This page is for the people doing due diligence on CART - security, IT, and technical teams evaluating us before a deployment. For product details, see the product overview.
CART runs on load-balanced, autoscaling infrastructure with failover contingencies built in. SalesLead.ai does not guarantee uninterrupted availability and makes commercially reasonable efforts to maintain system uptime, consistent with the Master Services Agreement.
CART reads cart, checkout, and customer contact data from your Shopify store to run SMS conversations. It does not access unrelated store data, financial account details, or admin-level settings.
Access is read-only. The Shopify integration requests only read_orders, read_customers, read_products, and read_inventory scopes, nothing that creates, modifies, or deletes data in your store.
Your Shopify access token is encrypted at rest and only decrypted server-side when CART needs to fetch checkout data. It is never exposed to client-side code.
CART checks for new abandoned checkouts every 15 minutes. Once a checkout is detected, the Supabase real-time data layer keeps that cart's state and message history in sync for the rest of the conversation.
Underlying data processing and storage follow Supabase's own infrastructure and security posture, since that is the platform CART is built on.
How a recovered checkout actually moves through the system, end to end.
Every box in this diagram is a real system boundary, not a simplification. Read-only Shopify access, encrypted credentials, and the 15-minute polling cadence are documented above.
SalesLead.ai engages the following subprocessors to deliver the Services:
This list reflects current subprocessors as of the date below. Contact us for the most current list or to be notified of changes.
Last updated: July 31, 2026
Client data is retained only as long as necessary to provide the Services and meet legal, regulatory, and contractual obligations. Upon termination, clients may request access to their data within 30 days; after that window, SalesLead.ai may delete client data unless retention is required by law.
If SalesLead.ai becomes aware of a security incident affecting client data, we will notify affected clients without undue delay, and in any case within the timeframe required by applicable law. Notification will include the nature of the incident, the data affected, and the steps taken to address it, to the extent known at the time.
A Master Services Agreement and Data Processing Agreement are required for every CART deployment, including the Revenue Proof trial. Contact us to put these in place before your trial begins.
If your team needs a completed security questionnaire, a call with someone technical, or documentation beyond what's here, reach out directly.
Contact us →