Data and vendors
Data Inventory and Vendor List
This page summarizes the main categories of data Carro processes and the vendors or subprocessors that may receive data to provide checkout, retail management, payment, email, storage, and support functionality.
Last updated: 2026-07-02
1. Scope and source of inventory
This inventory is based on the Carro application schema, public routes, checkout flow, authentication code, payment integration, upload utilities, and package dependencies reviewed during implementation. It should be updated whenever Carro adds new forms, cookies, analytics, marketing pixels, AI features, vendors, support tools, or payment flows.
2. Data categories
Account and authentication data
- Examples
- Email, display name, password hash, sessions, password reset tokens, remember-device tokens, user agent, IP hash, device label, timestamps.
- Purpose
- Create accounts, authenticate users, secure sessions, remember trusted devices, recover accounts, and prevent abuse.
- Systems
- Application database, authentication APIs, HTTP-only cookies, transactional email for password reset.
Store and employee data
- Examples
- Store name, slug, store email, phone, address, description, owner, employees, roles, invitations, onboarding status, logo, colors.
- Purpose
- Operate retailer workspaces, manage employee access, show public store context, and support onboarding.
- Systems
- Application database, upload storage for logos/assets, manager dashboard, onboarding flows.
Product and inventory data
- Examples
- Product names, prices, currency, sizes, images, image paths, SKU/QR code values, item status, stock counts, archive state.
- Purpose
- Manage inventory, generate QR-code checkout flows, display shopper product details, and maintain stock records.
- Systems
- Application database, QR/PDF utilities, upload storage for product photos, public product and checkout pages.
Cart, checkout, and transaction data
- Examples
- Cart IDs, cart lines, device IDs, item reservations, subtotal, payment-intent IDs, transaction status, purchase time, receipt email, refund status.
- Purpose
- Operate checkout, preserve carts, process payments, send receipts, verify sales, support refunds, and prevent stale holds.
- Systems
- Application database, browser storage/cookies for cart continuity, Stripe, receipt email delivery.
Support, legal, privacy, and security requests
- Examples
- Contact emails, request details, transaction or account identifiers submitted by users, vulnerability reports, privacy-rights requests.
- Purpose
- Respond to support, billing, privacy, accessibility, abuse, legal, and security inquiries.
- Systems
- Email inboxes at carro-app.com and any support workflow Carro later adopts.
Technical and operational data
- Examples
- IP address, user agent, request metadata, diagnostic logs, API events, error context, service-worker/app state, deployment/runtime metadata.
- Purpose
- Keep the service reliable and secure, investigate errors, prevent fraud/abuse, and maintain operational records.
- Systems
- Hosting/runtime logs, application database where applicable, optional monitoring/error tools if enabled.
3. Vendors and subprocessors
Stripe / Stripe Connect
- Role
- Payment processor and connected-account provider
- Data involved
- Payment details, payment intent IDs, connected-account onboarding details, identity/bank information, fraud signals, refunds, disputes, transaction metadata.
- Current status
- Active for payments and retailer onboarding when configured.
Database and hosting infrastructure
- Role
- Application hosting and database operations
- Data involved
- Application records, logs, environment/runtime metadata, and operational data needed to run Carro.
- Current status
- Active; exact provider depends on deployment environment.
Cloudflare R2 or compatible object storage
- Role
- Object storage for uploaded assets
- Data involved
- Store logos, product photos, upload paths, and related metadata.
- Current status
- Used when object storage is configured; local storage may be used in development.
Resend or transactional email provider
- Role
- Transactional email delivery
- Data involved
- Recipient email addresses, receipt/reset content, delivery metadata, message IDs, and email status.
- Current status
- Used when transactional email is configured.
PostHog or analytics provider
- Role
- Product or website analytics
- Data involved
- Usage events, page/activity metadata, device/browser information, and identifiers if enabled.
- Current status
- Not currently active in the reviewed package dependencies; require consent/notice controls before enabling non-essential tracking.
Sentry or error monitoring provider
- Role
- Error monitoring and diagnostics
- Data involved
- Error traces, stack traces, device/browser context, request metadata, and limited user/account context if configured.
- Current status
- Not currently active in the reviewed package dependencies; document and configure data minimization if enabled.
AI API providers, if later enabled
- Role
- AI-assisted features
- Data involved
- Prompts, inputs, outputs, and related metadata for AI features.
- Current status
- No active public AI provider dependency found in the reviewed package dependencies; add AI terms before enabling user-facing AI.
4. Retention and updates
Carro keeps personal information only as long as reasonably necessary for service delivery, security, legal compliance, dispute resolution, fraud prevention, financial records, and business operations. Specific retention periods vary by data type and legal need. Session, remember-device, and password reset records are designed to expire or become unusable after limited periods.
Carro should review this inventory before launch and after any material vendor, cookie, analytics, AI, payment, or data-model change.
5. Privacy requests and vendor questions
For privacy requests, vendor questions, or data-processing inquiries, email privacy@carro-app.com.
Carro LLC