CROCart
Privacy Policy
Effective date: July 3, 2026
CROCart (“CROCart,” “we,” “us,” or “our”) is a Shopify application developed and operated by PRP Webs (“Developer”). This Privacy Policy explains what information CROCart collects, how it is used, and how it is protected when a merchant installs CROCart on their Shopify store (the “Merchant,” “you”).
This policy applies to CROCart's collection and use of data through the Shopify Admin application and its companion storefront cart-drawer extension. It does not apply to Shopify's own services, which are governed by Shopify's Privacy Policy.
If you have questions about this policy, contact us at cg@prpwebs.com.
1. What CROCart Does
CROCart replaces or enhances a Shopify store's shopping cart with a customizable “cart drawer.” It lets a Merchant configure the drawer's appearance, upsell and cross-sell product recommendations, tiered free-shipping/reward progress bars, discount code entry, cart notes, trust badges, and an empty-cart state — and provides the Merchant with an in-app analytics dashboard summarizing drawer performance (impressions, checkout conversions, and revenue by feature).
CROCart has two components:
- Admin application — where the Merchant configures the cart drawer and views analytics.
- Storefront extension — a Shopify theme app extension installed into the Merchant's live theme, which renders the cart drawer to the Merchant's shoppers.
2. Information We Collect
2.1 Merchant and Store Account Information
When a Merchant installs CROCart, Shopify's OAuth process grants CROCart the following, which we store to operate the app:
- Access tokens used to authenticate CROCart's requests to the Merchant's Shopify store on the Merchant's behalf.
- Authorized staff account details (first name, last name, email address, Shopify user ID, locale, and account-owner/collaborator status) for the staff member who installed or authorized the app, where Shopify provides this as part of the session.
- Shop domain and OAuth scope grants.
2.2 Store Configuration Data
We store the cart-drawer settings the Merchant configures in the admin app — for example, colors, fonts, layout choices, upsell product selections, reward-tier rules, discount codes created through the app, cart notes, trust badge text, and a brand logo image (uploaded to the Merchant's own Shopify Files/CDN, not to CROCart's servers). This is Merchant-authored configuration data, not personal data about the Merchant's shoppers.
2.3 Aggregate, Anonymous Usage Analytics
The storefront cart drawer sends anonymous event data to CROCart to power the Merchant's analytics dashboard — for example, a cart impression, an upsell shown, a checkout started, or a checkout completed, along with the associated revenue amount, product ID, and feature module. These events are not linked to any individual shopper. We do not record or store, alongside these events, any shopper name, email address, physical address, phone number, customer ID, session ID, cart token, cookie identifier, IP address, or device fingerprint.
We also read aggregate order totals from the Merchant's store (via the Shopify Admin API, using the order's total value and Shopify order ID only, for de-duplication) to back-fill checkout-completed analytics. We do not read or store customer names, emails, shipping addresses, or line-item details from orders.
2.4 Billing Information
CROCart offers a free plan and a paid subscription plan. Subscription billing is handled entirely by Shopify's own Billing API — CROCart never receives, processes, or stores credit card numbers, billing addresses, or other payment instrument data. We store only which plan tier (free or paid) is currently active for the store.
2.5 Information We Do Not Collect
CROCart does not request the Shopify permissions needed to read customer records, and it does not collect or store:
- Shopper names, email addresses, phone numbers, or shipping/billing addresses
- Payment card or other payment instrument details
- Order-level customer identity or line-item contents
3. How the Storefront Extension Interacts With Shoppers' Carts
The cart-drawer extension reads and updates a shopper's cart using Shopify's own standard, first-party cart APIs (the same mechanism the store's theme already uses) — it does not create a separate identity or session for the shopper, and it does not set its own tracking cookies or write to the shopper's browser storage beyond what is needed to render the cart UI.
4. How We Use Information
We use the information described above to:
- Operate and authenticate the app’s connection to the Merchant’s Shopify store
- Save and apply the Merchant’s cart-drawer configuration
- Generate the Merchant’s in-app analytics dashboard
- Process the Merchant’s subscription plan via Shopify Billing
- Provide customer support to the Merchant
- Maintain the security and integrity of the app
We do not sell personal data, and we do not use store or shopper data for advertising or profiling purposes.
5. Data Sharing
We do not share Merchant or shopper data with third-party analytics, advertising, or marketing vendors — CROCart has no integrations with external analytics, error-tracking, email, or ad-tech services. The only external system CROCart communicates with is Shopify itself, via the Shopify Admin GraphQL API and Shopify Billing API, using the access scope the Merchant has granted.
We may disclose information if required by law, to enforce our terms, or to protect the rights, property, or safety of CROCart, our Merchants, or others.
6. Data Retention and Deletion
Store configuration data, session/access tokens, and analytics events are retained for as long as the app remains installed on the store, so that the app continues to function correctly.
When a Merchant uninstalls CROCart, we automatically delete that store's session data, cart-drawer configuration, and analytics events. Shopify additionally sends a shop/redact webhook approximately 48 hours after uninstallation, which we use to confirm this deletion has occurred.
7. GDPR / CCPA Mandatory Webhooks
In compliance with Shopify's data protection requirements, CROCart implements Shopify's three mandatory privacy webhooks:
customers/data_request— Because CROCart does not store any data tied to an individual shopper (see Section 2.5), there is no shopper-specific data to compile or return in response to a data request.customers/redact— Because CROCart's analytics events are not linked to any individual shopper identifier, there is no per-shopper record to delete in response to this request.shop/redact— Upon receipt (issued ~48 hours after app uninstallation), CROCart permanently deletes all remaining session, configuration, and analytics data associated with that store.
8. Data Security
Access tokens and configuration data are stored in a private, access-controlled PostgreSQL database used exclusively by CROCart. Access to this infrastructure is restricted to authorized personnel. While we take reasonable measures to protect information, no method of storage or transmission is completely secure, and we cannot guarantee absolute security.
9. Merchant Rights and Control
A Merchant may access, update, or delete their cart-drawer configuration at any time through the CROCart admin interface, and may uninstall the app at any time from the Shopify admin, which triggers the deletion described in Section 6. Merchants may also contact us directly with any data-related request at the email below.
10. Children's Privacy
CROCart is a business-to-business tool intended for use by Shopify merchants and their authorized staff. It is not directed at children, and we do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the app's functionality or applicable law. We will update the “Effective date” above when changes are made. Continued use of CROCart after changes take effect constitutes acceptance of the revised policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact:
PRP Webs
Email: cg@prpwebs.com