CARTOLOG
Privacy policy
How Cartolog handles information when merchants and shoppers use the app.
Last updated: September 21, 2026.
Cartolog is operated by Umi's Dev. Contact support@umisdev.com about this policy or a privacy request.
What this policy covers
Cartolog provides cart, product search, recommendation and activity-reporting features for Shopify stores. Merchants choose how these features are configured. A store’s own privacy policy covers its relationship with shoppers, purchases and communications. Shopify handles checkout, payments and the store’s order records.
Information we process
- Merchant and installation information. Store domain, installation status, configuration, billing status and setup progress. Shopify session information can include a merchant staff member’s ID, name, email and locale. Access and refresh tokens are encrypted in app storage.
- Catalog information. Product and variant identifiers, names, descriptions, SKUs, collections, translations and configured search fields are copied for catalog synchronization and search. Shopify is queried for current contextual availability and pricing.
- Plan recommendations. We request an aggregate count of non-test orders for the preceding 30 days. This feature does not fetch or store individual order records, customer names, addresses or emails.
- Search and context. Search text, selected product options, country, language and currency are processed to return relevant products. We do not keep a server-side shopper search history or raw search text in app analytics.
- Cart information. Cart contents, notes and gift messages are handled in the shopper’s browser through Shopify’s cart service. Cartolog does not store them in its server database. They may become part of the merchant’s Shopify order.
- Optional activity. When permitted, Cartolog records event types such as cart opens, submitted searches, recommendation interactions, successful cart actions and checkout clicks. Daily counts and short-lived random event receipts are stored. Cartolog does not assign a permanent shopper identifier or attribute revenue to these actions.
- Support and service operation. If you contact us, we receive the information you send so we can respond. Infrastructure providers may process connection and security information, such as IP addresses and request metadata, to deliver and protect the service.
How we use information
We use this information to authenticate installations, synchronize catalogs, deliver the features merchants enable, verify app access and billing status, provide support, prevent abuse and handle privacy requests. Cartolog does not use shopper search or cart information for advertising or sell that information.
Consent and browser storage
Cartolog checks the store’s Shopify privacy permissions before recording optional analytics or saving recent searches. If permission is unknown or denied, the corresponding optional processing stays off. Necessary cart and search requests can still work.
With preferences permission, up to five recent searches can be saved in that browser. They expire after seven days when accessed and can be removed with Clear history. Cartolog clears this saved history when it detects that the permission has been revoked. Shoppers can manage their choices through the store’s privacy controls.
Service providers and processing locations
Cartolog uses Shopify for platform integration and commerce, Vercel for application hosting, Neon for the application database, and Typesense Cloud for product search. The application and database are configured in the Washington DC region; the search service is in Northern Virginia. Providers may operate supporting infrastructure in other locations, so processing may occur outside your country.
Information is shared with these services as needed to operate Cartolog, and may be disclosed when required by law. Their handling of platform, security, billing and infrastructure records is also subject to their applicable terms and privacy policies.
Retention and removal
- Installation settings and the active catalog are retained while the app is installed. Retired catalog revisions are scheduled for pruning after 30 minutes.
- Daily activity totals are scheduled for deletion after 180 days. Event deduplication receipts, completed or cancelled jobs, and delivery receipts are scheduled for deletion after 14 days. Unresolved operational jobs remain until resolved or the installation is removed.
- Uninstalling disables processing, removes app sessions and queues deletion of the shop’s search copies and app database records. Cleanup can take time and is retried if a service is unavailable. An unlinked delivery hash may remain for up to 14 days to prevent repeated processing.
- Shopify’s cart, order and billing records are controlled by Shopify and the merchant, rather than deleted by Cartolog. Provider logs, any backup copies and support correspondence have separate retention requirements; contact us for a request concerning these records.
Your requests and choices
You can contact us to request access, correction or deletion of personal information handled by Cartolog, or to ask about its use. Include the store domain and the nature of your request; do not send a password, access token or payment information. We may ask for information needed to verify the request and coordinate with the merchant or service provider.
Shoppers should contact the store for requests about purchases and its customer records. Cartolog also handles Shopify’s privacy-request notifications for the information it holds. Merchants can disable features or uninstall the app through Shopify Admin.
Changes to this policy
We will update this page when Cartolog’s data practices change and revise the date above. Contact support@umisdev.com if you have questions.