Plain-English summary. SalesLead.ai (CART) sends SMS conversations on behalf of Shopify merchants to shoppers who've already started checkout. This policy explains what information we collect to run that infrastructure, how we use it, who we share it with, and what rights you have over it. The legal detail below is real and binding, but we've tried to say it the way we'd say it out loud.
SalesLead.ai is operated by SalesLead AI LLC, together with its parent companies, subsidiaries, affiliates, and related entities (together, "SalesLead.ai," "we," "our," or "us"). This Privacy Policy covers our websites, applications, and Services, however you reach them.
If you're a customer with a signed Master Services Agreement or Service Order, that agreement controls wherever it conflicts with this Policy. This Policy fills in the rest.
Account information: your name, email address, phone number, company name, and billing details, when you sign up for the Services.
Communications: anything you send us directly - emails, chats, calls, support tickets.
Usage data: IP address, browser type, operating system, and referring URLs, so we can run and improve the Services. We do not sell this data.
Cookies and similar technologies: used for functionality, analytics, security, and service improvement. See Section 8.
SMS, email, and voice interaction data: CART operates on behalf of our Shopify merchant clients, so when a shopper texts, emails, or talks with CART, we process and store that conversation. What we collect and how long we keep it is set by the client's configuration and their agreement with us.
All SMS communications sent through the Services include carrier-required disclosures, including message and data rate notices where applicable. Recipients may opt out of further messages at any time by replying STOP, and may request assistance by replying HELP. The Services process these opt-out requests automatically and immediately cease further messaging to that recipient. Message frequency varies based on Client's configured cart recovery sequence. CART's currently active engine, Abandoned Cart Recovery, only initiates outreach to shoppers who have already started checkout with a Client.
We may collect information about you from publicly available sources, business partners, or third-party vendors to supplement our data.
How we use information depends on the role we're playing when we collect it. Most of the time, that role is running CART on a client's behalf.
We use information to:
When we process a shopper's data through CART, we're acting as a service provider on our client's behalf, not deciding independently who gets messaged or why. That decision, and the responsibility for having proper consent to make it, sits with our client.
We use information to:
We may use information to:
We may analyze usage data, performance metrics, and aggregated interaction data to:
Where feasible, such analysis is conducted on aggregated or de-identified data.
Our services may utilize automated technologies, including artificial intelligence (AI) chatbots, conversational agents, or automated messaging systems, to communicate with users through text messages, chat interfaces, email, or other digital communication channels. These systems may respond to inquiries, provide information, or facilitate transactions on behalf of our clients. If a user asks whether they are communicating with a person or an automated system, the system will disclose that clearly and immediately.
We may share your information with third-party vendors who provide services on our behalf. We do not sell your information. Current subprocessors include:
This list reflects current subprocessors as of the Effective Date above and is kept in sync with our Security page.
We may share information with telecommunications carriers, messaging platforms, email service providers, cloud infrastructure providers, and other technology service providers as necessary to deliver managed execution infrastructure on behalf of our clients.
Such providers process information solely for purposes of message delivery, infrastructure operation, compliance requirements, and related execution services.
Information may be shared with client-designated agencies, partners, or vendors where necessary to provide the Services and in accordance with applicable agreements.
We may disclose your information:
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.
We may share information with our parent companies, subsidiaries, affiliates, and related entities for purposes consistent with this Privacy Policy, including service delivery, infrastructure operation, customer support, security monitoring, and internal business operations. This includes Agentum Solutions LLC, an affiliate that performs technical development, infrastructure operations, and delivery services on our behalf.
Our clients are. Before a merchant can send a single message through CART, they need proper consent under the Telephone Consumer Protection Act (TCPA), CAN-SPAM, Do Not Call rules, CCPA, GDPR, and any carrier requirements that apply. That's on them, not us.
We don't decide who a client messages, what they say, or verify that their consent records are legally sufficient. We provide the infrastructure that sends the messages they've configured.
We don't sell personal information, and we don't use client-provided shopper data for our own marketing. We process it as a service provider, under our clients' instructions.
If you're a California resident, you have the right to:
Access and portability: ask what personal information we've collected about you.
Deletion: ask us to delete it, subject to certain exceptions.
Opt-out: opt out of the sale of personal information, where applicable.
To exercise your rights, please contact us at:
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdiction with similar data protection laws, you may have the right to:
Where SalesLead.ai acts as a data processor on behalf of its clients, clients are responsible for responding to data subject requests and fulfilling controller obligations unless otherwise contractually agreed.
For GDPR-related inquiries, please contact:
Personal information processed through the Services may be transferred to and processed in the United States or other jurisdictions where SalesLead.ai or its service providers operate.
Where required by applicable law, appropriate safeguards are implemented to support lawful cross-border data transfers.
Where SalesLead.ai acts as a data processor, international transfers are conducted in accordance with client instructions and applicable contractual terms.
This Policy is also intended to comply with applicable U.S. state privacy laws, including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other comprehensive state privacy laws as they take effect. Residents of these states have rights that may include the right to access, correct, delete, or opt out of certain processing of their personal data, consistent with the rights described in this Policy.
We use technical, administrative, and physical safeguards sized to the sensitivity of the data we process. No system is unbreakable, and we can't guarantee absolute security, but we take it seriously.
Where we integrate with Shopify, access is read-only and scoped to what's needed to run the Services. Your Shopify access token is encrypted at rest and only decrypted server-side when needed to fetch checkout data; it is never exposed to client-side code.
In the event SalesLead.ai becomes aware of a security incident resulting in unauthorized access to or disclosure of personal data processed under this Policy, SalesLead.ai will notify affected Clients without undue delay, and in any case within the timeframe required by applicable law. Notification will include, to the extent known at the time, the nature of the incident, categories of data affected, and steps SalesLead.ai is taking in response. This notification obligation applies to Client data; notification to individual end-users remains Client's responsibility unless otherwise required by law.
SalesLead.ai retains personal information only for as long as necessary to provide the Services, fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, and enforce applicable agreements.
Retention periods may vary based on client agreements, regulatory requirements, telecommunications carrier obligations, dispute resolution needs, and the operational requirements of managed execution infrastructure.
Where SalesLead.ai acts as a data processor, retention is governed by client instruction and applicable contractual terms, subject to legal and regulatory obligations.
Upon termination, clients may request access to their data within 30 days; after that window, SalesLead.ai may delete client data unless retention is required by law.
We use cookies and similar technologies for functionality, analytics, security, and service improvement. Current tools include:
This list reflects tools currently in use and is updated as our toolset changes. You can manage cookie preferences through your browser settings, or opt out of Google Analytics specifically via Google's browser opt-out add-on.
The Services aren't for anyone under 18. We don't knowingly collect personal information from minors.
We may update this Privacy Policy from time to time. Changes will be posted with a new "Effective Date." Your continued use of the Services constitutes your acceptance of the updated Privacy Policy. For a plain-language summary of what's changed and when, see our Policy Updates page.
We may transfer or assign the operation of the Services, including the processing of personal information, to affiliated entities within our corporate structure. Any such transfer will remain subject to the protections described in this Privacy Policy.
If you have questions or concerns about this Privacy Policy, please contact us: