Legal
Privacy policy
What CartBloom stores, what it deliberately does not, and how to get any of it back or erased.
CartBloom is a product of Pinion Labs Inc., which is the data controller for the personal data described in this policy.
Last updated
The short version
- CartBloom holds merchant configuration — your offers, your design settings, a token to write them to your store.
- It requests no access to customers or orders, and holds no personal data about your shoppers.
- Storefront visitors never contact CartBloom's servers. The widget is served by Shopify.
- Uninstalling the app erases everything stored for your store.
A summary is not the policy. The sections below are.
Who we are, and who this policy covers
CartBloom is a Shopify app that adds a reward progress bar to a merchant's cart. It is a product of Pinion Labs Inc., which operates the app and is the data controller for the data described here.
This policy covers two groups of people, and it is worth being clear which is which, because they are treated very differently.
- Merchants — the people who install CartBloom and use its embedded admin. We store data about your store so the app can work. That data is described in full below.
- Shoppers — the people who visit a merchant's storefront and see the progress bar. We store nothing about them. We do not receive their names, email addresses, order history or any other personal data, and their browsers never make a request to us.
Where this policy says "we" or "us", it means Pinion Labs Inc.. Where it says "your store", it means the Shopify store on which CartBloom is installed.
What CartBloom stores
Four things, all of them about the store rather than about a person:
- Your offer configurations — the tiers you set, their thresholds, the reward at each tier, the gift products you selected, and your design settings (colours, font sizes, weights, padding, corner radius, layout and placement).
- A Shopify access token for your store, so the app can write those offers to it. The token is granted by Shopify when you install the app and is revoked when you uninstall.
- A record of each publish, so that you can see what was published and roll back to a previous version of an offer.
- Session records for the embedded admin, so that the app knows the browser session in the Shopify admin belongs to your store.
The gift products stored in a configuration are product references from your own catalogue — identifiers, titles and images that Shopify already publishes on your storefront. They are not personal data.
The permissions we ask Shopify for
CartBloom requests exactly two Shopify access scopes, and no others:
- write_discounts — to create and update the discounts that deliver your reward tiers.
- read_products — to show your catalogue in the app so you can pick gift products.
CartBloom requests no access to customers and no access to orders, and therefore receives none. This is not a policy choice that we could quietly reverse; it is enforced by Shopify at the API boundary. An app that has not been granted a scope cannot read the data behind it.
One consequence is worth spelling out. If you target a tier at customers with a particular tag, that check is evaluated inside Shopify's own discount function, which answers yes or no at checkout. It never hands CartBloom a customer record — we do not learn who the shopper is, what tags they carry, or whether they qualified.
What CartBloom does not do
Stated plainly, because the absence of collection is easy to claim and worth being specific about:
- We store no shopper personal data — no names, no email addresses, no postal addresses, no order history, no payment details.
- We set no cookies for authentication, and no tracking or advertising cookies of any kind.
- We run no analytics and load no third-party trackers on merchant storefronts.
- We do not build shopper profiles, and we do not track shoppers across stores or across sessions.
- We do not sell, rent or share data with anyone. There is no advertising business here to feed.
- We do not use your data to train machine-learning models.
Shoppers and the storefront widget
When a shopper opens the cart on a store running CartBloom, their browser does not contact CartBloom's servers. Not for the configuration, not for the images, not for a beacon. The offer configuration is delivered by Shopify itself, inlined into the page that Shopify serves.
This was an architectural decision made for performance and reliability — the app cannot slow a storefront down or go down with it — but the privacy consequence is the more important one: we have no storefront request logs, because there are no storefront requests. There is no IP address, user agent or page URL for us to hold, discard or be asked to produce.
Whether a shopper is entitled to a reward is decided by a Shopify Function running inside Shopify's checkout, not by us and not by the storefront. That function runs on Shopify's infrastructure and is subject to Shopify's own privacy commitments to the merchant.
Where data is stored, and how it is protected
CartBloom runs on Cloudflare Workers, with data stored in Cloudflare D1. Data is encrypted at rest, and all traffic between your browser, Shopify and CartBloom travels over TLS.
Access to production data is limited to the people who operate the app, and only for the purposes of running it — investigating a fault you have reported, restoring a configuration, or responding to a request under this policy.
Two service providers process data on our behalf, and there is no third:
- Cloudflare, Inc. — hosting and database (Cloudflare Workers, Cloudflare D1).
- Shopify Inc. — the platform CartBloom is installed on, which delivers the app's admin, serves the storefront widget and runs the checkout function.
Both operate globally, which means your configuration data may be processed outside your own country. Transfers are covered by those providers' own data-protection terms, including standard contractual clauses where they apply.
Why we hold what we hold
Under the GDPR, the legal basis for processing merchant data is performance of a contract: you installed the app so that it would run your offers, and it cannot do that without storing them and without a token to write them to your store. Publish history exists so that you can roll back a change you regret, which is part of the same service.
We do not process merchant data on the basis of consent for marketing, because we do not use it for marketing.
Retention and deletion
Data is kept for as long as the app is installed, because that is how long it is needed. Uninstalling CartBloom erases all stored data for that store.
CartBloom implements Shopify's three mandatory privacy webhooks:
- customers/data_request — acknowledged with nothing to return. There is no customer data to produce, because none is ever held.
- customers/redact — acknowledged with nothing to erase, for the same reason.
- shop/redact — erases every record we hold for the store: offer configurations, the access token, publish history and session records.
The two customer-facing topics are answered honestly rather than ignored: we confirm receipt, and there is genuinely nothing to hand over or delete.
Your rights as a merchant
You can ask us at any time to:
- Access — tell you exactly what we hold for your store.
- Export — send you your offer configurations and publish history in a machine-readable format.
- Correct — fix anything inaccurate, though in practice you can edit configurations yourself in the app.
- Delete — erase everything for your store. Uninstalling does this automatically; ask us if you would like written confirmation.
- Restrict or object — limit how we process your data, or object to a particular processing activity.
Write to support@cartbloom.space from an address associated with the store. We will respond within 30 days, and usually much sooner. There is no charge.
If you are in the UK or the EEA and you believe we have handled your data badly, you have the right to complain to your local supervisory authority. We would rather you told us first, but that right is yours regardless.
If a shopper asks you about their data
Occasionally a shopper will send a merchant a subject access or erasure request that names every app on the store. For CartBloom the answer is short: CartBloom holds no personal data about your shoppers, receives no customer or order data from Shopify, sets no cookies in shoppers' browsers and receives no requests from them.
If you need that in writing to satisfy a request or an audit, email support@cartbloom.space and we will confirm it.
GDPR and CCPA posture
For merchant data, Pinion Labs Inc. acts as a data controller in respect of your account and store configuration, and as a processor to the extent it acts on your instructions within your store. Because no shopper personal data ever reaches us, the controller/processor question that usually dominates app privacy policies has very little surface area here.
Under the CCPA and CPRA, CartBloom does not sell or share personal information, and has no personal information about California consumers shopping on your store to sell or share. We do not use or disclose sensitive personal information for any purpose beyond providing the service. We do not offer financial incentives in exchange for personal information, and there is no "Do Not Sell or Share My Personal Information" mechanism to offer because there is nothing to opt out of.
CartBloom is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
If something goes wrong
If we become aware of a breach affecting merchant data, we will notify affected merchants without undue delay and, where required, the relevant supervisory authority within 72 hours of becoming aware of it. The notification will say what happened, what data was involved, and what we are doing about it.
If you believe you have found a security issue in CartBloom, please report it to support@cartbloom.space. We will acknowledge the report and keep you updated while we fix it.
Changes to this policy
When this policy changes, the last-updated date at the top of the page changes with it, and the previous version is superseded from that date.
If a change is material — if we start collecting something we do not collect today, add a service provider, or change what a Shopify permission is used for — we will notify installed merchants in the app and by email before it takes effect, not after. A change that only clarifies wording will simply appear with a new date.
Contact
CartBloom is operated by Pinion Labs Inc.. Privacy questions, data requests and security reports all go to support@cartbloom.space. A person reads it.
support@cartbloom.space is a placeholder address for this site build and should be replaced with the live support inbox before launch.