Privacy Policy
Last updated: August 12, 2026
1. Who we are
SalvaCart ("SalvaCart", "we", "us") is a cart-recovery service for Shopify stores, operated by Juan Diego Santano Avila, sole proprietor, based in Spain. Contact: support@salvacart.com.
SalvaCart works in two roles. For visitors of this website and for the merchants who use our service, we act as a data controller. For the personal data of a store's customers that we process to provide the service, we act as a data processor on behalf of the merchant (the store you bought from), who remains the controller of that data.
2. Categories of personal information we collect
Depending on how you interact with SalvaCart, we collect the following categories of personal information:
- Identifiers — first name, email address, and mobile phone number, as provided during a store's checkout or when you contact us.
- Commercial information — items placed in a shopping cart, order totals, currency, discount codes issued and redeemed, and whether a purchase was completed.
- Communications — the content of SMS conversations between you and the store's SalvaCart assistant, and emails you send to our support address.
- Consent records — the SMS marketing consent status captured by Shopify at checkout, your double opt-in confirmation, and any opt-out (STOP) requests, with timestamps.
- Internet activity — basic technical logs generated when our servers receive requests (timestamps, IP address, delivery status of messages), used for security and troubleshooting.
All the above categories exclude text messaging originator opt-in data and consent; this information won't be shared with any third parties.
3. Why we process this data (purposes and legal bases)
- Sending cart reminder messages — only to customers who gave explicit SMS marketing consent at checkout and confirmed by SMS (legal basis: consent, Art. 6(1)(a) GDPR). You can withdraw consent at any time by replying STOP.
- Answering your replies with an automated assistant so you can finish your purchase (legal basis: consent and our merchants' legitimate interest in serving their customers, Art. 6(1)(f) GDPR).
- Honoring opt-outs — we keep a suppression list (as a non-reversible cryptographic hash of the phone number) so that a number that opted out is never contacted again (legal basis: legal obligation and legitimate interest).
- Reporting to the merchant — recovered orders and aggregate statistics (legal basis: performance of our contract with the merchant).
- Security and abuse prevention — technical logs and rate limiting (legal basis: legitimate interest).
We do not sell personal information, and we do not use it for advertising networks or profiling unrelated to cart recovery.
4. Subprocessors and data sharing
We share personal data only with the service providers strictly necessary to operate SalvaCart:
| Provider | Purpose | What they receive |
|---|---|---|
| Twilio Inc. (USA) | SMS delivery and reception | Phone number, message content, delivery metadata |
| Anthropic, PBC (USA) | AI processing of conversation replies | Conversation text, cart items and totals, customer first name. We never send phone numbers, email addresses or postal addresses to the AI model. |
| Cloud hosting provider | Application and database hosting | All service data, encrypted at rest. The specific provider will be named here before public launch. |
Where these providers are located outside the European Economic Area, transfers are protected by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable. We also share data with Shopify as part of the store's own platform, under the merchant's existing agreement with Shopify.
5. Retention
- Cart and conversation data: kept while the merchant uses SalvaCart and deleted within 30 days after uninstallation, or earlier upon a valid deletion request.
- Opt-out records: kept indefinitely as a hashed suppression entry, because the obligation not to contact you survives deletion of your other data.
- Technical logs: kept up to 90 days.
6. Security
Personal data such as phone numbers, email addresses and access tokens is encrypted at rest (AES-256-GCM) and in transit (TLS/HTTPS). Access is limited to what the service strictly needs, and administrative access to merchant dashboards is authenticated.
7. Your rights
Under the GDPR (and, for California residents, the CCPA/CPRA) you may request access, correction, deletion, portability, or restriction of your personal data, and you may object to processing. If you are a store's customer, you can contact either the store you bought from or us directly at support@salvacart.com — we will honor merchant-forwarded requests within 30 days. You can withdraw SMS consent at any time by replying STOP to any message.
If you are in Spain or elsewhere in the EU, you also have the right to lodge a complaint with your supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD, aepd.es).
8. Children
SalvaCart is not directed at children and we do not knowingly process data of anyone under 16. If you believe a minor's data reached us, contact us and we will delete it.
9. Changes to this policy
We will post any changes on this page and update the date above. Material changes affecting how messages are sent will be notified to merchants directly.
10. Contact
SalvaCart · Juan Diego Santano Avila (sole proprietor), Spain · support@salvacart.com