Back

Privacy policy

1. INTRODUCTION

1.1. This Privacy Policy describes how Carte.store ("Carte.store", "we", "us", or "our") collects, uses, and shares personal information in connection with the websites, applications, and services made available under the name Carte.store (the "Service"), including the storefront hosting service, file hosting and delivery infrastructure, and the merchant dashboard.

1.2. Carte.store is a hosting provider for webstores, as described in our Terms of Service. Payment processing for stores hosted on the Service is provided by the Whop Payments Network and its affiliated payment providers ("Whop"), a third-party payment service with its own privacy practices. Section 5 explains how data flows between the Service and Whop.

1.3. This Policy applies to three groups of people:

2. INFORMATION WE COLLECT

2.1. Merchant account information. When a Merchant account is created, we collect and store the Merchant's name, email address, profile image (if provided), and an account identifier from the system that provisioned the account. If a password is set for the account, we store it only in a securely hashed form; we never store plaintext passwords. We also store limited sign-in security metadata (such as failed sign-in attempt counts) to protect accounts.

2.2. Merchant content. We store the content Merchants upload to operate their webstore, including product files, product names and descriptions, prices, images, and store branding. Product files and images are stored with our infrastructure providers and served through a content delivery network.

2.3. Buyer order information received from Whop. We do not collect payment information from Buyers directly (see Section 5). After a purchase is processed by Whop, Whop transmits transaction records to us so that we can deliver the purchased files and provide the Merchant's order dashboard. These records may include: the Buyer's name, email address, username and user identifier on Whop, country, billing address, the product purchased, transaction amounts, taxes and fees, refund and dispute status, the payment method type, the card brand, and the last four digits of the payment card.

2.4. Delivery and download activity. To show Merchants whether a purchase was fulfilled, we record the delivery status of the purchase email (including a message identifier from our email provider), the number of times purchased files were downloaded, and the times of the first and most recent download.

2.5. Visitor analytics. Storefront visit counting is cookieless and privacy-preserving. When a Visitor loads a storefront, we compute a one-way, salted hash from the visit date, the store identifier, the Visitor's IP address, and browser user agent. Only this hash is stored. The raw IP address and user agent are processed in memory for the duration of the request and are never stored. Because the current date is part of the hash input, the hash changes every day and cannot be used to track a Visitor across days. The deduplication records themselves are automatically deleted after approximately two days; only aggregate counts (such as daily visitor totals) are retained.

2.6. Communications. If you contact us (for example at [email protected]), we collect the contents of your message and your contact details.

3. WHAT WE DO NOT COLLECT

3.1. We do not collect or store full payment card numbers, card verification codes (CVV/CVC), bank account numbers, or any other payment credentials. Payment details entered at checkout are collected directly by Whop inside Whop's own checkout interface and are never transmitted to or through Carte.store systems. See Section 5.

3.2. We do not use advertising cookies or third-party advertising or tracking technologies on storefronts or on our website, and we do not sell personal information.

4. HOW WE USE INFORMATION

4.1. We use the information described above to:

4.2. We do not use personal information for advertising, profiling, or automated decision-making that produces legal effects.

5. PAYMENTS, WHOP, AND PCI DSS

5.1. Checkout on storefronts hosted by the Service is provided by Whop through an embedded checkout that loads directly from Whop. All information a Buyer enters at checkout, including email address, billing details, and payment card or other payment credentials, is collected and processed by Whop under Whop's own terms and privacy policy, available at whop.com. Whop acts independently of Carte.store with respect to this data.

5.2. Payment card data is handled entirely within Whop's payment infrastructure, which Whop operates in accordance with the Payment Card Industry Data Security Standard (PCI DSS). Carte.store systems never receive, process, store, or transmit cardholder data. The only card-related information we receive from Whop is the card brand and the last four digits of the card, which are industry-standard display references and are not sufficient to make charges.

5.3. Whop is also responsible for merchant identity verification (KYC), the holding and settlement of Merchant balances, payouts, refunds, chargebacks, disputes, and any tax calculation, collection, or remittance features, each governed by the Merchant's direct agreement with Whop and by Whop's privacy policy.

5.4. The merchant dashboard displays order, balance, and payout data retrieved from Whop's systems. Whop's records remain the authoritative source of this data.

6. OUR ROLE IN PROCESSING BUYER DATA

6.1. Merchants are independently responsible for their relationship with their Buyers. For Buyer order information that we store and process (Sections 2.3 and 2.4), we act as a service provider (processor) on behalf of the Merchant, processing that data only to provide the Service: delivering purchased files, showing the Merchant their orders, and supporting refunds and customer service.

6.2. Merchants are responsible for complying with the privacy and consumer protection laws that apply to their own sales, including providing their Buyers with any legally required privacy notices and honoring Buyer privacy rights with respect to data the Merchant controls.

6.3. Whop determines its own purposes and means for the payment data it collects and is not our sub-processor.

7. HOW WE SHARE INFORMATION

7.1. We share personal information only with service providers who process it on our behalf to run the Service:

7.2. We may also disclose information if required by law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Carte.store, our users, or the public.

7.3. If Carte.store is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice of any such change in ownership or control of personal information.

7.4. We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

8. COOKIES

8.1. We use only essential cookies. Merchants who sign in to the dashboard receive an authentication session cookie required for the Service to function. We do not use analytics, advertising, or cross-site tracking cookies.

8.2. Public storefronts do not set tracking cookies. Visitor counting works as described in Section 2.5, without cookies or persistent identifiers.

9. DATA RETENTION

9.1. Merchant account information is retained while the account is active and for a reasonable period afterward as needed for legal, accounting, and security purposes.

9.2. Order records are retained while the associated Merchant account is active, because they form the Merchant's business records for deliveries, refunds, disputes, and tax purposes.

9.3. Visitor deduplication records are deleted automatically after approximately two days, as described in Section 2.5.

9.4. Merchant-uploaded files are retained until the Merchant deletes them or the account is terminated, after which they may be deleted as described in the Terms of Service.

10. SECURITY

10.1. We use commercially reasonable technical and organizational measures to protect personal information, including encryption of data in transit, hashed password storage, access controls, and one-way hashing of visitor analytics data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. INTERNATIONAL TRANSFERS

11.1. The Service is operated from the United States, and information we collect is stored and processed in the United States and in other locations used by our service providers. Where legally required, we rely on appropriate safeguards for international transfers of personal information.

12. YOUR RIGHTS AND CHOICES

12.1. Depending on where you live, you may have rights over your personal information, such as the right to access, correct, delete, or receive a copy of it, the right to object to or restrict certain processing, and the right to lodge a complaint with a supervisory authority.

12.2. Merchants may exercise these rights by contacting us at [email protected].

12.3. Buyers should direct requests concerning a purchase first to the Merchant they bought from (who controls the sale relationship) or to Whop (who controls the payment data). Where we hold Buyer order data as a service provider, we will assist the Merchant in fulfilling verified requests, and we will fulfill requests directed to us where the law requires us to do so.

12.4. We do not discriminate against anyone for exercising privacy rights.

13. CHILDREN

13.1. The Service is not directed to children. Merchants must be at least 18 years old. We do not knowingly collect personal information from children under 13; if we learn that we have done so, we will delete it.

14. CHANGES TO THIS POLICY

14.1. We may update this Privacy Policy from time to time. We will post the updated version on this page and, for material changes, notify Merchants through the dashboard or by email. The "effective date" below reflects the latest revision.

15. CONTACT

15.1. Questions or requests regarding this Privacy Policy should be sent to [email protected].

15.2. This Privacy Policy is effective as of July 23, 2026.