Privacy

How Cartograph handles your data.

This page summarizes how the Cartograph website, early-access and design-partner submissions, advertising measurement, and connected services handle data. Cartograph does not currently operate a public automated scanner, and submitting a form on this site does not start one.

What we collect today

  • Information you intentionally submit through an early-access or design-partner form: storefront URL, work email, company name, and any optional context you choose to share.
  • Standard website and advertising-measurement data described in the section below.
  • Data from a service you explicitly connect, such as Google Merchant Center — see that section below.

Submitting a form does not cause Cartograph to scan, crawl, or send automated requests to your storefront.

What we never require

Neither today's website and form handling nor any future authorized assessment capability requires:

  • Access to your admin or backoffice systems.
  • Access to your payment account, processor, or PSP.
  • Customer data, order data, or any personally identifiable information about your shoppers.
  • Production credentials, API keys, or webhook secrets.

How we use the information

We use the information you intentionally submit through this website to evaluate your request and to follow up about it. Cartograph does not sell merchant data, and we do not share an individual merchant submission with third parties without permission.

Any aggregate benchmarks published in future will be anonymized, and individual merchants will not be identifiable in them.

Advertising and conversion measurement

We use the OpenAI Ads Pixel on our website to measure what happens after someone visits from an ad — including when a visitor submits an early-access or design-partner request. This helps us understand advertising attribution, campaign performance, and optimization.

The Pixel may store an OpenAI click reference (oppref) in first-party browser storage or cookies to associate a later conversion with the ad click that brought the visitor here.

Automatic Advanced Matching is enabled for the OpenAI Web Pixel. Where supported, the Pixel may detect eligible contact information entered into forms (such as an email address), normalize it, and hash it with SHA-256 in the browser before the hashed value is transmitted for conversion measurement. Raw customer information is not sent through Automatic Advanced Matching.

When a genuine new early-access or design-partner lead is created, our application sends a conversion event to OpenAI. That event payload is limited to a type identifier and does not intentionally include raw email, store URL, company, or other form fields.

Paid landing pages may record a minimal first-party campaign receipt when a visit arrives with campaign parameters. That receipt is limited to a server timestamp and static campaign, creative, and landing labels, and is used only for campaign quality checks and reconciliation. It does not contain email, merchant domain, IP address, user agent, or shopper data.

The Pixel is loaded only after a visitor allows advertising measurement. You can change that choice at any time using "Privacy choices" in the site footer. We use these technologies subject to applicable notice and consent requirements. For more information, see OpenAI's Privacy Policy and Conversion Terms.

Retention and deletion

Information you submit through this website is retained while we are evaluating or following up on your request. You can request deletion of your submitted information at any time by emailing contact@cartographintelligence.com.

Google Merchant Center data

If you connect a Google Merchant Center account, Cartograph requests one Google scope: https://www.googleapis.com/auth/content. This is read-only access to your Merchant Center account through the Merchant API. We never write to your account, change your products, or place ads.

What we read. Account-level product status counts (active, pending, disapproved), your most recent feed upload batch and its item counts, and per-product status information including offer IDs, titles, destination and country status, and item issues.

What we store. Two things, both scoped to your workspace:

  • Snapshots of the above, so the dashboard can show change over time. We keep the most recent 168 snapshots per account — roughly one week at hourly refresh — and older ones are deleted automatically.
  • Your Google refresh token, encrypted at rest. It is never stored in plain text and never leaves our systems.

We store no Google account passwords, no payment or billing data, and no personal data about your customers from this connection.

What we do with it. We use it solely to produce the readiness and evidence reports you see in your own dashboard. We do not sell it, share it with third parties, use it for advertising, or use it to train machine-learning models. It is not combined with other merchants' data in any form that identifies you.

Disconnecting. You can revoke Cartograph's access at any time from your Google Account permissions page, which immediately stops us obtaining new access tokens. To have your stored credential and snapshots deleted, email contact@cartographintelligence.com and we will remove them.

Google API Services User Data Policy. Cartograph's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Security contact

For security reports or questions about how Cartograph processes data, contact contact@cartographintelligence.com.