Privacy Policy

Please read the terms of our privacy policy below.

This Privacy Policy describes how your personal information is collected, used, and shared.

It applies to cartflows.com, to our store and checkout at my.cartflows.com, and to translate.cartflows.com and ideas.cartflows.com (together, the “Site”). CartFlows is a suite of WooCommerce plugins — CartFlows Funnel Builder, Modern Cart, Cart Abandonment Recovery, Power Coupons and Variation Swatches. When one of our plugins runs on a store you operate, you decide what your own forms and checkout collect and you are responsible for the privacy policy shown to your customers. The points where our own services sit in the data path on a store you run are described under Using CartFlows On Your Own Website below.

Who We Are

We are Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States.

Email: [email protected]

What Personal Information We Collect

When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.

Cookies and Similar Technologies

Cookies are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies — including pixels, tags, local storage and session-recording tools — across our Site in four categories:

  • Essential — required for core site functionality, including security, load balancing, keeping the contents of your cart and remembering your cookie choice.
  • Functional — remember your preferences and settings, and which variant of a page you were shown.
  • Analytics — help us understand how visitors use our Site, including session replay and heatmaps, and test improvements to site design.
  • Marketing — used for advertising measurement, remarketing and targeted advertising.

Non-essential cookies and technologies (Functional, Analytics and Marketing) are set only after you provide consent through our cookie preference banner. You can change your preferences at any time by clicking Cookie Preferences in the footer, and withdrawing consent is as easy as giving it.

A list of the cookies and tracking technologies our scanner detects on this Site, with the provider, purpose, duration and domain for each, is on our Cookie Policy page, which is linked from the footer and from the cookie preference banner. A scanner sees what loads on the pages it visits, so a technology that appears only on a page it has not yet scanned may not be listed straight away.

We honor the Global Privacy Control (GPC) signal where required by law. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information.

Retention: records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.

Comments

Where a post on our blog accepts comments, we collect the data shown in the comment form, along with your IP address and browser user-agent string, to help with spam detection.

An anonymized string created from your email address (a hash) may be shared with the Gravatar service to check whether you use it, and Gravatar also supplies the author’s picture in the author box on each post.

Contact Forms

Information submitted through contact forms on our Site is sent to our self-hosted support desk.

We may collect information submitted through contact forms, including (but not limited to) your first and last name and email address. This information may be shared with our email marketing services, including our self-hosted CRM.

Support

To help with our products, we may ask for temporary access to your website — either your live site or a staging copy, whichever you prefer — such as an admin login or FTP or database credentials. Troubleshooting typically takes place directly on your site, and in those cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this is not always feasible.

In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Once the issue is resolved, we delete these copies from our systems.

Information submitted through support forms is managed through our self-hosted support portal.

A few important points about access shared with our support team:

  • We use any access you provide strictly for debugging your specific issue, on your site itself.
  • We do not copy or retain your site’s data on our own systems.
  • We do not share access or data with anyone outside the company.
  • We cannot be held responsible for loss of private information from your database or website. If you’re able to share a staging site and keep a working backup of anything shared with us, we recommend doing so.

Retention: Where troubleshooting happens on your site directly rather than on data transferred to us, there is no site-data copy for us to retain, and you are responsible for rotating or revoking any login, FTP, or database credentials you shared with us once your issue is resolved – we have no further use for them once the support ticket closes. Where we’ve created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved.

We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed. We do this so we can refer back to how a past issue was resolved if it recurs, and to analyze recurring issues internally to improve our products and reduce future support volume. Support ticket records are not shared with any third party – they remain strictly between you and us.

If your site contains your own customers’ or visitors’ personal data (for example, order or form submissions) that we may view while troubleshooting on your site, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose – you remain responsible for your own compliance obligations toward your site’s visitors and customers.

Purchase

If you purchase products or services from us, our payment gateway provider may require your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.

All direct payment gateways adhere to PCI-DSS standards, managed by the PCI Security Standards Council (a joint effort of Visa, MasterCard, American Express, and Discover), which help ensure secure handling of card information.

When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, shipping address, payment information, email address, and phone number.

Retention: Billing and transaction records are retained for as long as your account or license remains active (including to support plan renewals). Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request – this is a standard, legally-recognized exception to deletion rights, not a workaround, and applies specifically to financial/transaction records rather than personal information generally.

Licence Keys

A license key is required to validate your purchase and unlock benefits like automatic updates, developer support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.

Retention: License activation records are retained for as long as the license remains active, and for a reasonable period thereafter for support and renewal purposes.

Information About Your Website and Server Configuration

When you use our WordPress products, we may receive non-personal information about your website, including (but not limited to): whether SSL is installed, Curl/PHP/MySQL versions, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version. Learn more here.

We collect this non-personal information to develop better, more compatible software and serve our customers more effectively.

Using CartFlows On Your Own Website

When you run CartFlows on a store of your own, you decide what your funnels, checkout and abandoned-cart messages collect, and you are responsible for the privacy policy shown to your shoppers. This section sets out what the plugin does with your shoppers’ data, so that you can describe it accurately in your own policy.

Your shoppers’ data does not reach us. Everything in the abandoned-cart path stays on your own server:

  • An email address entered before checkout is completed is saved directly to your own WordPress database, into the CartFlows cart-abandonment tables alongside the message templates, send history and tracking records. It is not sent to us.
  • Recovery emails are sent by your own site, through your own mail stack or SMTP provider.
  • Open and click tracking runs on your own domain, not on ours.
  • Delivery status callbacks from your SMS provider come back to an endpoint on your own site.

Two message gateways, both using your own credentials, both contacted directly by your server rather than by us:

  • SMS is sent to Twilio, authenticated with your own Twilio Account SID and Auth Token.
  • WhatsApp is sent to Meta, through the WhatsApp Business Cloud API on the Meta Graph API — not through Twilio — authenticated with your own Meta access token. This means Meta receives the phone number and message content of any shopper you send a WhatsApp recovery message to.

Your gateway credentials are encrypted in your own site’s options table using your site’s own WordPress security keys and salts. We cannot decrypt them, including when helping you with a support ticket.

If you connect a webhook or automation, you are choosing where the data goes. The abandoned-cart webhook trigger sends the full shopper record — name, phone number, billing and shipping addresses, email address, the products in the cart, the cart total and the checkout URL — to whatever URL you configure. We do not see that destination’s contents, and the controller obligations for that transfer are yours.

What does reach us is about you as our customer, not about your shoppers:

  • Usage counts about which features are in use, only if you opted in to usage tracking. No shopper records are included.
  • Your name and email from the onboarding wizard, as described in the section above, and any survey response you choose to give.
  • A licence check to my.cartflows.com carrying your licence key, your site domain and the plugin version. This one is required to validate a Pro licence and cannot be switched off.
  • Content requests to cartflows.com to fetch product notices and documentation for display in your dashboard, and a script loaded from app.suretriggers.com to render part of the plugin’s admin screens.

Who We Share Your Data With

Some of our advertising and analytics tools involve sharing personal information with third parties for cross-context behavioral advertising, as that term is defined under California law – meaning those partners may use information about your activity on our sites to show you relevant ads elsewhere. This sharing only happens for the categories below, and only after you’ve provided consent through our cookie preference banner (or, where applicable, is subject to your California opt-out rights described in the California Privacy Rights section below).

The categories of third parties we work with, and what they receive, include:

CategoryService (domain detected)What they receivePurposeSale / Share / Service Provider
Tag managementGoogle Tag Manager (googletagmanager.com)IP address, browser and device information, page URLLoads and manages our other scripts and tags, and reads your consent status to decide which may runService provider, not sold or shared
Server-side conversion forwardingMeta Conversions API Gateway (mpc2-prod-26-is5qnl632q-uc.a.run.app)Page and conversion events, IP address, browser informationReceives events from our Site and forwards them to Meta from our server rather than from your browser. Because this happens on our side, browser settings cannot control itShared for cross-context behavioral advertising
Server-side analytics identifiersGoogle, first-party (FPID and FPLC cookies)A visitor identifier set by our server rather than by Google’s scriptMeasure site usage where browser-set analytics cookies are unavailable or short-livedShared for cross-context behavioral advertising
Advertising and conversion measurementGoogle Ads and DoubleClick (googleads.g.doubleclick.net, doubleclick.net, pagead2.googlesyndication.com)Page views, device and browser identifiers, cookiesAd performance measurement, remarketing, targeted advertisingShared for cross-context behavioral advertising
Advertising and conversion measurementMeta Pixel (connect.facebook.net, facebook.com)Page views, device and browser identifiers, cookies, and only where you have consented, hashed contact information via Meta’s Advanced MatchingAd performance measurement, remarketing, targeted advertisingShared for cross-context behavioral advertising
Website analyticsGoogle Analytics 4 (google-analytics.com, region1.google-analytics.com)Page views, device and browser identifiers, cookiesUnderstand site usage. GA4 data may also build Google Ads audiences via Ads LinkingShared for cross-context behavioral advertising
Session analyticsMicrosoft Clarity (clarity.ms, scripts.clarity.ms, p.clarity.ms, bing.com)Session interactions — clicks, scrolling, mouse movement — and page URLsSession replay and heatmaps, to find usability problemsService provider, not sold or shared
On-site experimentationSigmize (api.sigmize.com)Browsing behavior, page interactions, assigned test variantA/B testing to improve user experience and site designService provider, not sold or shared
SEO and backlink analyticsAhrefs (analytics.ahrefs.com)Page views, referrer, device informationMeasure organic search performanceService provider, not sold or shared
AI chat and documentationPowerful Docs (app.powerfuldocs.com)Chat messages, and name and email if provided during the conversationAI-powered documentation and chat assistance. Loads after you provide consentService provider, not sold or shared
Video embedsYouTube (youtube.com, youtube-nocookie.com, youtu.be) and Wistia (fast.wistia.net)Page views, device and browser identifiers, standard platform cookiesDisplay embedded video content. Loads after you provide consentShared; loads after consent
Bot protectionGoogle reCAPTCHA (google.com, gstatic.com)Device and browser signals, and how you interact with the pagePrevent spam and automated abuse on our formsService provider, not sold or shared
Payments and checkoutStripe (js.stripe.com) and PayPal (paypal.com), on my.cartflows.comBilling and payment details, IP addressTake and process payments and manage your licenceService provider, not sold or shared
Account sign-inGoogle Sign-In (accounts.google.com)Email address, Google account identifierLet you sign in to your account with a Google accountService provider, not sold or shared
Content delivery and securityCloudflare, and script libraries from cdnjs.cloudflare.com and apis.google.comIP address, request metadataSite performance, security, and loading shared JavaScript librariesService provider, not sold or shared
Order attributionSourcebuster, first-party on my.cartflows.comReferring site, campaign parameters, session entry page, session count, browser user agentAttribute an order to the campaign that produced itService provider, not sold or shared
Site statisticsJetpack / WordPress.com (stats.wp.com)Page views, IP address, request metadataSite statistics on my.cartflows.comService provider, not sold or shared
WordPress core servicesWordPress.org (s.w.org)Basic request metadataCore WordPress functionality such as emoji support and update checksService provider, not sold or shared
Email deliveryAmazon SESEmail addressTransactional and marketing email sent from our serversService provider, not sold or shared
Author avatarsAutomattic (secure.gravatar.com)Hashed email addressShow the author’s profile picture in the blog author boxService provider, not sold or shared
Affiliate attributionAffiliateWP, on my.cartflows.comReferral and click identifiersTrack and pay affiliate referrals on purchasesService provider, not sold or shared
Plugin onboardingwebhook.ottokit.com (Brainstorm Force)Your first name, last name and email address, if you complete the onboarding wizardSend the store email report you asked for, service messages about the plugin, and any NPS or deactivation survey you choose to answerService provider, not sold or shared
Plugin admin interfaceapp.suretriggers.com (Brainstorm Force)IP address, request metadataLoads a script that renders part of the plugin’s admin screens in your WordPress dashboardService provider, not sold or shared
Message delivery, from your storeTwilio (SMS) and Meta WhatsApp Business Cloud API (WhatsApp)A shopper’s phone number and the message contentOnly where you have configured abandoned-cart recovery on your own store. Your server contacts these providers directly, using your own credentials, and we are not in the pathNot our transfer — see Using CartFlows On Your Own Website
Legal and corporateCourts, regulators and authorities; and an acquirer in a merger or saleOnly what is requiredWhere the law requires disclosure, or where our business is acquired or merged and your information transfers to the new owner so we can continue to serve youNot sold or shared

How we classify these recipients: the last column reflects the written agreement and data-processing terms we have in place with each provider, and the way we have configured the service. It is our assessment rather than a guarantee about a provider’s own practices, and we review it when we add a provider or change a configuration.

On Meta’s Advanced Matching specifically: this feature, which lets Meta match hashed contact information to a Meta account for better ad targeting, is active only for visitors who have consented to marketing cookies.

How Long We Keep Your Data

We keep personal information only for as long as we need it for the purpose we collected it, or for as long as the law requires. In practice:

  • Cookie consent records: up to 365 days.
  • Support ticket records, including screenshots and logs: 3 years from the date the ticket is closed.
  • Purchase and licence records: for as long as you hold a licence with us, and afterwards for the period our tax and accounting obligations require.
  • Contact form submissions: for as long as needed to resolve your request and to keep a record of the correspondence.
  • Blog comments: for as long as the comment remains published.
  • Newsletter subscription: until you unsubscribe or withdraw consent.
  • Order-attribution and analytics cookie data: for the durations listed on our Cookie Policy page.
  • Data held by a provider named above — for example the IP address in a Stripe payment record — is retained by that provider under its own rules rather than ours.

You can ask us to delete your data sooner. See What Rights You Have Over Your Data below.

California Privacy Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to request a copy of it.
  • Right to delete personal information we have collected from you, subject to certain exceptions.
  • Right to correct inaccurate personal information we maintain about you.
  • Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this means opting out of the advertising and conversion-measurement tools — Meta Pixel, Google Ads, DoubleClick, Google Analytics, the server-side tagging container, and Meta-owned and YouTube embeds — that involve cross-context behavioral advertising. We do not treat the other recipients listed in this policy as sales or shares: each is engaged under a written agreement that limits their use of personal information to providing their service to us.
  • Right to limit the use and disclosure of sensitive personal information, where applicable.
  • Right to non-discrimination for exercising any of the above rights.

To opt out of the sale or sharing of your personal information, click on the Cookie Preferences button on the respective site’s footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request.

To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law, with a possible 45-day extension for complex requests, in which case we will notify you of the extension and the reason. You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify the agent’s authority.

Your Rights Under India’s Digital Personal Data Protection Act (DPDP)

If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:

  • Right to access a summary of the personal data we hold about you and how we process it.
  • Right to correction and erasure of your personal data.
  • Right to grievance redressal, as described below.
  • Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal.

We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.

Grievance Officer: Vrunda Kansara, [email protected]

If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the details above. We will acknowledge your grievance within 72 hours of receipt, including a reference number and expected resolution timeline. We aim to resolve most grievances within 30 days, and in all cases within 90 days, as required under the DPDP Rules, 2025.

How Secure Is My Information

We take reasonable precautions and follow industry best practices to protect your personal information from being inappropriately lost, misused, accessed, disclosed, altered, or destroyed.

Credit card information, when provided, is encrypted using secure socket layer (SSL) technology.

What Rights You Have Over Your Data

If you’d like to confirm what personal data we hold about you, modify it, understand the purpose of collection and processing, or stop data sharing/processing, contact us at [email protected].

You can also request information about the source of your personal data (if not provided directly by you) or how long it will be retained. You have the right to request deletion of data no longer needed for its original purpose, or to cease its processing. Please note that certain records – such as financial and transaction records – may be retained even after a deletion request, where retention is required by applicable tax, accounting, or audit obligations, consistent with the recognized legal exceptions to the right of deletion. You can request we stop using your data for direct marketing purposes, and you may withdraw consent at any time by clicking “unsubscribe” in our emails.

Legal basis for processing (EEA/UK visitors): Depending on the purpose, we process your data based on: your consent (e.g., non-essential cookies, marketing communications), the necessity of processing to perform our contract with you (e.g., fulfilling a purchase), our legitimate interests (e.g., improving our services, fraud prevention), or compliance with a legal obligation.

If you believe we haven’t complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority. Within technical limits, we will provide your personal data to you or your data protection authority upon request.

If we can’t provide requested data within a reasonable timeframe, we will let you know when it will be available; if we deny a request, we will explain why.

Children’s Online Privacy Protection Act Compliance

We do not knowingly collect personal information from children under the age of 13. If we determine we’ve collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.

Third-Party Links

We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.

Affiliate Disclosure

Some third-party links on our Site may be affiliate links. We earn a referral fee when you buy services from companies we recommend. We only recommend products we believe add value to our customers.

Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.

Remarketing and Targeted Advertising

We work with third parties – including Google Analytics, Google Ads, Meta (Facebook and Instagram), TikTok, Snapchat, and Microsoft Clarity – to provide targeted advertisements or marketing communications that may interest you, based on your browsing activity on our sites. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.

You can opt out of targeted advertising through:

Or by clicking on the Cookie Preferences button on the respective site’s footer, which applies across all the advertising partners listed in this policy.

Newsletter Emails

By becoming a site user, member, or customer, you acknowledge and agree to be signed up for our newsletter. From time to time, we may contact you about product announcements, software updates, and special offers. You may opt out at any time via the “unsubscribe” link in our emails. We will only send marketing communications to users located in the EEA with their prior consent.

Will This Privacy Policy Ever Change

We may update this Policy to keep pace with changes in our Site, Software, Services, business, and applicable laws. We will always maintain our commitment to respecting your privacy. Continued use of our Site, software, and services after a policy change means you agree to the updated policy.

Contact Us

For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:

Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States

Last updated: 25 August 2026

Try CartFlows Suite Risk-Free for 14 Days

You are protected by our no questions asked refund policy.