Privacy Policy
CartSync Pro by F12 Labs. Last updated September 30, 2026.
1. Introduction
CartSync Pro ("we", "our", "the app") is a Shopify application that saves signed-in customers' shopping carts and restores them on the other devices they shop from. On the Pro plan, Cart Helper lets store staff view and edit a customer's saved cart. This policy explains what data the app collects, how it is used, where it is stored and how it is protected.
2. Data We Collect
CartSync Pro handles only what it needs to sync carts:
- Cart contents: the product variant IDs and quantities in a signed-in customer's cart, and the time the cart was saved.
- Customer ID: the Shopify customer ID of the signed-in customer, which Shopify supplies with each storefront request so the cart is saved to the right customer.
- Store session: the store's Shopify domain, the access token Shopify issues to the app and the scopes granted, and a setting that controls whether the app shows a "leave a review" prompt.
When staff use Cart Helper, the app reads customer names and email addresses from Shopify to show search results, and product, price and inventory details to show what is in a cart and whether it is in stock. These are displayed in the admin and not stored by the app.
3. Data We Do Not Collect
The app does not collect payment details, passwords, addresses, phone numbers, order contents, browsing history or analytics about shoppers. Carts of guests who are not signed in are never sent to the app.
4. How We Use Data
- To save a signed-in customer's cart and restore it on their other devices.
- To empty a customer's saved cart when they place an order, so purchased items are not restored again.
- To let store staff view and edit a customer's saved cart in Cart Helper.
- To check whether the app embed is switched on in the store's live theme.
Data is never used for advertising, profiling or any purpose unrelated to the app.
5. Where Data Is Stored
- In Shopify: cart contents are stored in a metafield on the customer's own Shopify record (namespace
custom, keycustom_cart). We keep no copy of carts on our servers. - In our database: only the store session described above, in a PostgreSQL database hosted by F12 Labs.
- In memory and logs: to limit abuse, the app counts cart saves per customer ID in memory for one minute at a time. Application logs record the store, customer ID and number of items for each cart save, for troubleshooting.
6. Access Scopes and Why We Need Them
- write_customers: to read and write the cart metafield on customer records, and to search customers in Cart Helper.
- read_products: to show product names, variants, images and prices for items in a saved cart.
- read_inventory and read_locations: so Cart Helper can check stock at the locations the online store sells from before products are added to a customer's cart.
- read_orders: to receive the order-created notification that tells the app to empty the customer's saved cart. Only the customer ID is used.
- read_themes: to check whether the app embed is enabled in the live theme.
7. On the Storefront
When the merchant enables the app embed, a script runs on the storefront for signed-in customers only. It sends cart contents to the app through Shopify's app proxy, on the store's own domain. It uses browser storage for short-lived operational data:
- localStorage: a copy of the cart saved as the shopper leaves a page, so the next page can use it straight away. It is removed once the cart has been saved to Shopify.
- sessionStorage: the time the current browsing session started, used to decide whether to merge or replace the cart on sign-in.
The app sets no cookies and loads no third-party scripts.
8. Data Sharing
We do not sell, rent or share data with third parties. Data moves only between the shopper's browser, Shopify and the app.
9. Data Retention
- A customer's saved cart stays in their metafield until it changes, until they place an order (when it is emptied), or until the customer record is deleted.
- When the app is uninstalled, the store session is deleted from our database straight away. Cart metafields stay on customer records in Shopify, where the merchant can delete them; the app no longer reads or writes them.
- When Shopify sends the
shop/redactrequest, 48 hours after uninstall, any remaining data for the store is deleted from our database.
10. GDPR and Data Requests
CartSync Pro responds to Shopify's mandatory privacy webhooks. Because the app keeps no customer data in its own database, customer data requests and customer redaction requests are fulfilled by Shopify from the customer record, including the custom.custom_cart metafield. Merchants can view a customer's saved cart in the Customer's Active Cart block or in Cart Helper, and remove it by clearing the cart or deleting the metafield.
Merchants and customers can also contact us about any data request at the address below.
11. Security
All traffic uses HTTPS. Storefront requests go through Shopify's app proxy, which signs each request; the app verifies the signature and takes the customer ID only from Shopify. Admin pages require an authenticated Shopify session, and each customer can save at most 30 carts a minute.
12. Changes
If we change what the app collects or how it is used, we will update this page and the date at the top.
13. Contact
For privacy questions or data requests, email support@ftwelvelabs.com.
This policy applies to the CartSync Pro Shopify app by F12 Labs.