Privacy Policy

Last updated: 12 June 2026

At Astrocart, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our e-commerce platform, website at astrocart.com, and related services. This policy is compliant with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

The data controller responsible for your personal data is:

  • Company: Astrocart UK LTD
  • Company Number: 12809988
  • VAT Number: GB434386878
  • Address: Astrocart HQ, Thompson Yard, Southbank Road, Middlesbrough, TS3 8RQ
  • Email: [email protected]
  • Website: astrocart.com

Where this policy refers to "we", "us", or "our", it refers to Astrocart as the data controller.

2. What Data We Collect

2.1 Information You Provide Directly

We collect personal data that you voluntarily provide to us when you register for an account, use the Service, make a purchase, contact us, or otherwise interact with us:

  • Account Information: Full name, email address, password (hashed), telephone number, and business name;
  • Billing Information: Billing address and payment method details. We do not store full credit or debit card numbers on our servers. Payment information is collected and processed securely by Stripe, our third-party payment processor, in accordance with PCI DSS standards;
  • Store Information: Product listings, product images, product descriptions, pricing data, inventory levels, and store settings;
  • Customer Data: Data you collect from your store's customers (names, addresses, order information) is processed by us on your behalf as a data processor;
  • Communications: The content of emails, support tickets, contact form submissions, and any other correspondence with our team;
  • Marketing Preferences: Your consent status and preferences for receiving marketing communications from us.

2.2 Information Collected Automatically

When you access or use the Service, we automatically collect certain technical and usage information:

  • Device Information: IP address, browser type and version, operating system, device type, and screen resolution;
  • Usage Data: Pages visited, features used, actions taken within the platform, time spent on pages, and clickstream data;
  • Log Data: Server access logs including timestamps, referring/exit pages, and error reports;
  • Cookie Data: Information collected through cookies and similar technologies (see Section 10 below).

2.3 Information from Third Parties

We may receive personal data about you from third parties, including:

  • Payment Processors: Transaction confirmations and billing details from Stripe;
  • Analytics Providers: Aggregated or pseudonymised usage data;
  • Import Services: Data you choose to import from other platforms (e.g., Shopify, WooCommerce) when migrating to Astrocart.

3. How We Use Your Data

We use the personal data we collect for the following purposes:

3.1 Providing and Operating the Service

  • Creating and managing your account;
  • Hosting and operating your online store;
  • Processing transactions and sending related notifications (e.g., order confirmations, shipping updates);
  • Providing customer support and responding to enquiries;
  • Managing your subscription and billing.

3.2 Improving and Developing the Service

  • Analysing usage patterns to improve user experience and platform performance;
  • Conducting internal research and development;
  • Training and improving our AI-powered features (using anonymised or aggregated data only);
  • Identifying and fixing technical issues, bugs, and errors.

3.3 Communications

  • Sending administrative communications, including service updates, security alerts, and account notifications;
  • Sending marketing communications about our products, features, and services (only with your consent);
  • Responding to your comments, questions, and support requests.

3.4 Security and Compliance

  • Detecting, preventing, and addressing fraud, abuse, and security threats;
  • Enforcing our Terms of Service and other agreements;
  • Complying with applicable laws, regulations, and legal processes.

4. Legal Bases for Processing

Under the UK GDPR, we rely on the following legal bases to process your personal data:

Purpose Legal Basis
Providing the Service, managing your account, processing payments Performance of contract (Article 6(1)(b) UK GDPR)
Improving the Service, analytics, internal research Legitimate interest (Article 6(1)(f) UK GDPR)
Sending marketing communications Consent (Article 6(1)(a) UK GDPR)
Preventing fraud, ensuring security Legitimate interest (Article 6(1)(f) UK GDPR)
Tax records, regulatory compliance Legal obligation (Article 6(1)(c) UK GDPR)
Administrative and service communications Performance of contract / Legitimate interest

Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interest at any time.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to third parties. We will never sell your data. We may share your personal data in the following limited circumstances:

5.1 Service Providers

We share data with trusted third-party service providers who assist us in operating the Service. These providers are contractually obligated to process data only on our instructions and in accordance with applicable data protection laws:

  • Stripe — Payment processing. Stripe processes your payment information in accordance with PCI DSS standards. See Stripe's Privacy Policy;
  • Google Cloud Platform — Cloud infrastructure and hosting. Data is stored in EU/UK data centres;
  • Cloudflare — Content delivery network (CDN), DDoS protection, and DNS. See Cloudflare's Privacy Policy;
  • Email Service Providers — For sending transactional and marketing emails on our behalf;
  • AI Service Providers — For powering AI features within the platform. We send only the minimum data necessary and do not share personal customer data with AI providers;
  • Connected Advertising Platforms (Meta, Google, TikTok) — Where a merchant has connected their own advertising account, we transmit conversion and catalogue data to that platform on the merchant's behalf, subject to shopper consent. See Section 15 below.

5.2 Legal Requirements

We may disclose your personal data if required to do so by law, regulation, legal process, or enforceable governmental request, or where we believe disclosure is necessary to:

  • Comply with applicable law, regulation, or court order;
  • Protect the safety, rights, or property of Astrocart, our users, or the public;
  • Detect, prevent, or address fraud, security, or technical issues;
  • Respond to a lawful request by a public authority, including law enforcement.

5.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and provide you with options regarding your data.

6. International Data Transfers

Your personal data is primarily stored and processed within the United Kingdom and the European Economic Area (EEA). Where we transfer personal data outside the UK/EEA, we ensure that appropriate safeguards are in place, including:

  • Adequacy Decisions: Transfers to countries that the UK Secretary of State has determined provide an adequate level of data protection;
  • International Data Transfer Agreement (IDTA): Standard contractual clauses approved by the UK Information Commissioner's Office (ICO);
  • Additional Safeguards: Encryption, pseudonymisation, and access controls as appropriate.

Cloudflare may process some data at edge locations globally as part of its CDN service. This processing is subject to Cloudflare's data processing addendum and appropriate transfer safeguards.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our specific retention periods are:

  • Account Data: Retained for the duration of your active account and for 30 days after account closure (to allow for reactivation). After 30 days, your data is permanently deleted unless we are required to retain it for legal purposes;
  • Transaction and Billing Records: Retained for 7 years after the transaction date, as required by UK tax and accounting regulations (HMRC requirements);
  • Support Communications: Retained for 2 years after the resolution of the enquiry;
  • Marketing Consent Records: Retained for as long as your consent is valid, and for 3 years after withdrawal to demonstrate compliance;
  • Server Logs: Retained for 90 days for security and debugging purposes;
  • Cookie Data: Retained in accordance with the retention periods set out in Section 10 below.

When personal data is no longer required, it is securely deleted or anonymised so that it can no longer be associated with you.

8. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to certain conditions and exceptions:

  • Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you, together with information about how we process it;
  • Right to Rectification (Article 16): You have the right to request that we correct any inaccurate or incomplete personal data we hold about you;
  • Right to Erasure (Article 17): You have the right to request the deletion of your personal data where there is no compelling reason for us to continue processing it. This right is subject to certain exceptions, including where retention is necessary for legal compliance;
  • Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest its accuracy;
  • Right to Data Portability (Article 20): You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller;
  • Right to Object (Article 21): You have the right to object to processing of your personal data based on legitimate interest. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests;
  • Right to Withdraw Consent: Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

8.1 Exercising Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within one calendar month. In complex cases, or where we receive a large number of requests, we may extend this period by a further two months, in which case we will inform you of the extension and the reasons for it within the first month.

We may ask you to verify your identity before processing your request. There is no fee for exercising your rights, unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest;
  • Secure password hashing using industry-standard algorithms (bcrypt);
  • Role-based access controls and the principle of least privilege;
  • Regular security assessments and vulnerability testing;
  • DDoS protection and web application firewall via Cloudflare;
  • Automated backups with encryption;
  • Incident response procedures and breach notification processes.

While we take all reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

10. Cookies and Similar Technologies

We use cookies and similar tracking technologies to enhance your experience, analyse usage, and support the functionality of the Service.

10.1 Types of Cookies We Use

  • Strictly Necessary Cookies: These cookies are essential for the basic functionality of the Service, including authentication, session management, and security. They cannot be disabled without affecting the operation of the Service. Duration: session or up to 30 days;
  • Analytics Cookies: These cookies help us understand how visitors interact with the Service by collecting information about pages visited, time spent, and navigation patterns. This data is aggregated and anonymised. Duration: up to 2 years;
  • Preference Cookies: These cookies remember your settings and preferences (such as language, theme, and display options) to provide a more personalised experience. Duration: up to 1 year;
  • Marketing Cookies: With your consent, we may use marketing cookies to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. Duration: up to 1 year.

10.2 Managing Cookies

When you first visit our website, we will ask for your consent before placing any non-essential cookies. You can manage your cookie preferences at any time through:

  • Our cookie consent tool (available via the cookie banner or footer link);
  • Your browser settings (note: disabling certain cookies may affect the functionality of the Service).

For more information about cookies and how to manage them, visit www.allaboutcookies.org.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as soon as reasonably practicable. If you believe we have inadvertently collected data from a child, please contact us at [email protected].

12. Marketing Communications

We may send you marketing communications about our products, features, and services, but only with your explicit consent. You can withdraw your consent and opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link at the bottom of any marketing email;
  • Updating your communication preferences in your account settings;
  • Contacting us at [email protected].

Please note that even if you opt out of marketing communications, we will still send you essential service-related communications (such as billing notifications, security alerts, and important account updates) as these are necessary for the performance of our contract with you.

13. Third-Party Links and Services

The Service may contain links to third-party websites, services, or applications that are not operated by Astrocart. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service. We are not responsible for the privacy practices or content of third-party services.

14. Your Store's Customers

If you operate a store on the Astrocart platform, you are the data controller for any personal data you collect from your customers. Astrocart acts as a data processor on your behalf. You are responsible for:

  • Having your own privacy policy that informs your customers about how their data is collected and used;
  • Obtaining any necessary consents from your customers for data processing;
  • Complying with all applicable data protection laws, including the UK GDPR, in relation to your customers' data;
  • Responding to data subject requests from your customers in a timely manner.

We will assist you in meeting your data protection obligations as set out in our Data Processing Agreement, which forms part of our Terms of Service.

15. Connected Advertising and Marketplace Accounts

Merchants may choose to connect third-party advertising and marketplace accounts (such as Meta, Google, TikTok and eBay) to their store. When you connect an account, we receive and process, on your instruction:

  • Your authorised account list and identifiers;
  • Advertising performance data (such as reach, clicks, spend and conversions);
  • Pixel and product-catalogue identifiers.

We use this data solely to provide the connected features to your store: displaying your advertising performance in your dashboard, keeping your product catalogues synchronised, and reporting your store's sales back to the platform for conversion measurement (only where the shopper has consented to tracking). Access tokens are stored encrypted at rest. Connected-account data is retained only while your connection is active and is deleted when you disconnect the account or close your store. We do not sell connected-account data, use it for our own advertising, or combine it across merchants.

Astrocart's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy;
  • Post the revised policy on our website;
  • Send you an email notification if the changes are material and you have an active account;
  • Where required by law, obtain your consent to the revised policy before it takes effect.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

17. Complaints

We take all complaints about our data handling practices seriously. If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please reach out to us first at [email protected] and we will do our best to resolve the matter promptly.

18. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Enquiries

We aim to respond to all data protection enquiries within one calendar month of receipt.