YOUR DATA. YOUR CHOICES.

Cartdini privacy notice

Pro subscriptions are not open yet. This notice describes the current website and plugin data handling; commercial-service details remain under review.

Who is responsible?

This notice covers the Cartdini website, staff workspace and optional Pro license service. The legal seller and website operator is A.M.E.X. Internet Marketing ltd.

Makariou III, No.9, Larnaca, 7530, Cyprus

Privacy and support contact: support@cartdini.com Email us for setup, billing or privacy questions.

If a shop uses Cartdini checkout fields, that shop controls the customer information collected through those fields. Contact that shop about its checkout data.

Optional visitor analytics

Analytics is off until the site operator enables it and you choose Accept analytics. Rejecting has no effect on access to the website or purchases. Use Privacy choices in the footer at any time to reject analytics or withdraw consent. We also treat Global Privacy Control and Do Not Track signals as a request to keep optional analytics off.

With consent, we count visits to public pages, daily unique browsers and approximate countries supplied by our hosting network. A country estimate can be affected by VPNs or network routing; it is not GPS or a precise address. Daily browser counts are estimates, not counts of identified people.

Our analytics database does not store your full IP address, email, browser user-agent, query strings, full referral URLs, form contents, payment information or license key. We do not join these counts to staff accounts, purchases or licenses. We do not run advertising pixels, sell analytics profiles, track across websites or automatically subscribe visitors to marketing. Administration, payment confirmation and customer download pages are excluded from optional analytics.

Cookies and browser storage

PurposeWhat it doesLifetime
Privacy preferenceRemembers acceptance or rejection, including the notice version. Necessary to honor your choice.180 days
Optional analytics identifierA random first-party browser identifier, set only after acceptance. Reporting identifiers are separated by UTC day.24 hours; removed on rejection
Staff sign-in and securitySecure session, request-protection and temporary 2FA challenge cookies. Required to use the staff workspace.Session: 30 minutes maximum, 15 minutes idle. Request protection: 10 minutes. 2FA challenge: 5 minutes.
Payment confirmationA secure cookie links the returning browser to its checkout attempt.24 hours
Currency preferenceStores only a currency explicitly selected by you in browser local storage.Until you choose automatic currency or clear browser storage

Stripe and the hosting platform may use their own necessary technologies when you use their hosted services, including a private-site access gate. Their notices apply to those services. Clearing necessary cookies may sign you out or interrupt payment confirmation. Optional analytics stays off if preferences cannot be loaded reliably.

Purchases, billing and downloads

Stripe processes card payments and subscription billing. Card numbers and security codes do not enter this website’s database. We retain purchase, customer, subscription and invoice identifiers, the selected plan/site allowance, amount, currency, paid period, access status and a hashed download-key reference. Authorized support staff can request the customer name and email from Stripe when handling a purchase. Download access is verified with Stripe; owners can record support notes or suspend access and replace compromised keys.

Staff accounts and invitations

The staff workspace is invitation-only. It stores an email address, role, password hash, access state and sign-in times. Passwords are hashed rather than stored in readable form. Google Authenticator-compatible two-factor authentication is optional. When enabled, its setup secret is encrypted and one-use recovery codes are stored as hashes. We retain short-lived session and invitation/reset records and an audit history of administrative actions. A verified hosting identity is used only to establish the initial owner account.

If transactional email is configured, invitation and password-reset emails are delivered through Resend. We send the recipient’s email and the message required for that request. We do not enroll recipients in a marketing list. Without a mail connection, an owner can issue a private account link for direct sharing with the intended recipient.

Cartdini on a WordPress shop

Checkout field values and settings stay in the shop’s WordPress database. Cartdini Free sends no usage telemetry to us. Cartdini Pro’s installed checkout features do not depend on a live license connection.

Pro version 0.1.0-rc.2 adds an optional license connection. It starts only when a WordPress administrator enters a purchase key and authorizes the disclosed communication. Connection, manual checks, daily scheduled checks and an authenticated Pro update download send the shop URL, a random installation identifier and Cartdini Pro, WordPress, WooCommerce and PHP versions. We retain connection status and successful check-in times to enforce the purchased update/support site allowance and help diagnose service problems. No checkout fields, orders or shop customer data are sent. Pro RC6 update downloads also send the requested release version. The updater verifies the downloaded package locally; Cartdini does not enable automatic installation.

The purchase key is exchanged for a restricted installation token. The token is encrypted locally using the shop’s WordPress security salts; its hash is stored by the license service. Disconnecting releases the site seat. Removing the local connection stops future checks, but may require the owner to free the seat on the server. Deactivating Pro stops its scheduled checks. Uninstalling removes local connection credentials; checkout configuration and order values are retained.

Why we process information

Optional analytics relies on your consent, which you can withdraw through Privacy choices. Account access, payment fulfillment, downloads, requested communications and license support are used to provide the service you or your organization requests. Security and access records support our legitimate interests in preventing abuse and operating the service. Financial records may also be retained to meet applicable legal obligations. The seller must confirm the appropriate legal basis and mandatory retention rules for its jurisdiction before commercial launch.

Retention

Analytics event-deduplication records expire after 24 hours, daily pseudonymous browser records after 31 days and aggregate page/country counts after 395 days. Expired records are removed in bounded cleanup batches during use of the service; expired aggregates are excluded from reporting. Withdrawal stops future analytics and removes the browser identifier; prior aggregate counts are not reversed.

Staff invitations expire after 24 hours, password-reset links after 15 minutes and sign-in challenges after 5 minutes. Expired account-link records are removed after a further 31 days during routine cleanup. Expired sessions and abuse-prevention counters are cleaned up as the service is used. Security rate limits use temporary hashed identifiers; they are separate from visitor analytics.

Purchase, license-connection, support and administrative audit records are retained to operate subscriptions, handle support and disputes, and meet applicable obligations. They currently require a controlled retention/deletion review by the operator. The seller must finalize its jurisdiction-specific schedule and backup retention before live sales; this build does not claim automated deletion of those business records. Audit records cannot be edited or deleted through the staff dashboard.

Service providers and international handling

The website uses OpenAI Sites and its Cloudflare-hosted infrastructure for hosting, database and package storage. Network providers necessarily receive connection information, including an IP address, to deliver and protect the site; their operational logs are separate from our limited analytics database. Stripe handles payments, and Resend is used only if account email is configured. These providers may process data internationally. The seller must confirm applicable provider agreements, locations and transfer safeguards before launch. We do not claim EU-only hosting.

OpenAI privacy notice · Cloudflare privacy notice · Stripe privacy notice · Resend privacy notice

Your rights and requests

Depending on your location, you may be entitled to access, correct, delete, restrict or obtain a portable copy of your personal information, object to certain processing, withdraw consent or complain to a data-protection authority. Contact the published privacy/support address. We may need to verify your identity and explain records that must be retained. Do not email passwords, recovery codes, full card details or license keys. A request concerning a shop’s checkout data should go to that shop.

We will update this notice when practices change. The operator must review changes before enabling new collection. This notice describes the implemented service; it is not a certification of legal compliance.

Blog articles and authors

Published articles can include the author or organization’s name, biography, profile link and article images. Staff choose these public details separately from their login email. Drafts and revision history are limited to authorized staff. Images are uploaded through the dashboard; do not include customer, payment or confidential information in an article image. The blog does not provide public comments or a newsletter signup.

If optional visitor analytics is enabled and you consent, public blog page views are included in the aggregate page and country reports described above. We do not collect your article-search terms through these analytics.