CartSmith · Legal
Privacy Policy
Last updated
CartSmith is a software studio that builds Shopify apps. This policy covers this website — cartsmith.dev — including its support portal, and what happens when you browse it, open a support request, or email us. Data handled by our apps is governed by each app's own privacy policy; those are linked below.
Browsing this website#
Reading the site requires no account and creates no profile:
- No advertising or cross-site trackers. We run no ad pixels and sell no data, on a site that also hosts privacy policies — that's on purpose.
- Theme preference. Your dark/light choice is stored in your browser's local storage. It never leaves your device.
- Hosting logs. Our hosting provider records standard request logs (IP address, browser user agent, requested page) to operate and secure the service. They are retained short-term and never used to profile you.
Support accounts#
Using the support portal requires signing in — with your email only. There are no passwords: we email you a one-time sign-in link, which is also how your account is created. For that we store:
- your email address (and a display name, if you ever provide one);
- session records so you stay signed in on your device — sessions live in an essential, httpOnly cookie, used for nothing else;
- timestamps such as when the account was created and last used.
Support tickets#
When you open a request, we store what you submit: the request type, subject, and message thread, plus the optional app and store domain fields if you fill them in. Tickets and their replies are kept in our database so both sides keep the history, and are retained until you ask us to delete them. Don't include passwords, API keys, or payment details in a ticket — we will never ask for them.
Ticket activity triggers transactional email — confirmation when you open a request, and a notification when we reply or the status changes. These are service emails, not marketing; there is no mailing list to unsubscribe from.
Spam protection#
The sign-in and request forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person. Turnstile may process technical signals from your browser (such as your IP address) for that purpose under Cloudflare's privacy policy.
When you email us#
Email works without any account. When you write to support@cartsmith.dev we receive your address and message, use them to reply, and keep the thread as ordinary correspondence records. You are never added to a marketing list.
Our apps have their own policies#
Each CartSmith app publishes its own privacy policy describing exactly what that app collects from merchants and their customers:
- Printscape privacy policy — the live product personalizer for Shopify print-on-demand stores.
If you use one of our apps as a merchant, or shop at a store that runs one, the app's policy is the one that applies to that data.
Sharing and service providers#
We do not sell personal information. The service providers that process website and support data on our behalf are: our hosting provider (runs the site and database), Resend (delivers transactional email), and Cloudflare (Turnstile spam protection). Each processes data solely to provide that service.
Your rights#
Depending on where you live, you may have statutory rights to access, correct, or delete personal information (for example under the GDPR or CCPA). For this site that means your support account, your tickets, and our correspondence. Open a request or email us with the subject "Privacy request" and we will honor any reasonable request — including deleting your account and tickets entirely — wherever you are.
Changes#
If this policy changes, the update appears on this page with a new date above. Changes to an app's data practices are made in that app's own policy.
Contact#
Questions about privacy at CartSmith: support@cartsmith.dev or open a request.