Data & Security
Security is foundational to Cartiva. This page summarises how we protect merchant and shopper data.
Last updated: 24 June 2026
1. Encryption
All data is encrypted in transit (TLS 1.2+). Sensitive credentials such as Shopify access tokens are encrypted at rest with AES-256 before they touch our database.
2. Tenant isolation
Cartiva is multi-tenant by design. Every database query is scoped to a single merchant, so one store can never read another store's conversations, orders, or customers.
3. Least-privilege access
We request only the Shopify scopes required to operate. Order tracking and address changes always require a verified shopper contact (the email or phone on the order) before any data is revealed.
4. Sub-processors
Reasoning runs on OpenAI and voice on Sarvam AI; both process data only to fulfil a request and not to train on your data under our configuration. Hosting, database, email (Resend), and optional telephony (Twilio) providers are bound by data-processing agreements.
5. Payments
We never store card numbers. Checkout happens on Shopify's secure, PCI-compliant checkout; billing is handled by our payment provider.
6. Data deletion
Merchants can request deletion of their account and associated conversation data. Cartiva honours verified shopper erasure (GDPR-style) requests, including purging the relevant transcripts and attachments.
7. Reporting a vulnerability
Found a security issue? Please email security@teckstaq.com. We investigate all reports promptly.