Privacy Policy for CartGate
Last Updated: July 28, 2026
The checkout analytics described under Analytics have been active since July 24, 2026. This policy was updated on the date above to describe them.
Introduction
CartGate ("we", "our", or "us") is a Shopify app that validates cart contents at checkout, blocking incompatible product combinations and enforcing purchase rules configured by the merchant. This Privacy Policy explains how we collect, use, store, and protect information when you use our application.
This policy applies to merchants who install CartGate and to their customers whose cart data is processed by our checkout validation function or whose blocked checkout is counted by our checkout pixel.
Information We Collect
1. Merchant Information
When you install CartGate, we collect and store:
- Shop Information: Your Shopify shop domain, shop name, and associated account details provided through Shopify OAuth
- Email Address: Your email address, used for account communication, product updates, and milestone emails
- Authentication Data: OAuth access tokens and session tokens required to interact with your Shopify store
- App Configuration: Your cart validation rules, including incompatible product combinations, solo-purchase restrictions, and enforcement settings (block or warn)
2. Customer Information
When your customers proceed to checkout:
- Cart Contents: Product IDs and variant IDs in the customer's cart are processed in real time by our validation function to check against your configured rules. The validation function runs as a Shopify Function (compiled to WebAssembly) entirely within Shopify's infrastructure. Cart contents are never transmitted to or stored on our servers.
- Blocked Checkout Events: CartGate installs a Shopify Web Pixel in your checkout that reports when one of your validation rules actually blocked a checkout. The report contains a Shopify checkout session identifier, the identifier and text of the blocking message that was displayed, and event timestamps. It contains no cart contents and no customer identity, contact, address, or payment information — those fields are absent from the event contract entirely, not filtered out after the fact.
3. Technical Information
- Session Data: Server-side session tokens for merchant authentication, stored with a 7-day time-to-live (TTL) and automatically deleted upon expiration
- Blocked Attempt Counters: Daily per-shop, per-rule counts of how many checkouts your rules blocked. These are aggregate numbers, not records of individual shoppers.
- Deduplication Keys: To avoid counting the same blocked checkout twice, we briefly retain a checkout session identifier alongside the shop and rule it applied to. These keys are deleted within 7 days and are never used to build a profile, contact a shopper, or link activity across sessions or stores.
- Webhook Data: App installation, uninstallation, and mandatory compliance webhook events from Shopify
How We Use Your Information
Merchant Data
We use merchant information to:
- Authenticate and authorize access to your Shopify store
- Store and apply your cart validation rules via Shopify metafields
- Send transactional emails related to your account (e.g., service notices, security alerts)
- Send occasional product update emails when a feature you use is changing or improving (you may unsubscribe at any time)
- Send occasional milestone emails when your store reaches a notable number of blocked checkouts (you may unsubscribe at any time)
- Provide customer support
See Email Communications below for exactly what we send and how to stop it.
Customer Data
Cart contents are used solely to evaluate your checkout validation rules in real time, inside Shopify's infrastructure. Blocked-checkout events are used solely to produce the aggregate counts you see in the app and the milestone emails described below. CartGate does not collect, store, or retain customer identity, contact, address, or payment information, and does not use any customer data for advertising, profiling, or resale.
Data Storage and Security
Where We Store Data
- Cloudflare D1 Database:
- Shop records (domain, email, configuration state)
- App settings and onboarding status
- Daily aggregate blocked-checkout counts per shop and per rule
- Short-lived deduplication keys containing a checkout session identifier (deleted within 7 days)
- Cloudflare KV Storage:
- Merchant session tokens (encrypted, 7-day TTL with automatic expiration)
- Shopify Metafields (stored within your Shopify store):
- Cart validation rules (under the
$app:cart-gatenamespace) - Warning display rules (under the
cart_gatenamespace) - All metafield data remains within your Shopify store and under your control
- Cart validation rules (under the
Security Measures
- All data transmitted over HTTPS/TLS encryption
- OAuth 2.0 authentication with Shopify (token exchange flow)
- Session tokens stored server-side with automatic expiration
- Webhook request validation using Shopify HMAC signatures
- Infrastructure hosted on Cloudflare's global network with built-in DDoS protection
- Blocked-checkout reports are authenticated with a per-shop token and rate-limited
- No customer identity, contact, address, payment, or cart data is stored on our servers
Data Sharing and Third Parties
We share data with the following third parties:
Cloudflare
- Purpose: Application hosting, database, and session storage
- Data Shared: Merchant shop data, session tokens, app configuration, blocked-checkout counts
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
Shopify
- Purpose: App platform, merchant store integration, checkout validation, checkout pixel
- Data Shared: Validation rules (via metafields), webhook events
- Privacy Policy: https://www.shopify.com/legal/privacy
We do not share your data with:
- Advertising networks
- Data brokers
- Marketing or ad-targeting platforms
- Any other third parties not listed above
Analytics
CartGate's only analytics are the blocked-checkout counts described above. They exist to show you how often your rules are working and to power the milestone emails described below.
- Collection happens through a Shopify Web Pixel that CartGate installs in your checkout. It subscribes to exactly two Shopify events — checkout started, and a validation message being displayed — and to nothing else.
- The pixel sets no cookies, reads no cookies, and performs no fingerprinting or cross-site tracking.
- What we store from it is counters, plus a deduplication key that is deleted within 7 days.
- We do not use a third-party analytics provider, and blocked-checkout data is never shared, sold, or used for advertising.
Data Retention
Automatic Expiration
- Session Tokens: Automatically expire and are deleted after 7 days
- Customer Cart Data: Not stored — processed in real time only
- Deduplication Keys: Deleted within 7 days of being written
Active Use
- Shop records and app configuration are retained for the duration of your use of CartGate
- Aggregate blocked-checkout counts are retained for the duration of your use of CartGate, so you can see your own history
- Validation rules stored in Shopify metafields persist within your Shopify store
After Uninstallation
When you uninstall CartGate:
- Session tokens are automatically deleted upon expiration (within 7 days)
- Shop records and configuration data are retained for up to 12 months after uninstallation to allow seamless restoration if you choose to reinstall
- After 12 months, all shop data is permanently deleted from our systems
- Metafield data in your Shopify store remains under your control — you may delete it through the Shopify admin at any time
- You may request immediate deletion of all your data at any time by contacting us (see "Contact Us" below)
Your Data Rights
As a Merchant
You have the right to:
- Access: Request a copy of all data we store about your shop
- Correct: Update your validation rules and configuration at any time through the app
- Delete: Request immediate deletion of all your data by contacting us, or uninstall the app (data deleted within 12 months)
- Portability: Request your data in a portable format
- Unsubscribe: Opt out of product update and milestone emails at any time via the unsubscribe link in any such email
As a Customer
CartGate does not collect your name, email address, postal address, payment details, or cart contents, and cannot identify you. Cart contents are evaluated in real time within Shopify's infrastructure and are never sent to us. If your checkout was blocked by a merchant's rule, we record an aggregate count for that merchant and briefly hold a checkout session identifier — for no more than 7 days, solely to avoid double-counting — which is not used to identify, contact, profile, or track you. If you have questions about how a merchant uses CartGate on their store, please contact the merchant directly.
Compliance with Privacy Laws
GDPR (European Union)
For merchants and customers in the EU/EEA:
- We process merchant data based on contractual necessity (to deliver the service you installed) and legitimate interest (to tell you about changes to features you use and about your own store's blocked-checkout milestones, with opt-out available for both)
- Customer cart data is processed by a Shopify Function running within Shopify's infrastructure — CartGate acts as a processor under the merchant's controllership
- Blocked-checkout events are likewise processed as a processor on the merchant's behalf, limited to aggregate counting; the deduplication key is a pseudonymous checkout session identifier deleted within 7 days
- You have the right to data portability, erasure, restriction of processing, and to lodge a complaint with your local supervisory authority
- We comply with Shopify's mandatory GDPR webhooks for data deletion requests
- Data is stored on Cloudflare's infrastructure, which maintains appropriate safeguards for international data transfers
CCPA (California)
For California residents:
- We do not sell personal information
- We do not share personal information for cross-context behavioral advertising
- You have the right to know what personal information is collected, to request deletion, and to non-discrimination for exercising your rights
Shopify Mandatory Compliance Webhooks
We handle Shopify's mandatory compliance webhooks:
- customers/data_request: We will respond within 30 days. Note: CartGate stores no customer-identifying data, so there is generally nothing to return.
- customers/redact: We will process the request within 30 days. Note: CartGate stores no customer-identifying data; the only shopper-adjacent value we hold is a checkout session identifier that is automatically deleted within 7 days.
- shop/redact: We will delete all shop data, including blocked-checkout counts, within 30 days of receiving the request.
Cookies and Tracking
CartGate does not use cookies.
- No browser cookies are set or read by CartGate
- No fingerprinting, no advertising trackers, and no cross-site or cross-store tracking
- All merchant session management is server-side with automatic expiration
- The one client-side component CartGate runs is the Shopify Web Pixel described under Analytics. It runs inside Shopify's sandboxed pixel environment, observes only two checkout events, and reports only blocked-checkout events.
Note: Shopify's embedded app framework may set its own cookies as part of its authentication and session management. Those cookies are governed by Shopify's Privacy Policy.
Email Communications
CartGate is a small, independent product, and its emails are meant to read that way. There is no newsletter, no drip campaign, and no marketing list. We send you the following:
- Transactional Emails: Service-related notices, security alerts, and account notifications. These are necessary for the operation of the service and cannot be opted out of while you use CartGate.
- Product Updates: Occasional notes about changes and improvements to CartGate — most often when a feature you are already using is getting better, so you know what changed and how to take advantage of it. We send these when there is something genuinely useful to tell you, not on a schedule. You may unsubscribe at any time using the link in every such email.
- Milestone Emails: When your store passes a notable number of blocked checkouts, we may email to let you know what CartGate has caught for you. These are generated from the aggregate counts described under Analytics and contain only your own store's numbers. You may unsubscribe at any time using the link in every such email.
Unsubscribing from product update or milestone emails does not affect your use of CartGate; you will continue to receive transactional emails.
We will never sell your email address or share it with third parties for marketing purposes.
Children's Privacy
CartGate is a business-to-business application intended for use by Shopify merchants. It is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
Data Breach Notification
In the event of a data breach that affects your information:
- We will notify affected merchants within 72 hours of becoming aware of the breach, as required by GDPR
- Notification will include the nature of the breach, categories of data affected, and remediation steps taken
- We will cooperate with relevant supervisory authorities as required by law
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- The "Last Updated" date at the top will be revised
- Merchants will be notified of material changes via email
- Continued use of CartGate after changes constitutes acceptance of the revised policy
Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to submit a data deletion request, please contact us:
Email: [email protected]
Mailing Address: 6545 Market Avenue N., Suite 100, North Canton, Ohio 44721
When contacting us about a data request, please include:
- Your Shopify shop domain
- A description of your request
We will respond to all requests within 30 days.
By installing and using CartGate, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.