Privacy Policy
Last updated: 24 May 2026
Green Cart Carbon ("the App", "we") is a Shopify application operated by SEEDVISION SAS, a French société par actions simplifiée registered under 103 159 596 R.C.S. Nantes, VAT FR4401.103159596, with its registered office in Nantes, France. SEEDVISION SAS publishes the App and the website seedvision.fr. The App is hosted at greencartcheckout.com.
This Privacy Policy explains what personal data we collect when merchants install the App and when their customers complete a checkout with a climate contribution. It applies to both groups. A French version is available at Politique de confidentialité.
1. Data we collect
1.1 From merchants (Shopify store owners)
When a merchant installs the App via the Shopify OAuth flow, Shopify provides us with:
- Shop domain (e.g.
your-store.myshopify.com) and Shop ID - OAuth access token (stored encrypted), scoped to the permissions the merchant explicitly granted
- Granted permission scopes
- Stripe customer ID if the merchant subscribes to a paid plan
- Merchant contact email if provided during setup
- App configuration: pricing tiers, default distance, carbon project name, language
1.2 From end customers (shoppers of merchant stores)
When a customer's order includes a climate contribution, Shopify's orders/paid webhook delivers to us strictly what is required to issue the certificate:
- Order ID and order number on the merchant's store
- Customer email — used solely to deliver the PDF certificate
- Estimated delivery distance selected at checkout
- Amount contributed and CO₂ kilograms offset
- Certificate serial number generated by us
We do not receive or store customer name, postal address, phone number, payment details, IP address, or any cross-session tracking identifiers.
1.3 Technical data
Standard request metadata (timestamp, path, status, user agent) is logged for security and operations for a maximum of 30 days, without personal identifiers.
2. How we use this data
- Authenticate API calls to the merchant's Shopify store
- Create and maintain the hidden carbon offset product
- Process paid-order webhooks, calculate the contribution, and issue the certificate
- Send the PDF certificate by email to the customer
- Display impact metrics in the merchant's admin dashboard
- Bill the merchant for the platform fee via Stripe
We do not sell or rent personal data, profile customers across stores, or share data with advertisers or analytics platforms.
3. Data sharing
We share limited data only with the following operational third parties:
- Shopify — platform the App runs on; we exchange merchant authorization and order data through its official APIs
- Stripe — payment processor for the merchant platform fee; receives merchant billing details directly, we only hold a customer ID reference
- Email service provider — receives the customer email address and PDF to deliver the certificate
- Carbon offset project operator — receives aggregated, anonymized contribution amounts for credit retirement; no personal data
4. Data retention
- Merchant data: retained while the App is installed. On uninstall (
app/uninstalledwebhook), we invalidate the access token immediately. Shop record kept up to 7 years for accounting/legal compliance. - Customer email: removed from records 30 days after issuance of the certificate.
- Certificate metadata: 7 years for carbon offset traceability.
- Technical logs: 30 days maximum.
5. Your rights (GDPR & French Data Protection Act)
- Right of access, rectification, erasure, restriction, portability, and objection
- Right to lodge a complaint with the CNIL — cnil.fr
- Shopify's mandatory privacy webhooks (
customers/data_request,customers/redact,shop/redact) are implemented and operational - All requests answered within 30 days as required by the GDPR
Customers of merchant stores may exercise these rights through us or through the merchant.
6. International transfers
Data is processed on EU servers. Where third-party processors operate outside the EU (Shopify, Stripe), transfers occur under Standard Contractual Clauses approved by the European Commission.
7. Security
- HTTPS/TLS encryption for all data in transit
- Encrypted database storage for OAuth access tokens
- HMAC-signed verification on all incoming webhooks
- CSP
frame-ancestorson the embedded admin app - Regular security audits and dependency updates
In case of a personal data breach affecting your data, we notify the CNIL within 72 hours and inform affected parties without undue delay (GDPR Art. 33).
8. Children's privacy
The App is a B2B service for Shopify merchants and is not directed at children under 16. We do not knowingly collect personal data from children.
9. Contact
SEEDVISION SAS
103 159 596 R.C.S. Nantes
Nantes, France
VAT FR4401.103159596
Email: contact@greencartcheckout.com
Website: seedvision.fr
10. Updates to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will be revised. For substantive changes, installed merchants will be notified via the App's admin dashboard at least 30 days before the changes take effect.
Green Cart Carbon is a product of SEEDVISION SAS — seedvision.fr. See also our pricing page.