Privacy Policy
Last updated: 5 August 2026
Who we are
Smart Cart OS is a Shopify app built and operated by Pea Soup Digital. This policy explains what data the app processes when a merchant installs and uses it, why we process it, where it is stored, and how it is deleted. In data protection terms, the merchant is the data controller for their store's data and Pea Soup Digital acts as a data processor on their behalf.
What data we process
Smart Cart OS operates its own application server and database. The following data is stored there:
- Merchant account and shop data — shop domain, Shopify access token, and the name, email address and locale of the staff account that installs the app. This is supplied by Shopify during installation and is used solely to authenticate the app to the store.
- App configuration — the spending goals, cross-sell settings, appearance options, and any collection or product level overrides the merchant configures.
- Order data used for revenue reporting — Shopify order ID, order number, order and subtotal value, currency, order date, line item titles and quantities, and which of those items were added through Smart Cart. This is used only to show the merchant how the cart is performing on their own store.
- Anonymous cart interaction events — the type of event (for example cart opened, item added, checkout clicked, goal reached), a randomly generated session identifier, the cart total, item count, product titles, and a timestamp.
What we do not process
- We do not collect or store customer names, email addresses, postal or billing addresses, phone numbers, or payment details. Our database contains no fields for them.
- We do not use cookies or advertising or tracking pixels. The session identifier used for cart analytics is held in the browser's
sessionStorageand is discarded when the browser tab is closed. - We do not sell, rent, or share merchant or customer data with third parties, and we do not use it for advertising or profiling.
- We do not build profiles of individual shoppers or link cart activity to identifiable people.
Why we process it, and the limits we apply
All processing exists for one purpose: to render the cart experience on the merchant's storefront and to report that cart's performance back to that same merchant. We request the minimum access needed for this. We hold Shopify protected customer data approval limited to analytics, and we have deliberately not requested access to customer name, email, phone or address fields. Data from one merchant's store is never used to serve another merchant.
Where data is stored and how it is protected
The application runs on Vercel with its serverless functions pinned to the London (lhr1) region, and data is stored in a PostgreSQL database hosted by Neon in the London (eu-west-2) region. Both processing and storage therefore take place in the United Kingdom. Data is encrypted in transit using TLS, including the connection between the application and the database, and encrypted at rest by the database provider. Access to production credentials is restricted to Pea Soup Digital personnel who need it to operate the service.
International transfers
Data is processed and stored in the United Kingdom. Our infrastructure providers, Vercel and Neon, are US-headquartered companies that may access data from outside the UK and EEA for support and maintenance purposes. Where such a transfer takes place it is covered by the providers' data processing agreements, which incorporate the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Shopify, as the source of the store data, operates under its own data processing terms with the merchant.
Legal bases and roles
The merchant who installs Smart Cart OS is the data controller for their store's data. Pea Soup Digital acts as a data processor and processes data only on the merchant's documented instructions, as given through their configuration of the app. Where personal data is processed, the merchant's lawful basis is normally their legitimate interest in operating and analysing their own store. This policy, together with our Terms of Service, forms the data processing terms between us; merchants who require a separate signed data processing agreement can request one using the contact details below.
Sub-processors
We use the following sub-processors to deliver the service: Vercel Inc. (application hosting, London region) and Neon Inc. (database hosting, London region). We do not use any advertising, analytics, or data enrichment sub-processors. We will update this list before adding any new sub-processor.
Retention and deletion
Data is retained only while the app is installed on the store. Smart Cart OS implements Shopify's mandatory compliance webhooks:
- shop/redact — when a merchant uninstalls, Shopify sends this request (typically 48 hours after uninstall) and we delete that store's records, including its configuration, order records, analytics events and session.
- customers/redact — where a customer erasure request references orders we hold, the corresponding records are removed.
- customers/data_request — we respond to customer data access requests forwarded by Shopify.
Merchants can also contact us at any time to request deletion of their data.
Third-party services
Smart Cart OS uses the Shopify Admin and Storefront APIs, including Shopify's Product Recommendations API, which are subject to Shopify's own privacy policy. Our infrastructure providers are Vercel (application hosting) and Neon (database hosting). We do not use analytics, advertising, or data enrichment services.
Your rights
Individuals whose data is processed through a merchant's store may exercise their rights of access, correction, erasure, restriction and objection. Requests are normally made through the merchant, who is the data controller, and Shopify forwards them to us through the compliance webhooks described above. You may also contact us directly using the details below.
Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with an updated date.
Contact
If you have questions about this policy, or wish to make a data protection request, contact us at andrewsimpson661@hotmail.com.