statement: We do not share, sell, rent, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes.

Mobile numbers and SMS opt-in records are used only to:

Message frequency: Message frequency varies. For Comebacks SMS, merchants typically send at most one comeback text per customer per 90-day window, subject to merchant settings and eligibility rules. Email recovery sequences are separate and follow merchant-configured delays.

Rates: Message and data rates may apply. Consent to receive texts is not a condition of purchase.

Opt out: Reply STOP to any Cartbeat-powered store message to unsubscribe. Reply HELP for help. You may also email info@cartbeat.app.

Full SMS consent flow, sample checkout disclosure, and merchant responsibilities: SMS Opt-In Policy.

Sharing & service providers (not marketing partners)

We use infrastructure providers solely to operate the product. They process data under our instructions and are not given mobile numbers or messaging consent to use for their own marketing or promotional purposes:

We may disclose information if required by law, to protect rights and safety, or in a business transfer (with this policy continuing to apply to personal data where required). We still do not sell mobile information or messaging consent for marketing.

Retention

Merchant and checkout data is kept while the app is installed and for a reasonable period after uninstall for logs and billing. SMS opt-out / suppression records are kept as long as needed to honor opt-outs. Shoppers who unsubscribe from email are suppressed immediately; SMS STOP is honored immediately for that number on that merchant program.

GDPR / Shopify mandatory webhooks

We implement Shopify’s required GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Merchants may contact us for data requests at info@cartbeat.app.

Shopper rights

Every recovery email includes one-click unsubscribe (RFC 8058). For SMS, reply STOP or email info@cartbeat.app to request suppression, access, or deletion where applicable.

Security

OAuth and webhook traffic is HMAC-verified. Secrets are stored server-side only. Merchants should use strong passwords on Shopify and Cartbeat billing accounts.

Changes

We may update this policy. Material changes will be reflected on this page with an updated date.