Français

BeamCart — Privacy Policy

Effective date: August 4, 2026 Last updated: September 2, 2026

BeamCart ("BeamCart", "we", "us") is a live video shopping app for Shopify. This policy explains what data BeamCart processes when a merchant installs and uses the app, how we use it, and the rights of merchants and their customers.

This policy is published by Barracuda Piscines Spas Béton inc. (110, rue George, unité 100). For any privacy question or request, contact us at support@beamcart.shop.


1. Summary

BeamCart lets a merchant's staff ("advisors") take live video calls from store visitors and add recommended products to the visitor's cart during the call.

BeamCart is designed to hold as little personal data as possible. In particular:

2. Data we process

2.1 Merchant / store data

When you install BeamCart, we store, for your store only:

2.2 Advisor accounts

For each advisor account you create, we store a username, a password hash (scrypt — the password itself is never stored in clear text), whether the account is a manager, and whether it is active.

An advisor may, if they wish, add a profile photo from their console. It is shown to your store's visitors when the advisor invites them to a call (the invitation card), and on their avatar in the console. It is optional, removable at any time by the advisor themselves, and deleted with the store's data on uninstall.

2.3 Call activity log

For each call we store an operational record containing: a random session identifier, timestamps (queued, claimed, ended), the advisor's name, the call language (fr/en), the customer's device type ("mobile" or "desktop"), whether it came from an invitation link, a transfer count, and the details of the products pushed to the cart (product name, variant and public price — this is data from your catalog, never customer data), with the name of the advisor who pushed each product. The advisor can also declare a sale closed outside the online store (optional amount) — an action by the employee for their own statistics, containing no customer data and never billed. This record is used for the merchant's own statistics, the advisor's history, and to measure usage against the billing plan (included call minutes and, where applicable, billable extra minutes).

The only pieces of customer personal data this record may contain are the first name the customer typed in themselves, if they typed one — it is optional and capped at 60 characters — and the free-text comment they may leave, just as optionally, when rating their call at the end (see below). The first name lets the advisor recognise their own calls for the day in the console ("Julie" rather than an identifier). The first name and the comment are deleted automatically 30 days after the call: the activity row remains for statistics and billing, but without them. No other end-customer personal data is stored — no email, no phone number, no address, no conversation content.

End-of-call rating. At the end of a call, the customer may — if they wish — rate their advisor and the call experience from 1 to 5, with an optional comment (400 characters at most). The ratings are anonymous numbers attached to the call and kept for the merchant's statistics; the comment follows the same rule as the first name (automatic deletion after 30 days).

2.4 On your Shopify orders

When an advisor pushes a product to a cart, BeamCart adds two hidden line-item properties to the resulting order in your Shopify store: the advisor's name (_Conseiller) and the call's session id (_AppelId). This lets your sales report attribute a sale to the advisor who assisted it. This data lives in your Shopify order, under your control.

Since September 2, 2026 the sales report does not rely on these properties alone: it cross-checks them against the server's call log (§2.3), which knows which advisor took the call and pushed each item — a property that matches no known call attributes nothing.

2.5 Billing ledger

To compute your plan's usage fees (commission on assisted sales and, where applicable, call minutes), we keep an audit ledger containing: the Shopify order number, the attributed amount (in your store's currency and converted to US dollars), and transmission timestamps. These amounts and call minutes are transmitted to Shopify (which handles all billing) as technical identifiers and quantities — they contain no personal data. Currency conversion uses a public exchange-rate service that receives no data from your store.

2.6 Advisors' internal notes

Your advisors can write free-text follow-up notes (a label and a body of their choosing) in their console. These notes belong to your store: they are visible only to your advisors, BeamCart attaches no Shopify customer data to them, and they are deleted with the store's data on uninstall. What goes into these notes is entirely your team's choice; if you record personal information in them, you remain responsible for it.

Team messages. Your advisors can also send each other short messages in their console (floor coordination) — to the whole team, to one colleague, or in a small group. These messages belong to your store: they are visible only to the conversation's members, BeamCart attaches no Shopify customer data to them, and they are kept for 180 days at most, then erased automatically — and deleted with the store's data on uninstall. When you delete an advisor account, their private conversations are erased and they are removed from groups. As with the notes above, what goes into them is entirely your team's choice; if personal information is recorded there, you remain responsible for it.

2.7 Local storage in the browser

On the storefront (the shopper). The widget uses the browser's sessionStorage — scoped to the tab and cleared when it closes — to let an in-progress call survive page navigation: the call session identifier and the state of the microphone and camera. Nothing is kept after the tab is closed.

Presence on the storefront. So that advisors can see who is browsing the store right now and offer help (a call invitation), the widget periodically transmits a random identifier scoped to the tab (stored in sessionStorage) along with the page being viewed. If the visitor is logged into their customer account on the store, their first name is transmitted with the presence and shown to that store's advisors — the same first name the call queue already displays during a call. The invitation may be sent by an advisor, or automatically when the merchant enables that setting (at most once per visit) — either way it is the same discreet card, which the visitor is free to ignore. This information is kept in server memory only — never in a database — and disappears less than three minutes after the visitor leaves. It can neither recognize a logged-out visitor across visits nor reconstruct a browsing history.

In the console (the advisor). The console uses the device's localStorage for its authentication token (see §2.2) and for preferences specific to that device: language, theme, display density, microphone, camera and audio-output selection, alert sound level and tone, sound-reminder cadence, background blur, alerts on/off, mirror view. It uses sessionStorage to remember which store it is serving. If an advisor works without a database, their follow-up notes also stay on their device (see §2.6).

BeamCart sets no advertising or tracking cookies.

2.8 Notification subscriptions

When an advisor turns on alerts in their console, we store a notification subscription issued by their browser: a technical device address (provided by their browser's notification service), two encryption keys that let us send them a message, their advisor name and their language. This subscription is used only to tell them a customer is waiting in the queue or that an appointment starts in ten minutes. It is deleted when they turn alerts off, when their browser tells us the subscription is no longer valid, and with the store's data on uninstall.

2.9 Video appointments

If the merchant enables appointment booking (offered to a visitor when no advisor is available), the customer picks a time slot and types in their own details. For each appointment we store: the slot's date and time, the customer's name and email, their phone and topic if given, the language, the store page they booked from, the status (booked, showed up, cancelled) and a random identifier that serves as the link to join the call at the scheduled time. These details let the advisor recognise the customer and pass them the call link.

Appointment emails. BeamCart may send the customer, on the store's behalf, the emails strictly tied to their appointment: the confirmation with the call link, and a reminder if an advisor triggers one. These emails are sent from support@beamcart.shop (through our email provider, see §5) with the store's name as the displayed sender, and replies go straight to the store's email. No newsletters, no marketing: only the emails of the appointment the customer booked themselves. If sending is not configured, the advisor sends the link from their own mailbox.

The name, email, phone and topic are erased automatically 30 days after the appointment; the row remains without them for statistics. Days the merchant marks unavailable are a store setting containing no personal data.

3. How we use data

We use the data above only to: provide the live-call and push-to-cart service; authenticate advisors; produce the merchant's own statistics and sales report; send queue notifications to advisors (browser notifications and web push, when the advisor enables them); operate billing; and keep the service secure and reliable. We do not sell data, and we do not use it for advertising or profiling.

4. Legal bases (GDPR) and Quebec Law 25

Where the GDPR applies, we process data on the basis of the contract with the merchant (to provide the app) and our legitimate interest in operating and securing the service. Where Quebec's Act respecting the protection of personal information in the private sector (Law 25) applies, processing is necessary to provide the service the merchant requested. BeamCart acts as a data processor / service provider on behalf of the merchant, who is the controller for their customers' data.

5. Service providers (sub-processors)

BeamCart relies on:

Each provider processes data only as needed to deliver its part of the service.

6. Data retention

Merchant, advisor, settings and call-log records are kept while the app is installed. When you uninstall BeamCart, the Shopify access token is deleted and the store is marked uninstalled; residual operational records may be retained for a limited period for billing and accounting, then deleted. You may request earlier deletion at support@beamcart.shop.

Specific periods: a call's first name and comment, 30 days; an appointment's contact details, 30 days after the appointment; team messages, 180 days; the data assembled for a customer's access request (§8) stays available to the merchant in the app while the app is installed, so they can answer the customer.

7. Security

Access tokens are stored encrypted at rest (AES-256-GCM). Advisor passwords are stored only as scrypt hashes. Call audio/video is transmitted over encrypted WebRTC connections and is not recorded. Database connections are encrypted (TLS); an advisor's session token expires after 30 days and is revoked when the password changes.

8. Your rights

Depending on your jurisdiction, you (and your customers, through you) may have rights to access, correct, or delete personal data. The only customer personal data BeamCart may hold is that of a video appointment (§2.9) and, where applicable, an advisor's note that mentions the customer (§2.6).

Shopify's mandatory privacy webhooks are honored automatically:

9. International transfers

Data may be processed in countries where our service providers operate. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.

10. Children

BeamCart is a business tool and is not directed to children.

11. Changes to this policy

We may update this policy; the "Last updated" date will change accordingly. Material changes will be communicated to merchants.

12. Contact

Barracuda Piscines Spas Béton inc. 110, rue George, unité 100 Privacy contact: support@beamcart.shop