Privacy Policy

Effective 2026-09-12

The short version: the snippet a store installs records what shoppers do on that store, under an anonymous id we keep in a first party cookie; we never store IP addresses or raw browser strings; the AI analyst only ever sees totals and rates; we do not sell data or use it for advertising; and any shopper can be deleted from the dashboard or the API. Stores are the controllers of their shoppers' data and we act as their processor under the terms in section 13.

1. Who this covers

This policy explains how RecartIQ ("RecartIQ", "we", "us") handles personal data. It covers three groups of people, and different sections apply to each:

  • Visitors to recartiq.com.
  • Customers: the people who create accounts and manage stores in the dashboard.
  • Shoppers: visitors to our customers' online stores, whose activity is measured by the tracking snippet those stores install. For shoppers, the store is the data controller and we act as its processor. If you are a shopper with a question about a specific store, contact that store first; its privacy notice governs.

2. What the snippet collects from shoppers

When a store installs RecartIQ, the snippet records events on that store's pages. Each event carries:

  • An anonymous identifier that we generate and keep in a first party cookie on the store's own domain, so repeat visits from the same browser can be counted as the same person.
  • A customer identifier only if the store chooses to send one (for example its own customer number after sign in or checkout), and any traits the store attaches to it.
  • What happened: page viewed, product viewed, added to cart, checkout started, order placed, refund, and friction signals such as a rejected coupon or an out of stock product. Orders include the order number, amounts and the products bought, as sent by the store.
  • Context: page URL and title, referrer, campaign parameters, screen size, language, timezone, and a session identifier.

On arrival we derive a device type (mobile, tablet, desktop), browser and operating system family, and country. We then discard the IP address and the raw user agent string. They are never written to our database.

What we do not collect: we do not read form contents, record sessions, capture keystrokes, or track shoppers across unrelated websites. Fields named like passwords or card numbers are removed on arrival. The snippet does nothing when a browser sends the Do Not Track or Global Privacy Control signal, unless the store has deliberately switched that behaviour off.

3. What we collect from customers

  • Account data: email address, name if you give one, a password hash if you sign in with a password, team membership and role.
  • Store data: store name, URL, timezone, currency, plan and usage counters.
  • Product usage: which recommendations you mark done or dismiss and the notes you add, questions you ask the analyst and its answers, and reports we generate for you.
  • Billing data: handled by Stripe. We keep the Stripe customer and subscription identifiers and the plan; we never see full card numbers.
  • Support correspondence when you email us.
  • Technical logs: request logs on our hosting provider, kept for a short period for security and debugging, which include IP addresses of dashboard and API requests.

4. How we use data

  • To provide the analytics: computing sessions, funnels, product performance, friction, retention and reports for the store that sent the data.
  • To generate recommendations. The weekly report and the chat analyst are produced with an AI model. The model receives aggregates only: totals, rates, rankings and the store's own settings. It never receives shopper identifiers, emails, order line details or free text from shoppers.
  • To run the Service: sign-in links, usage warnings, outcome verdicts, security, fraud and abuse prevention, and support.
  • To bill paid plans.
  • To improve the Service using aggregate, de-identified statistics that cannot be tied to a store or a shopper.

We do not sell personal data, do not use shopper data for advertising, and do not use Customer Data to train AI models.

6. Cookies

On recartiq.com we use only strictly necessary cookies: the session cookie that keeps you signed in, a CSRF token, and the operator session for our own staff. There are no advertising or third party analytics cookies on our website, so no consent banner is shown.

On stores that install the snippet, the snippet sets first party cookies on the store's domain:

  • riq_aid: anonymous browser identifier, 12 months.
  • riq_did: the customer identifier the store chose to send, 12 months.
  • riq_sid: session identifier, 30 minutes of inactivity.
  • riq_optout: set when a shopper opts out through the store's controls, 12 months.

Whether these cookies require consent depends on the store's location and the shopper's location. The store is responsible for its cookie notice; the snippet exposes opt out and opt in functions so a store can wire them to its consent tool.

7. How long we keep data

  • Raw events: 90 days on the free plan and 730 days on paid plans, then deleted by a scheduled job.
  • Daily aggregates (counts and rates per day, product and segment): kept for the life of the store. They contain no shopper identifiers.
  • Reports, recommendations and chat history: for the life of the store.
  • Account data: until you close your account, then 30 days for export and recovery, then deleted. Invoices are kept as long as tax law requires.
  • Hosting request logs: a short rolling window set by our hosting provider.
  • Backups: deleted data can persist in encrypted database backups for up to 30 days before it is overwritten.

8. Who we share data with

We share personal data only with the providers that run the Service (listed below as sub-processors), with professional advisers under confidentiality, when the law or a court requires it, and with a successor if our business is sold, in which case this policy continues to apply.

Sub-processors at the effective date:

ProviderPurposeLocation
Vercel, Inc.Application hosting, edge network, cron jobsUnited States (functions run in the US East region)
Neon, Inc.Postgres database storing events, accounts and reportsUnited States (AWS us-east-2)
Anthropic, PBCAI model that writes the weekly report and answers questions, from aggregates onlyUnited States
Zoho CorporationOutbound email: sign-in links, reports, noticesIndia
Stripe, Inc.Payment processing and invoicing for paid plansUnited States

We will update this list before adding a sub-processor that handles Customer Data and, for customers who ask at hello@recartiq.com, notify them by email so they can object.

9. International transfers

Our infrastructure is in the United States and India, so data may be processed outside your country. Where European or UK law applies, transfers rely on the providers' Standard Contractual Clauses or an adequacy decision, together with the safeguards described in the security section. Contact us for copies of the relevant terms.

10. Security

  • All traffic is encrypted in transit with TLS, and data is encrypted at rest by our database and hosting providers.
  • Passwords are stored only as salted scrypt hashes. Sign-in attempts are rate limited.
  • Every dashboard and API request is scoped to the stores the signed-in person belongs to. Write keys can only send events, never read them.
  • IP addresses and raw user agents are discarded on arrival. Obvious sensitive fields are dropped.
  • Access to production systems is limited to the people who operate the Service and is protected by separate credentials.

No system is perfectly secure. If we learn of a breach affecting your data we will notify you without undue delay, and within 72 hours where the law requires it, with what we know and what we are doing.

11. Your rights

Depending on where you live you may have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to complain to a supervisory authority. To exercise them:

  • Customers: most things are self service in Settings, including exporting data and deleting shoppers. For anything else email hello@recartiq.com. We answer within 30 days.
  • Shoppers: contact the store whose site you visited. Stores can delete or export any shopper from their dashboard or API, and we help them do so. If you cannot reach the store, email us and we will forward the request or act on it where we are able to.

California residents: we do not sell or share personal information as those terms are defined in the CCPA, and we do not use it for cross context behavioural advertising. You may ask what we hold and request deletion using the contacts above, and we will not discriminate against you for doing so.

12. Children

The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 as a customer. Stores are responsible for complying with children's privacy laws that apply to their own audiences.

13. Data processing terms for stores

These terms apply whenever we process shoppers' personal data on behalf of a store and form part of the Terms of Service. They are intended to satisfy Article 28 of the GDPR and equivalent laws.

  • Roles. The store is the controller; RecartIQ is the processor. The subject matter is website analytics for the store; the duration is the life of the account plus the deletion periods above; the data subjects are the store's shoppers; the data categories are those listed in "What the snippet collects".
  • Instructions. We process shopper data only to provide the Service as configured by the store, and as documented here. We will tell the store if we believe an instruction breaks the law.
  • Confidentiality. People who access shopper data are bound by confidentiality obligations.
  • Security. We maintain the measures in the security section and keep them proportionate to the risk.
  • Sub-processors. The store authorises the sub-processors listed above. We remain responsible for them and give notice of changes so the store can object.
  • Assistance. We help the store respond to shopper requests and, where relevant, with impact assessments and breach notifications, at no charge unless the effort is unreasonable.
  • Deletion and return. Stores can export and delete data at any time. At the end of the account we delete shopper data as described in the retention section.
  • Audit. On reasonable request we provide the information needed to show compliance and allow audits, at most once a year unless required by a regulator, with confidentiality protections and reasonable notice.
  • Transfers. As described in the international transfers section.

Stores that need a signed copy of these terms, or the EU or UK Standard Contractual Clauses, can request one at hello@recartiq.com.

14. Changes and contact

We may update this policy. Material changes are announced by email to customers or in the dashboard at least 14 days before they take effect; the effective date at the top always shows the current version.

Questions and requests: hello@recartiq.com. General contact: hello@recartiq.com.