- Who we are
- Information we collect
- Shopper data in the cart drawer
- How we use information
- AI product recommendations
- Sharing and service providers
- Data retention
- Security
- Your rights
- Shopify data requests
- Cookies and local storage
- International transfers
- Children's privacy
- Changes to this policy
- Contact us
1. Who we are
BoostlyCart — Cart Drawer Upsell ("BoostlyCart", "the app", "we", "us") is a Shopify application developed and operated by Zepto Apps. The app replaces the default Shopify cart with a cart drawer that can show volume discounts, cross-sells, reward progress bars, announcement and countdown bars, a discount code box, shipping estimates, gift wrapping, order notes, trust badges and express checkout buttons.
This policy applies to merchants who install BoostlyCart from the Shopify App Store, to shoppers who interact with the cart drawer on a merchant's storefront, and to visitors of boostlycart.com. By installing the app, you agree to the practices described here.
2. Information we collect
BoostlyCart only requests the Shopify API permissions it needs to deliver its features. You can review the exact permissions on the installation screen before approving them.
Store and account information
- Your myshopify.com domain, store name, primary email address, country, currency, locale, timezone, and Shopify plan
- Your app subscription status, selected plan, and installation date
- Your monthly order count — read from Shopify solely to determine whether your store is within the Free plan's 50-order allowance
Store content data
- Product and collection data — titles, handles, images, variants, prices and inventory status, used to build cross-sell and recommendation offers and to render line items in the drawer
- Discount data — the discounts the app creates and reads through Shopify's native discount system so that volume pricing, cross-sell offers and reward tiers apply correctly at checkout
- Shipping and location settings — your shipping zones and rates, used to return live shipping estimates inside the drawer
- Theme data — the app installs as an app embed block on Online Store 2.0 themes. It reads theme settings to match your styling and does not modify your theme's template files
- Your app configuration — the offers, rules, copy, colours, and any custom HTML or CSS you enter in the app settings
Usage and technical data
- Feature usage inside the app admin — which modules you enable, the offers you configure, and when
- Aggregated performance data about the drawer, such as how often an offer was displayed or accepted, used to show you results and improve the app
- Log data such as IP address, browser type, device type, and timestamps, collected for security and troubleshooting
- Error reports and performance diagnostics
3. Shopper data in the cart drawer
Unlike a purely back-office app, BoostlyCart runs on your live storefront, so it necessarily processes some information from the shoppers using it. We keep this to the minimum the features require.
What the drawer processes
- Cart contents — the products, variants, quantities, prices and line item properties currently in the shopper's cart, so the drawer can render them and decide which offers apply
- Line item properties — custom text, uploaded file references, engraving details, selling plans and bundle metadata added by other apps. BoostlyCart passes these through unchanged so they survive into checkout; it does not inspect or store their contents
- Shipping estimate inputs — the country, state or province, and postal code a shopper voluntarily enters to see live shipping rates. This is sent to Shopify to calculate rates and is not retained afterwards
- Order notes and gift notes — text a shopper types into the note or gift-note field, which is attached to the cart and passed to the order in your Shopify admin
- An anonymous cart or session identifier — used to keep drawer state, countdown timers and reward progress consistent across page views in a single visit
BoostlyCart does not collect, process or store payment card numbers, bank details or billing credentials. Express checkout buttons are rendered by Shopify and the payment provider; pressing one hands the shopper straight to Shopify's checkout, which BoostlyCart has no access to. We also do not build shopper profiles, run cross-site tracking, or sell or share shopper data with advertisers.
Where BoostlyCart handles information that Shopify classifies as protected customer data, we process it only to deliver the features you have enabled, keep it only as long as needed for that purpose, and handle it in line with Shopify's Protected Customer Data requirements. As the store owner, you are the data controller for your shoppers' information; we act as your processor.
4. How we use information
We use the information described above solely to:
- Render the cart drawer and the modules you have enabled on your storefront
- Decide which volume discounts, cross-sells, reward tiers and recommendations apply to a given cart
- Create and apply discounts through Shopify so the price shown in the drawer is the price paid at checkout
- Return live shipping estimates when a shopper requests them
- Authenticate your store and apply the correct plan and order allowance
- Show you performance data for your offers inside the app
- Provide live chat and email support when you contact us
- Monitor reliability, prevent abuse, and improve the app
- Send service and product notifications related to your installation
We do not sell your data, rent it, or use it for advertising.
5. AI product recommendations
BoostlyCart's AI-based product recommendation feature suggests complementary products to show as cross-sells. When this feature is enabled, product catalogue information — such as titles, descriptions, types, tags and the combination of items in a cart — may be sent to third-party AI or recommendation providers so that suggestions can be returned.
Only the data needed for the specific request is transmitted. We do not send shopper names, email addresses, shipping addresses, order history or payment information to AI providers. You can disable the recommendation module at any time in the app settings, and you remain responsible for reviewing which products are eligible to be recommended.
6. Sharing and service providers
We do not share your information publicly or with third parties, except with service providers that make the app work and only to the extent required. These include:
- Shopify — the platform your store runs on and the source of the data the app reads and writes, including carts, products, discounts, shipping rates and billing
- Cloud hosting, database and CDN providers — used to run the app's servers, serve the drawer script, and store your app settings
- AI and recommendation providers — used to generate product recommendations when you enable that feature
- Analytics and error monitoring providers — used to measure app reliability and diagnose issues
- Support tooling — used to operate live chat and email support when you contact us
These providers are bound by confidentiality obligations and may only process data on our instructions. We may also disclose information where required by law, or to protect our rights, safety, or property.
7. Data retention
We keep data only for as long as it is needed to provide the service.
- Shipping estimate inputs are used for the rate lookup and not retained afterwards
- Cart and session data is transient and expires with the shopper's session or shortly after
- Aggregated offer performance data is retained in non-identifying form while your installation is active
- Your app settings and offer configuration are retained while the app is installed
When you uninstall BoostlyCart:
- Our access token is revoked immediately by Shopify and we can no longer read your store data
- The drawer stops rendering on your storefront and your theme returns to its default cart, with no leftover snippets in your theme files
- Store data and app settings associated with your shop are deleted within 48 hours of uninstall, or within 30 days where a retention period is required for billing, legal, or security reasons
- Orders, order notes, gift notes and discounts already created in your store remain in your Shopify admin, because they belong to you
You may request earlier deletion at any time by contacting us.
8. Security
We protect stored information using commercially acceptable means to prevent loss, theft, unauthorized access, disclosure, copying, use, or modification. This includes encrypted connections (HTTPS/TLS), encrypted storage of access tokens, restricted internal access, and regular security updates.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a data breach affecting your store, we will notify you and the relevant authorities as required by law.
9. Your rights
Depending on where you are located, you may have the right to:
- Access the data we hold about your store
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Request a copy of your data in a portable format
- Withdraw consent, by uninstalling the app at any time
To exercise any of these rights, email us using the details in section 15. We respond to verified requests within 30 days. If a shopper contacts us directly about data held through your store, we will refer them to you as the store owner and assist you in responding.
10. Shopify data requests
As required by Shopify, BoostlyCart implements the mandatory compliance webhooks:
- customers/data_request — we search our records for data associated with the identified customer and return whatever we hold to you within 30 days
- customers/redact — any data associated with the identified customer is erased from our systems
- shop/redact — all data associated with your shop is deleted when this webhook is received, 48 hours after uninstall
11. Cookies and local storage
The BoostlyCart admin interface uses strictly necessary cookies and session storage to keep you signed in and to remember your preferences within the app.
On your storefront, the cart drawer may use the browser's local storage or a first-party cookie to remember drawer state — for example an open or closed panel, a dismissed announcement bar, or the remaining time on a countdown timer — so the experience stays consistent as a shopper moves between pages. These are functional only. We do not set advertising or cross-site tracking cookies, and the drawer does not fingerprint shoppers.
Our website, boostlycart.com, may use basic analytics cookies to understand page traffic.
12. International transfers
Zepto Apps operates from Bangladesh and uses service providers that may store or process data in other countries. Wherever data is processed, we apply the same protections described in this policy and use appropriate safeguards for international transfers.
13. Children's privacy
BoostlyCart is a business tool intended for Shopify merchants. It is not directed at children, and we do not knowingly collect information from anyone under 16.
14. Changes to this policy
We may update this policy to reflect changes in the app, our practices, or legal requirements. The revision date at the top of this page always shows when it was last changed. Material changes will be communicated through the app or by email. Continued use of BoostlyCart after an update means you accept the revised policy.
15. Contact us
If you have questions about this policy, or would like to make a privacy request, please reach out:
Developer of BoostlyCart — Cart Drawer Upsell