Privacy and data use

Smart Cart for Shopify · last updated 2026-08-22

This document is not finished, and here is exactly what is missing

Everything below describes what the app actually does and is accurate. These are the parts that cannot be written from the code, and have not been invented:

Who we are

This app is published by Sofcy Infotech, Mohali, Sahibzada Ajit Singh Nagar, Punjab 140308, India. Questions about anything on this page, or a request to delete data, go to yadav.creators@gmail.com.

Where your data is processed. United States — Amazon Web Services, US East (Ohio), us-east-2. The application, its database and its logs all run on the same instance in that region. The company that operates it is established in India.

Your account and your shop
Controller
Sofcy Infotech decides what is collected and why — your shop domain, your access token and the cart you configure.
Your shoppers
Processor
You decide. Anything the app handles about a shopper is handled on your instructions, and the app is built so that shopper personal data never reaches it at all.

What this app is

Smart Cart replaces the cart drawer on a Shopify store. It runs in two places: an admin area where a merchant configures their cart, and a small script on the storefront that draws the cart for shoppers.

Data about you, the merchant

Your shop's myshopify.com domain, and an offline Shopify access token issued to this app.

To identify your shop and to call the Shopify APIs you approved at install — creating the discount that pays out your reward tiers, reading your products for the picker, and reading your published theme to confirm the app embed is on.

For as long as the app is installed. Uninstalling marks the shop and starts the deletion window; Shopify also revokes the token at that moment, so it stops working immediately either way.

Your cart configuration — reward tiers, modules, colours, custom CSS, and any shopper wording you have written.

It is the thing you are building. It is also published into your storefront's page HTML, so treat it as public: it is not a place to put anything private.

Kept with version history so you can roll back, and removed with the shop after uninstall.

A Shopify session record, created by Shopify's own app library.

To keep you signed in to the embedded admin.

Until it expires or the app is uninstalled. This app uses OFFLINE access only — it never requests online tokens — so the staff-user columns Shopify's schema provides (name, email, user id) are not populated.

Data about your shoppers

The short version: the app is built so that shopper personal data never reaches it. It does not request Shopify’s customer data scope, and the parts of the code that build usage events refuse outright to carry a field named like personal data.

Cart contents while the drawer is open — products, quantities and prices, read from Shopify's own cart in the shopper's browser.

To draw the cart and work out which reward tiers a cart has reached. This is read in the browser and is not sent to us.

Not stored by us at all.

Anonymous usage events: which cart features were used, cart totals, and a session identifier.

To show you whether the cart is earning its place — how often it opens, and whether reward tiers are reached.

ONLY WHEN YOU TURN ANALYTICS ON. No cart published today sends any event, because a cart sends events only when its configuration carries an analytics endpoint and none is issued yet. When it is, events carry no name, email, address, phone or IP.

Order identifiers and cart tokens, for order attribution.

To join an order back to a cart the app was shown in, so revenue can be attributed to it.

Held for 90 days from the order, then deleted by the retention sweep. The app reads only the order id, cart token, currency, line count and cancellation reason — never the buyer's name, email, phone or address.

What is never collected

Fields stripped before anything is written to a log

Diagnostic logs are redacted by key. Any field whose name contains one of the following is replaced before the log line is written, wherever it appears and however deeply nested:

email · phone · firstname · first_name · lastname · last_name · fullname · full_name · address · address1 · address2 · street · zip · postal · postcode · city · province · country_name · latitude · longitude · ip · billing · shipping_address · customer

What the app stores in a shopper’s browser

KeyWhat it is for
sofcy_sid
sessionStorage

Groups a shopper's actions into one visit so a single session is not counted as many.

The browsing session, and reset after 30 minutes of inactivity.

Written without waiting for analytics consent.

sofcy_did
localStorage

Distinguishes a returning browser from a new one in usage counts.

Until the shopper clears their browser storage.

Only written after the shopper has given analytics consent.

sofcy_utm
sessionStorage

Remembers the campaign parameters (utm_source and the rest) that the visit arrived with, so a merchant can show a different cart offer to visitors from a particular campaign. Those parameters are only on the page a shopper lands on, and the cart is usually opened several pages later — without this the rule would silently never match.

The browsing session. It is not kept between visits.

Written without waiting for analytics consent.

sofcy_bucket
sessionStorage

A random value used to decide, consistently within one visit, whether this browser is inside a gradual rollout percentage you have set. It never leaves the device and is not sent to us or to anyone else.

The browsing session. It is not kept between visits.

Written without waiting for analytics consent.

Consent is read from Shopify's Customer Privacy API (`Shopify.customerPrivacy`), which reflects the consent banner and privacy settings already configured on your store.

Where consent is unknown rather than granted or denied, usage events wait instead of being sent on an assumption.

Deletion

The app responds to Shopify’s three mandatory privacy webhooks — customer data request, customer redaction and shop redaction. Because the app holds no shopper personal data, a customer request has nothing to return and a customer redaction has nothing to erase; both are answered rather than ignored. Uninstalling the app marks the shop for deletion of its configuration.

Uninstall starts a 90-day window. Within it, reinstalling restores your carts exactly as you left them. After it, a scheduled sweep deletes the shop and everything attached to it — configurations, versions, sessions and events. Asking us to delete sooner overrides the window entirely.

If you leave

Each commitment below says how it is guaranteed. Where the guarantee is structural — a permission we never asked Shopify for, a capability this app does not have — that is stated, because it is worth more than an assurance. Where it is a promise we keep by intention, that is stated too, in the same list rather than in smaller type.

Uninstalling removes the cart drawer completely. Nothing of ours is left behind in your theme, because nothing of ours was ever written into it.
How this is guaranteed: We request read_themes and never write_themes. The cart drawer is a theme app extension: Shopify renders it from our app and withdraws it on uninstall. Editing your theme files is not something we decline to do — it is a permission we do not hold.
We do not email or text you after you uninstall. No win-back sequence, no exit drip, no 'we noticed you left'.
How this is guaranteed: This app has no email or SMS capability at all — no mail provider and no messaging dependency. It also has no address to send to: Shopify's session table has a column for the installing staff member's email, and it is empty here, because this app requests offline access only and that column is filled only for online tokens.
Ask us to delete your data and it goes immediately — you do not have to wait out the retention window.
How this is guaranteed: Shopify's shop/redact webhook runs eraseShop, which routes through purgeShop and removes the shop, its configurations, its sessions and its events. It deliberately overrides the retention window: when erasure is requested, compliance beats retention.
If you simply uninstall and never contact us, your data is deleted within 90 days. Until then it is kept so a reinstall restores your carts instead of starting you over.
How this is guaranteed: RETENTION_DAYS = 90 in the code, applied by a sweep that deletes shops uninstalled longer ago than that. The number on this page is the number the job uses; a test fails if they stop matching.
At most one exit survey. If you ignore it, that is the end of it.
This one is a promise, not a mechanism. Nothing in the code enforces it yet, so we are telling you that rather than implying otherwise.

Contacting us about your data

Email yadav.creators@gmail.com with any question about what is held, or to ask for it to be deleted. Post reaches us at Sofcy Infotech, Mohali, Sahibzada Ajit Singh Nagar, Punjab 140308, India.

Shopper data requests normally reach us through Shopify rather than directly, because Shopify forwards them to every installed app automatically. Either route works.

Changes

This page is generated from the app’s own source, and an automated check fails the build if the app starts storing something this page does not describe.