Data Safety
ArrayCart isolates each tenant's business data per workspace and separates it from website, analytics and payment data. Access is protected by single sign-on, two-factor authentication and audit trails.
- Per-workspace data isolation
- TOTP two-factor authentication
- Encrypted credentials and full audit trails
- Effective date
- April 10, 2026
- Last reviewed
- July 19, 2026
- Measurement
- GA4 + Meta Pixel
- Isolation
- Per-tenant workspaces
Two data contexts
ArrayCart website and account data is handled separately from the business data a tenant enters into the platform.
ArrayCart website and account
The website collects the fields needed for waitlist, signup, subscription request, newsletter, support and contact forms. GA4/GTM analytics and Meta Pixel load automatically on website visits. Our payment provider processes payment, checkout, subscription and transaction workflows.
Tenant business data on the platform
When a tenant uses ArrayCart, the employees, customers, orders, inventory, accounting entries and messages they enter are hosted and processed by ArrayCart on the tenant's behalf. Each workspace's data is isolated from other tenants, and ArrayCart processes it only on the tenant's instructions to deliver the service.
Website data map
| Data | Collected | Purpose |
|---|---|---|
| Name, phone number, interested package, email, business type, subject, message body and optional product-update consent | Yes | Waitlist, signup, subscription request, newsletter, support and contact workflows. |
| GA4 page and session analytics | On website visits | Aggregate website performance and content measurement. |
| Payment, invoice, tax and subscription records | Yes, through our payment provider | Checkout, payment processing, subscription management, refunds and compliance. |
| Advertising pixels and retargeting | On website visits | Meta Pixel measures page visits, pricing visits and new waitlist conversions. |
| Heatmaps and session recordings | No | ArrayCart does not use heatmap or session recording tools. |
Platform data map
ArrayCart processes the business data a tenant enters as a processor, on the tenant's instructions.
| Business data on the platform | Role | Isolation |
|---|---|---|
| Employee, payroll and attendance records | Processed on the tenant's behalf | Isolated to the tenant's workspace. |
| Customer, order and inventory records | Processed on the tenant's behalf | Isolated to the tenant's workspace. |
| Accounting and business finance entries | Processed on the tenant's behalf | Isolated to the tenant's workspace. |
| Marketing and inbox messages | Processed on the tenant's behalf | Isolated to the tenant's workspace. |
| User accounts, roles and audit trails | Account data ArrayCart controls to run the platform | Scoped to the tenant's workspace. |
Tenant responsibilities
Tenants control the business data they enter into ArrayCart and how their own users access it.
If you use ArrayCart to manage your business, you are responsible for the accuracy and lawful basis of the data you enter, for maintaining your own customer-facing privacy notices where required, for managing your workspace users and roles, and for handling data-subject requests relating to the people whose data you add to the platform.
- Maintain a privacy notice for your customers and employees where your local obligations require one.
- Manage your workspace users, roles and two-factor authentication so only authorized people can access your data.
- Handle access, correction and deletion requests for the individuals whose data you enter into ArrayCart.
- Do not send secrets, full card numbers, passwords or unnecessary data exports to ArrayCart support.
Security measures
Transport
ArrayCart serves website and platform traffic over HTTPS, uses single sign-on and TOTP two-factor authentication, and applies per-endpoint rate limiting to protect access.
Access
Data access is limited by per-tenant and per-workspace isolation and by role-based controls, and is recorded in full audit trails for support, billing, analytics or legal purposes.
Storage
ArrayCart does not store card details, keeps credentials encrypted at rest, and stores each tenant's business data isolated within its own workspace.
Sub-processors and providers
| Provider | Purpose | Data involved |
|---|---|---|
| Google Analytics 4 | Aggregate website analytics | Website usage, device, browser and approximate location signals. |
| Meta Platforms, Inc. | Advertising and conversion measurement | Page visits, pricing-page visits and successful new waitlist conversions. Waitlist names and phone numbers are not included in Pixel events. |
| Payment provider | Payment processing and card handling | Checkout, subscription and transaction data required to complete payment. |
| Hosting provider | Platform and website hosting and security | Server logs and operational security data. |
Breach response
If ArrayCart becomes aware of a personal data breach affecting data under ArrayCart control, we will investigate, contain the issue, notify affected tenants and people where required, and notify supervisory authorities where required by law.
Tenants remain responsible for assessing and, where required, notifying about incidents that arise from how their own workspace users, credentials and exported data are handled outside ArrayCart.
Contact
Data safety questions can be sent to [email protected]. For privacy rights, include the email address connected to your ArrayCart signup, newsletter, support, checkout or subscription record.
Email data safety questionRelated policies
Each page covers one part of how ArrayCart handles privacy, payments, subscriptions, refunds, and accessibility.
Privacy Policy
What the ArrayCart website collects, why it is used, cookie consent behavior, and how to exercise privacy rights.
Read policyRefund Policy
The 60-day ArrayCart subscription refund guarantee and how refund requests are handled.
Read policyTerms of Service
The terms for using the ArrayCart website and ArrayCart subscriptions.
Read policyNeed a privacy, billing, or accessibility answer?
Email ArrayCart. We route rights requests, refund questions, and accessibility reports to the right place.
