Shopify App Privacy Policy
CartonPilot Packing Optimizer — Last updated: February 9, 2026
Introduction
This privacy policy describes how CartonPilot Packing Optimizer (the “App”), developed by CartonPilot (“we,” “us,” or “our”), collects, uses, and shares information from merchants who install and use the App through the Shopify platform.
By installing or using the App, you agree to the practices described in this policy. This policy supplements our general Privacy Policy and Terms of Service.
1. What Data We Access
The App requests the following Shopify API scopes:
- read_orders — To retrieve order line items (product names, quantities, weights) for packing optimization.
- read_products — To read product dimension metafields (length, width, height) for more accurate box-fitting calculations.
We do not access or store:
- Customer personal information (names, emails, addresses, phone numbers)
- Payment or financial information
- Customer browsing or purchasing behavior
- Marketing or analytics data
2. What Data We Store
The App stores the following data in its own database:
- Shopify session tokens — Required for authenticating requests between your store and the App. Deleted when you uninstall.
- Shop settings — Your CartonPilot API key, preferred box set, algorithm choice, default dimensions, and auto-optimize preference. Deleted when you uninstall.
- Optimization results — Shopify order IDs, order names (e.g., “#1042”), item counts, box counts, utilization percentages, and the packing result returned by the CartonPilot API. Deleted when you uninstall.
We do not store customer personally identifiable information (PII). Optimization results reference Shopify order IDs only, not customer data.
3. How We Use the Data
Data accessed from your Shopify store is used exclusively to:
- Send order item details to the CartonPilot packing optimization API
- Display optimization results (box counts, utilization) in the App
- Show dashboard analytics (orders optimized, average utilization)
- Automatically optimize new orders when the auto-optimize setting is enabled
Order data is sent to the CartonPilot API for processing. The API does not permanently store item dimensions or order details — data is processed in memory and discarded after the response is returned.
4. Third-Party Services
The App shares data with the following third-party services:
- CartonPilot API (cartonpilot.com) — Receives item dimensions and weights to compute optimal box configurations. Governed by the CartonPilot Privacy Policy.
We do not sell, rent, or share your data with any other third parties for marketing or advertising purposes.
5. Data Retention and Deletion
All data stored by the App is deleted when you uninstall it from your Shopify store. Specifically:
- On uninstall: Session tokens, shop settings, and all optimization job records are immediately deleted via the
app/uninstalledwebhook. - 48-hour redaction: Shopify sends a
shop/redactwebhook 48 hours after uninstall as a safety net. The App processes this by deleting any remaining data for your shop.
You can also request data deletion at any time by contacting us at support@cartonpilot.com.
6. GDPR and Customer Data
The App implements Shopify's mandatory GDPR webhooks:
- Customer data request (
customers/data_request) — The App does not store customer personal data, so no data is returned. - Customer data erasure (
customers/redact) — The App does not store customer personal data, so no erasure is needed. - Shop data erasure (
shop/redact) — All data for the shop is deleted.
7. Data Security
We protect your data with:
- Encryption in transit (HTTPS/TLS for all connections)
- Encrypted database storage for sensitive fields (API keys)
- Shopify's HMAC webhook verification for all incoming webhooks
- OAuth 2.0 authentication for the Shopify Admin API
8. Your Rights
As a merchant using the App, you have the right to:
- Access the data the App stores about your shop (visible in the App dashboard)
- Delete all data by uninstalling the App
- Request a data export by contacting us
- Disable automatic optimization at any time in Settings
- Revoke the App's API access by uninstalling
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated through the App or via email. Your continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this privacy policy or how the App handles your data, please contact us:
Email: support@cartonpilot.com
We will respond to your request within 30 days.