Who we are
CARTT.AI is an Australian-built multi-portal B2B2C e-commerce platform operated by CARTT.AI (ABN 71 393 051 974) of Byron Bay, New South Wales, Australia. References to "we", "us" and "CARTT.AI" in this Privacy Policy refer to the operator of the platform at cartt.ai.
This Privacy Policy is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Personal information we collect
We collect personal information in four different contexts, and some of it reaches us from other companies rather than from you:
Marketing and sales enquiries
When you submit a contact form, request a demo, or otherwise enquire about CARTT.AI, we collect your name, email address, company name, and the platform or context you describe in your message. We use this to respond to your enquiry and to follow up with related sales information you are likely to want.
Tenant administrator accounts
When you create or are invited to administer a CARTT.AI tenant, we collect your name, email address, role, and authentication credentials (stored as a one-way hash, never logged). We collect billing information (business name, ABN, billing address) for tenants on paid plans.
End-customer data (held on behalf of tenants)
CARTT.AI tenants operate online stores. The personal information of their end-customers (shoppers) is held by us on the tenant's behalf: the tenant decides what is collected and why, and we hold it and act on their configuration. Both of us have obligations for it under the Privacy Act - see Tenant data vs. platform data below.
Accounting records a tenant imports
Tenants using the accounting and bank-reconciliation features import their own financial records - bank statements, transaction lines, receipts and expense documents. Most of that is business data, but a statement names the people and businesses an account paid, so we treat it as personal information too. We have no bank feed and never ask for internet-banking credentials: a tenant uploads a CSV or PDF, or connects a reporting source such as PayPal. Reading a PDF statement, capturing a receipt or categorising lines by AI sends that content to Anthropic in the United States, and each of those is a button someone presses rather than something that happens on import. Section 3.8 of the Privacy Policy sets it out and prevails over this page.
Information that passes between us and other companies
Not everything comes from you directly. A shopper who signs in to a store with Google or Facebook instead of a password causes that provider to send us a profile; we keep the account identifier, the email address and (where supplied) the name, which is what creates or matches the customer record, plus - from Google only - whether that email address has already been verified, so the shopper is not asked to confirm it twice. We never receive the password. The profile that arrives is wider than the part we keep - Google adds the picture and nickname, Facebook adds gender, verification status, a profile link and the picture - and the rest is discarded rather than stored. A tenant who connects a Facebook, Instagram, TikTok, X or LinkedIn account so they can publish or advertise from the admin causes that platform to give us the page identifier, page name, profile picture and an access token, plus the advertising figures it attributes to their campaigns. Payment gateways, identity-verification services and public sources such as the Australian Business Register also tell us things, and a tenant's connected marketplace or point-of-sale system passes buyer and sale details through with the orders it sends. Sections 3.5 and 4 of the Privacy Policy set out the sources in full - 3.5 for information about you, 4 for information about a tenant's own customers.
It also runs the other way. Where a tenant connects a social or advertising account to publish or advertise from the admin, we send that platform the post - caption, images, video, links - and the campaign settings behind any ads, using the access token that account issued. Meta, X and LinkedIn process in the United States; TikTok's parent is Chinese-owned. A tenant who connects nothing sends nothing. Section 6.3 of the Privacy Policy governs and prevails over this page.
How we use your information
- To provide the service - authentication, billing, support, transactional notifications, and the day-to-day operation of your tenant.
- To respond to enquiries - replying to contact form submissions, sales conversations, onboarding scoping.
- To improve the platform - diagnosing bugs, analysing usage patterns, prioritising features. Some of that analysis is aggregate, but our own first-party tracker records event-level activity (pages viewed, links clicked, scroll depth, campaign parameters) against a visitor session, IP address, browser and device. We use no third-party analytics or advertising trackers on our own sites; the Cookies Policy describes ours and how to stop it.
- To meet our legal obligations - taxation, fraud prevention, lawful requests from Australian authorities.
We do not sell personal information to third parties.
Tenant data vs. platform data
CARTT.AI is a multi-tenant platform. We make a clear distinction between two categories of personal information:
Platform data - information about tenant administrators, billing contacts, and people who interact directly with cartt.ai (e.g. via the marketing site contact form). We decide how this information is handled, and this Privacy Policy governs it.
Tenant data - information about end-customers (shoppers) of stores running on CARTT.AI. This includes customer accounts, orders, addresses, support conversations, marketing list memberships and behavioural analytics. The tenant decides what is collected and why, and publishes its own privacy policy on its storefront. We hold that information on our infrastructure, which under the Privacy Act gives us obligations of our own - the "processor" label used by overseas privacy regimes does not remove them, and we don't claim it does. If you are a shopper and want a copy of your personal information or want it deleted, contact the store you purchased from in the first instance; they can usually resolve it faster. If they don't respond, or your concern is about the platform itself, write to legal@cartt.ai and we will deal with it. Section 9 of the Privacy Policy sets this out in full and prevails over this page.
When we share information
We share personal information in these circumstances:
- Sub-processors who run parts of the platform - hosting (Australian-based providers), email delivery (submitted through Amazon SES, in whichever region a tenant chooses when they connect their SES account - Sydney is the default, twelve are offered including four in the United States, both transactional mail and campaigns go through the one chosen, and some stores on this platform submit their mail in the United States today; section 7.1 of the Privacy Policy sets this out and prevails over this page - though the message layout is rendered by the MJML API, operated by Mailjet in the European Union, which receives the markup - for templated email (orders, invoices, campaigns) that markup is a template whose personal details our own servers fill in afterwards, but for a one-off message (an enquiry acknowledgement, a support ticket notification, something an operator types and sends) the wording and the names on it are in what we send; a message is then delivered to the recipient's own mailbox provider wherever that sits; and a tenant can route their transactional email through their own SMTP relay instead), email address verification (Bouncify, United States), bot protection on enquiry forms (Google reCAPTCHA Enterprise, United States, which receives device and session information from the visitor's browser), the typefaces on this marketing site (Google Fonts, United States - a file fetch rather than a script, but it still tells Google your IP address and that you were on cartt.ai - not which page, because we send a
Referrer-Policythat withholds the path from other domains; it does not apply to tenant storefronts, which serve their fonts from their own domain), the assets the admin panel itself loads from public networks rather than from our own servers (jsDelivr, which serves the JavaScript framework the admin is built on and so is fetched by every admin page, as well as the charts, the guided tour and the infographic studio's text renderer - it is operated from the United Kingdom; Google Fonts again, this time for the admin's own typefaces on every page, with a further set in the theme, changelog and email editors so a template can be previewed in the typeface it will be sent in; Google's asset host for the chart loader on one dashboard panel; CDNJS, operated by Cloudflare, for the layout library on the product listing screen; UNPKG for the globe imagery on the dashboard activity map, which loads only if that view is opened; placehold.co for the stand-in product images in transactional email previews, which are also the starting image in a page-builder section until replaced; and, on the screens that need them and only where the connection is configured, Stripe's payment script and PayPal's JavaScript SDK on the Wallet top-up page - Stripe's also on an agency's billing page - so the card and PayPal fields are rendered by the gateway rather than by us, and Google Maps for the map and marker icons on a customer's CRM record - Google, Cloudflare, Stripe and PayPal are United States companies and the rest operate outside Australia, each told the IP address, browser and admin domain - though not the page - of the staff member whose browser fetches from it, noting that an asset network answers from its nearest edge so the request may not leave the country even though the operator receives it; we intend to serve all of these from our own domain instead), SMS gateways the tenant selects (MessageMedia, Twilio, Vonage, Kudosity), AI providers used by the features the tenant has enabled (currently Anthropic, OpenAI, ElevenLabs, Black Forest Labs, fal.ai, Google Gemini, Sapling, Stability AI, Runway, and the Kling, Seedance and Hailuo video models - this list changes as providers do; sections 7.1 and 7.4 of the Privacy Policy name each provider with the country it processes in, and govern and prevail over this page), mapping and address lookup (Google Maps - an order-confirmation map sends the shopper's delivery address to Google from their own browser, and store-location addresses are geocoded from our servers), the map imagery those coordinates are drawn on (CARTO, United States - the store locator and the admin activity map fetch their background tiles from the viewer's own browser, which tells CARTO that browser's IP address and the area being viewed; a visitor's own position, where they ask for their nearest store, is read and used in their browser and is not sent to us or to CARTO), and the payment gateway the tenant has connected (eWAY, PayPal, Afterpay, Zip and Stripe among them). - Messaging channels the tenant enables - where a tenant sends verification codes or messages over WhatsApp, the recipient's number and the message go to Meta in the United States; where support alerts are routed to Telegram, the notification goes to Telegram.
- Accounting, inventory and shipping integrations - only with the tenant's explicit connection (MYOB, Xero, QuickBooks Online, Datapel WMS, Cin7 Core, Unleashed, Retail Express, Lightspeed Retail, Starshipit, Shippit). Customer, order and delivery details go with the integration; some of these providers process outside Australia, and section 7.1 of the Privacy Policy names the country for each and prevails over this page.
- Analytics and advertising tags the tenant adds to its storefront - where a tenant installs Google Analytics, Google Tag Manager or the Meta pixel, storefront browsing information goes to Google or Meta in the United States. That is the tenant's choice, disclosed on their storefront's cookie notice.
- Marketplaces and selling channels the tenant has connected - where a tenant sells through eBay or Amazon, buyer contact and delivery details come to us from the marketplace with the order, and order, fulfilment and tracking information goes back to it; both directions are processed in the United States. A Shopify connection exchanges customer and order records in Canada and the United States.
- Dropship suppliers - where a tenant sells a dropshipped product through our AliExpress integration, the customer's name, delivery address and contact details are sent to AliExpress so the supplier can ship to them directly, and are processed in Singapore and China.
- Where required by law - lawful Australian government requests, court orders, or fraud-prevention obligations.
- In a business transaction - if CARTT.AI is sold, merged or acquired, customer data may transfer as part of that transaction, subject to the acquirer's continuation of this Privacy Policy.
Storage and security
CARTT.AI is hosted in Australia. We use industry-standard technical and organisational measures to protect personal information: encryption in transit (TLS) on every connection we control, bar the /.well-known/ validation addresses used for certificate issuance and domain verification, which answer over plain HTTP on our own platform hosts and, depending on how a store's web server is configured, on some storefronts too - nothing personal is served from them, hashed passwords (bcrypt / Argon2), a separate database per tenant for store data, encrypted storage for third-party integration credentials, and network-level firewalls. Two qualifications we would rather state than imply away: platform-level records (billing, wallets, support) sit in one shared database where the separation is enforced by the application rather than by the database, and CageFS per-user process isolation applies to tenants on their own hosting account - stores on a cartt.ai subdomain share a platform account where it is deliberately switched off. The Security page sets both out. Two qualifications on that encryption sentence are named openly in section 7.3 of the Privacy Policy, which prevails over this page. The first is that a tenant who routes transactional email through their own SMTP relay determines the security of that hop. The second is that whether a stored credential is encrypted depends on the field, not on the screen it was typed into. Encrypted at rest, in five groups: credentials stored against a dedicated integration connection (marketplaces, shipping and freight carriers, point-of-sale terminals, EDI, the accounting and inventory systems a tenant connects, search and advertising accounts, video providers); the payment-gateway fields marked secret - the eWAY password, the Fat Zebra token and shared secret, the PayPal client secret, and the Afterpay and Zip API keys and webhook secrets; and a handful of individual settings encrypted one field at a time as their integrations were built - the Datapel password, and the MYOB client secret, cloud and local passwords and OAuth tokens; and a fourth group held against a record rather than a settings screen - an agency's own SMTP password under the white-label programme, the payment configuration stored against a Wallet, and the PayPal reporting client secret on a connected bank account; and a fifth belonging to the setup wizard - credentials typed into it are held encrypted in the wizard's own working store, which is emptied when provisioning completes (so an abandoned run leaves what was typed in place, and a value written before that store was encrypted is read back as it was stored), and provisioning writes the Stripe secret key, the PayPal client secret, the REX API key, the MYOB password and the freight carrier API key into settings encrypted, the SecurePay password excepted. Not encrypted: other credentials entered as a setting, because the systems consuming those values need the original - a tenant's own SMTP relay password, their SecurePay merchant identifier and password, the REX SOAP API key the gift-card and loyalty integration reads (a different field from the REX API key the wizard writes encrypted), an AI provider key supplied for the storefront chatbot or for accounting automation, the reCAPTCHA secret key, the Telegram bot token and webhook secret, the site-audit API key, and the eWAY API key that sits alongside the encrypted eWAY password. A gateway secret entered before that field was marked secret may also still be in the older unencrypted form, because we read it either way rather than lock a tenant out of their own gateway. Everything in that second list sits in the same access-controlled Australian database as everything else, reachable by that tenant's staff holding the relevant permission - by us: a CARTT.AI platform administrator can issue a one-time link that signs them in as a tenant's administrator for support, provisioning and incident response, and sees the same settings screens while signed in; and, where a tenant's account is managed by an agency under our white-label programme, by that agency's staff, who enter the clients assigned to them by the same mechanism and operate as the tenant's own administrator rather than as a platform super-administrator. Every entry of either kind is logged. It is withheld by name from our admin AI assistant. But it is not encrypted at rest, and a blanket sentence should not imply otherwise.
No system is impenetrable. If we become aware of a personal information breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme.
Retention
We keep platform data while your CARTT.AI account is active and for a reasonable period afterwards - billing records for 7 years, which is our own margin over the 5 years Australian tax law generally requires. Sales and marketing enquiries are kept for 24 months from your last contact with us - a target we clear on review rather than by a scheduled job, so ask us if you want an enquiry record deleted and we will action it when you ask. Section 7.2 of the Privacy Policy sets out every retention period on the same basis and prevails over this page.
Tenant data retention is governed by the tenant's own data retention policy. When a tenant closes their CARTT.AI account, tenant data is retained for at least 30 days so it can be exported, then purged in line with our offboarding procedure, except where retention is legally required. Purging a closed account is a reviewed step rather than an automatic one, so it may happen some time after that window; ask us at legal@cartt.ai if you want it done promptly. Section 7.2 of the Privacy Policy governs and prevails over this page.
Your rights under the Australian Privacy Principles
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you (APP 12).
- Request that we correct inaccurate personal information (APP 13).
- Make a complaint about how we have handled your personal information.
- Lodge a complaint with the Office of the Australian Information Commissioner: oaic.gov.au.
The Australian Privacy Principles do not give a general right to erasure, so we would rather not imply one - but section 8.6 of the Privacy Policy gives you one anyway: once the retention period for a category has passed you can ask us to delete it, without giving a reason, and that section sets out the two limits on what we can act on.
To exercise any of these rights, see Contact us.
Cookies and tracking
See our Cookies Policy for full details on the cookies we set, why we set them, our own first-party analytics, the Google reCAPTCHA that runs on our enquiry forms, and how to control them. One is worth naming here because it is the exception to everything else on this page: cartt_ad_attr is set by our platform - on this site and on merchant storefronts - when someone arrives by a link carrying a Google or Meta click identifier or utm_ campaign tags. It holds those parameters for 30 days, encrypted and readable only by our servers, so that an order placed in that window can be attributed to the campaign that produced it. It is the one cookie we set for a marketing purpose rather than a functional one. It captures nothing beyond those link parameters and the time they were captured, and it is not sent back to Google, Meta or any other advertising provider - but the merchant does see it, because attribution is its purpose: once written onto the order it forms part of that merchant's order record, and sitting there beside the name and address of an identified customer it is personal information in that context, whatever it may be on its own. Section 3.6 of the Privacy Policy governs it and prevails over this page.
AI processing
Tenants can use AI features in CARTT.AI (content generation, page audits, image generation, video studio, chatbot, AI Business Advisor). These features process tenant data through third-party AI providers (currently Anthropic Claude, OpenAI, ElevenLabs, Black Forest Labs Flux, fal.ai, Google Gemini, Stability AI, Runway, the Kling, Seedance and Hailuo video models, and Sapling, which scores generated text for how machine-written it reads), and that processing occurs outside Australia - section 7.1 of the Privacy Policy names the country for each, and note that Kling, Seedance and Hailuo are Chinese-owned models that may be processed in China. The tenant chooses which features to enable. Most features are metered through a prepaid wallet; some, including the AI Business Advisor, are included in the plan at no wallet charge.
For tenant administrators: where a provider offers such a commitment, we contractually require it not to train its general-purpose models on your content. Not every provider offers one - section 7.4 of the Privacy Policy and section 7 of the AI Content Disclaimer set out what we have contracted for and what we have not, and prevail over this page. The AI Business Advisor (Network tier) is grounded in your tenant's signals and never auto-acts - it only suggests work with deep-links for you to approve.
Changes to this policy
We may update this Privacy Policy. A material change is published as a new numbered version of the Privacy Policy and we email tenant administrators; publication is the step that always happens and is verifiable on that page, so treat the published version rather than your inbox as the authoritative record. Section 11 of the Privacy Policy governs and prevails over this page. The "Last updated" date at the top of this page reflects the most recent revision.
Contact us
For privacy enquiries, access requests, correction requests or complaints, contact us at legal@cartt.ai or via the contact form on our marketing site. We will acknowledge receipt within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner.