Privacy and data use
Smart Cart for Shopify · last updated 2026-08-22
This document is not finished, and here is exactly what is missing
Everything below describes what the app actually does and is accurate. These are the parts that cannot be written from the code, and have not been invented:
- A data contact on a domain the company controls. Requests currently reach a personal mailbox, which has no shared access and no continuity if one person is unavailable — and a statutory request carries a deadline. Interim, pending a company mailbox.
- A data processing agreement offered to merchants. One is now DRAFTED — see docs/legal/DPA.md — with its factual annexes derived from this same code, but it has not been reviewed by a qualified adviser and is not offered to anyone. It also lacks a transfer mechanism for merchants in the EEA or UK, which an India-established processor needs. Until it is reviewed and offered, the second question on Shopify's protected-customer-data form is still honestly answered No.
- Review by a qualified adviser. The governing law is now settled — this agreement is governed by the laws of India, with the courts at Chandigarh — but that decides which law reads the contract, not which data protection law applies to the processing: the GDPR applies additionally wherever a merchant sells into the EEA, and a contract cannot opt out of it. This page was written from what the code does, which makes it accurate, not sufficient.
Who we are
This app is published by Sofcy Infotech, Mohali, Sahibzada Ajit Singh Nagar, Punjab 140308, India. Questions about anything on this page, or a request to delete data, go to yadav.creators@gmail.com.
Where your data is processed. United States — Amazon Web Services, US East (Ohio), us-east-2. The application, its database and its logs all run on the same instance in that region. The company that operates it is established in India.
| Your account and your shop Controller | Sofcy Infotech decides what is collected and why — your shop domain, your access token and the cart you configure. |
|---|---|
| Your shoppers Processor | You decide. Anything the app handles about a shopper is handled on your instructions, and the app is built so that shopper personal data never reaches it at all. |
What this app is
Smart Cart replaces the cart drawer on a Shopify store. It runs in two places: an admin area where a merchant configures their cart, and a small script on the storefront that draws the cart for shoppers.
Data about you, the merchant
| Your shop's myshopify.com domain, and an offline Shopify access token issued to this app. | To identify your shop and to call the Shopify APIs you approved at install — creating the discount that pays out your reward tiers, reading your products for the picker, and reading your published theme to confirm the app embed is on. For as long as the app is installed. Uninstalling marks the shop and starts the deletion window; Shopify also revokes the token at that moment, so it stops working immediately either way. |
|---|---|
| Your cart configuration — reward tiers, modules, colours, custom CSS, and any shopper wording you have written. | It is the thing you are building. It is also published into your storefront's page HTML, so treat it as public: it is not a place to put anything private. Kept with version history so you can roll back, and removed with the shop after uninstall. |
| A Shopify session record, created by Shopify's own app library. | To keep you signed in to the embedded admin. Until it expires or the app is uninstalled. This app uses OFFLINE access only — it never requests online tokens — so the staff-user columns Shopify's schema provides (name, email, user id) are not populated. |
Data about your shoppers
The short version: the app is built so that shopper personal data never reaches it. It does not request Shopify’s customer data scope, and the parts of the code that build usage events refuse outright to carry a field named like personal data.
| Cart contents while the drawer is open — products, quantities and prices, read from Shopify's own cart in the shopper's browser. | To draw the cart and work out which reward tiers a cart has reached. This is read in the browser and is not sent to us. Not stored by us at all. |
|---|---|
| Anonymous usage events: which cart features were used, cart totals, and a session identifier. | To show you whether the cart is earning its place — how often it opens, and whether reward tiers are reached. ONLY WHEN YOU TURN ANALYTICS ON. No cart published today sends any event, because a cart sends events only when its configuration carries an analytics endpoint and none is issued yet. When it is, events carry no name, email, address, phone or IP. |
| Order identifiers and cart tokens, for order attribution. | To join an order back to a cart the app was shown in, so revenue can be attributed to it. Held for 90 days from the order, then deleted by the retention sweep. The app reads only the order id, cart token, currency, line count and cancellation reason — never the buyer's name, email, phone or address. |
What is never collected
- Shopper names, email addresses, phone numbers or postal addresses
- Payment details of any kind — the app never touches checkout or payment
- Shopper IP addresses
- The `read_customers` scope, which this app deliberately does not request
- `read_all_orders`, which would reach beyond the default 60-day window
Fields stripped before anything is written to a log
Diagnostic logs are redacted by key. Any field whose name contains one of the following is replaced before the log line is written, wherever it appears and however deeply nested:
email · phone · firstname · first_name · lastname · last_name · fullname · full_name · address · address1 · address2 · street · zip · postal · postcode · city · province · country_name · latitude · longitude · ip · billing · shipping_address · customer
What the app stores in a shopper’s browser
| Key | What it is for |
|---|---|
| sofcy_sid sessionStorage | Groups a shopper's actions into one visit so a single session is not counted as many. The browsing session, and reset after 30 minutes of inactivity. Written without waiting for analytics consent. |
| sofcy_did localStorage | Distinguishes a returning browser from a new one in usage counts. Until the shopper clears their browser storage. Only written after the shopper has given analytics consent. |
| sofcy_utm sessionStorage | Remembers the campaign parameters (utm_source and the rest) that the visit arrived with, so a merchant can show a different cart offer to visitors from a particular campaign. Those parameters are only on the page a shopper lands on, and the cart is usually opened several pages later — without this the rule would silently never match. The browsing session. It is not kept between visits. Written without waiting for analytics consent. |
| sofcy_bucket sessionStorage | A random value used to decide, consistently within one visit, whether this browser is inside a gradual rollout percentage you have set. It never leaves the device and is not sent to us or to anyone else. The browsing session. It is not kept between visits. Written without waiting for analytics consent. |
Consent is read from Shopify's Customer Privacy API (`Shopify.customerPrivacy`), which reflects the consent banner and privacy settings already configured on your store.
Where consent is unknown rather than granted or denied, usage events wait instead of being sent on an assumption.
Deletion
The app responds to Shopify’s three mandatory privacy webhooks — customer data request, customer redaction and shop redaction. Because the app holds no shopper personal data, a customer request has nothing to return and a customer redaction has nothing to erase; both are answered rather than ignored. Uninstalling the app marks the shop for deletion of its configuration.
Uninstall starts a 90-day window. Within it, reinstalling restores your carts exactly as you left them. After it, a scheduled sweep deletes the shop and everything attached to it — configurations, versions, sessions and events. Asking us to delete sooner overrides the window entirely.
If you leave
Each commitment below says how it is guaranteed. Where the guarantee is structural — a permission we never asked Shopify for, a capability this app does not have — that is stated, because it is worth more than an assurance. Where it is a promise we keep by intention, that is stated too, in the same list rather than in smaller type.
- Uninstalling removes the cart drawer completely. Nothing of ours is left behind in your theme, because nothing of ours was ever written into it.
- How this is guaranteed: We request read_themes and never write_themes. The cart drawer is a theme app extension: Shopify renders it from our app and withdraws it on uninstall. Editing your theme files is not something we decline to do — it is a permission we do not hold.
- We do not email or text you after you uninstall. No win-back sequence, no exit drip, no 'we noticed you left'.
- How this is guaranteed: This app has no email or SMS capability at all — no mail provider and no messaging dependency. It also has no address to send to: Shopify's session table has a column for the installing staff member's email, and it is empty here, because this app requests offline access only and that column is filled only for online tokens.
- Ask us to delete your data and it goes immediately — you do not have to wait out the retention window.
- How this is guaranteed: Shopify's shop/redact webhook runs eraseShop, which routes through purgeShop and removes the shop, its configurations, its sessions and its events. It deliberately overrides the retention window: when erasure is requested, compliance beats retention.
- If you simply uninstall and never contact us, your data is deleted within 90 days. Until then it is kept so a reinstall restores your carts instead of starting you over.
- How this is guaranteed: RETENTION_DAYS = 90 in the code, applied by a sweep that deletes shops uninstalled longer ago than that. The number on this page is the number the job uses; a test fails if they stop matching.
- At most one exit survey. If you ignore it, that is the end of it.
- This one is a promise, not a mechanism. Nothing in the code enforces it yet, so we are telling you that rather than implying otherwise.
Contacting us about your data
Email yadav.creators@gmail.com with any question about what is held, or to ask for it to be deleted. Post reaches us at Sofcy Infotech, Mohali, Sahibzada Ajit Singh Nagar, Punjab 140308, India.
Shopper data requests normally reach us through Shopify rather than directly, because Shopify forwards them to every installed app automatically. Either route works.
Changes
This page is generated from the app’s own source, and an automated check fails the build if the app starts storing something this page does not describe.