Security
Security Practices
Carro is built to support secure retail checkout, inventory management, and account access. This page summarizes the safeguards currently documented for public users and business customers.
Last updated: 2026-07-02
1. Transport and account security
- Carro should be served over HTTPS/TLS in production environments.
- Account authentication uses server-managed session cookies instead of exposing raw session tokens to client JavaScript.
- Passwords are validated before account creation and are not stored as plain text.
- Password reset tokens and remember-device tokens are designed to be limited-use or limited-lifetime credentials.
- Users are responsible for keeping passwords, devices, QR codes, and employee accounts secure.
2. Payments
Carro uses Stripe and Stripe Connect for payment-related workflows. Carro does not intend to store full payment card numbers. Stripe may collect and process payment details, connected-account onboarding details, identity verification information, fraud signals, and bank/account information under Stripe's own terms and security program.
3. Data storage and service providers
Carro stores account, store, inventory, cart, transaction, receipt, and operational records needed to provide the service. Product photos or store assets may be stored with object-storage providers such as Cloudflare R2 when enabled. Transactional emails may be sent through email providers such as Resend.
See the Privacy Policy for more detail about data categories, purposes, retention, vendors, and user rights.
4. Access controls and operations
- Retailer tools are separated from shopper checkout flows.
- Employee access should be limited to authorized users and removed when access is no longer needed.
- Administrative and production access should be limited to people who need it for operations, support, security, or legal compliance.
- Sensitive configuration such as API keys, database credentials, and payment credentials should be managed through environment variables or deployment secrets, not committed to source control.
5. Monitoring, backups, and incident response
Carro may use hosting, logging, analytics, and error-monitoring providers to maintain service reliability, investigate errors, and respond to abuse or security incidents. Backup, retention, and recovery practices should be tested before public launch and reviewed as the product matures.
If Carro becomes aware of a security incident affecting personal information, Carro will evaluate notice obligations under applicable law and notify affected users, business customers, regulators, or service providers where legally required.
6. Responsible disclosure
If you believe you have found a security vulnerability, please email founder@carro-app.com with enough detail for us to reproduce and assess the issue. Please do not access, modify, delete, exfiltrate, or publicly disclose data that is not yours.
Privacy questions or data-rights requests should be sent to privacy@carro-app.com.
Carro LLC