Privacy Policy

Your privacy matters to us. Learn how we protect and handle your information.

Last Updated: August 11, 2025

CartCorral Corp. ("CartCorral", "we", "our", or "us") respects your privacy. This Privacy Policy explains what Personal Information we collect, how we use it, and the choices you have when you use:

Our websites (the "Site")
Our products and services, including the CartCorral browser extension, application programming interfaces, associated software, developer tools, data, and documentation (the "Services")
"Personal Information" means information that identifies or can be reasonably linked to an individual.

1. Personal Information We Collect

1.1. Information You Provide

Account Information

When you create an account, we collect your email address and related details for authentication and communication.

Communications and Support

If you contact us, we will collect your name, email, and the contents of your message.

1.2. Social Media

We maintain pages on platforms like Instagram, Facebook, X/Twitter, YouTube, and LinkedIn. If you interact with those pages, we receive the information you choose to provide there and platform-provided analytics in aggregate.

1.3. Information Collected Automatically When You Use the Services

Log Data

IP address, browser type and settings, date/time of requests, and general interaction data with our Site or Services.

Usage Data

Feature usage, actions taken, session timing, device type, operating system, and browser version.

Device Information

Device name, OS, and browser.

Shopping Cart Data

On supported e-commerce sites, we collect item title, price, quantity, image URL, SKU or item ID, category or subtype, fulfillment type (when available), the site hostname, and timestamps, in order to provide the unified cart experience.

Diagnostics

De-identified error logs and performance metrics to fix bugs and improve performance.

Cookies and Similar Technologies

We use cookies and similar tools on our Site for functionality and analytics.

Extension Storage

The extension stores data locally using the browser's chrome.storage.local (or equivalent). This is separate from website cookies and is controlled by you within your browser.

Note on Network Observation (extension)

To detect cart activity, the extension observes relevant network activity on supported sites. Non-cart data that may be momentarily visible (for example, payment or login information) is not logged, stored, or transmitted and is discarded immediately within your browser.

Google/Chrome Policies: Where applicable, our use of Google APIs and Chrome extension capabilities adheres to the Chrome Web Store User Data Policy, including Limited Use requirements.

2. How We Use Personal Information

Provide, operate, maintain, and improve the Services.
Authenticate you and sync your carts when you enable cloud features.
Communicate with you (for example, service updates and policy changes).
Conduct internal research and analytics to improve features and performance.
Detect, prevent, and address fraud, abuse, security risks, and technical issues.
Comply with law, enforce our terms, and protect rights, safety, and property.

Aggregated and De-identified Information

We may use and share information that has been aggregated or de-identified so it cannot reasonably be linked to an individual.

3. Sharing and Disclosure

4. Managing Your Information / Contact Us

To access, update, or delete your account information, or if you have questions, email privacy@cartcorral.io.

5. California Privacy Rights (CPRA)

Right to Know

Request the categories and specific pieces of Personal Information we have collected, the sources, purposes, and categories of disclosures for the past 12 months (or longer if required).

Right to Delete

Request deletion of Personal Information, subject to legal exceptions.

Right to Correct

Request correction of inaccurate Personal Information.

Right to Opt-Out of Sale or Sharing

We do not currently "sell" or "share" Personal Information (as defined by California law). If this changes in the future, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism.

Right to Limit Use of Sensitive Personal Information

If we collect Sensitive Personal Information (for example, precise geolocation or payment data), you may request we limit its use to permitted purposes.

Right to Non-Discrimination

We will not discriminate against you for exercising these rights.

How to Exercise Your Rights

Email privacy@cartcorral.io. We will verify your request using information associated with your account or other acceptable methods. You may use an authorized agent; we may require proof of authorization and additional verification. If we cannot verify your identity, we may be unable to fulfill the request.

5A. Data Retention

Account Lifetime

Account and Authentication Data

Retained for the life of the account and deleted within 90 days of account deletion.

24 Months

Communications and Support

Retained up to 24 months unless a longer period is required by law or to resolve a dispute.

30-90 Days

Diagnostics and Logs

Retained up to 30–90 days unless needed to investigate issues or improve the Services.

Indefinite

Aggregated/De-identified Data

May be retained without a set deletion date, as it does not identify you.

Actual retention periods may vary based on legal, security, or operational requirements.

6. Children's Privacy

The Services are not directed to children under 13. We do not knowingly collect Personal Information from children under 13. If you believe a child has provided Personal Information to us, contact privacy@cartcorral.io and we will delete it.

7. Links to Other Websites

8. Security

We use administrative, technical, and organizational measures designed to protect Personal Information.

Security and Encryption

All connections between your device and our servers use HTTPS/TLS. When we store Personal Information in our cloud systems, we encrypt it at rest using industry-standard methods. Data stored locally by the extension (for example, via chrome.storage.local) is on your device and isolated from web pages by the browser, but is not end-to-end encrypted by us.

No Internet or email transmission is completely secure. Use caution when sending information by email.

9. International Users

If you access the Services from outside the United States, you understand that your information may be processed in the United States, where privacy laws may differ from those in your jurisdiction.

10. Your Choices

If you choose not to provide certain information, some features of the Services may not be available. You can control cookies in your browser settings and can clear the extension's local data from your browser at any time.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the "Last Updated" date above. If we make material changes, we will provide additional notice as appropriate.