CART.FUNCART.FUNV1

agentic ecommerce

/Legal

Legal · Cart.fun Protocol

Privacy Policy

Last updated: September 28, 2026

⚠

GEOGRAPHIC RESTRICTION — Cart.fun is not available to residents of the United States of America or any U.S. territory. By accessing or using the Services — including any automated or agentic interaction — you represent and warrant that you are not a U.S. person as defined under applicable law. Do not use these Services if you are located in or are a resident of the United States.

Contents

  1. 01Overview
  2. 02What Information Do We Collect?
  3. 03How Do We Process Your Information?
  4. 04Agent and Programmatic Caller Data Practices
  5. 05When and With Whom Do We Share Information?
  6. 06Third-Party Websites and Integrations
  7. 07Cookies and Tracking Technologies
  8. 08International Data Transfers
  9. 09How Long Do We Keep Your Information?
  10. 10How Do We Keep Your Information Safe?
  11. 11Do We Collect Information from Minors?
  12. 12What Are Your Privacy Rights?
  13. 13Do-Not-Track Signals
  14. 14EEA and UK Data Subject Rights
  15. 15Legal Bases for Processing (EU / UK)
  16. 16Updates to This Notice
  17. 17Contact
  18. 18Data Access, Correction, and Deletion Requests

01Overview

Cart.fun is an unincorporated, open-source on-chain commerce protocol operated by a small team. There is no legal entity behind this name — only smart contracts deployed on Base, Arc, and Robinhood Chain, a public REST API, and a public-facing UI.

This notice describes data practices for off-chain data incidentally collected when you interact with the Services — whether as a human user, an AI agent, an automated script, or any other programmatic client. On-chain data (wallet addresses, order data, receipt NFT metadata) is public by nature and beyond our control.

Questions or concerns? legal@cart.fun

What we collectWallet addresses, API key metadata, IP addresses, device/usage data, webhook endpoint URLs, and any contact info you voluntarily provide (e.g., email for support).
Sensitive dataWe do not collect sensitive personal information. We never see or store private keys or seed phrases.
Agent/M2M dataAPI requests from autonomous agents are logged like any other request. The operator who controls the API key is responsible for the data their agents transmit.
Right to erasureApplies to off-chain data only. On-chain data (orders, receipts, wallet addresses) is permanently public and cannot be deleted by anyone.

02What Information Do We Collect?

Information you or your systems provide.

  • Wallet addresses: Public keys used to interact with Cart.fun contracts on any supported chain. These are public by nature.
  • API keys: Metadata about API keys you generate (scope, creation timestamp, last-used timestamp, label). We do not store the raw key after generation.
  • Webhook endpoints: URLs and signing secrets you configure for event delivery. Secrets are stored encrypted.
  • Store configuration: Catalog data, product descriptions, invite lists, and pricing you upload via the merchant dashboard or API.
  • Contact data: Email addresses provided for support inquiries. No account system exists; email is used only for support responses.

Information automatically collected.

  • API request logs: Endpoint called, HTTP method, response status, timestamp, and the API key (or wallet) used. Logs are retained for a limited period for debugging and abuse prevention.
  • IP addresses: Collected per request by our hosting infrastructure. May be used for rate limiting and fraud detection.
  • Device and browser data: Browser type, OS, and referring URL when accessing the UI. Not collected for pure API callers.
  • Agent identity signals: User-Agent strings sent by API clients, including agent frameworks (e.g., LangChain, Claude, custom bots). Used for compatibility logging and abuse detection.

On-chain data (not under our control).

  • Every checkout, order, and receipt NFT is permanently recorded on the relevant public blockchain. This data is accessible to anyone and cannot be modified or deleted by Cart.fun or any other party.
  • Receipt NFT metadata may be pinned to IPFS, which is also public and permanent.

03How Do We Process Your Information?

  • Protocol operations: To process order quotes, validate checkout signatures, and serve store catalogs to both human and machine clients.
  • API and agent serving: To authenticate API keys, enforce rate limits, route requests, deliver webhooks, and serve machine-readable artifacts (OpenAPI, llms.txt, agent cards, skill files).
  • Abuse prevention: To detect suspicious API usage patterns, block sanctioned wallets, and enforce geographic restrictions.
  • Support: To respond to inquiries sent to legal@cart.fun or through any support channel.
  • Analytics: To understand aggregate usage patterns and improve the protocol. Analytics are aggregated and not used to build individual profiles.

04Agent and Programmatic Caller Data Practices

Cart.fun is designed for M2M commerce. The following practices apply specifically to autonomous agents and programmatic clients:

  • API key ownership: An API key is associated with the wallet that generated it. All requests made with that key are attributed to the key owner. The operator deploying an agent is responsible for all data transmitted by that agent.
  • No agent-specific profiling: We do not build behavioral profiles of individual agents beyond what is necessary for rate limiting, abuse detection, and debugging.
  • Webhook payloads: Webhook payloads contain order and receipt data for events in your store. You are responsible for the security of your webhook endpoint and the data you receive.
  • ERC-8004 agent card reads: Reading a store's agent card at /api/v1/stores/{chain}/{id}/agent is unauthenticated and publicly logged like any other request.
  • Machine-readable files: Requests to /llms.txt, /llms-full.txt, /openapi.json, and /skill.md are served publicly. We log access to these files for diagnostic purposes.

05When and With Whom Do We Share Information?

  • Public blockchains: All on-chain transactions are broadcast publicly. We do not control blockchain networks.
  • RPC and node providers: Network requests from the API and UI pass through third-party RPC providers.
  • Hosting and CDN providers: Our infrastructure is hosted on third-party platforms that may log request metadata.
  • IPFS pinning services: Receipt NFT metadata may be pinned via third-party IPFS gateways.
  • Analytics providers: Aggregated, anonymized usage data may be shared with analytics tools.

We do not sell personal data. We do not share data with advertisers. Disclosure beyond the above is limited to situations where required by applicable law.

06Third-Party Websites and Integrations

The Services link to or integrate with third-party blockchain explorers, wallet providers (e.g., WalletConnect, Rainbow, Phantom, Backpack), and decentralized applications. Data shared with these services is governed by their own privacy policies. Cart.fun is not responsible for third-party data practices.

07Cookies and Tracking Technologies

The UI uses cookies and similar technologies to persist wallet connection state, remember theme preferences, and analyze traffic. Pure API callers (no browser) are not subject to cookie-based tracking.

We do not use cookies for advertising or cross-site tracking.

08International Data Transfers

Hosting infrastructure, RPC endpoints, and CDN providers may be located outside your country of residence. Blockchain networks are globally distributed — any on-chain transaction is replicated across all nodes worldwide by design.

Because Cart.fun has no registered legal entity, we cannot execute Standard Contractual Clauses or equivalent formal transfer mechanisms. If this is a concern, consider that API interactions using only a pseudonymous wallet address may limit the personal data involved.

09How Long Do We Keep Your Information?

  • API request logs: Retained for a short rolling window for debugging and abuse detection, then deleted.
  • API key metadata: Retained until you revoke the key, plus a short period for audit purposes.
  • Webhook endpoint data: Retained while your store is active. Deleted on store deletion or on your request.
  • Support correspondence: Retained only as long as needed to resolve the inquiry.
  • On-chain data: Permanently stored on public blockchain networks. Cannot be deleted by Cart.fun or anyone else.

10How Do We Keep Your Information Safe?

Cart.fun is operated by a small team with no dedicated security team. We take reasonable measures to avoid storing unnecessary off-chain data and rely on reputable third-party infrastructure. Webhook signing secrets are stored encrypted. API keys are hashed after generation.

You are solely responsible for the security of your wallet's private keys, your API keys, and your webhook signing secrets. Cart.fun cannot recover lost assets or reverse on-chain transactions under any circumstances. If an API key is compromised, revoke it immediately from the merchant dashboard.

11Do We Collect Information from Minors?

We do not knowingly solicit data from or market to persons under 18 years of age. The protocol is not intended for use by minors, whether directly or through an agent system. By using the Services, you represent that the natural person authorizing the interaction is at least 18 years old.

12What Are Your Privacy Rights?

In some regions (EEA, UK, Canada, and other applicable jurisdictions outside the U.S.), you may have rights to access, rectify, or erase your personal information and to restrict processing.

Blockchain limitation: We can delete or anonymize off-chain data (API key records, support emails, webhook endpoints). We cannot delete, modify, or restrict access to any data recorded on a public blockchain — including wallet addresses, order data, and receipt NFTs.

To exercise your rights, contact legal@cart.fun. If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority.

13Do-Not-Track Signals

No uniform technology standard for recognizing Do-Not-Track (DNT) browser signals exists. We do not currently respond to DNT signals. Pure API callers are not affected by browser-based tracking settings.

14EEA and UK Data Subject Rights

If you are located in the EEA or UK, you have the following rights under applicable data protection law:

  • Right of access to your personal data
  • Right to rectification of inaccurate personal data
  • Right to erasure (off-chain data only — subject to blockchain immutability for on-chain data)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests

To exercise these rights, contact legal@cart.fun.

15Legal Bases for Processing (EU / UK)

Because Cart.fun has no registered legal entity, our ability to rely on formal GDPR legal bases is limited. To the extent any off-chain personal data is incidentally processed, we rely on:

  • Legitimate interests: Operating the API, detecting abuse, delivering webhooks, and maintaining platform integrity — where those interests do not override your fundamental rights.
  • Consent: Where you have voluntarily provided contact information for support.

Cart.fun does not process personal information of U.S. residents and does not rely on U.S. legal bases. If you are a U.S. resident, you must not use the Services.

16Updates to This Notice

We may update this notice from time to time. Changes are indicated by an updated "Last updated" date. We encourage periodic review. For programmatic callers, the current notice is always available at cart.fun/privacy.

17Contact

Cart.fun has no registered legal entity, no DPO, and no physical address. For questions about this notice:

Cart.fun (unincorporated protocol)

legal[@]cart.fun

Response times are best-effort. We are a small team.

18Data Access, Correction, and Deletion Requests

Based on applicable laws of your country (excluding the United States), you may have the right to request access to, correction of, or deletion of personal information we hold — subject to blockchain immutability constraints for on-chain data.

Submit data subject access requests to legal@cart.fun. Please include your wallet address and a description of the data in question.

← Back to Cart.funTermsPrivacy

Cart.fun · legal[@]cart.fun