Privacy Policy

Who Are We?

SureCart Inc., 2055 Limestone Rd, STE 200-C, Wilmington, Delaware 19808, is the controller of personal data collected through our own website, marketing, and account registration, and for the data of merchants and affiliates who contract with us.

Merchant stores. When you interact with a store that a merchant runs using SureCart, the merchant is the controller of that customer and order data, and SureCart acts as a processor that handles the data on the merchant’s instructions under a data processing agreement. In those cases, contact the merchant first to exercise your rights; we will support the merchant as required. Where SureCart uses that data for its own purposes (for example, aggregated service improvement or fraud prevention), SureCart acts as an independent controller for those specific purposes.

Contact. For privacy questions or to exercise your rights, email support@surecart.com. This is our official privacy contact. An EU/UK Article 27 representative and Data Protection Officer are not required for our operations.

Your Acknowledgment of This Policy

Providing personal data is voluntary, but some data is necessary to use the services (see Section 4). Where we rely on your consent, you may withdraw it at any time; withdrawal does not affect processing carried out before withdrawal, and may prevent us from providing certain features.

Personal Data We Collect

Merchants. Full name, business name, address, website URL, payment processor details, transaction records, and purchases.

End users (of merchant stores). Contact details, purchase and order history, and payment details, but not full card numbers or card security codes.

Affiliates. Payment data, payout data, and contact details.

Automatically collected data. Device type, browser type and version, IP address, screen size and resolution, language, pages viewed, and interactions with the site. We treat IP addresses, cookie identifiers, device identifiers, and online identifiers as personal data, because they can be linked to an individual.

Account and profile data you provide. Username, email address, profile picture, connected social accounts, and other data you enter.

Whether Data Is Required, and What Happens If You Don’t Provide It

  • Account creation and use of the services, your name and email are required to perform our contract with you; without them we cannot provide an account.
  • Purchases, payment and billing details are required to process a transaction and to meet legal/tax obligations; without them we cannot complete a purchase.
  • Optional data, profile picture, marketing preferences, and similar items are optional and can be omitted without losing core functionality.

Sources of Data

We collect personal data from: you directly; automatically from your device; from merchants (for data about their customers); from payment providers; from analytics and advertising providers; from affiliates; and, where applicable, from connected apps/plugins and identity-verification providers. Where we obtain data about you from a source other than you, we will provide the information required by GDPR Article 14, normally within one month, or at the first communication with you, or before the data is first disclosed, whichever is earliest.

Why We Use Data, and Our Legal Bases

PurposeLegal basis (GDPR)
Providing the services, your account, and checkoutPerformance of a contract (Art. 6(1)(b))
Processing payments; tax and accounting recordsLegal obligation (Art. 6(1)(c)) and contract
Security, fraud prevention, and service improvement (aggregated)Legitimate interests (Art. 6(1)(f))
Analytics, advertising technologies, and marketing to prospectsConsent (Art. 6(1)(a))
Newsletter and promotional emailConsent (Art. 6(1)(a))
Responding to legal requests and enforcing termsLegal obligation / legitimate interests

Where we rely on legitimate interests, you have the right to object (see Section 12). Where we rely on consent, you can withdraw it at any time.

Special-Category and Sensitive Data

SureCart does not seek to collect special-category data (health, religion, political views, sexual orientation, biometric or genetic data) or criminal-offence data, and merchants must not submit such data through the services. We do not use personal data to infer these characteristics. If such data incidentally appears (for example, in a support message or uploaded file), it is not used for profiling and is handled only as needed to provide the service.

For California purposes, the only sensitive personal information we process is account log-in credentials, used solely to authenticate you and secure your account. Because we do not use it to infer characteristics or for any purpose beyond those permitted under CPRA, the “right to limit” does not apply.

Information Captured in Forms

Where you begin entering information into certain forms, we may capture that information to provide support and, where you have opted in, to follow up with you about our products. We do not capture passwords, card security codes, or full card numbers in this way. Before this capture begins, we display a notice at the point of collection. Marketing use is based on your consent, collected through a clear opt-in checkbox on the form; support use is based on our legitimate interests. Where submitted data is stored in a CRM or other third-party system, we ensure that system provides appropriate data-protection safeguards. We also provide a Notice at Collection at each other point where we collect data (signup, checkout, newsletter, support, affiliate forms, and any identity-verification or offline collection).

Cookies and Tracking Technologies

We and selected providers use cookies and similar technologies (pixels, tags, local storage, and session-recording tools) in four categories: Strictly necessary (always active: session, security, spam protection); Functional (documentation help chat, fonts, images); Analytics (Google Analytics 4, Microsoft Clarity, Hex); and Advertising / Marketing (Meta Pixel, Google Ads).

The main tracking technologies we use are:

TechnologyProviderCategoryPurposeTypical duration
Google Analytics 4 (GA4 tracking tag)GoogleAnalyticsSite traffic and usage measurementUp to 2 years
Microsoft ClarityMicrosoftAnalyticsSession replay and heatmapsUp to 1 year / session
HexHexAnalyticsProduct and usage analyticsNo browser cookie (backend analytics)
Cloudflare Web AnalyticsCloudflareAnalyticsPrivacy-focused traffic measurementNo cookie
Meta Pixel / Conversions APIMetaAdvertisingAd delivery and conversion measurementUp to 90 days
Google AdsGoogleAdvertisingConversion tracking and linkingUp to 90 days
Google reCAPTCHAGoogleStrictly necessarySpam and abuse protection on formsSession / persistent
Google FontsGoogleFunctionalServes fonts (sends your IP to Google)No cookie
Bunny FontsBunny.netFunctionalServes fontsNo cookie
ShortPixelShortPixelStrictly necessaryImage optimization and deliveryNo cookie
GravatarAutomatticFunctionalAuthor avatars in the blog author boxNo cookie

The complete, always-current list (including provider, purpose, duration, and domain) is in our Cookie Policy, which is generated and kept up to date automatically.

Consent. Non-essential technologies (Analytics, Advertising, session replay, and similar) load only after you give valid consent where consent is required. We record your consent choice, and you can withdraw or change it at any time using the Cookie Preferences link in the footer, withdrawing is as easy as giving consent, and changes apply to future tracking. Some providers set no cookies but still receive your IP address and browser type when your browser loads their content (for example, Google Fonts, Bunny Fonts, ShortPixel, Cloudflare, Gravatar); we disclose them because this may be personal data under the GDPR.

How We Disclose Data

We use “disclose” for ordinary transfers to processors, service providers, payment providers, and merchants. We reserve “sharing” for its California statutory meaning; as explained in Section 14, SureCart does not share personal information under the CCPA.

We disclose personal data to the following categories of recipients, each only for the stated purpose and, where they act on our behalf, under a contract that restricts them to that purpose:

  • Payment providers (service providers): Stripe, PayPal, Mollie, Paystack, to process payments.
  • Hosting and infrastructure (service providers): UpCloud, Fly, AWS, to host the site and application.
  • Analytics (service providers): Google Analytics 4 (via a GA4 tracking tag), Microsoft Clarity, Hex, Cloudflare Web Analytics, to measure and improve the site.
  • Advertising providers: Meta (Meta Pixel and the Conversions API) and Google (Google Ads), to measure our advertising, acting as service providers and not for cross-context behavioral advertising.
  • Content delivery and site assets (service providers): Cloudflare, ShortPixel, Bunny.net, Google (fonts, reCAPTCHA), Automattic (Gravatar).
  • Support (service provider): PowerfulDocs.
  • Email, tax, monitoring (service providers): Postmark, TaxJar, Appsignal, Slack, Sigmize, Sentry, Logtail.
  • Merchants: when you purchase from a merchant store, to fulfil your order.
  • Legal recipients: courts, regulators, or authorities where required by law.

We use Google Tag Manager (GTM) together with a server-side tagging container (hosted on Google Cloud Run) that receives site events and forwards them through a GA4 tracking tag to Google Analytics 4, and, as we roll these out, to Meta’s Conversions API (CAPI) and Google Ads. These providers act on our behalf as service providers.

For each recipient group we can, on request, confirm the data disclosed, the purpose, and whether the recipient is a processor/service provider or uses the data for its own purposes.

International Data Transfers

Personal data may be processed outside your country, including in the United States. We rely on the transfer mechanisms actually applicable to each flow: the EU-U.S. / Swiss-U.S. Data Privacy Framework and UK Extension (see Section 20) where it applies; European Commission adequacy decisions; and Standard Contractual Clauses where no adequacy decision applies. Main destinations: the United States (where our servers are primarily located) and India (where we also operate). To request a copy or description of the safeguards, email support@surecart.com.

Your GDPR Rights

You have the right to: access your data and receive a copy; rectify inaccurate or incomplete data; erase data (Art. 17), subject to legal exceptions such as compliance with a legal obligation, establishment or defence of legal claims, or ongoing performance of a contract; restrict processing (Art. 18), while restricted, we store the data but do not otherwise use it until the restriction ends; object to processing based on legitimate interests and to direct marketing and related profiling at any time (Art. 21); data portability (Art. 20), for data you provided, where processing is automated and based on consent or a contract, in a structured, commonly used, machine-readable format, with direct transfer to another controller where technically feasible; withdraw consent; and lodge a complaint with a supervisory authority.

How to Make a Request

Email support@surecart.com. We will verify your identity before acting and may ask for information needed to do so.

  • GDPR: we respond within one month, extendable by up to two further months for complex requests, and will tell you within the first month if an extension applies.
  • California: we confirm receipt within 10 business days and respond within 45 calendar days, extendable once by another 45 days with notice. You may use an authorized agent (with proof of authorization). As an online business that deals with California consumers primarily online, we provide an email request method, support@surecart.com, consistent with the online-only exception in CCPA Regulation §7020(a).

We do not discriminate against you for exercising your rights.

Your California Privacy Rights (CCPA/CPRA)

SureCart does not sell your personal information, and does not share it for cross-context behavioral advertising, under the CCPA. Because no sale or sharing occurs, we are not required to provide a “Do Not Sell or Share My Personal Information” mechanism, and the Cookie Preferences tool is provided for consent and cookie control, not as a statutory opt-out.

Disclosure of categories (preceding 12 months)
CCPA categoryCollected?SourcesPurposesRecipient categories (service providers / contractors)SoldShared
IdentifiersYesYou; your device; cookiesAccounts, checkout, security, analyticsHosting, payment, analytics, support, CDN providersNoneNone
Customer records (§1798.80(e))YesYouCheckout, fulfilment, supportPayment, hosting, tax providersNoneNone
Commercial informationYesYour use of the serviceCheckout, support, analyticsPayment, hosting, analytics providersNoneNone
Internet/network activityYesCookies, analytics tools, server-side tagsAnalytics, securityAnalytics providersNoneNone
Geolocation (approximate)YesYour IPAnalytics, security, fraud preventionAnalytics, security providersNoneNone
Professional/employment infoYes (merchants)YouProviding the merchant serviceHosting, support providersNoneNone
InferencesLimitedDerived from analyticsService improvementAnalytics providersNoneNone
Sensitive personal information (log-in credentials)YesYouAuthentication and security onlyHosting providersNoneNone

We do not collect: protected classification characteristics; biometric information; audio/visual/sensory information; or education information.

Your California rights: to know/access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients. For personal information collected on or after 1 January 2022, you may request this information for a period longer than the prior 12 months, unless doing so proves impossible or would involve disproportionate effort. You also have the right to delete, to correct, to non-discrimination, and to use an authorized agent. The “right to limit sensitive personal information” does not apply because we use log-in credentials only for permitted purposes. Requests: see Section 13.

If a verified data flow later shows that any transfer to Meta, Google, the server-side tagging container, look-alike audiences, or customer-list tools constitutes a sale or sharing, this section and the table above will be updated to disclose it and to provide the required opt-out.

Format and availability

This policy and the California disclosures are provided in a format that is printable, readable on mobile devices, reasonably accessible to people with disabilities, and available in the languages in which SureCart ordinarily provides California contracts and sales information. The policy is linked conspicuously in the website footer.

Do Not Track

Because there is no common industry standard for “Do Not Track” (DNT) browser signals, SureCart does not respond to DNT signals. We provide the consent and cookie controls described in Section 9 instead.

Global Privacy Control

Because SureCart does not sell or share personal information, there is no sale or sharing activity for a Global Privacy Control (GPC) signal to stop. The categories we collect, their purposes, and their recipients are set out in the disclosure table in Section 14, which shows “None” for both sold and shared. This position is consistent with our advertising, account, offline, customer-list, and server-side data flows.

Your Brazilian LGPD Rights

You may exercise your LGPD rights, including confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or non-compliant data; portability; deletion of data processed with consent (subject to legal exceptions); information about entities with which data has been disclosed; information about the consequences of denying consent; and revocation of consent.

Your Rights Under India’s DPDP Act, 2023

If you are in India, you have the right to access a summary of your personal data and its processing; to correction, completion, updating, and erasure; to grievance redressal; to nominate another person to exercise your rights on death or incapacity; and to withdraw consent. Contact our grievance officer at support@surecart.com. If unresolved, you may escalate to the Data Protection Board of India.

Children and Minors

The services are intended for adults and are not directed to children. We do not knowingly collect personal data from a child below the age at which consent is required in their jurisdiction (for example, 16 in much of the EU, 13 under U.S. COPPA). Where consent-based processing involves a minor below the applicable age, we require verifiable parental consent. Consistent with Section 14, we do not sell or share the personal information of consumers under 16. If we learn we have collected a minor’s data without the required consent, we delete it promptly; contact support@surecart.com.

EU-US Data Privacy Framework

We comply with the EU-U.S. Data Privacy Framework, the Swiss-U.S. DPF, and the UK Extension as set forth by the U.S. Department of Commerce, and have certified our adherence to the applicable Principles. The FTC has jurisdiction over our compliance. If any conflict exists between this policy and the DPF Principles, the Principles govern. See https://www.dataprivacyframework.gov/. For onward transfers of DPF-covered data inconsistent with the Principles, SureCart Inc. remains liable.

Security and Data Breaches

We implement appropriate technical and organizational measures to protect personal data, and maintain and review them as required by law. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where GDPR Article 33 applies, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights (Article 34), as well as meeting other applicable breach-notification laws.

Data Retention

We keep personal data only as long as needed for the purpose for which it was collected, then delete or anonymize it. Indicative periods:

Data categoryRetention
Account dataFor the life of the account, then up to 90 days after closure
Order and transaction dataUp to 7 years (accounting and legal record-keeping)
Support messages24 months after resolution
Marketing dataUntil you unsubscribe or withdraw consent, then removed
Cookie/analytics dataPer the durations in the Cookie Policy
Security logs12 months
Backups30–90 days rolling
Deleted-account dataRemoved on the schedule above unless a legal exception applies

Where a precise period cannot be given, we use these criteria: the duration of our relationship, legal and tax obligations, and the time needed to resolve disputes.

Using Data for a New Purpose

Before using personal data we already hold for a new purpose, we will give you the information required by law about that new purpose. For California consumers, we will obtain consent before using personal information for a purpose that is materially different from what you would reasonably expect. We do not rely solely on updating this policy after a new use has started.

Changes to This Policy

We may update this policy. Material changes will be notified as required by law, and the “Last updated” date below will change. When we add or change third-party technologies, the Cookie Policy updates accordingly.

Last updated: 21 August 2026

Start Selling With SureCart Today

Simple setup, powerful features, and no coding required. Start selling without the hassle.

Image
Trusted by Thousands of Businesses
Image
Start for Free. No Credit Card Required
Image
World Class Support Team
Scroll to Top