Privacy Policy
Please read the terms of our privacy policy below.
This Privacy Policy describes how your personal information is collected, used, and shared.
It applies to cartflows.com, to our store and checkout at my.cartflows.com, and to translate.cartflows.com and ideas.cartflows.com (together, the “Site”). CartFlows is a suite of WooCommerce plugins — CartFlows Funnel Builder, Modern Cart, Cart Abandonment Recovery, Power Coupons and Variation Swatches. When one of our plugins runs on a store you operate, you decide what your own forms and checkout collect and you are responsible for the privacy policy shown to your customers. The points where our own services sit in the data path on a store you run are described under Using CartFlows On Your Own Website below.
Who We Are
We are Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States.
Email: [email protected]
What Personal Information We Collect
When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.
Cookies and Similar Technologies
Cookies are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies — including pixels, tags, local storage and session-recording tools — across our Site in four categories:
- Essential — required for core site functionality, including security, load balancing, keeping the contents of your cart and remembering your cookie choice.
- Functional — remember your preferences and settings, and which variant of a page you were shown.
- Analytics — help us understand how visitors use our Site, including session replay and heatmaps, and test improvements to site design.
- Marketing — used for advertising measurement, remarketing and targeted advertising.
Non-essential cookies and technologies (Functional, Analytics and Marketing) are set only after you provide consent through our cookie preference banner. You can change your preferences at any time by clicking Cookie Preferences in the footer, and withdrawing consent is as easy as giving it.
A list of the cookies and tracking technologies our scanner detects on this Site, with the provider, purpose, duration and domain for each, is on our Cookie Policy page, which is linked from the footer and from the cookie preference banner. A scanner sees what loads on the pages it visits, so a technology that appears only on a page it has not yet scanned may not be listed straight away.
We honor the Global Privacy Control (GPC) signal where required by law. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information.
Retention: records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.
Comments
Where a post on our blog accepts comments, we collect the data shown in the comment form, along with your IP address and browser user-agent string, to help with spam detection.
An anonymized string created from your email address (a hash) may be shared with the Gravatar service to check whether you use it, and Gravatar also supplies the author’s picture in the author box on each post.
Contact Forms
Information submitted through contact forms on our Site is sent to our self-hosted support desk.
We may collect information submitted through contact forms, including (but not limited to) your first and last name and email address. This information may be shared with our email marketing services, including our self-hosted CRM.
Support
To help with our products, we may ask for temporary access to your website — either your live site or a staging copy, whichever you prefer — such as an admin login or FTP or database credentials. Troubleshooting typically takes place directly on your site, and in those cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this is not always feasible.
In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Once the issue is resolved, we delete these copies from our systems.
Information submitted through support forms is managed through our self-hosted support portal.
A few important points about access shared with our support team:
- We use any access you provide strictly for debugging your specific issue, on your site itself.
- We do not copy or retain your site’s data on our own systems.
- We do not share access or data with anyone outside the company.
- We cannot be held responsible for loss of private information from your database or website. If you’re able to share a staging site and keep a working backup of anything shared with us, we recommend doing so.
Retention: Where troubleshooting happens on your site directly rather than on data transferred to us, there is no site-data copy for us to retain, and you are responsible for rotating or revoking any login, FTP, or database credentials you shared with us once your issue is resolved – we have no further use for them once the support ticket closes. Where we’ve created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved.
We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed. We do this so we can refer back to how a past issue was resolved if it recurs, and to analyze recurring issues internally to improve our products and reduce future support volume. Support ticket records are not shared with any third party – they remain strictly between you and us.
If your site contains your own customers’ or visitors’ personal data (for example, order or form submissions) that we may view while troubleshooting on your site, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose – you remain responsible for your own compliance obligations toward your site’s visitors and customers.
Purchase
If you purchase products or services from us, our payment gateway provider may require your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.
All direct payment gateways adhere to PCI-DSS standards, managed by the PCI Security Standards Council (a joint effort of Visa, MasterCard, American Express, and Discover), which help ensure secure handling of card information.
When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, shipping address, payment information, email address, and phone number.
Retention: Billing and transaction records are retained for as long as your account or license remains active (including to support plan renewals). Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request – this is a standard, legally-recognized exception to deletion rights, not a workaround, and applies specifically to financial/transaction records rather than personal information generally.
Licence Keys
A license key is required to validate your purchase and unlock benefits like automatic updates, developer support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.
Retention: License activation records are retained for as long as the license remains active, and for a reasonable period thereafter for support and renewal purposes.
Information About Your Website and Server Configuration
When you use our WordPress products, we may receive non-personal information about your website, including (but not limited to): whether SSL is installed, Curl/PHP/MySQL versions, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version. Learn more here.
We collect this non-personal information to develop better, more compatible software and serve our customers more effectively.
Using CartFlows On Your Own Website
When you run CartFlows on a store of your own, you decide what your funnels, checkout and abandoned-cart messages collect, and you are responsible for the privacy policy shown to your shoppers. This section sets out what the plugin does with your shoppers’ data, so that you can describe it accurately in your own policy.
Your shoppers’ data does not reach us. Everything in the abandoned-cart path stays on your own server:
- An email address entered before checkout is completed is saved directly to your own WordPress database, into the CartFlows cart-abandonment tables alongside the message templates, send history and tracking records. It is not sent to us.
- Recovery emails are sent by your own site, through your own mail stack or SMTP provider.
- Open and click tracking runs on your own domain, not on ours.
- Delivery status callbacks from your SMS provider come back to an endpoint on your own site.
Two message gateways, both using your own credentials, both contacted directly by your server rather than by us:
- SMS is sent to Twilio, authenticated with your own Twilio Account SID and Auth Token.
- WhatsApp is sent to Meta, through the WhatsApp Business Cloud API on the Meta Graph API — not through Twilio — authenticated with your own Meta access token. This means Meta receives the phone number and message content of any shopper you send a WhatsApp recovery message to.
Your gateway credentials are encrypted in your own site’s options table using your site’s own WordPress security keys and salts. We cannot decrypt them, including when helping you with a support ticket.
If you connect a webhook or automation, you are choosing where the data goes. The abandoned-cart webhook trigger sends the full shopper record — name, phone number, billing and shipping addresses, email address, the products in the cart, the cart total and the checkout URL — to whatever URL you configure. We do not see that destination’s contents, and the controller obligations for that transfer are yours.
What does reach us is about you as our customer, not about your shoppers:
- Usage counts about which features are in use, only if you opted in to usage tracking. No shopper records are included.
- Your name and email from the onboarding wizard, as described in the section above, and any survey response you choose to give.
- A licence check to my.cartflows.com carrying your licence key, your site domain and the plugin version. This one is required to validate a Pro licence and cannot be switched off.
- Content requests to cartflows.com to fetch product notices and documentation for display in your dashboard, and a script loaded from app.suretriggers.com to render part of the plugin’s admin screens.
Who We Share Your Data With
Some of our advertising and analytics tools involve sharing personal information with third parties for cross-context behavioral advertising, as that term is defined under California law – meaning those partners may use information about your activity on our sites to show you relevant ads elsewhere. This sharing only happens for the categories below, and only after you’ve provided consent through our cookie preference banner (or, where applicable, is subject to your California opt-out rights described in the California Privacy Rights section below).
The categories of third parties we work with, and what they receive, include:
| Category | Service (domain detected) | What they receive | Purpose | Sale / Share / Service Provider |
|---|---|---|---|---|
| Tag management | Google Tag Manager (googletagmanager.com) | IP address, browser and device information, page URL | Loads and manages our other scripts and tags, and reads your consent status to decide which may run | Service provider, not sold or shared |
| Server-side conversion forwarding | Meta Conversions API Gateway (mpc2-prod-26-is5qnl632q-uc.a.run.app) | Page and conversion events, IP address, browser information | Receives events from our Site and forwards them to Meta from our server rather than from your browser. Because this happens on our side, browser settings cannot control it | Shared for cross-context behavioral advertising |
| Server-side analytics identifiers | Google, first-party (FPID and FPLC cookies) | A visitor identifier set by our server rather than by Google’s script | Measure site usage where browser-set analytics cookies are unavailable or short-lived | Shared for cross-context behavioral advertising |
| Advertising and conversion measurement | Google Ads and DoubleClick (googleads.g.doubleclick.net, doubleclick.net, pagead2.googlesyndication.com) | Page views, device and browser identifiers, cookies | Ad performance measurement, remarketing, targeted advertising | Shared for cross-context behavioral advertising |
| Advertising and conversion measurement | Meta Pixel (connect.facebook.net, facebook.com) | Page views, device and browser identifiers, cookies, and only where you have consented, hashed contact information via Meta’s Advanced Matching | Ad performance measurement, remarketing, targeted advertising | Shared for cross-context behavioral advertising |
| Website analytics | Google Analytics 4 (google-analytics.com, region1.google-analytics.com) | Page views, device and browser identifiers, cookies | Understand site usage. GA4 data may also build Google Ads audiences via Ads Linking | Shared for cross-context behavioral advertising |
| Session analytics | Microsoft Clarity (clarity.ms, scripts.clarity.ms, p.clarity.ms, bing.com) | Session interactions — clicks, scrolling, mouse movement — and page URLs | Session replay and heatmaps, to find usability problems | Service provider, not sold or shared |
| On-site experimentation | Sigmize (api.sigmize.com) | Browsing behavior, page interactions, assigned test variant | A/B testing to improve user experience and site design | Service provider, not sold or shared |
| SEO and backlink analytics | Ahrefs (analytics.ahrefs.com) | Page views, referrer, device information | Measure organic search performance | Service provider, not sold or shared |
| AI chat and documentation | Powerful Docs (app.powerfuldocs.com) | Chat messages, and name and email if provided during the conversation | AI-powered documentation and chat assistance. Loads after you provide consent | Service provider, not sold or shared |
| Video embeds | YouTube (youtube.com, youtube-nocookie.com, youtu.be) and Wistia (fast.wistia.net) | Page views, device and browser identifiers, standard platform cookies | Display embedded video content. Loads after you provide consent | Shared; loads after consent |
| Bot protection | Google reCAPTCHA (google.com, gstatic.com) | Device and browser signals, and how you interact with the page | Prevent spam and automated abuse on our forms | Service provider, not sold or shared |
| Payments and checkout | Stripe (js.stripe.com) and PayPal (paypal.com), on my.cartflows.com | Billing and payment details, IP address | Take and process payments and manage your licence | Service provider, not sold or shared |
| Account sign-in | Google Sign-In (accounts.google.com) | Email address, Google account identifier | Let you sign in to your account with a Google account | Service provider, not sold or shared |
| Content delivery and security | Cloudflare, and script libraries from cdnjs.cloudflare.com and apis.google.com | IP address, request metadata | Site performance, security, and loading shared JavaScript libraries | Service provider, not sold or shared |
| Order attribution | Sourcebuster, first-party on my.cartflows.com | Referring site, campaign parameters, session entry page, session count, browser user agent | Attribute an order to the campaign that produced it | Service provider, not sold or shared |
| Site statistics | Jetpack / WordPress.com (stats.wp.com) | Page views, IP address, request metadata | Site statistics on my.cartflows.com | Service provider, not sold or shared |
| WordPress core services | WordPress.org (s.w.org) | Basic request metadata | Core WordPress functionality such as emoji support and update checks | Service provider, not sold or shared |
| Email delivery | Amazon SES | Email address | Transactional and marketing email sent from our servers | Service provider, not sold or shared |
| Author avatars | Automattic (secure.gravatar.com) | Hashed email address | Show the author’s profile picture in the blog author box | Service provider, not sold or shared |
| Affiliate attribution | AffiliateWP, on my.cartflows.com | Referral and click identifiers | Track and pay affiliate referrals on purchases | Service provider, not sold or shared |
| Plugin onboarding | webhook.ottokit.com (Brainstorm Force) | Your first name, last name and email address, if you complete the onboarding wizard | Send the store email report you asked for, service messages about the plugin, and any NPS or deactivation survey you choose to answer | Service provider, not sold or shared |
| Plugin admin interface | app.suretriggers.com (Brainstorm Force) | IP address, request metadata | Loads a script that renders part of the plugin’s admin screens in your WordPress dashboard | Service provider, not sold or shared |
| Message delivery, from your store | Twilio (SMS) and Meta WhatsApp Business Cloud API (WhatsApp) | A shopper’s phone number and the message content | Only where you have configured abandoned-cart recovery on your own store. Your server contacts these providers directly, using your own credentials, and we are not in the path | Not our transfer — see Using CartFlows On Your Own Website |
| Legal and corporate | Courts, regulators and authorities; and an acquirer in a merger or sale | Only what is required | Where the law requires disclosure, or where our business is acquired or merged and your information transfers to the new owner so we can continue to serve you | Not sold or shared |
How we classify these recipients: the last column reflects the written agreement and data-processing terms we have in place with each provider, and the way we have configured the service. It is our assessment rather than a guarantee about a provider’s own practices, and we review it when we add a provider or change a configuration.
On Meta’s Advanced Matching specifically: this feature, which lets Meta match hashed contact information to a Meta account for better ad targeting, is active only for visitors who have consented to marketing cookies.
How Long We Keep Your Data
We keep personal information only for as long as we need it for the purpose we collected it, or for as long as the law requires. In practice:
- Cookie consent records: up to 365 days.
- Support ticket records, including screenshots and logs: 3 years from the date the ticket is closed.
- Purchase and licence records: for as long as you hold a licence with us, and afterwards for the period our tax and accounting obligations require.
- Contact form submissions: for as long as needed to resolve your request and to keep a record of the correspondence.
- Blog comments: for as long as the comment remains published.
- Newsletter subscription: until you unsubscribe or withdraw consent.
- Order-attribution and analytics cookie data: for the durations listed on our Cookie Policy page.
- Data held by a provider named above — for example the IP address in a Stripe payment record — is retained by that provider under its own rules rather than ours.
You can ask us to delete your data sooner. See What Rights You Have Over Your Data below.
California Privacy Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to request a copy of it.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information we maintain about you.
- Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this means opting out of the advertising and conversion-measurement tools — Meta Pixel, Google Ads, DoubleClick, Google Analytics, the server-side tagging container, and Meta-owned and YouTube embeds — that involve cross-context behavioral advertising. We do not treat the other recipients listed in this policy as sales or shares: each is engaged under a written agreement that limits their use of personal information to providing their service to us.
- Right to limit the use and disclosure of sensitive personal information, where applicable.
- Right to non-discrimination for exercising any of the above rights.
To opt out of the sale or sharing of your personal information, click on the Cookie Preferences button on the respective site’s footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request.
To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law, with a possible 45-day extension for complex requests, in which case we will notify you of the extension and the reason. You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify the agent’s authority.
Your Rights Under India’s Digital Personal Data Protection Act (DPDP)
If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:
- Right to access a summary of the personal data we hold about you and how we process it.
- Right to correction and erasure of your personal data.
- Right to grievance redressal, as described below.
- Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal.
We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.
Grievance Officer: Vrunda Kansara, [email protected]
If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the details above. We will acknowledge your grievance within 72 hours of receipt, including a reference number and expected resolution timeline. We aim to resolve most grievances within 30 days, and in all cases within 90 days, as required under the DPDP Rules, 2025.
How Secure Is My Information
We take reasonable precautions and follow industry best practices to protect your personal information from being inappropriately lost, misused, accessed, disclosed, altered, or destroyed.
Credit card information, when provided, is encrypted using secure socket layer (SSL) technology.
What Rights You Have Over Your Data
If you’d like to confirm what personal data we hold about you, modify it, understand the purpose of collection and processing, or stop data sharing/processing, contact us at [email protected].
You can also request information about the source of your personal data (if not provided directly by you) or how long it will be retained. You have the right to request deletion of data no longer needed for its original purpose, or to cease its processing. Please note that certain records – such as financial and transaction records – may be retained even after a deletion request, where retention is required by applicable tax, accounting, or audit obligations, consistent with the recognized legal exceptions to the right of deletion. You can request we stop using your data for direct marketing purposes, and you may withdraw consent at any time by clicking “unsubscribe” in our emails.
Legal basis for processing (EEA/UK visitors): Depending on the purpose, we process your data based on: your consent (e.g., non-essential cookies, marketing communications), the necessity of processing to perform our contract with you (e.g., fulfilling a purchase), our legitimate interests (e.g., improving our services, fraud prevention), or compliance with a legal obligation.
If you believe we haven’t complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority. Within technical limits, we will provide your personal data to you or your data protection authority upon request.
If we can’t provide requested data within a reasonable timeframe, we will let you know when it will be available; if we deny a request, we will explain why.
Children’s Online Privacy Protection Act Compliance
We do not knowingly collect personal information from children under the age of 13. If we determine we’ve collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.
Third-Party Links
We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.
Affiliate Disclosure
Some third-party links on our Site may be affiliate links. We earn a referral fee when you buy services from companies we recommend. We only recommend products we believe add value to our customers.
Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.
Remarketing and Targeted Advertising
We work with third parties – including Google Analytics, Google Ads, Meta (Facebook and Instagram), TikTok, Snapchat, and Microsoft Clarity – to provide targeted advertisements or marketing communications that may interest you, based on your browsing activity on our sites. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.
You can opt out of targeted advertising through:
Or by clicking on the Cookie Preferences button on the respective site’s footer, which applies across all the advertising partners listed in this policy.
Newsletter Emails
By becoming a site user, member, or customer, you acknowledge and agree to be signed up for our newsletter. From time to time, we may contact you about product announcements, software updates, and special offers. You may opt out at any time via the “unsubscribe” link in our emails. We will only send marketing communications to users located in the EEA with their prior consent.
Will This Privacy Policy Ever Change
We may update this Policy to keep pace with changes in our Site, Software, Services, business, and applicable laws. We will always maintain our commitment to respecting your privacy. Continued use of our Site, software, and services after a policy change means you agree to the updated policy.
Contact Us
For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:
Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States
Last updated: 25 August 2026