Skip to content

Data Safety

ArrayCart isolates each tenant's business data per workspace and separates it from website, analytics and payment data. Access is protected by single sign-on, two-factor authentication and audit trails.

  • Per-workspace data isolation
  • TOTP two-factor authentication
  • Encrypted credentials and full audit trails
Effective date
April 10, 2026
Last reviewed
July 19, 2026
Measurement
GA4 + Meta Pixel
Isolation
Per-tenant workspaces

Two data contexts

ArrayCart website and account data is handled separately from the business data a tenant enters into the platform.

ArrayCart website and account

The website collects the fields needed for waitlist, signup, subscription request, newsletter, support and contact forms. GA4/GTM analytics and Meta Pixel load automatically on website visits. Our payment provider processes payment, checkout, subscription and transaction workflows.

Tenant business data on the platform

When a tenant uses ArrayCart, the employees, customers, orders, inventory, accounting entries and messages they enter are hosted and processed by ArrayCart on the tenant's behalf. Each workspace's data is isolated from other tenants, and ArrayCart processes it only on the tenant's instructions to deliver the service.

Website data map

ArrayCart website data map
DataCollectedPurpose
Name, phone number, interested package, email, business type, subject, message body and optional product-update consentYesWaitlist, signup, subscription request, newsletter, support and contact workflows.
GA4 page and session analyticsOn website visitsAggregate website performance and content measurement.
Payment, invoice, tax and subscription recordsYes, through our payment providerCheckout, payment processing, subscription management, refunds and compliance.
Advertising pixels and retargetingOn website visitsMeta Pixel measures page visits, pricing visits and new waitlist conversions.
Heatmaps and session recordingsNoArrayCart does not use heatmap or session recording tools.

Platform data map

ArrayCart processes the business data a tenant enters as a processor, on the tenant's instructions.

ArrayCart platform data map
Business data on the platformRoleIsolation
Employee, payroll and attendance recordsProcessed on the tenant's behalfIsolated to the tenant's workspace.
Customer, order and inventory recordsProcessed on the tenant's behalfIsolated to the tenant's workspace.
Accounting and business finance entriesProcessed on the tenant's behalfIsolated to the tenant's workspace.
Marketing and inbox messagesProcessed on the tenant's behalfIsolated to the tenant's workspace.
User accounts, roles and audit trailsAccount data ArrayCart controls to run the platformScoped to the tenant's workspace.

Tenant responsibilities

Tenants control the business data they enter into ArrayCart and how their own users access it.

If you use ArrayCart to manage your business, you are responsible for the accuracy and lawful basis of the data you enter, for maintaining your own customer-facing privacy notices where required, for managing your workspace users and roles, and for handling data-subject requests relating to the people whose data you add to the platform.

  • Maintain a privacy notice for your customers and employees where your local obligations require one.
  • Manage your workspace users, roles and two-factor authentication so only authorized people can access your data.
  • Handle access, correction and deletion requests for the individuals whose data you enter into ArrayCart.
  • Do not send secrets, full card numbers, passwords or unnecessary data exports to ArrayCart support.

Security measures

Transport

ArrayCart serves website and platform traffic over HTTPS, uses single sign-on and TOTP two-factor authentication, and applies per-endpoint rate limiting to protect access.

Access

Data access is limited by per-tenant and per-workspace isolation and by role-based controls, and is recorded in full audit trails for support, billing, analytics or legal purposes.

Storage

ArrayCart does not store card details, keeps credentials encrypted at rest, and stores each tenant's business data isolated within its own workspace.

Sub-processors and providers

Sub-processors and providers
ProviderPurposeData involved
Google Analytics 4Aggregate website analyticsWebsite usage, device, browser and approximate location signals.
Meta Platforms, Inc.Advertising and conversion measurementPage visits, pricing-page visits and successful new waitlist conversions. Waitlist names and phone numbers are not included in Pixel events.
Payment providerPayment processing and card handlingCheckout, subscription and transaction data required to complete payment.
Hosting providerPlatform and website hosting and securityServer logs and operational security data.

Breach response

If ArrayCart becomes aware of a personal data breach affecting data under ArrayCart control, we will investigate, contain the issue, notify affected tenants and people where required, and notify supervisory authorities where required by law.

Tenants remain responsible for assessing and, where required, notifying about incidents that arise from how their own workspace users, credentials and exported data are handled outside ArrayCart.

Contact

Data safety questions can be sent to [email protected]. For privacy rights, include the email address connected to your ArrayCart signup, newsletter, support, checkout or subscription record.

Email data safety question
Contact

Need a privacy, billing, or accessibility answer?

Email ArrayCart. We route rights requests, refund questions, and accessibility reports to the right place.

Messenger