Legal
Privacy Policy
This Privacy Policy explains how CartPlus: Cart Drawer Upsell ("CartPlus", "the app", "we", or "us") handles data when a Shopify merchant installs or uses the app. CartPlus is operated by Hunani Infotech / SRH Web Agency.
Effective date: September 15, 2026. This policy is published at https://cartplus.srhwebagency.com/privacy.
Data we access
CartPlus uses Shopify Admin GraphQL API permissions and a Theme App Extension to provide the cart drawer and upsell features. The current app scopes are: read_products,read_orders,read_themes.
- Store owner information: name, email, phone, and address provided through Shopify account and session records.
- Products, product listings, and collections: read access so merchants can select products for upsells and cross-sells.
- Orders (protected customer data, Level 1):
read_ordersis used only to receiveorders/createwebhooks for plan usage counting and shop-level cart analytics. We persist the minimum data required for that functionality: Shopify order id (dedupe), product ids, product titles, product types, line quantities, and revenue in cents. We do not store shopper names, emails, phone numbers, addresses, IP addresses, or payment details, and we do not store raw order webhook bodies. This is not an "opt out" of protected customer data — Level 1 access is declared because order line resources are customer-related even when identity fields are unused. - Online Store theme: read access to detect whether the CartPlus Theme App Extension is enabled.
- Customer device/browser data: basic browser request data used only to render the cart drawer and count drawer events. We do not sell or share personal information.
How we use data
We use data only to operate CartPlus for the merchant's Shopify store. This includes authenticating the embedded app, saving merchant drawer settings, showing selected products in the cart drawer, checking the theme embed status, counting plan usage, and showing shop-level analytics. Order data is processed solely for those stated merchant analytics and billing-usage purposes (data minimisation). We do not sell data to third parties. We do not use merchant or shopper data for advertising.
Data storage and retention
CartPlus stores app data on Hostinger-hosted application servers and in a Supabase-managed PostgreSQL database. Shopify session, shop, billing, drawer setting, upsell selection, and analytics records are kept while the app is installed and needed to provide the service.
On app uninstall or shop redact, CartPlus deletes shop sessions, settings, upsell records, usage counts, analytics totals, queued jobs, and related shop data. Compliance audit records may be retained to show that a Shopify privacy webhook was received and handled.
CartPlus implements Shopify's mandatory GDPR webhooks:customers/data_request, customers/redact, and shop/redact. Customer data requests and redaction requests are authenticated with Shopify webhook HMAC. CartPlus does not store raw customer webhook bodies.
Third-party services
CartPlus uses Shopify for OAuth, Admin GraphQL API access, Theme App Extension delivery, and Shopify Billing API subscription charges. Application hosting is provided by Hostinger. The production database is PostgreSQL hosted by Supabase. When the in-app Contact form is configured for outbound mail, messages are sent through Google's Gmail SMTP service to our support inbox. CartPlus does not use a separate third-party monitoring, advertising, or analytics vendor; shop-level drawer and order analytics are stored in our own database.
Your rights
Merchants may request access, correction, deletion, or export of their app data by contacting us at info@srhwebagency.com. If you are a shopper, please contact the Shopify store where you shopped; Shopify's customer privacy webhooks will route eligible requests to CartPlus when required.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy at this URL and update the effective date.
Contact
Privacy questions and data requests can be sent to info@srhwebagency.com.