Privacy and legal

Privacy Policy

Last updated: 3 October 2026

This policy explains how Uncart handles personal data on the uncart.ai website, in the Uncart merchant app (dashboard and Shopify/Shopware app), and in the WhatsApp and SMS messages Uncart sends and answers on behalf of shops.

Who we are

Uncart is a trading name of Woomega LLC, represented by Jordan Feeney, Flat 2, 53 Vincent Square, London SW1P 2NR, United Kingdom. Contact: hi@uncart.ai.

Uncart has two roles, depending on whose data it is:

Whose dataUncart's roleWho decides how it is used
Shoppers who message a shop through UncartProcessor, on the shop's behalfThe shop (the controller)
Merchants who use the Uncart app, and visitors to uncart.aiControllerUncart

If you are a shopper, the shop you bought from or chatted with is responsible for your data. Uncart processes it only to run that shop's messaging, under a data processing agreement with the shop. You can still contact Uncart directly, and we will pass your request to the shop or act on it where we can.

If you are a shopper

Uncart only messages you after you opt in, and it stops for good when you write STOP. We process your data on behalf of the shop, for these purposes only: confirming your opt-in, reminding you about your basket, answering your questions, and recording which orders came through Uncart so the shop can be billed.

What we hold, and where it comes from

DataWhere it comes fromWhy
Your mobile number (encrypted) and a keyed fingerprint of itYou, when you opt in on the shop's site or message the shopTo send and receive messages, and to recognise your STOP
Your consent record: channel, how you opted in, the wording version, the timeCreated when you opt in or outTo prove you agreed, and that we stopped when you asked
Your messages with the shop and the assistant (encrypted)You and the shopTo answer you and let the shop step in
Your basket: products, quantities, value, the shop's basket and checkout tokensThe shop (Shopify or Shopware)To remind you about what you left
Orders placed after an Uncart message or link: order number, value, refundsThe shopTo credit the order to Uncart and bill the shop
Your customer id at the shop, if you were signed inThe shopTo link your basket to your opt-in
Whether you are in the comparison (holdout) groupCalculated by UncartTo measure whether reminders help, without profiling you

We do not store your IP address, browser details, email address, postal address or payment details. The shop's site does not set an Uncart cookie.

Legal basis. Your consent (GDPR Art. 6(1)(a)) for messages you opted into; the shop's legitimate interest (Art. 6(1)(f)) for answering messages you send and for order attribution; legal obligation (Art. 6(1)(c)) for keeping proof of your consent and of a deletion.

Your choices. Write STOP at any time. You get one confirmation and nothing after it. Only you can opt in again, from your own WhatsApp.

The AI assistant

The assistant's first reply always says it is an AI. Before any text reaches the AI model, Uncart removes phone numbers, email addresses, postal addresses, payment and ID numbers, birth dates, order and tracking numbers, and names. The model never receives your name, number or address.

  • What the model sees: the shop's name and tone, your basket, live stock, size guide, delivery, payment and returns terms, the shop's rules, and the conversation with those details removed.
  • Which model: Anthropic's Claude, run through Amazon Bedrock's EU service from Frankfurt. Requests may be processed in another EU region (for example Ireland, Paris, Stockholm, Milan or Spain). AWS states that Bedrock does not use prompts or replies to train models.
  • Checks: every reply is checked before it is sent, by fixed rules and by a second AI check. A reply that might invent stock, prices or discounts, or ask for personal data, is replaced by a standard reply.
  • No profiling and no automated decisions with legal or similarly significant effects.

If you are a merchant or visit uncart.ai

For this data Uncart is the controller.

DataWhyLegal basis
Account: email, sign-in records, an encrypted authenticator secret, fingerprints of recovery codes and known devicesTo let you and your team sign in securelyContract, Art. 6(1)(b)
Shop address you type on the Log in or Install pageTo find your shop and start the connection; it is not storedContract, Art. 6(1)(b)
Your IP address, sent to our sign-in provider during sign-inTo block risky sign-ins and breached passwordsLegitimate interest, Art. 6(1)(f)
Shop connection: shop address, name, time zone, settings, encrypted access tokens for Shopify, WhatsApp and TwilioTo run the service for your shopContract
Billing: shop name, amounts, Stripe customer and payment-method ids (you enter card or bank details on Stripe's own page)To bill youContract; legal obligation for records
Audit log of settings changes (who and when, never your email)Security and accountabilityLegitimate interest
Emails you send to hi@uncart.aiTo replyContract or legitimate interest

Cookies. The uncart.ai website sets no cookies and uses no analytics or third-party content. Its access logs are off. The merchant dashboard sets only strictly necessary cookies: a sign-in session (ends after 30 minutes idle, 8 hours at most), a short sign-in step, and a device cookie (1 year) used to warn you about sign-ins from new devices. The demo sets a 7-day cookie with the invited name.

Who else processes data

Data is stored in Frankfurt, Germany (AWS eu-central-1). These providers process data for Uncart:

ProviderWhat forLocation
Amazon Web Services EMEA SARLHosting, database, encryption keys, sign-in (Cognito), email (SES), logsFrankfurt; website delivery worldwide via CloudFront
Amazon Bedrock (Anthropic Claude)Writing assistant replies, with personal details removedEU regions
Meta Platforms Ireland LtdSending and receiving WhatsApp messagesEU, possibly US
Twilio Inc.WhatsApp messaging for shops connected through TwilioUS
StripeBilling merchants (no shopper data)US/EU
Shopify / ShopwareThe shop's own platform, which sends Uncart basket and order eventsPer the shop

Where data goes to the United States, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. No SMS provider is in use yet. We give shops 30 days' notice before adding a new sub-processor.

How long we keep data

Deletion runs automatically every day. Database backups are kept for 7 days, so deleted data leaves the backups within 7 days.

DataKept for
Baskets and queued messages30 days
Conversations and messagesUp to 90 days (the shop can choose less)
Opt-in steps not completed7 days after they lapse
Links sent in messages, and their tap counts30 days after sending, or 3 days after the last tap
Orders credited to Uncart, holdout group, refunds12 months
A shopper with no activityErased after 24 months
Record that you wrote STOP or "Not me"24 months, so we never message you again; kept even after you ask us to delete your data
Proof of consent and of a deletion (a fingerprint, never your number)3 years
Server logs (they contain no phone numbers or message text)1 month
Merchant account dataUntil the account is closed
Billing recordsAs tax law requires (up to 10 years)

How to delete your data

You can have your data deleted at any time, free of charge. See uncart.ai/data-deletion for the steps.

How we protect data

  • Phone numbers, messages and access tokens are encrypted with AWS KMS keys held in Frankfurt; each value is bound to its shop, so one shop's data cannot be opened as another's.
  • Each shop's data is walled off in the database, and no shop can read another's.
  • Logs never contain phone numbers or message text.
  • Our team signs in with two factors, and sessions end after a short idle time.
  • Every change to settings and every admin action is recorded in an audit log that cannot be edited.
  • Messages from Shopify, Shopware and WhatsApp are checked for a valid signature before we act on them.

Your rights

You can ask for a copy of your data, for corrections, for deletion, or object to processing. Write to hi@uncart.ai. You can also complain to a data protection authority, such as the ICO in the UK or the authority in your EU country.

Changes and contact

We will post any change to this policy here, with its date, and tell shops 30 days before a change that affects them. Questions or requests: hi@uncart.ai, or write to Woomega LLC, Flat 2, 53 Vincent Square, London SW1P 2NR, United Kingdom.

For your data protection officer

More detail on how Uncart works for your shop, in addition to the Privacy Policy above.

Consent records

  • Shoppers get messages only after they opt in on WhatsApp, at one of the five opt-in points. An opt-in gives them something straight away, such as their basket link. Reminders are never sent without it.
  • We log opt-ins and STOPs with the channel, source, wording version and time. The log can’t be quietly edited, so any change shows.
  • After a STOP, only the shopper can opt back in.
  • You can export the log as a CSV file at any time. Shoppers appear by a code instead of their phone number.

The assistant and the AI Act

  • The first reply the assistant writes in a conversation says it comes from an AI, as Article 50 of the AI Act requires. The first message itself is a template your shop approves.
  • Before a reply goes out, a guard checks it against your shop data.
  • The assistant doesn’t profile shoppers or make decisions about them.

Quiet hours and limits

  • Reminders go out between 09:00 and 21:00 in your shop’s time zone.
  • Message limits are 2 per basket and 4 per shopper in any 30 days.
  • You can pause all sending from your dashboard, including reminders that are already waiting.

Privacy checks

More than 2,000 automated tests and 14 privacy checks run on every change we make. The privacy checks turn these rules into tests.

  1. Messages go only to shoppers with current consent for that channel.
  2. A STOP also cancels messages that are already queued.
  3. Quiet hours and message limits are respected.
  4. Shoppers in the test group (holdout) get no reminders.
  5. An order cancels any reminder that’s waiting.
  6. Phone numbers, emails and addresses are stripped before anything reaches the language model.
  7. Logs never contain phone numbers or message text.
  8. Shop data is kept separate, shop by shop.
  9. Incoming webhooks must be signed. Replays are rejected.
  10. Assistant replies are checked against your shop data before they’re sent.
  11. A deletion request removes the shopper’s data.
  12. Retention jobs delete data on schedule.
  13. A message is sent once, even after a retry.
  14. Phone numbers are encrypted at rest with AWS KMS keys, each value bound to its shop.

We won’t launch until all 14 pass.

Data processing agreement

We’ll publish the DPA here soon. Until then, ask us for the draft when you book.