Privacy policy
Last updated Sep 5, 2026
CometCarts (cometcarts.com) helps boutiques take orders during Facebook and Instagram lives, send invoices, and ship. This policy says what we keep, why, for how long, and how to have it deleted. It covers the site, the app, and the pages a store connects.
What we collect from store staff
Your email address and name, a password that our sign-in provider stores hashed, a device PIN stored hashed, and the settings of your store.
What we collect from connected pages
When a store owner connects a Facebook or Instagram page, Meta gives us the page's name and id and an access token limited to the permissions shown in the dialog. With it we read comments and messages on the page's posts and lives, learn when a live starts and ends, and send messages on the page's behalf. Tokens are kept in a table that no screen can read, and are deleted when the page is disconnected.
What we collect about buyers
What a buyer shares with a store: their name or handle and platform id, their comments and messages, the orders they place, a shipping address, and the details of their payments, deposits, and refunds. Buyers never sign in to CometCarts. The store's staff records this on their behalf, and the buyer sees it on their invoice link.
How we use it
Only to run the store's live sales: turning comments into orders, building invoices, sending invoice links and reminders, collecting payments, buying and printing shipping labels, keeping the deposit ledger, and keeping a record of who changed what.
AI reading of comments
Comments on a live are read by an AI model to suggest orders. Suggestions are advisory: only a person on the store's staff creates an order. Comments are sent to the model provider for that reading only and are not used to train models.
Who else sees data
Companies that run CometCarts for us, each under its own agreement: Supabase (database and sign-in), Vercel (hosting), Meta (pages and messages), Stripe (card payments), Shippo and EasyPost (shipping labels), PrintNode (printing), and an AI provider (comment reading). We do not sell data and do not share it for advertising. We disclose data when the law requires it.
How long we keep it
Raw deliveries from Meta and the other providers: 30 days. Comments and messages not tied to an order or a customer: 90 days. Handwriting images from the order pad: one year. Orders, invoices, payments, the deposit ledger, and the change record: kept as the store's business records while the store has an account, then deleted within 90 days of the account closing. Page tokens: deleted as soon as the page is disconnected.
Deleting your data
Store staff can disconnect a page in Settings, which deletes its token, and can delete a buyer's data at the buyer's request. If you remove CometCarts from your Facebook settings, the tokens from your login are deleted. Anyone can ask us to delete the data we hold about them by writing to hello@cometcarts.com from the address or account in question. We answer within 30 days and confirm when it is done.
Security
Data travels encrypted. Every row belongs to one store and the database refuses reads across stores. Tokens and secrets live out of reach of screens.
Children
CometCarts is for businesses and is not directed at children under 13.
Changes
When this policy changes, the date at the top changes with it, and store owners are told in the app.
Questions about this document: hello@cometcarts.com