YourCart Privacy Policy

Last Updated: 30 July 2026 ยท Version 1.2.0

This Privacy Policy explains how YourCart Ltd (registered as YOURCART.STORE LTD, Companies House No. 15316188, registered office 15 Timperley Lane, Leigh, Greater Manchester, WN7 3DZ, United Kingdom; "YourCart", "we", "us") collects and uses Personal Data when you interact with us. It covers our website at yourcart.store, the YourCart vendor admin app, the customer-facing apps and storefronts we publish on behalf of our merchants, and any other channel through which we communicate with you.


1. Who this policy covers

This policy describes the Personal Data we hold as Controller — that is, where we determine the purposes and means of processing. The principal categories of person it applies to are:

It does not cover:

2. Personal Data we collect

2.1 Merchant account data

When you sign up as a merchant, we collect:

Data Source Purpose
Name, email, business name, business address, telephone number You, at sign-up or in account settings Operating your account, contacting you, complying with our legal obligations
Authentication credentials (email + hashed password, or third-party auth identifiers from Apple / Google) You, or your chosen identity provider Authenticating you and securing your account
Billing and payment-method tokens (we do not store full card numbers — Stripe does) You, via Stripe Checkout / Stripe Elements. Not applicable to Shopify-linked merchants: your subscription is billed by Shopify under Shopify Managed Pricing and we receive no payment-method data for it at all — see section 2.4.5 Processing your subscription payments
Companies House number, VAT number where supplied You Verifying business status; tax reporting where required
Support correspondence, BugReport submissions, and any other content you send to us You Handling your enquiry; investigating issues; product improvement
App and admin-tool usage telemetry (sign-in events, admin actions, IP address, device and browser information) Automatically captured Security, fraud prevention, abuse detection, debugging, regulatory audit logging

2.2 Marketing-site visitor data

When you visit yourcart.store or other YourCart marketing or documentation pages, we may collect:

We use only strictly necessary cookies prior to your consent. Non-essential analytics, marketing, or product cookies (where used at all) are loaded only after you provide informed consent through our cookie banner — see section 5.

2.3 End-customer data — note for clarity

If you are an end customer using a merchant's YourCart-built shop or app, the merchant is the Controller of your data and you should consult that merchant's privacy policy. YourCart processes that data only on the merchant's instructions, under the Data Processing Agreement between us and the merchant. This Privacy Policy does not extend any rights to end customers against YourCart that the merchant's policy does not also provide.

2.4 Shopify-linked merchants

Where you install the YourCart sales-channel app on a Shopify store and connect it to a YourCart account ("linked mode"), the sections below describe what we receive, why, who controls it, and how long we keep it. Linked mode is a distinct product mode: the mode flag is set at connection and does not change for the life of the account.

2.4.1 How the connection is made, and what it grants

You start the connection from Shopify and approve a set of access scopes on Shopify's own consent screen. Approving it authorises Shopify to issue YourCart API credentials for your store. We store those credentials encrypted; they are never displayed in logs, alerts, status pages, or support correspondence, and they are the only means by which we reach your store's data. Our access exists solely through that grant and ends when you uninstall the app or Shopify revokes it.

At install we also register with Shopify for a fixed set of notifications ("webhooks") about your store. These are the only topics we subscribe to:

Notification Why we receive it
Product-feed created; full sync; full-sync finished; incremental sync Keeping your published catalogue current in your branded app
App subscription updated Confirming your Shopify billing state (see 2.4.5)
App uninstalled Stopping the connection and starting the exit process
App scopes updated Recording a change to what you have authorised
Customer data request (Shopify's mandatory compliance topic) Responding to a data-access request Shopify routes to us on your behalf
Customer redaction (Shopify's mandatory compliance topic) Actioning a customer-erasure notice Shopify routes to us on your behalf
Store redaction (Shopify's mandatory compliance topic) Deleting your store's data after uninstall — see 2.4.6

We verify the authenticity of every notification cryptographically before acting on it, and we never write the body of a notification into our logs. Our log entries record only the topic, your store's domain, and Shopify's notification identifier.

2.4.2 What we receive from your store

Data Source Purpose
Shop identity — your myshopify.com domain, your Shopify shop ID, your store's region and display currency Shopify, at install and on refresh Operating the connection; regional availability checks; showing prices in your store's currency; support
API access credentials issued by Shopify for your store Shopify, at install and on token refresh Authenticated read access to the data in this table; stored encrypted, never disclosed
Product catalogue — products, variants, product images, descriptions, collections, selling plans (subscription options), and available-to-sell inventory levels, for products you publish to the YourCart channel Shopify, ongoing one-way sync Displaying your catalogue in your branded mobile app
Order state for orders placed through your branded app Shopify, read live at the moment it is displayed Showing a shopper the status of their own orders

The sync is one-way and read-only. Data flows from Shopify to YourCart and never back: we do not create, edit, or delete products, collections, inventory, customers, or any other record in your Shopify store as part of the sync. Where the app offers a shopper an action that must change something in your store — placing an order at checkout, requesting a return, or cancelling an order — that action is performed against Shopify at the moment the shopper takes it, on their instruction, and is not part of the catalogue sync.

Checkout is Shopify's, not ours. When a shopper checks out, we hand the basket to Shopify and the shopper completes the purchase on Shopify's own hosted checkout. Payment details, delivery addresses, and contact details entered at checkout are collected by Shopify and are governed by your agreement with Shopify and your own privacy policy. We do not receive, store, or process them. If the shopper has given an email address in the app, we pass it to Shopify to pre-fill the checkout form; we do not retain it in connection with the checkout.

2.4.3 What Shopify does not give us

Shopify applies a protected-customer-data regime that limits which customer fields an app may read. YourCart operates inside the lowest tier of that regime and cannot read your customers' names, display names, or email addresses from Shopify — those fields are refused to our app by Shopify's own access control, not merely left unrequested. We do not retrieve customer postal addresses. We describe this as a limit on what is technically available to us, and it is enforced by Shopify rather than by our own restraint.

Where we display a shopper's order history in your branded app, we read it from Shopify at the moment it is displayed, using the shopper's own authenticated session, and we do not store a copy of it.

One exception, stated for completeness. The limit above describes what Shopify's product APIs and Customer Account API make available to us. Shopify's compliance notifications are a separate channel, and the body of a customer data-request or customer-redaction notice is sent to us containing that customer's Shopify id and, where Shopify includes them, their email address and telephone number. We store that notification body only so the notice can be verified and actioned. We delete it as soon as the notice has been actioned, and in any event notification records are purged on the schedule in section 7. We do not copy those fields anywhere else, and we do not use them for any purpose beyond answering the notice.

2.4.4 Who controls your app customers' data

For everything held about a shopper in your branded app — their basket, their app sign-in identity, their push-notification registration, and their messages to you — you are the Controller and YourCart is your Processor, under the Data Processing Agreement. That is the same relationship that applies to every YourCart merchant, and linking a Shopify store does not change it. Shopify is separately the Controller of the customer records held in your Shopify store, under your own agreement with Shopify.

A shopper may sign in to your branded app using their Shopify customer account. When they do, we receive a pseudonymous numeric customer identifier issued by Shopify and nothing else — no name, no email address, no telephone number (see 2.4.3). We store that identifier against a YourCart app account so the shopper can be recognised on their next visit and their basket and order history follow them. Their YourCart app account carries no name or email address, because we have none to store.

Where Shopify notifies us that one of your customers has requested erasure, we delete that customer's Shopify identifier from the app account we hold, so the account can no longer be associated with them. Any delivery address, contact detail, or message content that customer had saved in your branded app is erased at the same time. The app account itself remains as your own record, no longer linked to any Shopify customer.

2.4.5 Billing in linked mode

In linked mode your YourCart subscription is charged by Shopify, through Shopify's Managed Pricing, on your Shopify invoice. We do not take payment from you, we do not create a Stripe customer for you, and we receive no card or bank details in connection with your subscription. What we do receive from Shopify is the state of that subscription — whether it is pending, active, frozen, or cancelled — which we use to determine whether your account and your branded app are active. Shopify's own terms and privacy policy govern the payment itself.

2.4.6 Uninstall, deletion, and Shopify's compliance notices

When you uninstall the app, Shopify notifies us and we immediately stop syncing and treat your store as disconnected. Shopify then issues a store-redaction notice following the uninstall. On receiving that notice we delete the data we received from your store, category by category, as set out in the linked-mode table in section 7, and we complete that deletion within the period Shopify mandates. Deletion is retried if it does not succeed first time, and a failure that we cannot resolve automatically raises an alert to us for manual completion.

If you reinstall before that notice is executed, we do not run the deletion — deleting at that point would destroy the data of a live, reconnected store. This is a statement about DELETION only: whether your YourCart account and branded apps are restored is governed by section 12.5 of the Terms of Service, and once takedown has run a reinstall does not by itself reinstate them.

Customer erasure notices. Where Shopify routes one of your customers' erasure requests to us, we action it automatically on receipt and record that we have done so, as described in 2.4.4.

Customer data-access requests. Where Shopify routes one of your customers' data-access requests to us, our automated handler records an audited acknowledgement; it does not currently send you an export. What we hold for that customer is limited to what 2.4.4 describes — we hold no customer name, email address, or postal address from Shopify (see 2.4.3) and no stored copy of your order records. Ask us at admin@yourcart.store and we will provide it. You remain responsible for responding to your customer.

What survives deletion. Deleting your store's data does not delete your YourCart account. Your account record, our billing and accounting records, and our security and audit logs survive on the retention periods in section 7 — we are required to keep them, and they contain no data received from Shopify. Deleting your store's data is also not the same thing as closing your YourCart account; if you want the account itself closed, tell us at admin@yourcart.store.

Backups. Deletion takes effect immediately in our live systems. Our backups expire on their own cycle (section 7), so a copy may persist in an expiring backup for a short period after deletion. Backups are not used operationally and are not searched or restored except in a disaster-recovery event.

3. How we use Personal Data and our lawful basis

Purpose Lawful basis under UK GDPR
Operating your merchant account, providing the contracted YourCart service, processing your subscription Contract — performance of our agreement with you (Article 6(1)(b))
Authenticating you, securing your account, detecting and preventing fraud or abuse, rate-limiting Legitimate interest — securing the platform for all merchants (Article 6(1)(f))
Sending transactional emails (welcome, billing, password reset, system notifications, support replies) Contract (where the email relates directly to the service); legitimate interest (where operational)
Sending product updates, founding-cohort communications, or other commercial messages to active merchants Legitimate interest (Article 6(1)(f)) — soft opt-in under PECR Regulation 22(3) for existing customers, with an unsubscribe link in every message; consent for any new commercial channel where required
Complying with our legal obligations (tax reporting, ICO information notices, court orders, regulatory enquiries) Legal obligation (Article 6(1)(c))
Maintaining audit logs, business records, and accounting books Legal obligation (Companies Act 2006, HMRC retention rules); legitimate interest (Article 6(1)(f))
Defending or pursuing legal claims Legitimate interest (Article 6(1)(f))
Receiving, verifying, and actioning the mandatory compliance notifications Shopify sends about a linked store (customer data request, customer redaction, store redaction), and keeping a record that we did so Legal obligation (Article 6(1)(c)) where the underlying request is a data-subject right; contract (Article 6(1)(b)) — Shopify's platform terms are a condition of providing you the sales-channel app

We do not use Personal Data for automated decision-making with legal or similarly significant effects, do not carry out behavioural profiling for advertising purposes, and do not sell or rent Personal Data to third parties.

4. Sharing Personal Data

4.1 Sub-processors

We engage the following sub-processors to deliver the YourCart service. Where a sub-processor processes Personal Data of a merchant's end customers, this is governed by the Data Processing Agreement; the table below lists the same set as it applies to merchant-account-holder data we hold as Controller.

Sub-processor Purpose Data location Transfer mechanism
Stripe Payments Europe Ltd Subscription billing, payment-method tokenisation, Connect-account payouts Ireland (primary), United States (failover) Stripe is its own Controller for payment data; UK adequacy (EEA→UK) for the Irish leg
Google LLC (Firebase) Authentication, push-notification delivery (FCM), Firestore for ephemeral state United States UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses
Microsoft Ireland Operations Limited (Azure) Application hosting, SQL Server, Blob Storage, Key Vault, Application Insights UK South region (primary) Data residency UK; Microsoft Online Services DPA. EMEA contracting entity: Microsoft Ireland Operations Limited, 70 Sir John Rogerson's Quay, Dublin, D02 R296, Ireland
Mailgun Technologies Inc. Transactional email delivery United States UK IDTA to the EU Standard Contractual Clauses

A current sub-processor list is maintained at https://yourcart-api-prod.azurewebsites.net/SubProcessors. We will notify active merchants by email at least 14 days before any material change (addition or replacement of a sub-processor) takes effect.

4.2 Other recipients

In addition to the sub-processors above, we may disclose Personal Data:

We do not sell Personal Data to third parties for their own marketing purposes.

5. Cookies and similar technologies

We use only strictly necessary cookies before your consent — these are required for the site or admin tool to function and cannot be disabled (session, authentication, CSRF protection, basic security).

Where we use any non-essential cookies or similar technologies (analytics, product telemetry, marketing pixels), we will load them only after you have given informed consent through our cookie banner. The banner offers an "Accept" and a "Reject" of equivalent prominence; choosing "Reject" causes only strictly-necessary cookies to load. You can change your preference at any time from the cookie-preferences link in the website footer.

A list of cookies and their purposes is maintained on the cookie-preferences page itself.

6. International data transfers

Where we transfer Personal Data outside the United Kingdom, we rely on:

A current list of transfer destinations is given in section 4.1.

7. How long we keep Personal Data

Data category Retention period
Active merchant-account data For as long as your account is open, plus a wind-down period of up to 30 days after termination
Billing, invoicing, and accounting records 6 years from the end of the relevant accounting period (HMRC requirement under the Finance Act 2008 and Companies Act 2006)
Audit and security logs (admin actions, sign-in events, abuse-detection records) Up to 24 months for operational purposes; longer where required for legal claims or regulatory obligations
Support correspondence and BugReport submissions Up to 24 months from last interaction
Marketing-site analytics (where collected with consent) Up to 14 months at the analytics provider, or such shorter period as the provider's defaults dictate
Shopify-linked store data Deleted on Shopify's store-redaction notice following uninstall, within the timescale Shopify mandates. See the linked-mode table below for the disposition of each category. Billing, accounting, and audit records survive per the rows above
Backups Daily SQL backups with 30-day point-in-time recovery; deletion requests flow through to backups on the next backup-cycle expiry, not immediately

Where a longer retention period is required by applicable law, regulatory request, or to defend or pursue a legal claim, we retain the data for that longer period and segregate it from operational use where reasonably practicable.

Linked mode — what is deleted on a store redaction

Where you have connected a Shopify store, this is every category of data we hold that came from — or exists because of — that connection, and what happens to each when Shopify's store-redaction notice is executed. This table is the authoritative statement of our deletion behaviour in linked mode.

# Category What we hold What happens on store redaction
1 Synced catalogue Products, variants, images, descriptions, collections, selling plans, and available-to-sell inventory synced from your store Product and SKU records are disabled and soft-deleted, and their Shopify product and variant identifiers and available quantity are cleared. The underlying rows are retained in a deleted state because historic YourCart records reference them and cannot be orphaned, and dependent historic rows may remain
2 Shopping baskets Shoppers' in-app baskets and basket-change history over your catalogue Deleted outright
3 Push-notification registrations The device tokens shoppers' devices register to receive your notifications Deleted outright
4 Messages Messages between you and your app customers, and the rate-limit records that police them Deleted outright
5 Notification history The record of which notifications were sent to which device, including price-drop notifications Deleted outright
6 Shopify access credentials The API credentials Shopify issued for your store Every credential is erased. A minimal record that the connection existed and was redacted is kept, holding no credential material
7 Deletion audit record The record that a redaction was requested and completed Kept. It is our evidence that we complied, it contains no personal data, and it is the one thing a regulator or Shopify would ask us to produce
8 Shopify sign-in identity The pseudonymous Shopify customer identifier held against an app account where a shopper signed in with their Shopify customer account (2.4.4) Erased when Shopify sends us a customer-redaction notice for that shopper, together with their saved address and message content (2.4.4). A store redaction does not itself run this per-customer erasure; it removes the store data in rows 1–7, and the app account survives as YourCart account data

Alongside those categories, the operational records the connection generates are handled as follows. The queue of Shopify notifications for your store is deleted, except the redaction notice itself, which is kept as the audit record in row 7 and has its contents stripped. Application and error logs are append-only and are therefore not deleted but overwritten in place: any entry referencing your store's domain has its free-text content replaced with a redaction marker. Independently of any redaction, processed notification records are purged after 30 days, and notifications that failed permanently after 90 days.

Your YourCart account record, your app users' YourCart account identities (with any Shopify identifier removed, per row 8), and their notification preferences are not deleted by a store redaction: they are YourCart account data rather than data received from Shopify, and they are governed by the main retention table above. Closing your YourCart account is a separate request — see 2.4.6.

8. Security

We apply technical and organisational measures appropriate to the risk, including:

No information system is completely secure. We do not represent or warrant that our security measures will prevent every unauthorised access, and we accept no liability for breaches not directly attributable to a failure on our part to apply the measures described in this section. Our liability where it does apply is governed by our Terms of Service and the Data Processing Agreement, including the liability cap set out there.

9. Your rights

Subject to UK GDPR and the Data Protection Act 2018, you have the right to:

To exercise any of these rights, contact us using the details in section 12. We will respond within 30 days of receiving a verifiable request, subject to UK GDPR Article 12(3) which permits an extension where the request is complex or numerous. Where we cannot accommodate a request (for example, where retention is required by law), we will explain why.

We may need to verify your identity before acting on a request, particularly where the request relates to data we hold about a third party. We will not charge a fee for processing requests except where they are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse to act, in accordance with UK GDPR Article 12(5)).

10. Children

YourCart is a B2B service intended for use by merchants and their staff. The vendor admin tool, marketing site, and merchant-facing surfaces are not directed at children under 16 and we do not knowingly collect Personal Data from children under 16 in those contexts.

End-customer-facing storefronts and apps published on behalf of merchants may be used by individuals of any age permitted by the merchant's own products, content, and policies. The merchant is the Controller in that context and is responsible for any age-related compliance (for example, age-gating where required). Section 1 of the AUP and section 2.6 of the DPA limit the categories of data the merchant may collect through the platform, and high-risk Processing is excluded under DPA section 14.

11. Lodging a complaint

If you are dissatisfied with how we handle your Personal Data, please first contact us at admin@yourcart.store so that we can attempt to resolve the matter directly.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk · 0303 123 1113

Our ICO registration number will be published here once registration is complete (registration trigger: first merchant taking real customer orders).

12. Contact us

For privacy questions, Data Subject requests, or to raise concerns:

YourCart Ltd
Privacy: admin@yourcart.store
General support: admin@yourcart.store
Postal: 15 Timperley Lane, Leigh, Greater Manchester, WN7 3DZ, United Kingdom

We aim to acknowledge privacy emails within 2 UK business days and substantively respond within the 30-day UK GDPR window.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the service, sub-processor list, applicable law, or our practices. The version and last-updated date at the top of this document are the canonical record.

Continued use of the YourCart service after the effective date of a change constitutes acceptance of the updated policy, save where the change requires fresh consent.

14. Governing law

This Privacy Policy is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction over any dispute arising under or in connection with it, without prejudice to your statutory right to lodge a complaint with the ICO under section 11.