CartCapybara

Privacy Policy

Last updated: 12 August 2026

At a glance

This summary is for orientation only. The full Policy below is what applies.

  • CartCapybara has no account, no sign-up, and no login.
  • Your Cart Choices, pond, Ledger, Treasury, preferences, and Shopping Pause settings are stored locally by the app and are not uploaded to a CartCapybara-operated server. We do not receive them and cannot access them remotely. Copies may be included in your normal device or iCloud backups, which are controlled by Apple — see Section 12.
  • There is no advertising, no third-party analytics, no behavioural tracking, and no CartCapybara server holding your app data.
  • We do not receive your core app data. The personal information we directly receive is principally information you choose to send us, such as a support or privacy communication. Part A explains how we handle that.
  • Part B explains what CartCapybara does on your device, so you can see how the app works even though we never receive that information.

Who We Are

CartCapybara is provided by Deniz KAYA, who is responsible for the processing described in this Privacy Policy ("the Controller," "CartCapybara," "we," "us," or "our").

Controller contact details

Deniz KAYA

Privacy contact: privacy.cc@frontiermeow.com

Support: support.cc@frontiermeow.com

Scope

This Privacy Policy explains how CartCapybara handles information in connection with the CartCapybara iOS app, and communications you choose to send to us for support or privacy purposes.

It does not cover processing carried out independently by Apple or by websites you choose to share or open. Relevant information appears in Sections 4, 6, 10, and 12 below.

Legal function of this Policy

This document provides the information required under Article 13 and, where applicable, Article 14 GDPR and UK GDPR, and under Article 10 of Turkish Law No. 6698 (KVKK), in respect of the processing described in Part A and — to the extent applicable data-protection law treats particular locally generated operational information described in Part B as personal data processed under our responsibility — the relevant provisions of Part B. The required elements appear across Section 1, Part A, and Sections 14, 18, and 19.

Part B explains how CartCapybara works on your device and is included for transparency even where the information never reaches us. Sections 14 and 18 set out the legal position relevant to the different kinds of on-device activity.

How CartCapybara Handles Your Information

CartCapybara is designed to keep its core app data on your device. There is no CartCapybara account, sign-up, or login.

Words we use for parts of the app

CartCapybara uses a few names for its own features. They appear throughout this Policy, so they are explained here.

The current version of CartCapybara does not use:

Because of this design, two materially different situations arise, and this Policy keeps them separate:

Part A — Information that reaches us. Information you actively send us, principally support and privacy correspondence. We act as controller for that information in the ordinary way.

Part B — How CartCapybara works on your device. Functionality that runs on your device and produces information we never receive and cannot access remotely. Part B is provided so that you can understand how the app works; it does not describe information that we hold.

How information is obtained

Depending on the feature you use, information is obtained directly from you when you enter or send it, generated locally as CartCapybara operates, provided through Apple platform services where needed for a feature, or retrieved from a product webpage when you choose to share a link and CartCapybara makes the limited metadata request described in Section 10.

Part A

Information That Reaches Us

This Part covers information that we actually receive and hold. We act as controller for it, and the legal bases in Section 5 apply directly to it.

Support and Privacy Communications

If you contact us by email or another support channel, we receive the information you choose to send us. This may include:

We use this information to respond to your request, provide support, handle privacy requests, protect our legal interests, and maintain the security and reliability of CartCapybara.

Specially protected information. Please do not include specially protected information — of the kind described in Section 15 — in a support or privacy communication. We do not ask for it, and we do not need it in order to handle your request.

If you send us such information without our request, we will not use it to handle your enquiry. We will limit our engagement with it to what is necessary to identify and remove it, and will delete or redact it from the systems we actively use without undue delay and ordinarily within 30 days of receipt. Residual copies may remain temporarily in service-provider backups, where such backups exist, until they are overwritten or deleted through the provider's normal backup cycle. If we cannot answer your enquiry without that content, we will ask you to describe your issue again without it, rather than process it.

We retain such information beyond that point only where, and only to the extent that, it is strictly necessary for the establishment, exercise, or defence of a legal claim. In that case, and in addition to the general legal basis identified in Section 5, we rely on Article 9(2)(f) GDPR / UK GDPR and, under Turkish law, on Article 6(3)(d) KVKK (processing necessary for the establishment, exercise, or protection of a right).

Criminal convictions and offences. Under the GDPR and UK GDPR, information relating to criminal convictions and offences is governed by a separate regime under Article 10, and the conditions available under Article 9(2) do not apply to it. Under Turkish law, such information falls within the specially protected categories in Article 6 KVKK. We do not seek or ordinarily retain this information. If it is sent to us inadvertently, we will delete or redact it without undue delay, unless applicable law specifically requires or permits its retention and the relevant legal conditions are satisfied.

Purchases and Apple Services

CartCapybara offers one-time in-app purchases through Apple's StoreKit system. There is no subscription in the current version.

Apple processes payment and transaction information through the App Store. CartCapybara does not receive your payment card number, bank-account details, or Apple Account password.

Apple may provide us with sales, download, and financial reports relating to CartCapybara and its In-App Purchases. Those reports do not ordinarily identify individual purchasers to us.

App Store ratings and reviews. If you choose to rate CartCapybara or leave a written review, that rating or review is submitted to and handled through Apple's App Store. Written reviews may be published by Apple and made available to us through App Store Connect. We do not copy reviews into any CartCapybara-operated database. If you need help with the app, please contact us at the support address rather than through a review — a review is public, and we cannot discuss your issue privately there. Please do not include personal information in a public review that you would not want to make public.

CartCapybara's own use of StoreKit information on your device, including the local entitlement record, is described in Section 9.5.

Apple's processing in connection with the App Store, payments, Apple services, and device backups is governed by Apple's own terms and privacy practices.

Recipients

For information that reaches us, the following parties may process limited information:

Depending on the feature you choose to use, the following parties may also process information without it passing through us:

We do not provide CartCapybara data to advertisers or data brokers.

International Transfers

Core CartCapybara data is not uploaded to a developer-operated CartCapybara backend or server.

When you contact us from another country. Where you contact us directly — for example by sending us an email — you provide that information to us on your own initiative. Information provided directly by a data subject to a controller is not itself an international transfer under Chapter V of the GDPR, because the data subject is not a data exporter. The Controller is established in Türkiye, and reaching us from another country does not by itself make your message a restricted transfer.

Apple services and destination websites may also involve international processing under their own terms, privacy practices, and legal responsibilities.

Retention of Information That Reaches Us

Support and privacy communications. Subject to the shorter deletion rule in Section 3 for unsolicited specially protected information, support and privacy communications are retained for 24 months after the relevant request or correspondence is closed. If longer retention is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims, only the relevant material is retained for the period required by the applicable legal obligation or limitation period.

Retention of information that remains on your device is described in Section 13.

Part B

How CartCapybara Works on Your Device

This Part is provided so that you can understand how the app works. The information described here is stored locally by CartCapybara, or in the Apple App Group storage shared between CartCapybara and its own extensions, and is not sent to a CartCapybara-operated backend (servers). We do not receive it, do not hold a server-side copy, and cannot access it remotely. Because we do not receive it, we cannot produce, correct, restore, or remotely delete it for you. Copies of local app data may be included in device or iCloud backups controlled by Apple, as described in Section 12. Section 14 explains our legal position on this functionality, and Section 18 explains what it means for your rights.

On-Device Information

9.1 Cart Choices

When you create or import a Cart Choice, CartCapybara may store locally information such as:

This information is used only to provide the Cart Choice and cooling-off functionality.

An active Cart Choice remains locally stored until you make a decision about it or remove it. You can remove an unresolved Cart Choice using the app's Remove Cart Choice control. Removing it in this way deletes it from the active Cart Choices and does not add it to your Treasury history.

Because you choose what to enter, a Cart Choice title may reveal something personal about you. CartCapybara does not inspect, categorise, or transmit the content of your titles to a developer-operated server. See Section 15 in relation to specially protected information.

9.2 Decision History and Treasury

If you resolve a Cart Choice as Bought or Floated Away, CartCapybara stores a local decision record that may include:

Decision records form your local Ledger history. Treasury figures are calculated from that Ledger history when the Treasury is displayed. CartCapybara does not maintain a separate developer-side or server-side Treasury database.

9.3 Pond, Decorations, Themes, and Preferences

CartCapybara locally stores information needed to preserve your pond and app preferences, including:

Putting a decoration away removes it from its current placement but does not remove your ownership of the decoration.

9.4 Shopping Pause and Screen Time

Shopping Pause uses Apple's Family Controls, Managed Settings, and Device Activity technologies. Depending on the features you use, CartCapybara may store locally on your device:

These records are stored locally or in the App Group container so that the main CartCapybara app and its Screen Time extensions can coordinate.

We do not receive your Screen Time selections or tokens on a developer-operated server. CartCapybara cannot convert Apple's opaque Screen Time tokens into a developer-readable list of the apps you selected.

When an active Shopping Pause session ends, its active session record is removed. Relevant weekly summary information may remain locally. Turning a schedule off does not delete the saved schedule. You may clear your saved app/category selection when no pause is active.

9.5 Purchase Entitlements

CartCapybara uses StoreKit information on your device to determine which CartCapybara purchases you own, and may maintain a local entitlement record so that purchased functionality can be provided correctly. That information is held locally by the app and is not sent to a CartCapybara-operated server.

The entitlement record notes which product is owned and whether ownership is direct or through Family Sharing. It does not include your payment details, your Apple Account information, transaction identifiers, or purchase dates.

Share Extension, Product-Page Requests, and Links

If you choose to share a product page with CartCapybara, the Share Extension receives the information you intentionally share and may attempt to suggest a product title, price, and currency.

To do this, CartCapybara may make a limited network request directly from your device to the webpage you chose to share. The request does not pass through a CartCapybara server and does not use your stored website login session. As a technical consequence of the request, the website operator may receive an IP address associated with the request and standard network-request information.

When you deliberately use the Share Extension, you choose the webpage and initiate the request for product information. The request is made directly between your device and the website you selected. The request, webpage response, and network information received by that website are not sent to or retained on any CartCapybara-operated system. CartCapybara uses the webpage response only on your device to suggest information for the import you requested; we do not use it for analytics, tracking, advertising, profiling, or any other developer-side purpose. We do not operate the website, and the website operator remains responsible for the processing it carries out under its own terms and privacy practices. Our position is that we do not act as controller in respect of this user-directed interaction.

Opening a saved link. If you later tap a product link saved with a Cart Choice, it opens in your device's default browser. From that point, the browser and the destination website handle the visit under their own terms and privacy practices.

Pending imports. A shared item that has not yet been added to your pond may be held temporarily in local App Group storage. Pending imports can be manually discarded. Pending imports that remain unresolved are eligible for removal after approximately seven days through CartCapybara's normal reconciliation process.

Notifications

If you enable notifications, CartCapybara schedules notifications locally using Apple's notification system. CartCapybara does not operate a remote notification server for these reminders.

A ready-to-review notification may contain the title of the relevant Cart Choice so that you can recognise it. It does not include the Cart Choice price or source URL.

You can manage CartCapybara's notification preferences in the app, and manage system-level notification permissions in iOS Settings.

Device and iCloud Backups

CartCapybara does not currently use CloudKit or iCloud to synchronise your CartCapybara data between devices.

However, local CartCapybara app data may be included in your normal iOS device backup, including an iCloud Backup, depending on your device and Apple backup settings.

We do not receive or control those backup copies. Apple's handling and retention of iCloud or device backups is governed by Apple's own services and settings, and you can manage backup behaviour in your device's settings.

How Long On-Device Information Remains

CartCapybara uses different retention behaviour because different local records serve different functions.

Active Cart Choices. Retained until you resolve or remove them.

Completed decision history. Retained locally as part of your Ledger history until the relevant local app data is removed.

Treasury. Treasury totals are derived from Ledger history and are not separately persisted.

Pond and decoration data. Retained locally so that CartCapybara can preserve your pond, decoration ownership, and placement between launches.

Preferences and one-time state flags. Retained until changed, no longer needed, or the relevant local app data is removed.

Pending Share Extension imports. May be discarded manually and are eligible for automatic removal after approximately seven days through normal app reconciliation.

Shopping Pause. An active session record is removed when the session ends. Saved schedules, app/category selections, and applicable weekly history may remain until changed, cleared through available controls, or the relevant local app data is removed.

Deleting local app data. Deleting CartCapybara from the device removes its application data from that device in accordance with normal iOS behaviour. Copies may remain in device or iCloud backups controlled by Apple until those backups are deleted, replaced, or expire under Apple's rules.

Because we do not maintain a CartCapybara account or a server-side copy of your pond, Cart Choices, Ledger, or Shopping Pause state, we cannot remotely retrieve, restore, or erase that local content for you.

General

Sensitive and Specially Protected Information

CartCapybara does not ask you to provide specially protected information as part of its core functionality.

Different rules apply to different kinds of protected information:

Cart Choice content is stored locally by the app and is not uploaded to a CartCapybara-operated server. Depending on what you choose to enter, that content may nevertheless reveal information of these kinds.

We do not receive, read, or store Cart Choice content on a developer-operated server, and we cannot access it remotely. The fact that user-entered content may reveal specially protected information does not mean that all information described in Part B is personal data. The position described in Section 14 applies to the local handling of on-device information that constitutes personal data under applicable law.

CartCapybara does not analyse, categorise, or infer any sensitive or specially protected characteristic from your Cart Choices, your pond, or your Shopping Pause activity. See also Section 19.

CartCapybara is not designed for the storage of specially protected information, and for your own protection we recommend that you do not enter such information in a Cart Choice title or other free-text field. Such content may still appear in an on-screen notification, in a device or iCloud backup, or in a screenshot you later choose to send us.

Specially protected information that you send us in a support or privacy communication is different: that information does reach us and is handled as described in Section 3.

Advertising, Analytics, Tracking, and Sale of Data

The current version of CartCapybara does not include advertising SDKs, third-party analytics SDKs, behavioural tracking SDKs, or third-party crash-reporting SDKs.

We do not use CartCapybara data for targeted advertising. We do not sell personal data. We do not share personal data with advertisers or data brokers for cross-context behavioural advertising or similar tracking purposes.

Security

CartCapybara minimises exposure by keeping core app information inside the iOS app sandbox and the private App Group container used by CartCapybara and its extensions, rather than sending it to a CartCapybara backend.

We rely on the security protections provided by iOS and Apple's platform security, including device encryption. Keeping your device protected with a passcode and, where available, Face ID or Touch ID helps protect information stored on the device.

Network requests made by the Share Extension use the platform's normal secure transport protections where supported and required by iOS.

We do not claim that any storage or transmission method can provide absolute security.

Your Rights and Remedies

Depending on the applicable law and the circumstances, you may have the right to:

We do not carry out automated decision-making of that kind — see Section 19.

Your right to object to legitimate-interest processing

Where we process personal data on the basis of Article 6(1)(f) GDPR or the corresponding UK GDPR provision, you have the right to object at any time on grounds relating to your particular situation. If you object, we will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is required for the establishment, exercise, or defence of legal claims. CartCapybara does not use personal data for direct marketing.

On-device information and local controls

The information described in Part B is handled locally by CartCapybara and is not sent to a CartCapybara-operated backend. We do not receive it and do not maintain a server-side copy or identifier that would allow us to locate it in our systems. Copies may nevertheless be included in device or iCloud backups controlled by Apple, as described in Section 12.

As explained in Section 14, our position is that the content and choices involved in purely local, user-directed operations are not processed by us as controller.

Because we have no remote access to the on-device information described in Part B, we cannot retrieve, modify, restore, or erase it remotely on your behalf. Where a right applies to on-device information, the available in-app or device-level controls are generally the practical means by which that information can be accessed, changed, or removed, and you may delete the app to remove its application data from the device, subject to the backup considerations described in Section 12. You may still contact us with a rights request, and we will respond in light of the information we actually hold, our technical ability to act, and applicable law.

Where Article 11 GDPR or the corresponding UK GDPR provision applies to personal data processed without a need to identify the individual, a controller is not required to acquire or maintain additional identifying information solely in order to comply with data-subject rights. To the extent Article 11(2) applies and we can demonstrate that we are not in a position to identify you in relation to the relevant on-device personal data, Articles 15 to 20 do not apply unless you provide additional information that enables that identification.

KVKK and on-device information. KVKK does not contain a directly equivalent Article 11 rule. For a KVKK request concerning personal data that remains only on your device and that we do not possess or remotely access, we will explain the technical limitation and direct you to the available in-app or device-level controls. This does not affect your rights concerning personal data that we actually receive or otherwise hold.

Information we actually hold

Information described in Part A is subject to applicable data-subject rights in the ordinary way. To exercise those rights or ask a privacy question, contact:

Privacy contact: privacy.cc@frontiermeow.com

Where the GDPR or UK GDPR applies, we will respond without undue delay and ordinarily within one month of receipt. That period may be extended by up to two further months where permitted and necessary, taking into account the complexity and number of requests; if that happens, we will inform you within the initial one-month period and explain the reason.

We may need to verify your identity before acting on a request, and will ask only for information that is proportionate for that purpose.

If the EU GDPR applies, you have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.

If the UK GDPR applies, you have the right to complain to the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection. You can obtain current complaint information directly from the ICO.

Additional rights and remedies under KVKK

If your rights are governed by Turkish Law No. 6698 on the Protection of Personal Data (KVKK), your rights under Article 11 also include the right to:

Formal requests under KVKK may be submitted to the Controller using the methods permitted by Article 13 KVKK and the applicable Communiqué on the Procedures and Principles of Application to the Data Controller. For general privacy communication, or to ask for the current submission details, you may contact privacy.cc@frontiermeow.com.

Under KVKK, requests are handled as soon as possible and no later than 30 days, depending on the nature of the request. If your application is rejected, the response is inadequate, or no response is provided within the statutory period, you may lodge a complaint with the Turkish Personal Data Protection Board within the periods prescribed by Article 14 KVKK — generally within 30 days of learning the Controller's response and, in any event, within 60 days of your application to the Controller.

No Automated Decision-Making or Profiling

CartCapybara does not use your Cart Choices or Shopping Pause activity to profile you, and does not carry out automated decision-making producing legal or similarly significant effects concerning you.

Cooling periods and Shopping Pause rules operate according to choices and settings you make yourself, and are not used to infer a commercial behavioural profile about you.

Children

CartCapybara is not specifically directed to children. An App Store age rating reflects Apple's content-rating system and does not mean that CartCapybara is designed specifically for young children.

CartCapybara does not ask users to create an account or provide a date of birth, and because we receive no core app information from the app, we ordinarily cannot determine a user's age from core app use.

If you believe a child has provided personal data to us through a support or privacy communication, contact us at privacy.cc@frontiermeow.com so that we can review and, where appropriate, delete it.

Changes to This Privacy Policy

We may update this Privacy Policy if CartCapybara's functionality, legal obligations, or data practices change.

The "Last updated" date at the beginning of this Policy identifies the current version.

If we introduce a material change — for example cloud synchronisation, a CartCapybara backend, analytics, advertising, or materially different off-device processing — we will update this Policy before or when that processing begins, and provide additional notice where required.

Contact

For privacy questions or requests:

Deniz KAYA

Privacy: privacy.cc@frontiermeow.com

Support: support.cc@frontiermeow.com

↑