JA Cart Guard Privacy Policy
Last updated: 12 August 2026
Information processed
JA Cart Guard processes the store domain, app installation credentials, storefront IP address when it is available from trusted proxy headers, browser user agent, requested product variant IDs, country code when country blocking is configured, and security decisions solely to provide cart-abuse prevention and app administration.
Security and stored credentials
Shopify Admin tokens, cart-signing secrets, and Cloudflare Turnstile secret keys are encrypted at rest. Turnstile secret keys are never returned to the storefront browser. The app does not intentionally store payment-card data, customer account passwords, order contents, customer names, email addresses, or shipping addresses.
IP and country processing
IP allowlist and denylist rules are evaluated locally. On the direct storefront security request, Cloudflare supplies the originating visitor IP and country to the app origin through trusted edge headers. JA Cart Guard signs those values into a short-lived cart-bound context and does not send the storefront IP to a separate IP-geolocation provider.
Security logs and privacy requests
Security logs are retained for the configured retention period and then deleted. Merchants can request access, correction, or deletion through the support address below. Shopify privacy webhooks are handled by the app. Webhook audit logging retains only webhook ID, topic, shop domain, and timestamp; webhook bodies are not retained.
Third-party processors
Third-party processors may include Shopify, Cloudflare, and the hosting provider. Their use is limited to providing the app's security functions. Cloudflare supplies Turnstile verification and edge IP/country context for protected requests.
Contact
For privacy-related questions or requests, contact [email protected].