Last Updated: 15/3/2025

1. Introduction

CartFav (“we,” “us,” or “our”) is committed to protecting the privacy and security of our users (“you” or “your”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit https://www.cartfav.com (the “Site”) and use our services.

1.1 Business Information

    • Business Name: CartFav

    • Location: Fateh Pur, Layyah, Punjab, Pakistan

By using our Site, you agree to the collection and use of information in accordance with this Privacy Policy.


2. Information We Collect

2.1 Personal Information for Account Creation & Order Processing

When you create an account, we collect only the necessary details for user authentication and order fulfillment:

    • Full Name

    • Email Address

    • Billing & Shipping Address

    • Phone Number

    • Order History

We do not collect government-issued IDs or sensitive financial data, as payments are processed by third-party providers.

2.2 Payment Information

    • Payments are processed securely through Verifone, our third-party payment provider.

    • We do not store credit card or bank details on our servers.

    • Verifone’s privacy policy applies to all transactions.

2.3 Transaction and Order Data

    • We store order details for customer account history, refunds, and dispute resolution.

    • This data is retained for up to 5 years, or as required by tax regulations.

2.4 IP Address & Location Tracking

    • We collect your IP address to improve security, prevent fraud, and show country-specific products.

    • Retention: IP addresses are stored for up to 1 year in security logs.

    • This data is processed under legitimate business interest for security and localization.

2.5 Cookies & Tracking Technologies

We use cookies to:
✔ Improve website performance
✔ Personalize user experience
✔ Enable secure login sessions

Managing Cookies: You can manage or disable cookies via our Cookie Consent Tool.


3. How We Collect Your Information

We collect data through:

    • User Registration & Account Forms

    • Checkout & Payment Processing

    • Cookies & Web Tracking (Google Analytics, Facebook Pixel, etc.)

    • Third-Party Services (Cloudflare, Verifone, WordPress Plugins)

Each third-party service may have its own privacy policies, and users are subject to those policies when using the Site.


4. How We Use Your Information

We use your data to:
✔ Process & Deliver Orders
✔ Manage Your Account & Support Requests
✔ Improve Site Performance & Personalization
✔ Enhance Security & Fraud Prevention
✔ Send Promotional Emails (if opted in)

We do not sell or rent your personal data to third parties.


5. Sharing Your Information with Third Parties

5.1 Payment Processing

    • Payments are securely handled by Verifone.

    • We do not store credit card details.

5.2 Shipping & Order Fulfillment

    • Your shipping details (name, address, phone) are shared only with the vendor fulfilling your order.

    • Vendors must comply with our data protection guidelines.

5.3 Marketing & Analytics

    • We use Google Analytics, Facebook Pixel, and Cloudflare for website performance tracking.

    • These services may collect IP addresses and browsing data under their own privacy policies.

5.4 Vendor Access to Customer Data

    • Vendors receive only necessary buyer details to process orders.

    • Vendors must comply with CartFav’s Seller Agreement regarding data usage.

    • Vendors cannot use buyer data for marketing without consent.


6. Data Protection & Security Measures

6.1 Encryption & Security

    • Our website uses SSL encryption for all transactions.

    • Payments are processed via secure third-party gateways (Verifone).

    • We use Cloudflare for DDoS protection and Wordfence for website security.

6.2 Data Retention Policy

Data Type Retention Period
Account Information Until user requests deletion
Order History 5 years (for tax & legal compliance)
IP Addresses 1 year (for security logs)
Cookies & Tracking Data 6 months

6.3 Data Breach Notification Policy

    • In case of a significant risk of harm (financial fraud, identity theft), we will notify affected users within 72 hours.

    • A significant risk means a breach that exposes personal, financial, or account login information.


7. User Rights & Data Control

7.1 Access & Data Deletion

7.2 Opt-Out of Marketing Emails

    • You can unsubscribe from promotional emails anytime via the unsubscribe link in emails.

7.3 Cookie & Tracking Preferences

    • You can change cookie settings via our Cookie Consent Tool or your browser settings.


8. Cookies & Tracking Policy

We use cookies for:
✔ Secure login sessions
✔ Shopping cart functionality
✔ Performance tracking (Google Analytics, Facebook Pixel)

How to Manage Cookies?

    • Use browser settings to block non-essential cookies.


9. Compliance with Data Protection Laws

9.1 GDPR (For EU Users)

✔ You have the right to request data deletion.
✔ We collect only necessary personal data under legitimate interest.
✔ IP addresses are not permanently stored for marketing purposes.

9.2 CCPA (For California Residents)

✔ Users can request a copy of stored data.
✔ Users can opt out of personal data sharing.

9.3 Pakistani Data Protection Laws

Since CartFav is based in Pakistan, we comply with local regulations, including:

    • Pakistan Electronic Crimes Act (PECA 2016)—Ensuring data security.

    • Pakistan Personal Data Protection Bill (Proposed) – Once enacted, we will update our policies accordingly.


10. Updates to This Privacy Policy

We may update this policy occasionally. Any changes will be posted on this page with an updated “Last Updated” date.


11. Contact Us

For privacy-related inquiries, contact us at:

CartFav
 Fateh Pur, Layyah, Punjab, Pakistan
Email: [email protected]