Block Cart — Privacy Policy

Effective Date: April 6, 2026

Contact: support@block-cart.com

1. Overview

Block Cart ("we," "our," or "us") provides a Notion-connected ecommerce platform that allows users ("you") to create and manage online stores. This Privacy Policy explains how we collect, use, store, and protect your information when you use Block Cart.

By creating an account or using Block Cart, you agree to the terms of this Privacy Policy.

1.1 Your Role and Ours

When you use Block Cart to run your store, you control the customer data collected through your storefront (names, emails, shipping addresses, order details). Block Cart acts as a service provider processing that data on your behalf according to your instructions and our Terms of Service.

For your own account information (email, password, store settings), Block Cart is the data controller.

2. Information We Collect

We collect only the information required to operate your store and provide core platform functionality.

2.1 Account Information

We store the following information when you sign up:

  • Email address
  • Hashed password (never stored or viewed in plain text)
  • Stripe customer ID (created when you enable billing)
  • Store configuration settings (store name, theme settings, connected Notion workspace metadata)
  • API keys you generate for your tenant

2.2 Notion Data (Synchronized)

Block Cart reads and syncs data from your connected Notion workspace:

  • Product data
  • Customer records (if you store them in Notion)
  • Order records (if you store them in Notion)
  • Inventory properties
  • Database schema fields needed to run your storefront

We cache the following Notion content in Block Cart's database (PostgreSQL) for performance:

  • Full product records (name, price, description, inventory, and other properties) — synced from your Notion database and refreshed automatically
  • Product images re-hosted on Cloudflare R2 for optimized delivery
  • Internal store settings to enable sync
  • Minimal metadata to link your store to your Notion workspace

2.3 Platform Usage Data

We collect basic operational logs for security and performance purposes, such as:

  • Request logs (timestamp, URL path)
  • IP address (for abuse prevention)
  • Store sync events (success/failure)
  • Authentication logs (success/failure, device info)

Cookies

We use first-party, HttpOnly cookies to maintain your authenticated session. These cookies are set by Block Cart's servers and are not accessible to client-side scripts or third parties. We do not use advertising cookies or cross-site tracking cookies.

Analytics

We operate a first-party analytics system stored in our own database (PostgreSQL) to track basic platform usage such as page views and feature adoption. This data is used solely to improve Block Cart and is never shared with advertisers, data brokers, or third-party analytics services.

We do not run behavioral profiling, cross-site tracking, or marketing analytics.

2.4 Payment Information

All payment processing is handled by Stripe.

We never see or store:

  • full credit card numbers
  • CVV codes
  • card details

We only receive metadata from Stripe such as:

  • Stripe customer IDs
  • subscription status
  • invoices
  • payment intent IDs

3. How We Use Your Information

We use your information only to provide and improve the Block Cart service.

3.1 Platform Operations

  • Authenticate your account
  • Connect your store to Notion
  • Sync products, customers, and orders
  • Display your store to visitors
  • Manage your subscription or free trial
  • Generate API keys for headless integrations

3.2 Transactional Communications

We use Postmark to send transactional emails:

  • Account verification
  • Password resets
  • Order confirmations
  • Account deletion
  • Store deletion warnings

We do not send marketing emails unless you explicitly opt in (not active at this time).

3.3 Security

Logs and metadata may be used to:

  • Prevent abuse
  • Detect suspicious activity
  • Resolve technical issues
  • Maintain service reliability

4. Data Sharing & Third-Party Processors

We do not sell personal information. We do not share user data with advertisers or data brokers.

We use the following service providers to operate Block Cart:

4.1 Notion

Used as the primary CMS for your product, customer, and order data. Your data is stored directly in your Notion workspace.

4.2 Stripe

Used for payments, subscriptions, and billing.

4.3 Cloudflare R2

Used for image storage (optimized product images only).

4.4 Postmark

Used for sending transactional emails (account verification, password resets, order confirmations).

4.5 Railway

Used to host the application infrastructure.

4.6 Rollbar

Used for real-time error monitoring and diagnostics on both client and server. Error reports may include partial technical context (e.g., error messages, component names). Personally identifiable information is sanitized before transmission where possible.

We share only the data necessary for these services to operate.

4.6 Data Processing Locations

Block Cart's infrastructure is primarily located in the United States. Data may also be processed in regions where our service providers operate (e.g., Cloudflare's global network, AWS regions for email delivery). We use providers that maintain industry-standard security and data protection practices.

5. How We Protect Your Information

We use industry-standard security measures to protect your data, including:

  • Password hashing using secure, one-way algorithms
  • HTTPS/TLS encryption for all traffic
  • API key–based authentication for headless endpoints
  • Secure storage of secrets in environment variables
  • Access logging and IP-rate limiting
  • Scoped API permissions for Notion integrations

Although no platform can guarantee perfect security, we actively work to protect your information.

6. Data Retention

We retain data only as long as needed to operate your store.

Account Data:

Retained until you delete your account.

Store Data:

Retained while your store is active. When a store is deleted, its internal metadata is removed from Block Cart.

Notion Data:

We do not retain historical copies of your Notion databases.

Images in R2:

Deleted when your product or store is deleted.

Logs:

Retained for up to 30–90 days for security and system debugging.

7. Your Rights and Choices

Because we do not collect unnecessary personal data, your rights are simple:

  • You may delete your account at any time
  • You may delete your store at any time
  • You may disconnect Notion at any time
  • You may request export or removal of account data by emailing support@block-cart.com

8. Children's Privacy

Block Cart is not intended for individuals under age 13, and we do not knowingly collect data from minors.

9. Changes to This Policy

We may update this Privacy Policy as the platform evolves. If we make significant changes, we will notify you via email or within the app.

10. Contact Us

If you have questions or privacy concerns, you can contact:

Block Cart Support

support@block-cart.com