Legal

Privacy Policy

Last updated: July 21, 2026 · Applies to the cartviral Shopify app, the cartviral web cabinet, and cartviral.com

1. Overview

cartviral turns a store's product catalog into short-form video. This policy explains exactly what data the app reads, what it stores, what it never touches, how long data is kept, and how to reach us. It is written to be read, not skimmed past.

The short version: we read your product catalog and aggregate sales totals per product. We do not collect, store, or process your customers' personal information. No names, no emails, no addresses, no payment data, no checkout access.

2. What we access from your store

When you install cartviral on Shopify, the app requests these API scopes:

  • read_products - product titles, descriptions, images, variants, prices, inventory counts, and your shop's brand settings (colors, logo). This is the raw material your clips are made from.
  • read_orders - order dates and line items (product, quantity, discounted totals), used solely to compute per-product sales aggregates for the last 60 days. Customer fields on orders (name, email, phone, addresses) are never requested in our API queries and never reach our database.
  • write_products - used for exactly one thing: writing a product metafield (cartviral.pdp_video_url) so a generated clip can appear on that product's page in your storefront. We do not modify titles, prices, inventory, or any other product data.

The app is embedded in the Shopify admin and authenticates with Shopify session tokens. It has no access to your checkout, your customer accounts, or your storefront sessions.

3. What we store

  • Catalog cache - a copy of your product data (titles, descriptions, images metadata, variants, prices) so the studio can work without hammering the Shopify API.
  • Sales aggregates - per-product totals (units sold, order count, revenue) over 7, 30, and 60 day windows. Aggregates only: no individual order records, no customer identifiers.
  • Generated media - the video clips, scenes, and voiceovers the app renders for you, stored per shop.
  • Credit and billing ledger - your plan, credit balance, and an append-only log of credit grants and spends. Payment card data is never seen by us: Shopify installs are billed through the Shopify Billing API, web accounts through Stripe.
  • Shop profile - your myshopify domain, shop name, currency, detected niche, and brand colors.
  • Learning signals - anonymous per-shop statistics about which clip formats and hooks performed better, derived from your own approvals and the stats you enter. No personal data is involved.

4. What we do not collect

  • No customer personal information: no names, emails, phone numbers, or addresses of your buyers.
  • No payment or checkout data of any kind.
  • No customer-level order records: orders are read transiently and only per-product totals are kept.
  • No browsing or behavioral tracking of your storefront visitors.
  • No data is sold or shared with advertisers. Ever.

5. How data is used

Stored data serves exactly one purpose: producing and improving your short-form video content. Sales aggregates rank which products are worth a clip. The catalog cache feeds the render pipeline. Learning signals tune future waves for your shop only; they are never pooled across merchants and never used to train third-party AI models.

6. Service providers we rely on

cartviral uses a small set of processors, each receiving the minimum needed:

  • Railway - application hosting and storage. The app and its database are hosted on Railway infrastructure.
  • fal.ai - AI image and video generation. Receives product images and generation prompts for the clips you request. No customer data exists to send.
  • Fish Audio - voiceover synthesis. Receives the script text of your clips.
  • Shopify - authentication and billing for Shopify installs.
  • Stripe - billing for web cabinet accounts. Card data is handled entirely by Stripe.
  • Vercel - hosting for this marketing site.

7. Data retention and deletion

While the app is installed, data is kept so the product works. When you uninstall:

  • Your access tokens are invalidated and session records are deleted immediately.
  • Shopify sends us a shop redaction request (typically 48 hours after uninstall). On receiving it we permanently delete every record tied to your shop: catalog cache, sales aggregates, generated media files, render history, credit ledger, learning signals, and the shop profile itself.
  • In all cases, all shop data is deleted within 30 days of uninstall.

The app implements all three of Shopify's mandatory privacy webhooks:

  • customers/data_request - answered honestly: we hold no customer-level data to export.
  • customers/redact - nothing customer-level is stored, so there is nothing to erase; the request is acknowledged and logged.
  • shop/redact - triggers the full purge described above.

8. Web cabinet accounts

If you use cartviral outside Shopify (the web cabinet), we store your email address for passwordless login codes, plus the signup IP address and a technical fingerprint used only for abuse prevention (blocking bulk fake signups). Login codes are stored hashed and expire in 10 minutes. Delete your account by emailing us; the same full purge applies to your workspace data.

9. Cookies

The embedded Shopify app uses Shopify session tokens, not tracking cookies. The web cabinet sets a single first-party session cookie to keep you signed in. This marketing site sets no advertising or analytics cookies.

10. Security

All traffic is encrypted in transit with TLS. API access tokens are stored server-side and never exposed to the browser. Webhooks from Shopify are verified with HMAC signatures before processing. Media files are scoped per shop and served through authenticated, signed URLs.

11. Your rights

Under GDPR, CCPA, and similar laws you can request access to the data we hold about you or your shop, ask for correction or deletion, and object to processing. Because we hold no end-customer personal data, such requests in practice concern your shop and account data. Email us and we will respond within 30 days.

12. Changes to this policy

If this policy changes materially, the date at the top is updated and installed merchants are notified through the app. The current version always lives at cartviral.com/privacy.

13. Contact

Questions, data requests, deletion requests: support@cartviral.com