RecoverCart Privacy Policy
Last updated: August 19, 2026
RecoverCart ("the App") provides abandoned checkout recovery for Shopify stores. This policy describes what personal data the App processes, why, and how it is protected.
Data we collect and why
From merchants: when you install the App we store your shop domain and an API access token so the App can operate on your store. We collect your email address for billing and support communication.
From your customers: when a customer begins a checkout on your store, Shopify sends the App the checkout details — the email address (and optional phone number) the customer entered, the items and totals in their cart, and Shopify's checkout recovery link. We use this data for exactly one purpose: reminding that customer about their unfinished checkout on your behalf. We also process order information (order id and total) to recognize when a checkout was completed and attribute recovered revenue in your analytics.
What we do not do
We do not sell or rent personal data. We do not use customer data for advertising, profiling, or any purpose other than the recovery reminders and analytics described above. We process the minimum data needed to provide the service.
Sub-processors
Data is hosted on Railway (application and database hosting, encrypted in transit and at rest). Reminder emails are sent through Resend. If the merchant connects their own Twilio account, WhatsApp reminders are sent through Twilio. Each sub-processor only receives the data required to deliver its function.
Data retention and deletion
Checkout records are retained while relevant to the merchant's analytics or until the merchant deletes them. When a customer requests deletion of their data, or when Shopify sends us a GDPR redaction webhook (customers/redact), the customer's data is permanently deleted. When a merchant uninstalls the App, shop data is deleted following Shopify's shop/redact webhook. Customers may also contact the store they shopped with, or email us directly, to request deletion.
Security
All data is transmitted over TLS and stored encrypted at rest. Access to production data is limited to the App's operator. Webhooks are verified with HMAC signatures.
Contact
Questions or data requests: improvedrankings@gmail.com