Privacy policy

Navito Cart Drawer Privacy Policy

Last updated: September 25, 2026

Navito Cart Drawer (“Navito”, “we”, “us”) is a Shopify app that replaces a store’s cart with a customizable cart drawer. This policy explains what information we collect when a merchant installs Navito, how we use it, who it is shared with, how long we keep it and how to have it deleted.

In short

  • We keep only what the app needs to work: your store’s address, the access Shopify gives the app, your cart settings, your plan and your dashboard numbers.
  • We do not collect or store your customers’ names, emails, addresses or payment details. For your dashboard we keep only the number, date and amounts of orders placed through the Navito cart.
  • The cart runs on Shopify’s own cart. Navito sets no cookies and does no advertising or cross-site tracking. It counts how many shoppers open the cart — a number, nothing about who they are — and only when the shopper allows analytics.
  • We never sell or rent your information.
  • When you uninstall, your settings and access are deleted straight away and everything else within 48 hours.

1. Information we collect

When you install the app

Shopify gives us your store’s myshopify.com address, the permissions you approved and an access token that lets Navito work with your store through Shopify’s API. We do not ask for, or store, the names or email addresses of you or your staff (except when you contact support, see below).

What you enter in the app

  • Your cart settings: texts, colors, layout, the sections you switch on, progress bar goals, and the rules for upsells, free gifts and the cart add-on.
  • The products you choose for upsells, the free gift and the add-on. We keep their Shopify IDs; titles, images and prices are read from Shopify when needed.
  • Images you upload (such as a logo, badges or review photos). They are passed straight on to your own Shopify Files and we keep only their link.
  • Customer reviews you add to the reviews slider: the name, text, rating and optional photo you type in. See section 4.

What the app reads from your store

PermissionWhy Navito needs it
read_productsTitles, images and prices of the products you pick for upsells, the gift and the add-on.
write_discountsCreates the automatic discount that makes the free gift free and applies upsell discounts at checkout.
read_themesChecks whether the Navito app embed is turned on in your theme, for the setup guide.
write_filesSaves the images you upload to your Shopify Files.
read_localesLists your store’s languages for the cart translations.
read_ordersCounts how many orders your store received in each 30-day billing period, to work out the Navito Pro price. It also lets Shopify send us new orders so your dashboard can show what the Navito cart brought in: from an order placed through the cart we keep only its order ID, date, total, currency and the amount upsells and the cart add-on added — never the customer’s name, email, address or payment details. Other orders are not stored at all.

Billing

Payments are handled by Shopify, never by us. We keep your plan (Free or Navito Pro), the status and dates of your subscription and free trial, and whether it is a test charge.

When you contact support

The Help page in the app has a support chat run by tawk.to. It only loads when you click “Chat with us”. It then passes your store’s name, its myshopify.com address, your store’s email and your plan to the chat, so we know who we’re talking to and can reply by email if you’ve left. What you write in the chat is kept by tawk.to under its own privacy policy. If you email us instead, we keep your email to answer it.

Your dashboard

The dashboard shows your cart’s revenue, orders, visitors, upsell and add-on revenue, conversion rate and average order value. To count them, we keep:

  • for each order placed through the Navito cart: the order ID, date, total and currency, and the amount upsells and the add-on added;
  • for each day: how many shoppers opened the Navito cart — a single number per store per day.

So that an order placed through the cart can be recognised, the drawer adds a private attribute, __navito_cart, to the shopper’s cart. Shopify keeps it off the checkout; it appears on the order in your admin under Additional details.

On your storefront

The cart drawer runs in your shoppers’ browsers and works with Shopify’s own cart: cart contents, prices, discount codes and checkout go between the shopper and Shopify, not through our servers. Recommended products in Automatic mode come from Shopify’s product recommendations.

To make sure it shows your latest settings, the drawer asks our server for your store’s cart settings. That request contains your store’s address and a settings version number — nothing about the shopper. As with any website, our hosting provider may record the IP address and browser type of requests in its server logs, which are used only to keep the service running and secure and are deleted on the provider’s regular schedule.

The drawer saves a copy of your store’s cart settings, and the recommended products it has loaded, in the shopper’s browser storage so the cart opens quickly. These copies contain no personal information and are not used for tracking. The settings copy is refreshed at least once a day, and the recommendations are cleared when the browser tab is closed. Navito sets no cookies.

The first time a shopper opens the Navito cart in a visit, the drawer tells our server that the cart was opened, so it can be counted on your dashboard. The message contains your store’s address and nothing else: no cookie, no identifier and nothing about the shopper. It is only sent when the shopper’s browser allows analytics under your store’s privacy settings, which the drawer checks through Shopify’s Customer Privacy API — so a shopper who declines analytics in your cookie banner is not counted. A note in the browser’s session storage makes sure a shopper is counted once per visit; it is cleared when the browser session ends. Nothing is sent from the app’s preview or from Shopify’s theme editor.

At checkout, Navito’s discount function runs inside Shopify to make the free gift free and apply upsell discounts. It works only with the cart Shopify gives it and sends nothing to us.

2. How we use information

We use the information above only to provide Navito:

  • to show your cart drawer on your store and the live preview in the app;
  • to save and publish your settings to your store;
  • to apply free gifts and upsell discounts at checkout;
  • to run your Navito Pro subscription and charge the price that matches your order count;
  • to show you your cart’s numbers on the dashboard;
  • to answer you when you contact us by chat or email, and to fix problems.

We do not sell or rent information, use it for advertising, or use it for any purpose other than providing Navito to you.

3. Who we share it with

  • Shopify, which runs your store, your subscription and the app platform.
  • Render (render.com), which hosts Navito’s servers and database in the United States.
  • tawk.to, which runs the support chat — only when you open it (see “When you contact support”).

We share information with no one else, except where the law requires it. If Navito is ever sold or merged, we will tell you before your information is handled under a different policy.

4. Your customers’ information

Navito does not collect or store personal information about your customers: no names, emails, addresses or payment details. The dashboard keeps the ID and amounts of orders placed through the Navito cart, and a daily count of shoppers who opened the cart. For the reviews you add to the reviews slider, you decide what to publish and you are responsible for having your customers’ permission; we store those reviews only on your behalf, and you can edit or delete them in the app at any time.

Navito answers Shopify’s privacy requests. When a customer asks a store for their data, Shopify tells us; we hold no personal information about them, only the amounts of orders placed through the cart. When a customer asks for their data to be deleted, we delete our rows for the orders Shopify lists. A shopper with a question about their data should contact the store they bought from, and we will help the store answer it.

5. How long we keep information

  • While Navito is installed, we keep your settings and plan so the app keeps working.
  • When you uninstall Navito, we immediately delete your access token, your cart settings and your dashboard numbers, and mark your plan as Free.
  • 48 hours after you uninstall, Shopify asks us to erase your store’s data and we delete everything left, including your billing record.
  • Images you uploaded stay in your own Shopify Files, where you can delete them yourself.

6. Where information is processed

Navito is run from Pakistan and is not established in the European Union or the United Kingdom. Information is stored on servers in the United States and processed by Shopify. When information about stores in the European Economic Area, the UK or Switzerland is transferred, we rely on the safeguards in our providers’ data processing terms, such as the European Commission’s Standard Contractual Clauses.

7. Security

All connections to Navito use HTTPS. Access tokens are kept on our servers and never sent to the browser. Every message from Shopify is checked for Shopify’s signature before we act on it, and access to our systems is limited to the people who run Navito.

8. Your rights

You can ask us to show you, correct, export or delete the information we hold about your store, or object to how we use it. Email navitosupport@gmail.com from an address linked to your store and we will reply within 30 days. If you are in the European Economic Area or the UK, you can also complain to your local data protection authority.

9. Children

Navito is a tool for businesses and is not meant for children.

10. Changes to this policy

If we change this policy, we will update the date at the top of this page. If a change affects how we use your information, we will tell you in the app or by email before it takes effect.

11. Contact

Questions about this policy or your information: navitosupport@gmail.com.