CartRevive ("we", "us") is a Shopify application operated by Merchantry Labs that helps merchants recover abandoned checkouts by sending recovery messages to customers who consented to receive them. This policy explains what data we process, why, and the rights of everyone involved.
Data we process for merchants
When a merchant installs CartRevive, we receive and store: the store's name, domain, contact email, currency, plan status, and the settings the merchant configures (message templates, timing, discount tiers). Billing is handled entirely by Shopify — we never see payment card details. Merchants can export their own customers' contact and cart data from the app at any time; every export clearly marks each contact's marketing-consent status.
Customer data we process on merchants' behalf
To recover abandoned checkouts we process, as a data processor acting on the merchant's instructions: customer first name, email address, phone number, marketing-consent status, cart contents, cart value, and — when a checkout is completed — the order identifier and total. This data reaches us through Shopify's official APIs and webhooks.
We use this data for exactly one purpose: sending cart-recovery messages on the merchant's behalf and reporting the results to that merchant. We do not sell personal data, share it with advertisers, or use it for our own marketing. Ever.
Consent and opt-out
Recovery emails are only sent to customers whose checkout indicated marketing consent. Every email contains a one-click unsubscribe link (including the List-Unsubscribe header). Opting out stops all further messages immediately and permanently for that cart's customer.
Email engagement tracking
Recovery emails include an open-tracking pixel and tracked links. We use these signals for two things: showing merchants whether their messages work, and reducing message volume — a customer who opened an email is not sent the follow-up SMS. Engagement data is never used for profiling beyond the recovery sequence itself.
Retention and deletion
Cart and message data is retained while the merchant's installation is active, and automatically purged after 12 months. When a customer requests erasure, Shopify sends us a redaction webhook and we scrub that customer's personal data within the mandated window. When a merchant uninstalls, Shopify sends a shop-redaction webhook 48 hours later and we delete the store's data in full.
Security
Data is encrypted in transit (TLS everywhere) and at rest. Access is limited to Merchantry Labs personnel who operate the service, via key-based authentication. We keep an append-only audit log of every automated decision the system makes, and we maintain an incident response process: if a breach affects personal data, we will notify affected merchants and Shopify without undue delay.
Subprocessors
We rely on: Shopify (platform, APIs, billing), Resend (email delivery), Oracle Cloud (hosting), and — if SMS features are enabled — Twilio (SMS delivery). Each processes data only as needed to provide their service.
Your rights
Customers can exercise access and erasure rights through the merchant they shopped with; Shopify relays these requests to us automatically and we honor them. Merchants can request an export or deletion of their store's data at any time by contacting us.
Contact
Merchantry Labs · support@merchantrylabs.com
We may update this policy as the product evolves; material changes will be dated above and announced to installed merchants.