Privacy Policy
This Privacy Policy explains how ByteBunny, LLC ("ByteBunny," "we," "us") — the company that owns and operates NanoCart — collects, uses, and shares information when you visit nanocart.io, use the merchant dashboard at portal.nanocart.io, embed the NanoCart widget, run a NanoCart-hosted storefront, or buy from a store powered by NanoCart.
1. Two Roles: Merchants and Their Customers
NanoCart handles data in two different capacities:
- For merchants (people with NanoCart accounts): we decide how account and billing data is handled, and this policy applies directly.
- For merchants' customers (people who buy from, or subscribe to, a NanoCart-powered store): we process order and subscriber data on behalf of the merchant. The merchant is responsible for their own privacy practices. If you bought something from a NanoCart-powered store, your primary privacy relationship is with that store; contact the merchant first, and we will support their requests.
2. Information We Collect
Merchant accounts
- Account details: email address and authentication data (managed through AWS Cognito; we never see your password).
- Store data: store name, products, images, categories, coupons, shipping settings, storefront content, and configuration.
- Billing: subscription plan and payment status. Payments are processed by Stripe; we do not store full card numbers.
- Integration credentials you provide (for example Stripe/PayPal keys, Printful/Printify API keys), stored to operate your store.
- Usage and log data: API requests, IP addresses, browser type, and diagnostic logs used for security and reliability.
Merchants' customers (processed for the merchant)
- Order data: items purchased, amounts, shipping details, and email address for receipts and order updates.
- Subscriber data: email addresses and preferences submitted through a store's signup form, with a record of consent. These lists belong to the merchant; we host them and enforce unsubscribe handling.
- Payment card details go directly to Stripe or PayPal — they are never stored on NanoCart servers.
Website visitors
- Analytics: we use Google Analytics on our marketing site to understand traffic. It sets cookies and collects usage data subject to Google's policies. Our pricing calculator and checkout demo run entirely in your browser — nothing you type into them is sent to us.
- Functional cookies and local storage: used for sign-in sessions on the dashboard and cart state in the widget. We do not use advertising cookies or sell ad targeting data.
3. How We Use Information
- To provide, operate, and secure the Service — accounts, storefronts, checkout, orders, emails, and integrations.
- To bill subscriptions and prevent fraud and abuse.
- To send transactional email (receipts, order notifications, account messages) via Amazon SES, and — for merchants — occasional service announcements.
- To improve the Service using aggregated, de-identified usage data.
- To comply with law and enforce our Terms of Service.
We do not sell personal information, and we do not use merchants' customer data for our own marketing.
4. How We Share Information
We share data only with service providers needed to run NanoCart, under their own contractual and legal obligations:
- Amazon Web Services — hosting, storage, email delivery (SES), and authentication (Cognito), in the United States.
- Stripe and PayPal — payment processing for subscriptions and for merchants' sales.
- Printful / Printify — order details for merchants who enable print-on-demand fulfillment.
- Google Analytics — marketing-site usage statistics.
We may also disclose information if required by law, to protect rights and safety, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to previously collected data until updated).
5. Data Retention and Deletion
- Account and store data is kept while your account is active. After account closure, we delete or de-identify it within a reasonable period, except where retention is required (for example, billing records).
- Merchants can delete products, subscribers, and other store data from the dashboard at any time.
- Subscriber unsubscribe requests are honored automatically and suppressed from future sends.
6. Security
Data is encrypted in transit (TLS) and at rest, access is restricted and logged, authentication is handled by AWS Cognito, and card data never touches our servers. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you as required by law.
7. Your Rights
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to non-discrimination for exercising those rights. To exercise them, email hello@nanocart.io. If your data was collected by a NanoCart-powered store, we will route or support your request with that merchant. You may also lodge a complaint with your local supervisory authority.
8. International Visitors
NanoCart is operated from the United States and data is processed on servers in the United States. If you use the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.
9. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. We will post the updated version here with a new effective date and, for material changes, give merchants additional notice.
11. Contact
ByteBunny, LLC · NanoCart
Email: hello@nanocart.io
Dashboard