Privacy Policy
Effective and last updated: August 26, 2026
Kartlo is an eCommerce platform that lets businesses (“Sellers”) build online stores, take orders and manage their customers. It is operated by LouWard Labs (“Kartlo”, “we”, “us”). This policy explains how we handle personal data.
1. Who this policy covers
| Who you are | What we call you | Our role |
|---|---|---|
| You visit kartlo.app, read our content, or contact us | Visitor | Controller |
| You create a Kartlo account to run a store, or you are staff invited to one | Seller | Controller |
| You shop at, or share your details with, a store built on Kartlo | Shopper | Processor (the Seller is the controller) |
If you are a Shopper, the store you bought from decides why and how your data is used. Their privacy policy, shown on their store, governs that relationship. We process your data on their instructions, as described in Section 6. For requests about your data at a specific store, contact that store first; we will help them respond.
2. Data we collect
From Visitors
- Contact details you give us (name, email, company, message) when you fill a form, subscribe to a newsletter, or chat with support.
- Technical data collected automatically: IP address, device and browser type, pages viewed, referring site, approximate location derived from IP, and cookie identifiers (see Section 10).
From Sellers
- Account data: name, email, phone, password (hashed), language, time zone, profile photo.
- Business data: store name, legal business name, business address, trade licence or registration number, tax/VAT number, website, industry, and the legal and policy pages you publish.
- Billing data: plan, invoices, billing address, VAT status, and the last four digits and expiry of your payment card. Full card details are collected and stored by our payment processor, never by us.
- Usage data: actions in the dashboard, features used, support tickets, login history, IP addresses and devices used to sign in, API keys and webhook endpoints you create.
- Communications: emails, chat messages, and calls with our support team (calls may be recorded with notice).
- Staff data: name, email, role and activity of any team members you invite.
From Shoppers (processed on behalf of Sellers)
- Identity and contact details: name, email, phone, shipping and billing addresses.
- Order data: products bought, amounts, currency, discounts, payment method type (for example "card" or "cash on delivery"), shipping choice, tracking numbers, returns and refunds.
- Account data if the Shopper creates an account: login credentials (hashed), wishlist, saved addresses, reviews, loyalty balance.
- Marketing data: consent records for email, SMS and WhatsApp, and engagement with messages (delivered, opened, clicked).
- Behavioural data: pages viewed, products viewed, cart contents including abandoned carts, search terms.
- Technical data: IP address, device, browser, cookie identifiers.
We do not collect payment card numbers, CVV codes, or bank details from Shoppers. These are entered into payment forms hosted by the Seller’s payment provider.
From third parties
- Payment providers send us transaction status and, for Sellers, the results of their identity checks.
- Couriers send us shipment status.
- Sign-in providers (for example Google or Apple) send us your name and email if you choose to sign in with them.
- Publicly available business registers, where we verify a Seller's licence.
3. Why we use data and on what legal basis
| Purpose | Data | Legal basis (PDPL / GDPR) |
|---|---|---|
| Provide the service: create accounts, host stores, process orders, send transactional emails and notifications | Account, business, usage, order data | Performance of a contract |
| Bill Sellers and collect fees | Billing data | Performance of a contract; legal obligation (tax) |
| Verify Seller identity and licences; prevent fraud, abuse, phishing and counterfeit sales | Business, usage, technical data | Legal obligation; legitimate interests (platform integrity) |
| Provide support and respond to enquiries | Contact and communication data | Performance of a contract; legitimate interests |
| Secure the platform: monitor logins, detect attacks, keep audit logs | Technical and usage data | Legitimate interests; legal obligation |
| Improve the product and understand usage (aggregated and pseudonymised wherever possible) | Usage and technical data | Legitimate interests |
| Send Sellers marketing about Kartlo features, plans and events | Contact data | Consent (withdraw any time) or legitimate interests for existing customers, with opt-out |
| Comply with law: tax records, regulatory requests, court orders | All relevant data | Legal obligation |
| Process Shopper data for Sellers | Shopper data | We act on the Seller's instructions under our Data Processing Agreement; the Seller holds the legal basis |
We do not sell personal data. We do not use Shopper data to advertise to Shoppers, to build cross-store profiles, or for any purpose other than serving the store they interacted with.
4. Automated decisions
We use automated systems to flag fraud, spam, phishing and prohibited goods, and to enforce plan limits. Where an automated decision would significantly affect you (for example suspending a store), a person reviews it before or promptly after it takes effect, and you can ask us to reconsider by contacting privacy@kartlo.app.
5. Who we share data with
We share data only as needed to run the service:
- Sub-processors: hosting and infrastructure, database and backup, content delivery, email delivery, SMS and WhatsApp messaging, payment processing, customer-support tooling, analytics and error monitoring. The current list, with locations, is available on request from legal@kartlo.app. We notify Sellers at least 30 days before adding a sub-processor that will handle Shopper data.
- Payment providers the Seller connects (for example Stripe). They are independent controllers of the payment data they collect.
- Couriers and shipping aggregators the Seller uses, who receive the name, address and phone needed to deliver.
- Sellers receive the Shopper data collected through their own store.
- Professional advisers (lawyers, accountants, auditors, insurers) under confidentiality.
- Authorities where the law requires it or to protect rights, safety or property.
- A buyer or successor if Kartlo is sold or merges, in which case this policy continues to apply and we will notify you.
6. Sellers and Shopper data: our processor terms
When a Seller uses Kartlo to collect Shopper data, we act as processor under our Data Processing Agreement (available on request from legal@kartlo.app), which forms part of the Seller Terms. In summary, we:
- process Shopper data only on the Seller's documented instructions and for providing the service;
- keep it confidential and apply the security measures in Section 8;
- use only sub-processors bound by equivalent obligations;
- help the Seller respond to Shopper rights requests, breach notifications and impact assessments;
- delete or return Shopper data when the Seller's account ends, subject to Section 9;
- never use Shopper data for our own marketing or to build profiles across stores.
Sellers are responsible for having a lawful basis to collect Shopper data, publishing an accurate privacy policy on their store, obtaining consent for marketing, and honouring Shopper requests. Kartlo provides tools for consent capture, export and deletion to support this.
7. International transfers
Kartlo’s primary data hosting is on AWS ap-southeast-1 (Singapore) through our infrastructure providers. Some sub-processors operate in other countries, including the European Economic Area, the United Kingdom and the United States.
Where personal data leaves the UAE, the EEA or the UK, we rely on: transfers to countries recognised as providing adequate protection; the Standard Contractual Clauses of the European Commission and the UK Addendum; the EU–US Data Privacy Framework where the recipient is certified; and any mechanism approved under the UAE Personal Data Protection Law. Copies of the safeguards are available on request.
Sellers selling to residents of countries with data-localisation rules (for example Saudi Arabia) are responsible for confirming that the region Kartlo offers meets their obligations.
8. Security
We protect data with measures including encryption in transit (TLS) and at rest, tenant isolation so that each store’s data is logically separated and access-controlled, multi-factor authentication for Kartlo staff and offered to Sellers, role-based access, logging and monitoring, regular backups, vulnerability scanning, and staff training. Payment card data is handled by PCI DSS–compliant providers; Kartlo does not store card numbers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant authority and affected Sellers without undue delay and, where required, within 72 hours of becoming aware, and support Sellers in notifying their Shoppers.
Report security issues to security@kartlo.app.
9. How long we keep data
| Data | Retention |
|---|---|
| Seller account and business data | For the life of the account, then deleted 30 days after closure (backups purge within 90 days) |
| Invoices, tax and billing records | 5 years after the relevant tax year (UAE), or longer if another applicable law requires |
| Shopper data held for a Seller | Under the Seller's control while the store is active; deleted 30 days after the Seller closes the store unless the Seller exports or deletes it earlier |
| Support communications | 3 years after the ticket closes |
| Security and audit logs | 12 months, longer if needed for an investigation |
| Marketing consents and opt-outs | For as long as needed to honour the choice |
| Visitor analytics | 14 months, aggregated |
Before deleting a closed store, we give the Seller the ability to export products, customers and orders.
10. Cookies and similar technologies
On kartlo.app and the Seller dashboard we use:
- Essential cookies for sign-in, security, load balancing and remembering your language. These cannot be switched off.
- Analytics cookies to understand how the site and product are used. Set only with your consent where the law requires it.
- Marketing cookies to measure our own advertising. Set only with your consent.
You can change your choices at any time through your browser settings. A full list of cookies is available on request from privacy@kartlo.app.
Stores built on Kartlo set cookies needed to run the store (cart, session, language, currency). Sellers control any analytics or marketing pixels added to their store and must obtain consent through the cookie banner Kartlo provides.
11. Marketing communications
We send Sellers product news and offers by email only where permitted, and every message includes an unsubscribe link. Unsubscribing does not stop essential service messages (billing, security, changes to terms).
Marketing sent by Sellers to Shoppers through Kartlo (email, SMS, WhatsApp) requires the Seller to hold the Shopper’s consent. Every such message includes an opt-out. If you opt out of a store’s messages, we record it and block further marketing from that store through our platform.
12. Your rights
Depending on where you live, you may have the right to: access your personal data; correct it; delete it; restrict or object to processing; receive a copy in a portable format; withdraw consent; not be subject to solely automated decisions with legal or similar effects; and complain to a supervisory authority.
Visitors and Sellers: email privacy@kartlo.app or use the account settings page, where Sellers can update details, export their data, and delete their account. We respond within 30 days (or the period the applicable law requires) and may ask you to verify your identity.
Shoppers: contact the store you shopped with; its contact details are in its footer. If you cannot reach them or they do not respond, email us and we will assist. Shoppers with an account at a store can view, correct, export or delete their data from their account page.
Residents of the EEA/UK may complain to their national data protection authority. UAE residents may contact the UAE Data Office. California residents have rights under the CCPA/CPRA, including to know, delete, correct and opt out of “sale” or “sharing” (we do neither) without discrimination.
13. Children
Kartlo is not directed at anyone under 18. Sellers must be 18 or older to hold an account. We do not knowingly collect data from children; if you believe a child has provided data to us or to a store on Kartlo, contact privacy@kartlo.app and we will delete it. Sellers selling age-restricted goods are responsible for age verification.
14. Third-party links and services
Stores on Kartlo and our own site may link to third-party sites and services (payment providers, couriers, social networks). Their privacy practices are their own; read their policies.
15. Changes to this policy
We may update this policy. We will post the new version here with a new “last updated” date and, for material changes, notify Sellers by email or in the dashboard at least 30 days before they take effect. Continued use after that date means you accept the updated policy.
16. Contact
Data protection contact: LouWard Labs privacy team
Email: privacy@kartlo.app
Operator: LouWard Labs, United Arab Emirates