Privacy notice
Know what is used, why it is needed and how to stay in control.
Your store data stays in WordPress.
Free needs no WakeMyCart account. Recovery records stay on your store, and reminders go directly through your chosen email provider.
An optional account exchanges store, licence, update and basic health information. Current Free and Pro plugins do not report aggregate contact usage.
For a shopper’s order or checkout, contact the shop. For WakeMyCart enquiries, find the right privacy contact.
Who operates WakeMyCart?
- Legal entity
- A.M.E.X. Internet Marketing ltd
- Business address
- Makariou III, No.9, Larnaca, 7530, Cyprus
- Country of establishment
- Cyprus
- Registration and VAT details
- Company registration HE 377934. VAT registration 10377934Z.
- Support
- support@wakemycart.com
- Privacy contact
- support@wakemycart.com
- Data protection contact
- For privacy enquiries, email support@wakemycart.com or write to the company address above. Include WakeMyCart in your subject.
Our role and the information we use
The operator controls account administration, service security and support data. Each connected merchant controls its shoppers’ recovery data. Current Free and Pro keep recovery records and decisions in the merchant’s WordPress installation. Free needs no account and makes no normal account-service requests while disconnected. Optional connected accounts exchange store and installation details, licence/update requests and basic health status. Current plugins do not report aggregate contact usage. Retained legacy cloud records, migration assistance and any supplied support data are handled on documented instructions under the processing agreement. Store shoppers should also read the merchant’s notice.
| Information | Purpose and source |
|---|---|
| Email, workspace name, password hash, membership and terms acceptance | Provided during registration; used to administer accounts and the service relationship. Account email and credentials are needed for sign-in; public documentation needs no account. |
| Purchase records and introductory-offer eligibility | Billing history and a keyed identifier derived from the account email are used to apply one introductory annual discount per purchasing customer and prevent repeated use after cancellation, refund or account recreation. The identifier does not store the email in plain text and remains personal data. It is not based on shopper data and is not used for advertising. |
| Session tokens, encrypted authenticator secrets, hashed one-use recovery codes, team invitations, role changes and sign-in times | Created during use to authenticate requests, restrict access and investigate failures or abuse. Servers and contracted hosts may process IP addresses and request logs. |
| Support messages and supplied store references | Provided by you when asking for help; used to investigate and respond. Do not send passwords or unnecessary shopper records. |
| Merchant store registration, installation binding, license and coarse health codes | Only when an account is connected: store and installation details, licences, software versions and basic health status support account services and updates. Current Free and Pro plugins do not report aggregate contact usage. The account service records licence-check times, results and signed-entitlement expiry. Normal control requests contain no shopper email, cart, product, order, recovery token, recipient hash or message body. |
| Local recovery records: shopper details, cart/products, consent, messages, links, orders/refunds and observed checkout errors | Stored and processed in the merchant’s WordPress database. Emails go directly to the merchant’s own Resend or WordPress/SMTP provider. Earlier cloud-engine records may remain during a reviewed migration; original legacy links and feedback use a temporary relay. Payment-card data is not collected for recovery. |
Optional website visitor analytics
With your separate consent, this website records public page views, a random daily browser reference, the UTC time, approximate country and broad device category. It helps the operator understand website use. No full IP address, full user-agent, query string, fragment, referrer, account identifier or shopper record is stored in the analytics event table. The service does not use advertising pixels, fingerprinting, session recording or cross-site tracking.
Analytics starts off. Use the equally available Allow analytics and Decline analytics choices, or change them in Cookie settings. Account registration and website access do not depend on analytics consent. Withdrawal stops future collection and removes the daily visitor cookie. Existing records expire through scheduled cleanup after 90 days; where a record cannot be linked back to you, we do not collect extra identifying data solely to identify it. Browser Do Not Track and Global Privacy Control signals disable collection. Signed-in browsers and private account, admin and recovery pages are excluded.
The optional country feature uses a configured trusted hosting/CDN gateway to infer a country from the connection; no precise location is requested. Hosting infrastructure still processes network addresses to deliver and secure the site under the provider arrangements below. Country may be Unknown or inaccurate, for example with a VPN. Daily visitor references rotate at UTC midnight: reports count daily browsers, not identifiable people. The operator controls website analytics on the basis of consent and must include any gateway provider in the published provider register.
Purposes and lawful grounds
The operator must confirm the basis for each account, support, security and statutory record-keeping purpose before launch. A typical mapping is contract administration for the account holder; legitimate interests in responding to business contacts and securing the service, with the interests and balancing recorded; consent for optional browser storage; and identified legal duties for mandatory records. This draft mapping is not a substitute for that assessment.
Merchants decide and disclose the lawful basis for shopper processing and meet local electronic-marketing rules. The connector requires an unchecked, optional reminder opt-in; entering an email or accepting checkout terms alone does not authorise recovery capture. Declining reminders does not prevent purchase. Signing up for WakeMyCart does not subscribe you to promotional email.
Reminder selection, experiments and measurement
Optional Pro early cart capture lets a shopper request one cart-link email. That request does not enroll the shopper in a reminder sequence or newsletter. Ongoing cart reminders from this form require a separate unchecked choice and confirmation through the requested email. Opening or restoring the cart link alone does not grant that permission. The merchant stores the cart request locally and sends through its own provider; the shopper can continue shopping without requesting an email. Review the merchant’s notice for the enabled form, prompt preferences and retention.
Merchant rules can select reminders by cart amount, product/category, language or known customer type. Experiments randomly assign eligible shoppers to variants; offer limits use product costs and merchant expenses. These choices can change timing, content or discount availability. Ask the merchant about its configured logic and any applicable right to human review. A merchant must assess whether its use creates a legally or similarly significant automated decision.
Recovery links identify the saved checkout and record observed link use and associated orders. Automated email-security scans can affect click counts. The application adds no open-tracking pixel. The merchant must review and configure tracking in its own sending account; the plugin does not override that account’s domain tracking settings. Loading a logo or product image in an email may contact the image host. See reminder permission guidance.
Recipients and international processing
Authorised WordPress users can access local recovery information within their store permissions; account members access account and registry information. The merchant’s hosting and mail providers process local recovery records and message contents. The operator’s account-service providers receive the information needed for their services; required legal disclosures are assessed separately. The provider register records actual purposes, locations, retention and transfer arrangements. A European business address does not establish European-only processing.
Transfer arrangements: To be confirmed by the service operator before public launch. Ask the privacy contact for applicable safeguards. Payment processing remains separate and must be disclosed before accepting paid orders.
How long information is kept
| Record | Location | Routine retention |
|---|---|---|
| Optional Pro requested cart links | Merchant WordPress database and chosen sender | One explicitly requested cart email is separate from reminder permission. Encrypted request details and links expire after seven days; de-identified activity counts remain for 30 days and hashed abuse limits for two days, through bounded scheduled cleanup. Provider records and merchant backups follow their separate retention. A non-identifying prompt dismissal preference lasts for the browser tab session, with a page-memory fallback. |
| Website visitor analytics | WakeMyCart account service | Consented public page views, daily keyed browser references, approximate country and device category: 90 days, removed by scheduled retention batches. Daily browser cookie: until UTC midnight. Analytics allow/refuse cookie: 180 days without automatic renewal. |
| Operator access and license monitoring | WakeMyCart account service | Invitations are valid for 7 days and removed 30 days after expiry. Security and role-change audit records: 365 days. Detailed authenticated license checks: 90 days. The latest license-check timestamp and result remain with the store registry for the operator's account-retention period. |
| Checkout snapshots and product details | Merchant WordPress database | 30 days after last cart activity; bounded scheduled cleanup. |
| Recovery messages, consent events, checkout observations and order copies | Merchant WordPress database | Normally 90 days. Cart-linked records use last cart activity; order copies use their last update. Canonical WooCommerce orders follow the merchant’s separate policy. |
| Prepared message contents | Encrypted in the merchant WordPress database | Removed 48 hours after a terminal result. Unresolved attempts remain held for review and are removed with their cart records. |
| Recovery and unsubscribe tokens | Merchant WordPress database | Recovery links: up to 7 days and never beyond cart expiry. Unsubscribe links: up to 365 days. Only token hashes are stored; cleanup removes expired records. |
| Per-shopper usage reservations | Merchant WordPress database | Current UTC month and the previous calendar month. These usage records stay in WordPress. Current Free and Pro plugins do not report aggregate contact usage to the account service. |
| Experiment assignments | Merchant WordPress database | Until 90 days after the experiment’s final observation window. Earlier erasure removes the individual assignment; mature outcomes may remain as anonymous counters. |
| Statistical totals and staff audit records | Merchant WordPress database | Daily anonymous recovery totals: 13 months. Staff audit entries: 365 days. Archived financial totals stop changing when their underlying recovery order copies are deleted. |
| Suppression keys | Merchant WordPress database | Minimal keyed email references are retained to prevent renewed contact. These are personal data. The merchant must define and review their purpose and retention; a migration may also require a legacy suppression lookup. |
| Merchant accounts, store registry, licenses and coarse health; retained legacy usage allocations | WakeMyCart account service | Account and business-record criteria are completed by the operator below. Retained legacy usage allocations support accounting and duplicate-allocation prevention. Current Free and Pro plugins do not report contact usage; no shopper list is uploaded. |
| Purchase and introductory-offer eligibility records | WakeMyCart account service | Billing records follow the operator’s business-record criteria. The minimal keyed account-email identifier and offer-use record are retained while the once-per-customer annual introductory offer operates, including after account closure, subject to necessity review and applicable rights. No fixed year limit is currently assigned to that eligibility record; it contains no shopper data. |
| Account sessions and account mail | WakeMyCart account service | Sessions expire after 12 hours; invitations after 7 days. Expired verification/reset records are removed; account-mail receipts remain 30 days. Resolved service alerts: 90 days; account audit history: 365 days. |
| Legacy cloud recovery records and migration pages | WakeMyCart service, only for earlier cloud-engine stores | Legacy records are held during migration until import is verified and a reviewed cleanup is completed. Encrypted export pages expire after 24 hours. Original link and old-provider feedback compatibility lasts only until its recorded deadline, up to 365 days; cleanup and backup expiry must be verified separately. |
| Mail-provider records, support records and backups | The merchant’s or operator’s contracted providers, as applicable | Provider-specific contracts and completed retention criteria apply. Local erasure does not automatically delete a provider’s logs, WordPress backups or older cloud copies. |
Account-service retention is run by the operational monitor. Local recovery cleanup depends on the WordPress scheduler and uses bounded batches. Legacy cloud deletion requires a verified import and separate reviewed cleanup. Missed or failed jobs must be investigated; deletion is not instantaneous at the boundary.
Account, support, legal holds and suppression: To be confirmed by the service operator before public launch.
Account closure does not automatically remove required billing records or the minimal introductory-offer eligibility identifier. The latter is retained while the once-per-customer offer operates, subject to review of necessity and applicable rights. No fixed number of years is currently assigned to that eligibility record. Contact us to request an explanation or exercise the rights described below.
Backups and restoration handling: To be confirmed by the service operator before public launch.
Your choices and rights
You may request access, correction, erasure, restriction, objection, portability and applicable automated-decision protections. Availability depends on the processing and legal grounds. Withdrawal of consent does not affect earlier lawful processing. Direct-marketing objections stop further marketing.
Shoppers can untick the checkout reminder option or follow the unsubscribe confirmation in a recovery email. This stops eligible future sending; it cannot recall a message already accepted by the provider. Change optional tutorial storage through cookie settings. Use the privacy request page without needing an account.
Contact support@wakemycart.com or write to A.M.E.X. Internet Marketing ltd at the business address in the legal notice to request access, correction, erasure, restriction, objection or portability where applicable. You may complain to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority without contacting us first. You may complain to a competent data protection authority. Store deletion, account closure and local WordPress erasure are separate actions; the data-request guide explains coordination.
Scope and notice changes
WakeMyCart business accounts are intended for adults authorised to operate a store. Merchants must assess age and sensitive-data risks in their own catalogues and audiences. The service does not request special-category data or use checkout records to train AI models. Material changes to purposes, providers or this notice require updated information before the changed processing takes place.