Last updated August 9, 2026
Privacy Policy
How Cartsy handles information across our website, iOS app, Instagram bot, and support channels.
Who we are and where this applies
Cartsy is a product of CR AI Labs, Inc. This policy applies to the public website, authenticated web and iOS experiences, the Cartsy Instagram direct-message bot, and support interactions.
For privacy questions or requests, email hello@cartsy.com.
Privacy contact: hello@cartsy.com.
Information we handle
The information depends on how you use Cartsy and can include:
- Account and profile details, such as name, email address, profile image, sign-in provider identifiers, language, country, and optional preferences or demographic details you choose to provide.
- Messages, searches, prompts, feedback, photos, videos, links, shared social posts, captions, product identifications, and the results Cartsy creates from that content.
- When you message the Instagram bot: Instagram sender and account identifiers, username, message identifiers, message or attachment payloads, linking status, and delivery records.
- Products, retailer links, selected variants, saved items, collections, carts, and interactions with offers.
- If a Cartsy-managed checkout is explicitly offered: delivery address, order contents, totals, payment status, shipment, return, and refund records. A payment processor handles payment-card details; Cartsy stores processor and payment-status references rather than full card numbers.
- App version, device or browser type, language, country inferred from language or time zone, pages or screens viewed, feature events, and diagnostic or crash details.
- Information you include when you contact support, including the account email and any order or troubleshooting details you send.
Where information comes from
We receive information from:
- You, when you create an account, send content, shop, change settings, or ask for support.
- Your chosen sign-in provider, limited to the identity and profile fields returned by the sign-in flow.
- A connected messaging service when you message Cartsy, share an attachment, or connect a messaging identity to a Cartsy account.
- The website, app, backend, and analytics tools when you use the service.
- Public webpages, social posts, product pages, and search results that Cartsy retrieves to answer a request.
How we use information
We use information to:
- Receive and analyze content; run chat and product search; show offers; save posts, products, collections, and carts; and support available order features.
- Use your language, country, history, and stated preferences to make results more relevant.
- Authenticate users, link Instagram conversations safely, prevent abuse or fraud, and investigate errors.
- Measure feature use, diagnose failures, operate the service, and improve Cartsy.
- Send requested sign-in, support, order, delivery, or push-notification messages.
- Comply with applicable law, protect users and the service, and enforce our Terms.
AI, search, and social-content processing
Cartsy sends relevant prompts, messages, images, audio, videos, captions, and product context to OpenAI and Google Gemini for automated processing that identifies items, answers questions, transcribes audio, and supports product search. Cartsy also uses search and social-content retrieval providers to find offers and retrieve public posts. Only information needed for the requested task is sent. Automated results can be incomplete or wrong.
To process a social share, Cartsy may use connected social-content and retrieval services to obtain a public post, then store a working copy of its caption, author details, metadata, and media. Do not send private or third-party content unless you are allowed to use it.
Cookies, local storage, and analytics
The website uses browser storage for authentication sessions, security checks, language and appearance choices, onboarding state, and temporary checkout state. The iOS app similarly stores session and preference data on the device.
When analytics is configured, Cartsy records page or screen views, feature events, device or browser information, and an account or anonymous identifier. The web analytics service may use cookies or similar browser storage. Cartsy removes known sign-in and account-linking secrets from analytics URLs before events are sent.
Cartsy does not currently provide a separate cookie-preference panel. You can clear site data in your browser, reset app data, or block storage through device or browser controls, but doing so can sign you out or break saved preferences. Sign-in providers, connected messaging services, payment processors, and retailer sites may set their own storage under their policies.
Retention, deletion, and security
Cartsy does not currently publish fixed retention periods for most data. We keep information while it is needed to provide and secure the service, maintain records, resolve disputes, and meet legal or accounting obligations. In the current implementation:
- Using Delete account in the iOS app removes the Cartsy account, its authentication identity, and user-owned database records such as chats, posts, offers, saved items, and carts. The Instagram identity is detached rather than erased from every delivery record.
- Successful copies of public social-post metadata and media are stored in a shared cache without a fixed automatic expiry. Because that cache is organized by public content rather than by user, deleting one account does not delete the shared copy.
- Uploaded or shared media objects and provider copies may remain after account deletion because there is not yet a documented automatic object-deletion schedule. Contact us if you need a specific stored item reviewed for deletion.
- Order, payment-status, shipment, return, refund, security, delivery, and legal records may be retained after account deletion when needed for those purposes.
- Service providers and backups can retain copies under their own deletion and backup schedules.
Your choices and requests
You can change available language, country, appearance, and profile settings in Cartsy; unlink by signing out where offered; and control push notifications in your device settings.
In the iOS app, open Account and choose Delete account. This action is permanent for the account records it removes. If you cannot use the app, contact support from the email associated with your account.
You may ask to access, correct, or delete information. Depending on where you live, you may also have rights to object, restrict processing, portability, or appeal a decision. We may need to verify your identity. Email hello@cartsy.com.
Children and international processing
Cartsy is not designed for children. Do not use Cartsy if you are below the minimum age required to consent to the service where you live. If you believe a child provided personal information, contact us.
Cartsy and its providers operate in the United States and other countries. Information can therefore be processed outside the country where you live, subject to applicable safeguards and provider terms.
Changes and contact
We may update this policy as Cartsy changes. We will post the revised version here and change the date above. If a change materially affects how we handle information, we may also provide notice in the service or by email when appropriate.
Questions, complaints, and privacy requests can be sent to hello@cartsy.com.
