Skip to content

Legal

Draft

Privacy policy

How Cartpy intends to handle personal data — in plain language, structured around Brazil's LGPD (Law No. 13,709/2018).

Draft revision: August 3, 2026

This document is a draft

The text below is under legal review and is not yet the approved version of Cartpy's privacy policy. It describes the practice we are building, but it is not a final legal commitment. The approved version will be published on this same page with its own revision date.

Data we collect

We collect the minimum the operation requires. Every category below exists for a concrete reason — none of it is collected "just in case".

Producer account
Name, email, and access credentials, used to authenticate and protect your account.
Company details
Legal name, CNPJ or CPF, and address, used to identify the operation and meet tax obligations.
Sales operation
Products, offers, orders, and fulfillment data, used to run the journey from offer to doorstep.
Buyer data
Name, contact details, and delivery address of store customers. Cartpy processes this data on the producer's behalf, in the role the LGPD defines for parties operating on behalf of another business.
Payment provider keys
API credentials you connect to the platform, stored encrypted and used exclusively to route transactions through your own account.

Sharing with payment providers

Cartpy runs on a direct-connection model: you connect your own account at one of the compatible providers: Pagar.me, Mercado Pago, Asaas, PagBank, and Stripe. When an order is paid, the data needed to process the transaction is transmitted to the provider you chose — and to no one else.

The provider's processing is governed by the contract and privacy policy you hold directly with them. Cartpy does not sell personal data and does not share data with third parties for advertising purposes.

Data-subject rights

Among others, the LGPD guarantees every data subject the right to:

  • Confirm that their data is being processed
  • Access the data we hold about them
  • Correct incomplete, inaccurate, or outdated data
  • Request anonymization, blocking, or deletion of unnecessary data
  • Request portability of their data to another provider
  • Know who their data is shared with
  • Withdraw previously given consent

Data-subject channel

The official data-subject contact channel and the identity of the data protection officer (DPO) will be published in this section as soon as Cartpy's privacy structure receives legal approval.

Until then, no privacy contact announced outside this page should be treated as official.

Data retention

The draft establishes a simple retention model:

  1. Account and operational data is kept while the account remains active.
  2. Tax and transaction records are preserved for the periods Brazilian law requires, even after the account is closed.
  3. Data with no active purpose and no legal retention requirement is deleted or anonymized.

Security

Payment provider credentials are stored encrypted. Internal access to personal data is restricted by permission controls and logged for auditing.

No system is immune to incidents. If a relevant security incident affects personal data, notification to data subjects and to the competent authority will follow what the LGPD mandates.