CartiGo ("we", "our", or "the app") is an on-demand delivery and eCommerce shopping application developed by GeekyWebTech.
This policy explains what information we collect, how we use it, and how we protect it.
CartiGo allows you to browse products, place orders, make payments through third-party gateways, track deliveries, and manage returns — all from your mobile device.
By using CartiGo, you agree to the practices described in this policy.
Information We Collect
Account details — your name, email address, phone number, and password when you register.
Delivery addresses — street address, city, state, postal code, and country for order delivery.
Profile photoOptional — avatar image you upload to personalize your account.
Order data — products purchased, order history, return/refund requests, and review submissions.
Payment method selection — we record which payment method you chose (COD, Razorpay, Stripe, PayPal). We do not store credit card numbers, bank details, or UPI PINs.
Product reviews — star ratings and written reviews you submit for products.
Device token (FCM) — a Firebase Cloud Messaging token used to deliver push notifications to your device.
Usage data — pages viewed, products browsed, search queries, and video reels watched.
How We Use Your Information
To create and manage your account
To process and deliver your orders
To send order status updates via push notifications (placed, shipped, delivered)
To process payments through third-party payment gateways
To manage return and refund requests
To display your reviews and ratings on product pages
To send promotional notifications and exclusive offers (you can opt out anytime)
To improve our app, products, and services
To respond to your support inquiries
To prevent fraud, abuse, or unauthorized access
We do not sell, rent, or trade your personal information to third parties.
Payment Security
CartiGo does not store any sensitive payment credentials. We do not store:
Credit or debit card numbers
Bank account details or UPI PINs
PayPal login credentials
Razorpay or Stripe secret keys on the client
All payment processing is handled securely by certified third-party providers (Razorpay, Stripe, PayPal).
Only the payment method selection and transaction confirmation status are stored on our servers.
Third-Party Services
We use the following third-party services that may process limited data:
Firebase Cloud Messaging (Google) — for delivering push notifications. Only your device token is shared.
Razorpay — for processing UPI, card, and netbanking payments in India.
Stripe — for processing international credit/debit card payments.
PayPal — for processing PayPal account payments.
No other third parties receive your personal data.
Data Security
All communication between the app and our server uses HTTPS (TLS encryption).
Passwords are hashed using bcrypt — we cannot see your password.
Authentication uses secure JWT tokens with automatic expiration and refresh.
Auth tokens are stored in encrypted device storage (Flutter Secure Storage).
Payment credentials are never stored on our servers — processed directly by the gateway.
Deletion requests are processed within 30 days.
Certain records (e.g., financial transaction logs) may be retained as required by law.
Children's Privacy
CartiGo is not intended for children under 13. We do not knowingly collect personal
information from children. If you believe a child has provided us with their data, please
contact us immediately and we will delete it.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the effective date at
the top of this page. Continued use of the app after changes means you accept the updated policy.
Questions or Concerns?
If you have any questions about this privacy policy or want to request data deletion, reach out to us.