1. Introduction

Whaleal ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Whaleal Cart application (the "App") for abandoned cart recovery services.

By installing or using the App, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Store Information

We collect and store the following information from your Shopify store:

  • Shop Domain: Your Shopify store URL (e.g., mystore.myshopify.com)
  • Abandoned Checkouts: Customer email addresses, cart items, total prices, and checkout timestamps
  • Customer Information: Names, email addresses, and phone numbers (only for customers who abandoned carts)
  • Order Data: Recovery status, email open rates, and click-through rates

2.2 Usage Information

We automatically collect information about how you use the App:

  • Email sending statistics and quotas
  • App configuration settings
  • Feature usage patterns
  • Performance metrics

2.3 Data We Do Not Collect

We process personal data on a minimum necessary basis. We do not:

  • Track or profile general website visitors on your storefront (no storefront pixels or cookies from Whaleal Cart)
  • Sell, rent, or trade personal information
  • Use personal data for advertising or unrelated marketing
  • Collect data beyond abandoned checkout recovery and related analytics

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To send abandoned cart recovery emails on your behalf
  • Analytics: To track email performance and provide recovery statistics
  • Communication: To send you important updates about the App
  • Support: To provide customer support and troubleshoot issues
  • Improvement: To analyze usage patterns and improve the App
  • Compliance: To comply with legal obligations and enforce our terms

We use personal data only for the purposes listed above. We do not use merchant or customer data for unrelated advertising, profiling, or resale.

4. Customer Consent & Opt-Out

Whaleal Cart respects customer consent and marketing preferences:

  • One-click unsubscribe: Every recovery email includes an unsubscribe link; opted-out customers will not receive further emails
  • GDPR webhooks: We honor Shopify mandatory webhooks — customers/redact, customers/data_request, and shop/redact
  • No sale of personal data: We do not sell customer personal data (not applicable to our service)
  • No automated legal decisions: We do not use automated decision-making that produces legal or similarly significant effects on individuals (not applicable)

5. Merchant Agreement & Transparency

By installing Whaleal Cart, you enter into a data protection arrangement with Whaleal governed by this Privacy Policy and our Terms of Service. We clearly disclose:

  • What we collect: Section 2 — abandoned checkout and recovery-related data only
  • Why we collect it: Section 3 — cart recovery, analytics, support, and compliance
  • How long we keep it: Section 7 — maximum 180 days for customer records
  • How we protect it: Sections 8–10

6. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following situations:

  • Service Providers: With email delivery services (e.g., Resend) to send recovery emails
  • Shopify: As required to integrate with the Shopify platform
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

7. Data Retention

We retain personal data only as long as necessary to provide the App services. Our maximum retention period for customer-related records is 180 days.

  • Active Stores: Data is retained while the App is installed, subject to the 180-day maximum
  • Abandoned Checkouts & Recovery Emails: Customer checkout and email-related records are retained for up to 180 days, then deleted
  • Uninstalled App: All shop data is deleted via Shopify shop/redact webhook (typically within 48 hours; no later than 30 days per Shopify requirements)
  • Analytics Data: Aggregated, non-identifying statistics may be retained indefinitely

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in Transit: All API and App traffic uses HTTPS/TLS
  • Encryption at Rest: Production databases and backups are stored on encrypted cloud infrastructure
  • Encrypted Backups: Database backups use the same encrypted storage as production data
  • Access Control: Merchant API access requires Shopify Session Token authentication; each shop can only access its own data
  • Access Logging: Access to customer-data APIs (dashboard, checkouts, email history) is logged with shop, path, time, and IP (no customer PII stored in audit logs); retained 12 months
  • Environment Separation: Development and production use separate databases (rescue_dev vs rescue)
  • Data Loss Prevention: Personal data is not copied to unauthorized devices; production access is restricted; outbound email is sent only through approved processors (Resend)
  • Third-Party Processors: Email delivery (Resend) and hosting providers are used under contractual data protection obligations

9. Employee Access to Personal Data

Whaleal restricts internal access to customer personal data:

  • No internal customer browser: There is no staff-facing dashboard to search or browse merchant customer records
  • Need-to-know basis: Only authorized personnel may access production systems for support, operations, or security
  • Infrastructure access: Production database and server access is limited, password-protected, and not shared with unauthorized persons
  • Strong passwords: All production system accounts require strong, unique passwords (minimum 12 characters, mixed case, numbers, and symbols); credentials are not shared and are rotated when personnel change
  • Support requests: When assisting merchants, we access only the minimum data required to resolve the issue

10. Security Incident Response

If we become aware of a security incident affecting personal data, we will:

  • Investigate and contain the incident promptly
  • Assess impact on merchants and their customers
  • Notify affected merchants without undue delay when required by law
  • Cooperate with Shopify and regulators as applicable
  • Take remedial steps to prevent recurrence

Report security concerns to hi.whaleal@gmail.com.

11. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal data
  • Export: Request export of your data in a machine-readable format
  • Opt-out: Uninstall the App to stop all data collection

To exercise these rights, please contact us at hi.whaleal@gmail.com

12. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

13. Children's Privacy

The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date.

15. Shopify Data Protection Commitments

Whaleal Cart meets Shopify Partner data protection requirements for processing merchant customer personal data. Summary:

RequirementOur Commitment
Process data on a minimum-necessary basisYes — Section 2.3; only abandoned checkout recovery data
Inform merchants what data is processed and whyYes — Sections 2, 3, and 5
Use data only for stated purposesYes — Section 3; no unrelated use or resale
Privacy & data protection agreement with merchantsYes — this Policy + Terms of Service upon install
Respect customer consent decisionsYes — Section 4 (unsubscribe + GDPR webhooks)
Respect opt-out of data saleNot applicable — we do not sell personal data
Opt-out of automated legal/significant decisionsNot applicable — no such automated decisions
Defined data retention periodsYes — Section 7 (maximum 180 days for customer records)
Encryption in transit and at restYes — Section 8 (HTTPS/TLS; encrypted cloud storage)
Encrypted backupsYes — Section 8
Separate test and production dataYes — Section 8 (separate dev/production databases)
Data loss prevention (DLP) policyYes — Section 8
Restrict employee access to customer dataYes — Section 9
Strong employee password requirementsYes — Section 9
Log access to personal dataYes — Section 8 (API access audit logs)
Security incident response policyYes — Section 10

16. Contact Us

If you have any questions about this Privacy Policy, please contact us:

17. Shopify App Store

This App is hosted on the Shopify App Store. By using the App, you also agree to Shopify's Terms of Service and Privacy Policy.

View GDPR Compliance →
View Terms of Service →