01Overview
Cart.fun is an unincorporated, open-source on-chain commerce protocol operated by a small team. There is no legal entity behind this name — only smart contracts deployed on Base, Arc, and Robinhood Chain, a public REST API, and a public-facing UI.
This notice describes data practices for off-chain data incidentally collected when you interact with the Services — whether as a human user, an AI agent, an automated script, or any other programmatic client. On-chain data (wallet addresses, order data, receipt NFT metadata) is public by nature and beyond our control.
Questions or concerns? legal@cart.fun
02What Information Do We Collect?
Information you or your systems provide.
- Wallet addresses: Public keys used to interact with Cart.fun contracts on any supported chain. These are public by nature.
- API keys: Metadata about API keys you generate (scope, creation timestamp, last-used timestamp, label). We do not store the raw key after generation.
- Webhook endpoints: URLs and signing secrets you configure for event delivery. Secrets are stored encrypted.
- Store configuration: Catalog data, product descriptions, invite lists, and pricing you upload via the merchant dashboard or API.
- Contact data: Email addresses provided for support inquiries. No account system exists; email is used only for support responses.
Information automatically collected.
- API request logs: Endpoint called, HTTP method, response status, timestamp, and the API key (or wallet) used. Logs are retained for a limited period for debugging and abuse prevention.
- IP addresses: Collected per request by our hosting infrastructure. May be used for rate limiting and fraud detection.
- Device and browser data: Browser type, OS, and referring URL when accessing the UI. Not collected for pure API callers.
- Agent identity signals: User-Agent strings sent by API clients, including agent frameworks (e.g., LangChain, Claude, custom bots). Used for compatibility logging and abuse detection.
On-chain data (not under our control).
- Every checkout, order, and receipt NFT is permanently recorded on the relevant public blockchain. This data is accessible to anyone and cannot be modified or deleted by Cart.fun or any other party.
- Receipt NFT metadata may be pinned to IPFS, which is also public and permanent.
03How Do We Process Your Information?
- Protocol operations: To process order quotes, validate checkout signatures, and serve store catalogs to both human and machine clients.
- API and agent serving: To authenticate API keys, enforce rate limits, route requests, deliver webhooks, and serve machine-readable artifacts (OpenAPI, llms.txt, agent cards, skill files).
- Abuse prevention: To detect suspicious API usage patterns, block sanctioned wallets, and enforce geographic restrictions.
- Support: To respond to inquiries sent to legal@cart.fun or through any support channel.
- Analytics: To understand aggregate usage patterns and improve the protocol. Analytics are aggregated and not used to build individual profiles.
04Agent and Programmatic Caller Data Practices
Cart.fun is designed for M2M commerce. The following practices apply specifically to autonomous agents and programmatic clients:
- API key ownership: An API key is associated with the wallet that generated it. All requests made with that key are attributed to the key owner. The operator deploying an agent is responsible for all data transmitted by that agent.
- No agent-specific profiling: We do not build behavioral profiles of individual agents beyond what is necessary for rate limiting, abuse detection, and debugging.
- Webhook payloads: Webhook payloads contain order and receipt data for events in your store. You are responsible for the security of your webhook endpoint and the data you receive.
- ERC-8004 agent card reads: Reading a store's agent card at
/api/v1/stores/{chain}/{id}/agentis unauthenticated and publicly logged like any other request. - Machine-readable files: Requests to
/llms.txt,/llms-full.txt,/openapi.json, and/skill.mdare served publicly. We log access to these files for diagnostic purposes.
06Third-Party Websites and Integrations
The Services link to or integrate with third-party blockchain explorers, wallet providers (e.g., WalletConnect, Rainbow, Phantom, Backpack), and decentralized applications. Data shared with these services is governed by their own privacy policies. Cart.fun is not responsible for third-party data practices.
08International Data Transfers
Hosting infrastructure, RPC endpoints, and CDN providers may be located outside your country of residence. Blockchain networks are globally distributed — any on-chain transaction is replicated across all nodes worldwide by design.
Because Cart.fun has no registered legal entity, we cannot execute Standard Contractual Clauses or equivalent formal transfer mechanisms. If this is a concern, consider that API interactions using only a pseudonymous wallet address may limit the personal data involved.
09How Long Do We Keep Your Information?
- API request logs: Retained for a short rolling window for debugging and abuse detection, then deleted.
- API key metadata: Retained until you revoke the key, plus a short period for audit purposes.
- Webhook endpoint data: Retained while your store is active. Deleted on store deletion or on your request.
- Support correspondence: Retained only as long as needed to resolve the inquiry.
- On-chain data: Permanently stored on public blockchain networks. Cannot be deleted by Cart.fun or anyone else.
10How Do We Keep Your Information Safe?
Cart.fun is operated by a small team with no dedicated security team. We take reasonable measures to avoid storing unnecessary off-chain data and rely on reputable third-party infrastructure. Webhook signing secrets are stored encrypted. API keys are hashed after generation.
You are solely responsible for the security of your wallet's private keys, your API keys, and your webhook signing secrets. Cart.fun cannot recover lost assets or reverse on-chain transactions under any circumstances. If an API key is compromised, revoke it immediately from the merchant dashboard.
11Do We Collect Information from Minors?
We do not knowingly solicit data from or market to persons under 18 years of age. The protocol is not intended for use by minors, whether directly or through an agent system. By using the Services, you represent that the natural person authorizing the interaction is at least 18 years old.
12What Are Your Privacy Rights?
In some regions (EEA, UK, Canada, and other applicable jurisdictions outside the U.S.), you may have rights to access, rectify, or erase your personal information and to restrict processing.
Blockchain limitation: We can delete or anonymize off-chain data (API key records, support emails, webhook endpoints). We cannot delete, modify, or restrict access to any data recorded on a public blockchain — including wallet addresses, order data, and receipt NFTs.
To exercise your rights, contact legal@cart.fun. If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority.
13Do-Not-Track Signals
No uniform technology standard for recognizing Do-Not-Track (DNT) browser signals exists. We do not currently respond to DNT signals. Pure API callers are not affected by browser-based tracking settings.
14EEA and UK Data Subject Rights
If you are located in the EEA or UK, you have the following rights under applicable data protection law:
- Right of access to your personal data
- Right to rectification of inaccurate personal data
- Right to erasure (off-chain data only — subject to blockchain immutability for on-chain data)
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interests
To exercise these rights, contact legal@cart.fun.
15Legal Bases for Processing (EU / UK)
Because Cart.fun has no registered legal entity, our ability to rely on formal GDPR legal bases is limited. To the extent any off-chain personal data is incidentally processed, we rely on:
- Legitimate interests: Operating the API, detecting abuse, delivering webhooks, and maintaining platform integrity — where those interests do not override your fundamental rights.
- Consent: Where you have voluntarily provided contact information for support.
Cart.fun does not process personal information of U.S. residents and does not rely on U.S. legal bases. If you are a U.S. resident, you must not use the Services.
16Updates to This Notice
We may update this notice from time to time. Changes are indicated by an updated "Last updated" date. We encourage periodic review. For programmatic callers, the current notice is always available at cart.fun/privacy.
17Contact
Cart.fun has no registered legal entity, no DPO, and no physical address. For questions about this notice:
Cart.fun (unincorporated protocol)
legal[@]cart.funResponse times are best-effort. We are a small team.
18Data Access, Correction, and Deletion Requests
Based on applicable laws of your country (excluding the United States), you may have the right to request access to, correction of, or deletion of personal information we hold — subject to blockchain immutability constraints for on-chain data.
Submit data subject access requests to legal@cart.fun. Please include your wallet address and a description of the data in question.