SHOPIFY APPS
SHOPIFY APPS
Standalone web applications designed to seamlessly integrate into Shopify stores.
OUR APPS
FEATURED APPS
Discount and price checkout
Automate tracking price history and display the lowest price in the last 30 days.
Products Ingredients & Nutrition
Perfect for compliance with food labeling regulations in the US, Canada, and Europe
SmileScore
Ideal for businesses targeting a younger demographic or leveraging social media marketing.
Search
Privacy policy
CartCraft Pte. Ltd. (UEN: 202417742K) (“CartCraft”, “we”, “our” or “us”) is the controller responsible for the personal data processed through this website and through our Shopify apps. This Privacy Policy explains what data we process, why we process it, who receives it, how long we keep it and what rights you have.
We are based in Singapore. Because we offer our services to customers in the European Union, the EU General Data Protection Regulation (GDPR) applies to that processing under Art. 3 (2) (a) GDPR, alongside the Singapore Personal Data Protection Act (PDPA). Where the two frameworks differ, we apply the standard that gives you the stronger protection.
We collect the data you actively provide to us, together with the technical data your browser transmits automatically when you open a page. Depending on how you interact with us, this includes:
We do not collect behavioural data about visitors to this website. We use no analytics, tracking, advertising or profiling services.
When you visit our website, the web server automatically records technical information sent by your browser. This includes your IP address, the date and time of the request, the page requested, the referring page, and your browser and operating system version. We need this data to deliver the website and to detect and defend against attacks.
This data is not merged with other data sources and is not used to identify individual visitors.
Legal basis: our legitimate interest in the secure and reliable operation of our website (Art. 6 (1) (f) GDPR).
Retention: log files are deleted automatically after 14 days.
You can contact us by e-mail at contact@cartcraft.io. We process the name, email address and message you provide, together with any attachments, in order to handle your enquiry.
Messages are received in our business mailbox and are not stored in the website database. The providers that operate our mailboxes are listed under “Data Sharing and Third-Party Services” below.
Please do not send confidential documents or personal data concerning third parties unless this is genuinely necessary for your enquiry.
Legal basis: steps taken at your request prior to entering into a contract (Art. 6 (1) (b) GDPR) and our legitimate interest in responding to enquiries (Art. 6 (1) (f) GDPR).
Retention: enquiry correspondence is deleted once it is no longer needed, at the latest after 24 months, unless statutory retention periods apply.
Our website does not set cookies of its own. We do not use analytics, tracking, advertising or profiling services, and we do not embed external fonts, maps, social media plugins or video platforms. Apart from the two cases described below, everything needed to display our pages is served from our own servers.
Because we set no cookies of our own that would require consent under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), we do not display a cookie banner for our own website.
One thing on our pages loads from a third party without asking you first. Our blog overview and our blog articles show an author image that is loaded from Gravatar. This transmits your IP address to the provider, but it does not set a cookie.
The step by step guides on our app pages and in two of our blog articles come from Scribe, and they only load if you ask for them. Until then you see a placeholder that names the provider, and nothing is sent to Scribe. When you press the button on that placeholder, the guide is loaded in a frame from Scribe’s servers, and Scribe then sets a cookie and runs its own analytics inside that frame. Your click is your consent for that, and it applies to that one page view.
Both services, the data involved and the legal basis are described under “Data Sharing and Third-Party Services” below. You can prevent the author image from loading by using a content blocker in your browser.
We use the data described above for the following purposes:
We do not use your data for automated decision-making or profiling.
We retain the data collected through our Shopify apps for 30 days after the app is uninstalled from your shop. If you would like your data deleted sooner, contact us and we will remove it from our systems promptly.
For our other products and services, we may keep data for longer where this is necessary to handle support enquiries, to defend legal claims or to meet statutory retention obligations, in particular the retention periods that apply to invoices and accounting records. Once the purpose no longer applies and no retention obligation stands in the way, we delete the data.
We do not sell your personal data. Below we list the providers involved in our processing, separated into those who act on our instructions and those who receive data in their own right.
Each of the following providers processes personal data on our instructions under a data processing agreement.
We use Stripe to process payments and to issue invoices for our services. Stripe Payments Europe, Ltd. (Ireland) acts as our processor; depending on the service used, data may be transferred to Stripe, Inc. in the United States.
Once you become a customer, the following data is processed by Stripe on our behalf: your name and company name, billing address, email address, VAT identification number where provided, the invoice items and amounts, and the payment status. Payment details such as card or bank account data are entered directly into Stripe’s systems and are never stored by us.
Stripe also sends invoice and payment emails on our behalf, showing cartcraft.io as the sender.
Legal basis: performance of a contract (Art. 6 (1) (b) GDPR) and compliance with statutory retention obligations (Art. 6 (1) (c) GDPR).
Retention: invoice data is kept for the statutory retention periods that apply to us.
Transfers outside the EU: covered by the EU Standard Contractual Clauses concluded with Stripe.
Stripe privacy policy: https://stripe.com/privacy
Our website is hosted by Hetzner Online GmbH in Germany. All website data, including the server log files, is stored on servers within the European Union. We have a data processing agreement in place with Hetzner.
Legal basis: our legitimate interest in the reliable operation of our website (Art. 6 (1) (f) GDPR).
Hetzner privacy policy: https://www.hetzner.com/legal/privacy-policy/
Email sent to our cartcraft.io addresses is received and stored with Amazon Web Services (Amazon WorkMail). Mail content is stored on AWS servers in the United States.
Legal basis: our legitimate interest in operating a reliable business email service (Art. 6 (1) (f) GDPR).
Transfers outside the EU: covered by the EU Standard Contractual Clauses concluded with AWS.
AWS privacy notice: https://aws.amazon.com/privacy/
Email addressed to our cartcraft.io addresses is forwarded to a business mailbox operated by Google Ireland Ltd., where we read and answer it. Mail content may be transferred to the United States.
Legal basis: our legitimate interest in operating a reliable business email service (Art. 6 (1) (f) GDPR).
Transfers outside the EU: covered by the EU Standard Contractual Clauses concluded with Google.
Google privacy policy: https://policies.google.com/privacy
The providers in this group do not act on our instructions. They receive data in their own right, either because content is loaded from their servers, or because you use their service yourself.
The setup guides on our app pages and in two of our blog articles come from Scribe, a service of Colony Labs, Inc. in the United States. They do not load with the page. You first see a placeholder that names Scribe and the transfer, and up to that point nothing is sent there. Only when you press the button on the placeholder is the guide loaded. From that moment your IP address and your browser information are transmitted to Scribe so that the guide can be displayed, Scribe sets a cookie, and it runs its own analytics inside the embedded frame. We have no influence on that processing.
Legal basis: your consent, given by pressing the button on the placeholder (Section 25 (1) TDDDG for the storage of and access to information on your device, and Art. 6 (1) (a) GDPR for the processing that follows). You can withdraw it by reloading the page, which brings the placeholder back and loads nothing further.
Transfers outside the EU: Scribe states that it relies on the EU Standard Contractual Clauses and on the EU-U.S. Data Privacy Framework.
Scribe privacy policy: https://scribe.com/legal/privacy
Our blog overview and our blog articles show an author image that is loaded from the Gravatar service. Gravatar is operated by Aut O’Mattic A8C Ireland Ltd. in Ireland together with Automattic Inc. in the United States. When you open one of those pages, your IP address and your browser information are transmitted to Automattic so that the image can be delivered. This request does not set a cookie.
Legal basis: our legitimate interest in a consistent presentation of our blog (Art. 6 (1) (f) GDPR).
Transfers outside the EU: Automattic states that it relies on the EU Standard Contractual Clauses.
Automattic privacy policy: https://automattic.com/privacy/
Some of our pages link to a booking page hosted by Calendly, LLC in the United States, so that you can arrange an appointment with us. Opening our website transmits no data to Calendly. Data is processed there only once you follow the link, and the details you enter when booking, in particular your name, your email address and the appointment time, reach us through Calendly.
Legal basis: steps taken at your request prior to entering into a contract (Art. 6 (1) (b) GDPR).
Transfers outside the EU: Calendly states that it relies on the EU-U.S. Data Privacy Framework and on the EU Standard Contractual Clauses.
Calendly privacy notice: https://calendly.com/legal/privacy-notice
Some of the service providers we use process data outside the European Economic Area, in particular in the United States. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses under Art. 46 (2) (c) GDPR, supplemented where appropriate by additional technical and organisational measures. Some providers are additionally certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision. The mechanism that applies to each provider is stated in the section above.
You can request a copy of the safeguards in place by writing to contact@cartcraft.io.
Where data is processed in Singapore, comparable safeguards under the Personal Data Protection Act (PDPA) apply.
We implement appropriate technical and organisational measures to protect your information against unauthorised access, alteration, disclosure or destruction.
Our website uses TLS encryption for all connections, which you can recognise by the https:// prefix in your browser’s address bar. Access to our systems is restricted to the people who need it, and our servers are kept up to date with security patches.
Please note that no method of transmission over the internet or of electronic storage is completely secure.
Where the GDPR applies to the processing of your personal data, you have the following rights:
If you are located in Singapore, the rights under the Personal Data Protection Act (PDPA) apply in addition: access to and correction of your personal data, and withdrawal of consent.
To exercise any of these rights, write to us at contact@cartcraft.io.
Our website and apps are intended solely for businesses and business customers. We sell our products and services exclusively to businesses (B2B) and do not target children under the age of 13. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.
If you believe that we might hold information from or about a child under 13, contact us at contact@cartcraft.io so that we can take the necessary steps.
For any question about this Privacy Policy, or to exercise your rights, contact the controller:
CartCraft Pte. Ltd.
1 North Bridge Road, #B1-35
High Street Centre
Singapore 179094
Email: contact@cartcraft.io
We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR.
We may update this Privacy Policy from time to time, for example when we change a service provider or add a new service. The current version is always published on this page.
This Privacy Policy was last updated on 29 August 2026.