What runs on your storefront
Cart Alarm adds a Shopify web pixel to your storefront. It runs inside Shopify's pixel sandbox, and only for shoppers whose consent settings allow analytics. In the shopper's browser it notices three things:
- A product page was viewed
- An Add to Cart form was submitted
- Shopify confirmed that an item was added to the cart
The pixel decides in the browser whether each Add to Cart try worked. It then sends our server a short message with four things: your shop's domain, a public key for your shop, one word (worked, failed, add without a try, or view), and a random number made fresh on every page load.
What the pixel does not send
- No names, emails, phone numbers, or addresses
- No customer ID, account details, or login state
- No cart contents, product names, variant IDs, prices, or order details
- No page addresses and no browsing history
- No cookies are set, and nothing is stored in the shopper's browser
The random page-load number exists so that one confused shopper can't trigger an alert alone. It changes on every page load, is hashed before we store it, and can't be linked to a person.
What the app reads from Shopify
With the access you grant at install, the app reads your shop's name, contact email, timezone, and Shopify shop ID. It uses the email as the starting address for alerts, which you can change, and the timezone to show times in your local time.
What the app stores, and where
- Your Shopify session. The shop domain and the access token Shopify issues at install.
- Your shop record. Shop domain, name, timezone, the alert email address, and the app's settings and status for your shop.
- Counts. How many Add to Cart tries worked and failed, and how many product views there were, in 5-minute blocks.
- Recent tries. For each of the last 48 hours of tries: the time, whether it worked, and the hashed page-load number.
- Alerts. When each alert opened and closed.
Our hosting provider's request logs may briefly record IP addresses, as any web server's do. We don't store them in our database or use them for anything.
How long data is kept
- Recent tries are deleted after 48 hours.
- Counts are deleted after 90 days.
- Everything held for your shop is deleted when you uninstall the app, and again if Shopify sends a shop redaction request.
- No customer personal data is held, so a customer data or redaction request has nothing to return or erase. We still answer each request.
Third parties
The app is hosted on Vercel. Its database is run by Neon. Alert emails are sent through Resend, which receives your alert email address and the text of each alert. These are service providers that process the data above so the app can run. No data is sold, and none is shared for advertising.
Your rights
You can uninstall Cart Alarm at any time from your Shopify admin, which removes its access and deletes what it holds for your shop. You can also ask us what is held about your shop, or ask us to delete it, by email. We answer within 30 days.
Contact
JPM Inc, james@jamesmckinney.xyz
Changes to this policy
If this policy changes, the effective date at the top of the page changes with it. Material changes will be noted in the app.