Privacy and Data Protection

Privacy Policy

Learn how Clocart handles data for logistics fulfillment, Shopify connections, rate calculation, label purchase, tracking, wallet activity, and support.

Privacy Policy

Last updated: July 23, 2026

This policy explains how Clocart and deployments based on this system collect, use, retain, and protect data related to merchants, users, Shopify stores, orders, shipping addresses, shipments, wallets, and support requests.

Key Commitments

  • We process data only as needed to provide logistics fulfillment, rates, labels, tracking, reconciliation, support, and security.
  • Shopify store data is used according to granted scopes and isolated by store, tenant, and bound user where applicable.
  • Regular users see their own logistics data by default; tenant-wide views require explicit administrative permission and intent.
  • We do not sell personal information or use order/customer data for unrelated advertising profiles.

Data We Process

Account and tenant data: username, email, phone, company or team information, roles, permissions, login state, language preference, and security logs.

Logistics fulfillment data: order references, recipient name, company, phone, email, ship-from and ship-to addresses, parcel weight and dimensions, declaration data, carrier, service, labels, tracking numbers, tracking events, and exception status.

Shopify integration data: shop domain, authorization state, encrypted token references, order and fulfillment data, webhook events, scope changes, and app uninstall records.

Finance and wallet data: recharge orders, balances, debits, refunds, reconciliation adjustments, and billing fields. We do not store full card numbers in the frontend.

Support and contact data: contact forms, tickets, conversation records, categories, related order references, and handling status.

Technical data: IP address, device and browser details, visited paths, error logs, performance logs, cookies, session identifiers, and abuse-prevention signals.

How We Use Data

  • To create and manage accounts, tenants, roles, permissions, store bindings, and system configuration.
  • To calculate rates, generate quotes, purchase or void labels, synchronize fulfillment status, return tracking numbers, and display tracking events.
  • To process wallet top-ups, shipping charges, refunds, reconciliation, insurance claims, and operational reports.
  • To respond to contact forms and support tickets, including linking orders, addresses, or shipments when needed for troubleshooting.
  • To maintain security, audits, fraud prevention, service availability, debugging, and compliance records.
  • To send service notices, configuration alerts, system announcements, and transactional messages where authorized or legally permitted.

Shopify and Third-Party Services

When you connect a Shopify store, we access or process order, customer, fulfillment, location, and shop data only according to authorized scopes. The data is used for rates, shipping, fulfillment sync, after-sales lookup, and compliance webhooks.

We may share necessary data with carriers, warehouse or logistics providers, wallet/payment services, email or messaging gateways, cloud infrastructure, and security audit tools. Third-party providers may process data only for service purposes and under our instructions. We use reasonable efforts to minimize transferred fields and apply encryption, access controls, and audit logs.

When Shopify sends customer data, erasure, shop uninstall, or scope update webhooks, we record and process them according to platform requirements.

Isolation, Permissions, and Security

The system isolates data by tenant, store, user, role, and resource permission. Regular business pages show current-user data by default; tenant-wide views require explicit permission and data scope.

Access tokens, API secrets, and sensitive configuration are encrypted or masked. We avoid exposing full secrets, tokens, or payment-sensitive fields in logs.

We use HTTPS, permission checks, audit logs, session controls, server-side validation, backups, and least-privilege practices. No system can guarantee absolute security. If you discover a security issue, please contact us using the details in this policy.

Cookies and Local Storage

We use necessary cookies and local storage for login state, language selection, theme preference, session security, and site functionality. If analytics or support widgets are enabled, they are configured through site settings and should follow the privacy commitments of those services. You can restrict cookies in your browser, but login, language switching, or admin features may not work properly.

Retention

Account, order, shipment, wallet, audit, and ticket data is retained as needed to provide the service, fulfill contracts, resolve disputes, reconcile finance, meet tax duties, or comply with law. After store disconnection, app uninstall, tenant suspension, or deletion requests, we will delete, anonymize, or restrict data that is no longer needed where feasible. Backups, logs, and compliance records may be retained for a reasonable period for security, audit, or disaster recovery.

Your Choices and Rights

You can log in to view and update account details, language preferences, store connections, ship-from addresses, contacts, and certain business settings. You may request access, correction, export, deletion, or restriction of your personal information. We will handle requests according to account permissions, legal requirements, and business record obligations. Merchants are responsible for ensuring that customer, order, and recipient information submitted to the system has a lawful source and necessary authorization.

Cross-Border Processing

Cross-border logistics may require order, address, parcel, declaration, carrier, and tracking data to be transferred to logistics providers in destination countries or regions. Where data is transferred across borders, we use reasonable safeguards based on fulfillment necessity, contractual arrangements, platform authorization, or applicable law.

Children

The service is intended for merchants and business users, not children. We do not knowingly collect personal information from children. If you believe such information was submitted by mistake, contact us.

Policy Updates

We may update this policy as products, laws, platform rules, or business processes change. Material changes will be communicated through the site, admin console, or other reasonable channels. Continued use of the service means the updated policy applies to later processing activities.

Contact Us

For privacy requests, security issues, or data processing questions, use the site contact form or email [email protected]. If your service is operated by another brand or tenant, please first use the operator contact details shown on that service page.

Privacy Policy - Clocart