# Privacy Policy — BusinessCart.ai

> How BusinessCart.ai collects, uses, shares, and protects information from companies, customers, and storefront visitors. Updated March 2026.

Canonical URL: <https://businesscart.ai/privacy-policy>

---

# Privacy Policy

Last updated: March 2026

## Sections

-   [Introduction](#introduction)
-   [Who This Applies To](#who-this-applies-to)
-   [Information We Collect](#information-we-collect)
-   [How We Use Your Information](#how-we-use-your-information)
-   [Payments and Financial Data](#payments-and-financial-data)
-   [How We Share Your Information](#how-we-share-your-information)
-   [Storefront and Public Data](#storefront-and-public-data)
-   [Data Security](#data-security)
-   [Data Ownership](#data-ownership)
-   [Your Rights and Choices](#your-rights-and-choices)
-   [Contact Us](#contact-us)

## Introduction

BusinessCart.ai is a US-based e-commerce platform that provides businesses with their own branded online store, private commerce portal, and B2B tools. This Privacy Policy explains how we collect, use, and protect information across the platform, including the web portal, mobile app, D2C storefronts, and API.

By using BusinessCart.ai, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the platform.

## Who This Applies To

BusinessCart.ai serves multiple types of users. This policy applies to all of them:

-   **Companies (Sellers):** Businesses that create an account, manage products, configure pricing, and sell through the platform.
-   **Customers (Buyers):** Individuals who register with a company code to browse catalogs, place orders, and manage their account through the portal or mobile app.
-   **Storefront Visitors:** Anyone who visits a company's public D2C storefront and may place an order without registering for a portal account.

## Information We Collect

We collect only the information necessary to operate the platform:

-   **Account Information:** Name, email address, phone number, and company name provided during registration.
-   **Company Data:** Business name, logo, brand colors, product catalog (names, descriptions, prices, images), location details, and operating hours uploaded by companies.
-   **Order Data:** Items purchased, quantities, delivery addresses, order status, and order history.
-   **B2B Configuration:** Per-customer pricing, payment method preferences, delivery options, spending limits, and credit limits set by companies for their customers.
-   **Device and Usage Data:** Browser type, device type, and pages visited, used to maintain platform performance and security.

## How We Use Your Information

-   Create and manage your account (company or customer).
-   Generate and host your branded D2C storefront from your product catalog.
-   Process orders, quotes, and checkout transactions.
-   Apply per-customer B2B configuration (pricing, payment methods, delivery options).
-   Send order confirmations, quote updates, and account notifications.
-   Generate SEO metadata (sitemaps, meta tags, schema markup) for your storefront.
-   Monitor platform performance and prevent abuse.

## Payments and Financial Data

**BusinessCart.ai does not process or store credit card numbers, bank account details, or other sensitive financial information.**

Payments are processed entirely through the company's own payment provider: Stripe, Amazon Pay, or Authorize.net. When a customer makes a payment, they are redirected to or interact with the payment provider's secure interface. BusinessCart.ai receives only a confirmation that the payment succeeded or failed.

Companies configure their own payment provider credentials on the platform. These credentials are encrypted at rest using AES-256-GCM encryption and are never exposed through the interface or API.

## How We Share Your Information

We do not sell your information. We share data only in these situations:

-   **Between Companies and Their Customers:** When a customer places an order, the company receives the customer's name, delivery address, and order details necessary to fulfill the order.
-   **Payment Providers:** Order amount and reference information is shared with the company's configured payment provider (Stripe, Amazon Pay, or Authorize.net) to process payments.
-   **Public Storefronts:** Product names, descriptions, prices, images, and company branding are published on the company's public D2C storefront. This is by design. Storefronts are intended to be publicly accessible.
-   **Legal Requirements:** We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of BusinessCart.ai, our users, or others.

## Storefront and Public Data

When a company adds products and configures their profile, BusinessCart.ai automatically generates a public D2C storefront. This storefront is static HTML served from a global content delivery network and is intentionally designed to be readable by search engines, AI assistants, and web browsers.

The following data is publicly visible on storefronts: company name, logo, brand colors, product names, descriptions, prices, images, and category structure. Customer data, order data, B2B configuration, and payment credentials are never exposed on storefronts.

## Data Security

We take data security seriously. The platform uses the following measures:

-   All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
-   Payment gateway credentials are encrypted at rest using AES-256-GCM.
-   Authentication uses JWT tokens with automatic expiration.
-   The platform runs on cloud infrastructure with automated security updates and no shared servers.

No system is perfectly secure. While we implement industry-standard protections, we cannot guarantee absolute security. If you become aware of a security issue, please contact us immediately.

## Data Ownership

**Companies own their data.** Your products, customer relationships, order history, and business configuration belong to you. BusinessCart.ai is a platform. We host and process your data to provide the service, but we do not claim ownership of it.

If you close your account, we will delete your data from our active systems upon request. Some data may be retained temporarily in backups or as required by law.

## Your Rights and Choices

-   You can review and update your account information at any time through the portal.
-   You can request deletion of your account and associated data by contacting us.
-   Companies can remove products, customer associations, and business data at any time.
-   Customers can disassociate from a company or delete their account at any time.

## Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at: [help@businesscart.ai](mailto:help@businesscart.ai)

BusinessCart, Inc., United States
