BeamCart — Privacy Policy
Effective date: August 4, 2026 Last updated: August 13, 2026
BeamCart ("BeamCart", "we", "us") is a live video shopping app for Shopify. This policy explains what data BeamCart processes when a merchant installs and uses the app, how we use it, and the rights of merchants and their customers.
This policy is published by Barracuda Piscines Spas Béton inc. (110, rue George, unité 100). For any privacy question or request, contact us at support@beamcart.shop.
1. Summary
BeamCart lets a merchant's staff ("advisors") take live video calls from store visitors and add recommended products to the visitor's cart during the call.
BeamCart is designed to hold as little personal data as possible. In particular:
- We do not store the video or audio of calls. They are transmitted live for the duration of a call and are never recorded.
- We do not store the personal data of your store's customers (no names, no emails, no addresses).
- We use read-only access to your product catalog and orders. From orders we only read line items and amounts (to attribute sales to advisors and compute billing) — never your customers' identity fields. BeamCart never has permission to write to carts or checkout through the Shopify Admin API — products are added to the cart entirely in the shopper's browser.
2. Data we process
2.1 Merchant / store data
When you install BeamCart, we store, for your store only:
- your
.myshopify.comdomain and public domain; - the Shopify Admin API access token issued to BeamCart at installation, stored encrypted (AES-256-GCM), used to read your product catalog and cross-reference which assisted calls led to a paid order;
- a Storefront API token (encrypted) used to power product search inside the advisor console;
- your settings: button position, language, statistics time zone, and console opening hours;
- your billing plan identifier and, on the free plan, your choice to allow or not billing of call minutes beyond the included quota.
2.2 Advisor accounts
For each advisor account you create, we store a username, a password hash (scrypt — the password itself is never stored in clear text), whether the account is a manager, and whether it is active.
2.3 Call activity log
For each call we store an operational record containing: a random session
identifier, timestamps (queued, claimed, ended), the advisor's name, the
call language (fr/en), whether it came from an invitation link, a transfer
count, and a count of items pushed to the cart. This record is used for the
merchant's own statistics and to measure usage against the billing plan
(included call minutes and, where applicable, billable extra minutes).
This record contains no personal data about your customers. A logged-in customer's first name may be shown to the advisor during a call, but it is not saved.
2.4 On your Shopify orders
When an advisor pushes a product to a cart, BeamCart adds two hidden line-item
properties to the resulting order in your Shopify store: the advisor's name
(_Conseiller) and the call's session id (_AppelId). This lets your sales
report attribute a sale to the advisor who assisted it. This data lives in your
Shopify order, under your control.
2.5 Billing ledger
To compute your plan's usage fees (commission on assisted sales and, where applicable, call minutes), we keep an audit ledger containing: the Shopify order number, the attributed amount (in your store's currency and converted to US dollars), and transmission timestamps. These amounts and call minutes are transmitted to Shopify (which handles all billing) as technical identifiers and quantities — they contain no personal data. Currency conversion uses a public exchange-rate service that receives no data from your store.
2.6 Advisors' internal notes
Your advisors can write free-text follow-up notes (a label and a body of their choosing) in their console. These notes belong to your store: they are visible only to your advisors, BeamCart attaches no Shopify customer data to them, and they are deleted with the store's data on uninstall. What goes into these notes is entirely your team's choice; if you record personal information in them, you remain responsible for it.
2.7 Local storage in the browser
The store widget uses the browser's localStorage to let an in-progress call
survive page navigation; the advisor console uses sessionStorage to remember
which store it is serving. BeamCart sets no advertising or tracking cookies.
3. How we use data
We use the data above only to: provide the live-call and push-to-cart service; authenticate advisors; produce the merchant's own statistics and sales report; send queue notifications to advisors (browser notifications and web push, when the advisor enables them); operate billing; and keep the service secure and reliable. We do not sell data, and we do not use it for advertising or profiling.
4. Legal bases (GDPR) and Quebec Law 25
Where the GDPR applies, we process data on the basis of the contract with the merchant (to provide the app) and our legitimate interest in operating and securing the service. Where Quebec's Act respecting the protection of personal information in the private sector (Law 25) applies, processing is necessary to provide the service the merchant requested. BeamCart acts as a data processor / service provider on behalf of the merchant, who is the controller for their customers' data.
5. Service providers (sub-processors)
BeamCart relies on:
- Shopify — the platform on which the app runs and the source of catalog and order data;
- LiveKit Cloud — real-time relay of call audio/video for the duration of a call (not recorded);
- Railway — application hosting and the PostgreSQL database that stores the data described in section 2.
Each provider processes data only as needed to deliver its part of the service.
6. Data retention
Merchant, advisor, settings and call-log records are kept while the app is installed. When you uninstall BeamCart, the Shopify access token is deleted and the store is marked uninstalled; residual operational records may be retained for a limited period for billing and accounting, then deleted. You may request earlier deletion at support@beamcart.shop.
7. Security
Access tokens are stored encrypted at rest (AES-256-GCM). Advisor passwords are stored only as scrypt hashes. Call audio/video is transmitted over encrypted WebRTC connections and is not recorded.
8. Your rights
Depending on your jurisdiction, you (and your customers, through you) may have rights to access, correct, or delete personal data. Because BeamCart holds no personal data about your store's customers, a customer data request will normally confirm that we hold no such data.
Shopify's mandatory privacy webhooks are honored:
customers/data_request— we confirm what customer data we hold (normally none);customers/redact— we confirm there is no customer personal data to delete;shop/redact— we delete the store's data after uninstall.
9. International transfers
Data may be processed in countries where our service providers operate. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.
10. Children
BeamCart is a business tool and is not directed to children.
11. Changes to this policy
We may update this policy; the "Last updated" date will change accordingly. Material changes will be communicated to merchants.
12. Contact
Barracuda Piscines Spas Béton inc. 110, rue George, unité 100 Privacy contact: support@beamcart.shop