Privacy Policy
Effective date: August 26, 2026
Jobair Technologies ("we," "us," "our") operates Cartiva Business OS at https://cartivaos.com. This Privacy Policy explains how we process personal data when merchants and their authorized users use the service, including the current Shopify store connection feature.
Roles
For workspace and business data entered by a merchant, the merchant is generally the controller and Jobair Technologies acts as a processor providing the hosted platform. For Jobair Technologies's own account, billing, security, and support activities related to the service, Jobair Technologies is the controller.
Data we process today
Account and workspace data
- User account identifiers, name, email address, authentication and security settings.
- Workspace, business profile, location, and operational records created in Cartiva.
- Security audit events such as sign-in, access denial, and integration events.
Shopify connection and sync data
When a merchant connects a Shopify store and runs manual sync, Cartiva stores the minimum needed to maintain the connection, perform Cartiva → Shopify catalog and inventory push, and process mandatory compliance webhooks:
- Shop domain (for example, example.myshopify.com).
- Shopify shop identifier and granted OAuth scopes.
- Encrypted offline access token and optional encrypted refresh token (never stored in plaintext).
- Connection status, install/disconnect timestamps, and non-sensitive shop metadata such as shop name.
- Product and variant mapping records linking Cartiva product/variant identifiers to Shopify product, variant, and inventory item global IDs after catalog sync.
- Location mapping records linking Cartiva business locations to Shopify location global IDs and location names.
- Manual catalog sync run records: status, created/updated/skipped/failed counters, start and finish timestamps, and sanitized per-product error summaries (product identifier, SKU, message).
- Manual inventory sync run records: status, processed/updated/skipped/failed counters, start and finish timestamps, and sanitized per-item error summaries (product identifier, SKU, message).
- Inventory quantities are read from Cartiva and pushed to Shopify during manual inventory sync. Cartiva does not maintain a separate long-term copy of Shopify inventory levels beyond sync run counters, mapping state, and error summaries shown in the product.
- Webhook delivery metadata: topic, Shopify webhook delivery ID, API version, irreversible payload hash, optional Shopify customer numeric identifier for compliance processing, result code, and timestamps.
Manual catalog and inventory sync are initiated by authorized workspace users. Syncs are not automatic or real-time. Cartiva pushes active Cartiva products, variants (including size, color, and other variant options configured in Cartiva), and sellable inventory to Shopify.
In this release Cartiva does not import or store Shopify orders, Shopify customer name/email/phone/address, or Shopify product images. Order and customer synchronization are not provided. Product images are not synced to or from Shopify in this release.
Shopify app pricing
The Cartiva Business OS Shopify app is free. It does not use the Shopify Billing API and does not add subscriptions or usage charges through Shopify.
Purposes
- Provide and secure the hosted Cartiva Business OS platform.
- Authenticate users, enforce permissions, and maintain tenant isolation.
- Connect and maintain an optional Shopify store integration.
- Run manual Cartiva → Shopify catalog and inventory sync when requested by the merchant.
- Receive and process mandatory Shopify compliance webhooks.
- Send transactional service email when configured (for example, password reset and verification).
- Maintain security logs and minimal integration audit records.
Legal bases (EEA/UK merchants)
- Contract: providing the service the merchant requested.
- Legitimate interests: securing the platform, preventing abuse, and maintaining integration integrity, balanced against merchant and user rights.
- Legal obligation: responding to valid compliance webhook and lawful requests where applicable.
Retention
- Shopify webhook delivery audit metadata is retained up to 90 days, then deleted automatically where applicable.
- Encrypted Shopify tokens, product/variant mappings, location mappings, and sync run records are removed when a store is disconnected, uninstalled, or shop-redacted.
- Other workspace records follow the merchant's ongoing use of Cartiva and applicable backup retention configured for the environment.
Deletion and compliance webhooks
Cartiva processes Shopify mandatory webhooks for customer data requests, customer redaction, shop redaction, and app uninstallation. Customer export requests return only Shopify-derived personal data stored by Cartiva (typically none in this release beyond optional compliance webhook customer numeric identifiers in delivery audit metadata). Customer redaction completes safely without modifying unrelated native Cartiva customer records. Shop redaction and uninstall remove Shopify connection data, encrypted tokens, product and location mappings, catalog and inventory sync run records, webhook delivery records, and related integration metadata for the affected shop without deleting the Cartiva workspace or native Cartiva product records.
Sharing and sale of personal data
We do not sell personal data. We share data only with subprocessors that help us operate the service, subject to contractual protection:
- Railway — application and database hosting.
- PostgreSQL — primary database engine used by the hosted environment.
- Resend — transactional email delivery for the web application when enabled.
- Shopify — when a merchant connects a store, for OAuth authorization and webhook delivery configured by the merchant's app installation.
- Cloudflare — optional custom-domain edge routing when a merchant enables supported domain features documented in the platform.
International processing
Merchants may access the service internationally. Subprocessors may process data in countries other than the merchant's own, using appropriate contractual safeguards where required.
Security measures implemented in software
- HTTPS for public application endpoints in production configuration.
- Hashed session tokens and Argon2 password hashing for local credentials.
- AES-256-GCM encryption for Shopify offline access tokens at rest in the application database.
- HMAC verification for Shopify OAuth callbacks and webhooks before processing.
- Signed OAuth state cookies and tenant row-level security for Shopify integration tables.
- Webhook idempotency and secret redaction in integration logging paths.
Your rights and contact
Merchants and authorized users may access, correct, or delete account data through the product where available, or by contacting [email protected]. Shopify end-customer requests received through Shopify's compliance webhooks are handled through the connected store's Cartiva integration as described above.