Legal
Privacy Statement
Last Updated: February 16, 2026 · Effective Date: February 9, 2026
Carpe Inventory IQ (“we,” “us,” or “our”) is operated by Carpe Per Diem, Inc. We are committed to protecting your privacy and being transparent about how we handle your data. This Privacy Statement explains how we collect, use, store, and protect information when you use our multi-channel inventory management platform (“Service”).
By using Carpe Inventory IQ, you agree to the collection and use of information in accordance with this statement. If you do not agree, please do not use our Service.
1. Information We Collect
A. Account and Contact Information
- Business name and store domain
- Email address (for account access and notifications)
- Shopify store owner information (as provided by Shopify)
B. Product and Inventory Data
- Product names, SKUs, and descriptions
- Product variants and attributes
- Inventory quantities and locations
- Product costs and pricing information
- Supplier information
- Bill of Materials (BOM) data
- Purchase order information
C. Sales and Order Data
- Order numbers and line item details
- Order dates and fulfillment status
- Sales quantities (for velocity calculations)
- Marketplace order identifiers (Shopify, Amazon, Walmart)
D. Technical and Usage Data
- IP addresses and browser information
- Device type and operating system
- Pages visited and features used
- Timestamps of actions
- Error logs and performance data
E. Authentication Data
- Shopify OAuth access tokens
- Amazon SP-API credentials
- Walmart API credentials
- Session identifiers
Information We Do NOT Collect:
- Customer personal information (names, addresses, phone numbers)
- Customer payment information (credit cards, bank accounts)
- Customer browsing history or shopping behavior
- Social Security numbers or tax IDs
- Health or biometric data
Important: We do not collect, store, or process your customers’ personal information.
While our app requires access to order data to track inventory movements (which SKUs sold, in what quantities, and on which channel), we only extract the product and quantity information needed for inventory calculations. We do not read, store, or retain customer names, email addresses, phone numbers, shipping addresses, or any other personally identifiable information from your orders. Your customers’ personal data never enters our system.
2. How We Collect Information
A. Direct Collection
- Information you provide when creating an account
- Data entered into forms (SKUs, suppliers, purchase orders)
- Settings and preferences you configure
B. Automated Collection via Marketplace APIs
- Shopify: Product data, inventory levels, and order information via Shopify Admin API
- Amazon: Product listings, inventory, and order information via Amazon Seller Partner API
- Walmart: Product listings, inventory, and order information via Walmart Marketplace API
C. Technical Collection
- Server logs generated during your use of the Service
- Session cookies for authentication (essential functionality only)
- No advertising or tracking cookies
3. How We Use Your Information
A. Service Delivery
- Provide inventory management functionality
- Sync inventory levels across Shopify, Amazon, and Walmart
- Generate purchase order recommendations
- Calculate product velocity and demand forecasting
- Manage Bill of Materials (BOM) and manufacturing workflows
- Track inventory movements and adjustments
B. Account Management
- Create and maintain your account
- Authenticate users and maintain security
- Process payments and manage subscriptions
C. Service Improvement
- Analyze usage patterns to improve features
- Diagnose and fix technical issues
- Develop new features based on user needs
D. Communication
- Respond to support requests
- Provide important updates about the Service
- Send security alerts
E. Legal Compliance
- Comply with legal obligations
- Enforce our Terms of Service
- Protect against fraud and abuse
- Respond to law enforcement requests
Legal Basis for Processing (GDPR):
- Contractual Necessity: Processing is necessary to perform our contract with you
- Legitimate Interest: We have a legitimate interest in improving and securing our Service
- Consent: Where required, we obtain your explicit consent
- Legal Obligation: We process data to comply with applicable laws
4. Data Storage and Security
A. Data Location
Your data is stored in secure databases located in the United States, maintained in SOC 2-compliant data centers. To ensure fast, reliable access worldwide, the Service is delivered through a global content delivery network (CDN) that caches static assets and application code at edge locations closer to you. The CDN does not store your merchant business data — all persistent data, including inventory records, order data, and account information, resides in our US-based infrastructure.
A current list of subprocessors is available upon request at privacy@carpeinventory.com.
B. Security Measures
- Encryption in Transit: All data transmitted using TLS/HTTPS encryption
- Encryption at Rest: Database encryption for stored data
- Access Controls: Role-based access control (RBAC) and authentication
- API Security: HMAC signature verification for all marketplace webhooks
- Regular Security Updates: Continuous monitoring and patching
- Secure Token Storage: OAuth tokens encrypted and securely stored
C. Data Isolation
- Multi-tenant architecture with strict data separation
- Each merchant’s data is isolated and accessible only to authorized users
- No data sharing between merchant accounts
D. Security Limitations and Breach Notification
While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security. In the event of a data breach that affects your information:
- We will notify affected merchants by email within 72 hours of confirming the breach
- We will notify the relevant supervisory authorities where required by applicable law (e.g., GDPR, state breach notification statutes)
- Our notification will include the nature of the breach, the categories of data affected, and the steps we are taking in response
5. Data Retention and Deletion
A. Active Accounts
We retain your data for as long as your account is active and you continue using our Service.
B. Account Deletion
When you uninstall our app or delete your account:
- Immediate Action: Your account is deactivated and API access tokens are revoked
- Grace Period: Your data is preserved for 30 days in case you reinstall
- Data Deletion: All merchant data is permanently deleted after 30 days
- What is Deleted: All SKUs, inventory records, BOMs, purchase orders, locations, suppliers, and associated data
- No Recovery: Once deleted, data cannot be recovered
C. Legal Retention
We may retain certain data longer if required by law, including:
- Financial records (for tax compliance)
- Audit logs (for security and fraud prevention)
- Aggregated, anonymized analytics (no personal identification)
D. Backup Retention
Data in automated backups is deleted within 30 days following account deletion.
7. Marketplace-Specific Data Handling
A. Shopify Data
- We access data via official Shopify Admin API
- OAuth tokens are stored securely and never shared
- We comply with Shopify’s API Terms of Service and Partner Program Agreement
- Our app requests the
read_ordersscope to track which products sold and in what quantities for inventory calculations. We extract only SKU identifiers, quantities, and order reference numbers from order data. We do not read, store, or process any customer personal information (names, emails, addresses, phone numbers) contained in order records. - Mandatory GDPR webhooks implemented:
- customers/data_request
- customers/redact
- shop/redact
B. Amazon Seller Partner API
- We access data via Amazon SP-API under the Selling Partner Agreement
- We comply with Amazon’s Data Protection Policy (DPP)
- Data usage is limited to providing inventory management services as described in this statement
- We do not store Amazon customer personal information
- Credentials are encrypted and rotated per Amazon’s requirements
C. Walmart Marketplace API
- We access data via Walmart Marketplace API
- We comply with Walmart’s Marketplace Developer Agreement and API Terms of Use
- Inventory and order synchronization (no customer personal data access)
- Secure credential storage and transmission
8. Your Privacy Rights
A. GDPR Rights (European Economic Area)
If you are located in the EEA, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (“right to be forgotten”)
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Withdraw consent at any time where consent is the basis for processing
B. CCPA Rights (California)
California residents have the following rights:
- Right to Know: Request information about data collected, used, and shared
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of sale of personal information (we do not sell data)
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising rights
C. PIPEDA Rights (Canada)
Canadian users have rights to:
- Access personal information
- Correct inaccuracies
- Withdraw consent
- File complaints with the Privacy Commissioner
D. How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@carpeinventory.com
- Subject Line: “Privacy Rights Request”
- Required Information: Your name, email, and Shopify store domain
We will respond to requests within 30 days (or as required by applicable law).
9. International Data Transfers
Our Service is operated from the United States. If you are located outside the United States, your information will be transferred to and processed in the United States.
A. Data Transfer Mechanisms
- We comply with applicable data protection laws for international transfers
- We implement appropriate safeguards including encryption and security measures
- We rely on Standard Contractual Clauses (SCCs) where applicable
B. EU-US Data Transfers
For transfers from the EEA to the US, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Supplementary security measures to protect data
By using our Service, you consent to the transfer of your information to the United States and other countries where we or our service providers operate.
10. Children's Privacy
Our Service is designed for business use and is not intended for children under 18. We do not knowingly collect personal information from children under 18.
If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information immediately.
If you believe we have collected information from a child under 18, please contact us at privacy@carpeinventory.com.
12. Third-Party Services
Our Service integrates with the following third-party platforms:
A. Shopify
- Privacy Policy: shopify.com/legal/privacy
- Purpose: E-commerce platform integration
- Data Shared: Product and inventory data
B. Amazon Seller Central
- Privacy Policy: amazon.com/privacy
- Purpose: Marketplace inventory and order synchronization
- Data Shared: Product listings, inventory levels, and order data
C. Walmart Seller Center
- Privacy Policy: corporate.walmart.com/privacy-security
- Purpose: Marketplace inventory and order synchronization
- Data Shared: Product listings, inventory levels, and order data
We also use trusted third-party service providers for infrastructure, communications, and system operations. These providers process data solely on our instructions and are contractually bound to maintain confidentiality. A current list of subprocessors is available upon request at privacy@carpeinventory.com.
We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies.
13. Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in our practices or legal requirements.
A. Notification of Changes
- Minor Changes: Updated “Last Updated” date at the top of this statement
- Material Changes: Email notification to registered users at least 30 days before changes take effect
B. Your Acceptance
Continued use of the Service after changes become effective constitutes acceptance of the revised statement.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Statement or our data practices, please contact us:
Carpe Inventory IQ
Mailing Address:
Carpe Per Diem, Inc.
365 W 125th St, UNIT 2666
New York, NY 10027
United States
For GDPR Requests: Email privacy@carpeinventory.com with “GDPR Request” in the subject line.
For CCPA Requests: Email privacy@carpeinventory.com with “CCPA Request” in the subject line.
We will respond to all requests within 30 days or as required by applicable law.