Last updated: July 17, 2026. This Privacy Policy applies only to Cart Marshal by HansonCore, LLC DBA Five Acre Code.
Scope
Cart Marshal is a Shopify app for configuring checkout rules. Merchants use the embedded Shopify admin app. End customers interact with Shopify Checkout, not the Cart Marshal admin app.
This policy describes data handled by Cart Marshal. Shopify's own data handling, billing, checkout, platform, and merchant services are governed by Shopify's policies and agreements.
Data we store
Cart Marshal stores merchant and app configuration needed to operate the app, including:
- Shop domain and store profile details.
- Shopify app session records and encrypted tokens required for app operation.
- Rule definitions, rule status, Shopify resource identifiers, schedule settings, eligibility settings, tags, targeting selections, and merchant-entered labels or messages.
- App settings, including merchant-managed payment method names, field visibility settings, PO Box keywords, defaults, cached store metadata, and billing plan state.
- Administrative activity needed for lifecycle, audit, troubleshooting, timeline, settings history, and support, including comments entered by authorized store users.
- Limited Shopify privacy-request metadata, such as webhook and request IDs, Shopify customer ID, number of order IDs included in the request, request status, and timestamps. Cart Marshal does not copy the underlying customer profile or order history into its database when handling these requests.
- Support emails and attachments you choose to send.
- Security, operational, request, webhook, and error logs, with sensitive values scrubbed where practical.
Cart Marshal does not store customer payment card numbers, saved payment credentials, end-customer profiles, full order history, customer phone numbers, customer browsing behavior, or marketing behavior profiles. It does not copy customer email addresses from Shopify Checkout or Shopify customer profiles into its app database.
If you enter a customer email address or other personal data in a rule condition, label, message, audit comment, or support request, Cart Marshal stores that merchant-provided content as part of the rule, audit trail, or support record. Do not enter payment card numbers or saved payment credentials in these fields.
Data used at runtime but not stored as customer profiles
Shopify Functions may read checkout runtime fields needed to evaluate merchant-configured rules, including cart details, product and variant identifiers, quantities, subtotals, delivery country, customer email, customer tag matching, customer ID, number of orders, B2B company context, address lines for PO Box detection, and ZIP/postal code for ZIP-based rules.
These checkout fields are used to evaluate rules at checkout runtime and are not stored by Five Acre Code as customer profiles. Shopify controls the checkout runtime environment.
Shopify permissions
Cart Marshal requests 14 Shopify scopes for discounts, products, customers, shipping, markets, payment customizations, delivery customizations, cart transforms, and validations. The exact current scope list and merchant-facing explanation are published at /apps/cart-marshal/policies/app-permissions/.
How we use data
We use data to provide, secure, maintain, troubleshoot, bill, improve, and support Cart Marshal, including creating and managing rules, checking rule health, showing plan access, responding to support requests, investigating security events, complying with Shopify requirements, and protecting the service from abuse.
We do not sell personal information. We do not operate a third-party advertising profile for end customers through Cart Marshal.
Subprocessors
Current subprocessors and service providers are listed at /apps/cart-marshal/policies/data-processing/.
Retention
We retain merchant app configuration while the app is installed or as needed to provide the service, support the merchant, maintain security, comply with Shopify requirements, preserve audit records, resolve disputes, enforce agreements, or meet legal obligations.
After uninstall, Shopify sends a shop deletion webhook under its privacy flow. Cart Marshal purges per-shop app records after uninstall according to that flow. Some records, such as support emails, security logs, backups, legal records, billing references, and abuse-prevention records, may be retained for reasonable business, security, legal, audit, or dispute-resolution purposes.
Data deletion
Cart Marshal implements Shopify privacy webhook handlers for customer data requests, customer deletion, and shop deletion. Because the app does not store customer-identifying checkout records, customer-level requests typically have no stored customer record to return or delete.
Merchants can send privacy questions or requests to support@fiveacrecode.com. Include the shop domain and request type. Do not include unnecessary customer personal data in the initial email.
Security
Security practices are summarized at /apps/cart-marshal/policies/security/. No internet service can be guaranteed perfectly secure. Merchants should review their own Shopify account access, staff permissions, app install permissions, and rule publishing process.
Contact
Privacy questions can be sent to support@fiveacrecode.com.