BeamCart — Privacy Policy
Effective date: August 4, 2026 Last updated: September 2, 2026
BeamCart ("BeamCart", "we", "us") is a live video shopping app for Shopify. This policy explains what data BeamCart processes when a merchant installs and uses the app, how we use it, and the rights of merchants and their customers.
This policy is published by Barracuda Piscines Spas Béton inc. (110, rue George, unité 100). For any privacy question or request, contact us at support@beamcart.shop.
1. Summary
BeamCart lets a merchant's staff ("advisors") take live video calls from store visitors and add recommended products to the visitor's cart during the call.
BeamCart is designed to hold as little personal data as possible. In particular:
- We do not store the video or audio of calls. They are transmitted live for the duration of a call and are never recorded.
- We hold very little personal data about your store's customers: only the details a customer types in themselves to book a video appointment (name, email, optional phone and topic — see §2.9), erased automatically 30 days after the appointment, and the optional first name of a call (§2.3). Never an address, never conversation content.
- We use read-only access to your product catalog, orders and customer list. From orders we only read line items and amounts (to attribute sales to advisors and compute billing). When an advisor uses the console search, BeamCart queries your Shopify customer list live (name, email, phone, order count, total spent): results are displayed on screen and then forgotten — never copied or stored by BeamCart. BeamCart never has permission to write to carts or checkout through the Shopify Admin API — products are added to the cart entirely in the shopper's browser.
2. Data we process
2.1 Merchant / store data
When you install BeamCart, we store, for your store only:
- your
.myshopify.comdomain and public domain; - the Shopify Admin API access token issued to BeamCart at installation, stored encrypted (AES-256-GCM), used to read your product catalog and cross-reference which assisted calls led to a paid order;
- a Storefront API token (encrypted) used to power product search inside the advisor console;
- your settings: button position, language, statistics time zone, and console opening hours;
- your billing plan identifier and, on the free plan, your choice to allow or not billing of call minutes beyond the included quota.
2.2 Advisor accounts
For each advisor account you create, we store a username, a password hash (scrypt — the password itself is never stored in clear text), whether the account is a manager, and whether it is active.
An advisor may, if they wish, add a profile photo from their console. It is shown to your store's visitors when the advisor invites them to a call (the invitation card), and on their avatar in the console. It is optional, removable at any time by the advisor themselves, and deleted with the store's data on uninstall.
2.3 Call activity log
For each call we store an operational record containing: a random session
identifier, timestamps (queued, claimed, ended), the advisor's name, the
call language (fr/en), the customer's device type ("mobile" or
"desktop"), whether it came from an invitation link, a transfer count, and the
details of the products pushed to the cart (product name, variant and public
price — this is data from your catalog, never customer data), with the
name of the advisor who pushed each product. The advisor
can also declare a sale closed outside the online store (optional amount) —
an action by the employee for their own statistics, containing no customer data
and never billed. This record is used for the merchant's own statistics, the
advisor's history, and to measure usage against the billing plan (included call
minutes and, where applicable, billable extra minutes).
The only pieces of customer personal data this record may contain are the first name the customer typed in themselves, if they typed one — it is optional and capped at 60 characters — and the free-text comment they may leave, just as optionally, when rating their call at the end (see below). The first name lets the advisor recognise their own calls for the day in the console ("Julie" rather than an identifier). The first name and the comment are deleted automatically 30 days after the call: the activity row remains for statistics and billing, but without them. No other end-customer personal data is stored — no email, no phone number, no address, no conversation content.
End-of-call rating. At the end of a call, the customer may — if they wish — rate their advisor and the call experience from 1 to 5, with an optional comment (400 characters at most). The ratings are anonymous numbers attached to the call and kept for the merchant's statistics; the comment follows the same rule as the first name (automatic deletion after 30 days).
2.4 On your Shopify orders
When an advisor pushes a product to a cart, BeamCart adds two hidden line-item
properties to the resulting order in your Shopify store: the advisor's name
(_Conseiller) and the call's session id (_AppelId). This lets your sales
report attribute a sale to the advisor who assisted it. This data lives in your
Shopify order, under your control.
Since September 2, 2026 the sales report does not rely on these properties alone: it cross-checks them against the server's call log (§2.3), which knows which advisor took the call and pushed each item — a property that matches no known call attributes nothing.
2.5 Billing ledger
To compute your plan's usage fees (commission on assisted sales and, where applicable, call minutes), we keep an audit ledger containing: the Shopify order number, the attributed amount (in your store's currency and converted to US dollars), and transmission timestamps. These amounts and call minutes are transmitted to Shopify (which handles all billing) as technical identifiers and quantities — they contain no personal data. Currency conversion uses a public exchange-rate service that receives no data from your store.
2.6 Advisors' internal notes
Your advisors can write free-text follow-up notes (a label and a body of their choosing) in their console. These notes belong to your store: they are visible only to your advisors, BeamCart attaches no Shopify customer data to them, and they are deleted with the store's data on uninstall. What goes into these notes is entirely your team's choice; if you record personal information in them, you remain responsible for it.
Team messages. Your advisors can also send each other short messages in their console (floor coordination) — to the whole team, to one colleague, or in a small group. These messages belong to your store: they are visible only to the conversation's members, BeamCart attaches no Shopify customer data to them, and they are kept for 180 days at most, then erased automatically — and deleted with the store's data on uninstall. When you delete an advisor account, their private conversations are erased and they are removed from groups. As with the notes above, what goes into them is entirely your team's choice; if personal information is recorded there, you remain responsible for it.
2.7 Local storage in the browser
On the storefront (the shopper). The widget uses the browser's
sessionStorage — scoped to the tab and cleared when it closes — to let an
in-progress call survive page navigation: the call session identifier and the
state of the microphone and camera. Nothing is kept after the tab is closed.
Presence on the storefront. So that advisors can see who is browsing the
store right now and offer help (a call invitation), the widget periodically
transmits a random identifier scoped to the tab (stored in
sessionStorage) along with the page being viewed. If the visitor is logged
into their customer account on the store, their first name is
transmitted with the presence and shown to that store's advisors — the same
first name the call queue already displays during a call. The invitation may
be sent by an advisor, or automatically when the merchant enables that
setting (at most once per visit) — either way it is the same discreet card,
which the visitor is free to ignore. This information is
kept in server memory only — never in a database — and disappears less
than three minutes after the visitor leaves. It can neither recognize a
logged-out visitor across visits nor reconstruct a browsing history.
In the console (the advisor). The console uses the device's localStorage
for its authentication token (see §2.2) and for preferences specific to that
device: language, theme, display density, microphone, camera and audio-output
selection, alert sound level and tone, sound-reminder cadence, background
blur, alerts on/off, mirror view. It uses sessionStorage to remember which store it
is serving. If an advisor works without a database, their follow-up notes also
stay on their device (see §2.6).
BeamCart sets no advertising or tracking cookies.
2.8 Notification subscriptions
When an advisor turns on alerts in their console, we store a notification subscription issued by their browser: a technical device address (provided by their browser's notification service), two encryption keys that let us send them a message, their advisor name and their language. This subscription is used only to tell them a customer is waiting in the queue or that an appointment starts in ten minutes. It is deleted when they turn alerts off, when their browser tells us the subscription is no longer valid, and with the store's data on uninstall.
2.9 Video appointments
If the merchant enables appointment booking (offered to a visitor when no advisor is available), the customer picks a time slot and types in their own details. For each appointment we store: the slot's date and time, the customer's name and email, their phone and topic if given, the language, the store page they booked from, the status (booked, showed up, cancelled) and a random identifier that serves as the link to join the call at the scheduled time. These details let the advisor recognise the customer and pass them the call link.
Appointment emails. BeamCart may send the customer, on the store's behalf, the emails strictly tied to their appointment: the confirmation with the call link, and a reminder if an advisor triggers one. These emails are sent from support@beamcart.shop (through our email provider, see §5) with the store's name as the displayed sender, and replies go straight to the store's email. No newsletters, no marketing: only the emails of the appointment the customer booked themselves. If sending is not configured, the advisor sends the link from their own mailbox.
The name, email, phone and topic are erased automatically 30 days after the appointment; the row remains without them for statistics. Days the merchant marks unavailable are a store setting containing no personal data.
3. How we use data
We use the data above only to: provide the live-call and push-to-cart service; authenticate advisors; produce the merchant's own statistics and sales report; send queue notifications to advisors (browser notifications and web push, when the advisor enables them); operate billing; and keep the service secure and reliable. We do not sell data, and we do not use it for advertising or profiling.
4. Legal bases (GDPR) and Quebec Law 25
Where the GDPR applies, we process data on the basis of the contract with the merchant (to provide the app) and our legitimate interest in operating and securing the service. Where Quebec's Act respecting the protection of personal information in the private sector (Law 25) applies, processing is necessary to provide the service the merchant requested. BeamCart acts as a data processor / service provider on behalf of the merchant, who is the controller for their customers' data.
5. Service providers (sub-processors)
BeamCart relies on:
- Shopify — the platform on which the app runs and the source of catalog and order data;
- LiveKit Cloud — real-time relay of call audio/video for the duration of a call (not recorded);
- Railway — application hosting and the PostgreSQL database that stores the data described in section 2;
- Brevo — sending the appointment emails (§2.9): for each send it receives the customer's email and name, and the subject and text of the message. Nothing else, and never for advertising purposes.
Each provider processes data only as needed to deliver its part of the service.
6. Data retention
Merchant, advisor, settings and call-log records are kept while the app is installed. When you uninstall BeamCart, the Shopify access token is deleted and the store is marked uninstalled; residual operational records may be retained for a limited period for billing and accounting, then deleted. You may request earlier deletion at support@beamcart.shop.
Specific periods: a call's first name and comment, 30 days; an appointment's contact details, 30 days after the appointment; team messages, 180 days; the data assembled for a customer's access request (§8) stays available to the merchant in the app while the app is installed, so they can answer the customer.
7. Security
Access tokens are stored encrypted at rest (AES-256-GCM). Advisor passwords are stored only as scrypt hashes. Call audio/video is transmitted over encrypted WebRTC connections and is not recorded. Database connections are encrypted (TLS); an advisor's session token expires after 30 days and is revoked when the password changes.
8. Your rights
Depending on your jurisdiction, you (and your customers, through you) may have rights to access, correct, or delete personal data. The only customer personal data BeamCart may hold is that of a video appointment (§2.9) and, where applicable, an advisor's note that mentions the customer (§2.6).
Shopify's mandatory privacy webhooks are honored automatically:
customers/data_request— we assemble what we hold about that customer (appointments, notes mentioning them) and make it available to the merchant in the app, "Privacy" page, so they can hand it to the customer within the required time;customers/redact— we erase their appointment details (upcoming appointments are cancelled) and delete the notes that mention them;shop/redact— we delete all of the store's data after uninstall, appointments and access requests included.
9. International transfers
Data may be processed in countries where our service providers operate. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.
10. Children
BeamCart is a business tool and is not directed to children.
11. Changes to this policy
We may update this policy; the "Last updated" date will change accordingly. Material changes will be communicated to merchants.
12. Contact
Barracuda Piscines Spas Béton inc. 110, rue George, unité 100 Privacy contact: support@beamcart.shop