Last updated 10 August 2026
Privacy
What CartGuard stores
CartGuard stores the cart rules you create, the compiled configuration derived from them, a history of configuration changes, your subscription status, and your app settings. Each record is scoped to your store.
Your store’s contact details
CartGuard also stores your store’s own account information: the myshopify domain, the store name, and the store contact email addresses Shopify provides (shop.email and shop.contactEmail). You can set a different address for CartGuard in Settings; that override applies to CartGuard only and is never written back to Shopify.
These details are used for four things and nothing else:
- running the service and identifying your store;
- billing and subscription notices;
- telling you when something needs your attention — checkout protection stopping, a configuration failing to publish, a security issue;
- product updates and release notes, which are off unless you switch them on in Settings.
These are merchant contact details: they identify your store account, not a shopper. They are not customer data. If you uninstall CartGuard, it stops sending you anything.
What CartGuard does not store
CartGuard does not store carts, orders, checkouts, customer names, email addresses, phone numbers, addresses or payment details. It does not track shopper browsing behaviour and it does not build customer profiles. Rule evaluation happens inside Shopify, so cart contents are never sent to CartGuard.
A rule can target customer tags — for example, only allowing a product for customers tagged wholesale. That check runs inside Shopify’s checkout validation function, which answers only whether a tag you named is present. No customer name, email address, phone number or address is read, and nothing about a shopper reaches CartGuard’s servers or is stored anywhere.
Access to your Shopify store
CartGuard requests three scopes: read_products to let you pick products when authoring a rule, and read_validations and write_validations to install and update the checkout validation that enforces your rules. It does not request access to customers, orders or Protected Customer Data.
Sub-processors
CartGuard runs on Railway (application hosting and PostgreSQL database) and integrates with Shopify. No other third party receives your data. There are no analytics or advertising trackers in the app.
Retention and deletion
Configuration history is retained for 30, 90 or 365 days depending on your plan, and older records are pruned automatically. When you uninstall CartGuard, your sessions are deleted immediately and Shopify removes the checkout validation. Your rules are retained so a reinstall restores your setup; you can request their permanent deletion at any time.
GDPR and compliance requests
CartGuard implements Shopify's mandatory compliance webhooks. Because it holds no customer personal data, a customer data request returns nothing and a customer redaction request has nothing to erase. A shop redaction request removes the store's records.
Contact
For privacy questions, write to us through the support page.