Privacy Policy
This policy explains how ClaimCart handles merchant, Instagram, buyer, and order information.
Effective September 5, 2026
Information we collect
ClaimCart receives account details supplied by merchants, including name and email address. Pre-registration also collects an Instagram username, account type, store category, approximate order volume, optional application notes, and acceptance of the beta terms so we can assess eligibility and manage the onboarding queue. When a merchant connects Instagram, we may receive the professional account username, account identifier, merchant-selected or published media, captions, product mappings, comments containing configured claim keywords, and identifiers needed to send permitted private replies.
Merchants may store products, variants, stock, regular and sale prices, promo-code rules, delivery settings, payment instructions, refund policies, refund windows, and buyer-facing refund reasons. When a buyer uses checkout, we collect name, email, phone number, shipping address, selected products and quantities, promotional code used, consent choice, order and payment-proof records, shipping updates, and technical information required to protect the signed checkout session. A buyer refund request can contain its selected reason, note, status, seller response, policy snapshot, and timestamps.
ClaimCart software billing is handled by Paddle. ClaimCart receives transaction and entitlement details needed to activate and support plan access but not full card numbers. Seller-product payment information is handled according to the method displayed by the merchant; uploaded payment proof is stored for merchant review.
How we use information
We use information to publish or connect Instagram posts, detect eligible claim comments, reserve inventory, calculate sale prices, validate promo codes, provide checkout, create and fulfill orders, display policies, route refund requests, preserve auditable status history, prevent duplicate events, provide analytics, secure the service, and provide support. We do not sell personal information.
Sharing and service providers
Information is shared only as needed with infrastructure providers that host ClaimCart, Paddle for ClaimCart billing, Meta and Instagram for connected features, payment services selected by a merchant, and the merchant responsible for the buyer's order. Buyer contact details and refund requests are visible to that merchant for order support. Marketing consent is stored separately; order-related contact does not itself authorize marketing. Merchants are independently responsible for customer communications, fulfillment, legal notices, refund decisions, and buyer payment providers.
Cookies and local storage
We use an essential HTTP-only session cookie for merchant login, short-lived session storage for dashboard caches, and local storage for interface preferences and same-browser update signals. Studio uses IndexedDB for drafts, source media, edits, captions, product selections, and a reusable image/logo, including demo drafts. These stay on this browser/device, may remain after sign-out, and do not sync. Clear ClaimCart site data to remove them. First-party traffic measurement records page paths, referral origins, campaign labels, and a random session identifier; signed checkout tokens are excluded. Embedded YouTube content and external services have their own policies. See our Cookie Policy for details.
Studio media
Editing and draft storage happen in your browser. Publishing uploads prepared media to our infrastructure for Meta retrieval. Finalized media is readable by anyone holding its unguessable URL. Temporary publishing files become eligible for cleanup after 48 hours; daily cleanup and failures can delay removal. Payment-proof files remain private. Removing a draft or temporary upload does not remove a post already published on Instagram.
Retention and security
We retain information only while reasonably needed to operate the service, maintain order records, meet legal obligations, resolve disputes, and prevent abuse. We use access controls, encrypted transport, restricted server credentials, signed checkout links, and expiring reservations. No internet service can guarantee absolute security.
Your choices and rights
You may disconnect ClaimCart from Instagram through Instagram’s Apps and Websites settings. You may request access, correction, or deletion using the instructions on our Data Deletion page. Applicable privacy rights vary by location.
Children and international use
ClaimCart is intended for businesses and is not directed to children under 13. Information may be processed in countries other than the country where a user lives, subject to applicable safeguards.
Changes
We may update this policy as ClaimCart changes. The effective date above identifies the current version. Material changes will be communicated through the service when appropriate.
Contact
For privacy questions or requests, email contact@claimcart.store. Include the ClaimCart account email and connected Instagram username relevant to the request.