← Back to QuillCart

Privacy Policy

Last updated: November 28, 2025

1. Introduction

QuillCart is a service operated by DATA MONTANA, a company registered in France at 60 Rue François 1er, 75008 Paris, France (“we”, “us”, “our”).

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our WhatsApp-powered AI commerce platform. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and French data protection laws.

Contact us:
Email: contact@quillcart.com
Data Protection Officer: contact@quillcart.com

2. Information We Collect

2.1 Business Users (Merchants)

When you create a QuillCart account, we collect:

  • Account Information: Email address, name, profile picture (via Google/OAuth sign-in)
  • Business Information: Store name, business name, contact details, business address
  • Product Data: Product listings, prices, descriptions, images you upload
  • Financial Information: Payment card details (processed by Stripe), bank account details for payouts
  • Phone Numbers: WhatsApp Business numbers purchased through our platform
  • Usage Data: Conversation logs, message counts, platform activity

2.2 End Customers (WhatsApp Users)

When customers interact with merchant AI agents via WhatsApp, we process:

  • WhatsApp Phone Number: To identify and respond to conversations
  • Conversation Content: Messages exchanged with AI agents
  • Order Information: Items ordered, delivery details, payment status
  • Interaction Data: Timestamps, message types (text, images, voice)

2.3 Consultants (Partners)

If you join our consultant program:

  • Company name, professional experience, website
  • Commission and payout records
  • Bank account details for commission payouts (via Stripe)

3. How We Use Your Information

We use your information to:

  • Provide Services: Operate AI-powered WhatsApp agents, process orders, handle payments
  • Process Payments: Charge for services, process customer payments, pay out commissions
  • Improve AI: Train and improve our AI agents using conversation data (anonymized)
  • Communicate: Send service updates, billing notifications, support responses
  • Comply with Law: Meet legal obligations, respond to lawful requests
  • Prevent Fraud: Detect and prevent fraudulent activity

4. Legal Basis for Processing (GDPR)

We process your data based on:

  • Contract Performance: To provide the services you signed up for
  • Legitimate Interest: To improve our services, prevent fraud, ensure security
  • Legal Obligation: To comply with tax, accounting, and regulatory requirements
  • Consent: Where required, such as for marketing communications

5. Data Sharing and Third Parties

We share data with the following service providers:

ServicePurposeLocation
ClerkAuthenticationUSA (SCCs)
StripePayment processingUSA (SCCs)
TwilioPhone numbers, WhatsAppUSA (SCCs)
Meta (WhatsApp)WhatsApp Business APIUSA (SCCs)
GroqAI inferenceUSA (SCCs)
RailwayBackend hostingUSA (SCCs)
TigerDataDatabase hostingEU

SCCs = Standard Contractual Clauses approved by the European Commission for international data transfers.

6. Data Retention

  • Account Data: Retained while your account is active, deleted upon account deletion request
  • Conversation History: Retained until you delete the conversation or your account
  • Financial Records: Retained for 10 years after account deletion (French legal requirement)
  • Deletion Logs: Anonymized audit records retained for compliance purposes

7. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Delete your account and data (see Data Deletion)
  • Portability: Download your data in a machine-readable format (available in Settings)
  • Restriction: Limit how we process your data
  • Object: Object to processing based on legitimate interest
  • Withdraw Consent: Where processing is based on consent

To exercise these rights, contact us at contact@quillcart.com or use the self-service options in your account Settings.

8. Cookies and Tracking

We use essential cookies only:

  • Session Cookies: To keep you logged in (via Clerk authentication)
  • Security Cookies: To prevent cross-site request forgery

We do not use advertising cookies, tracking pixels, or third-party analytics.

9. Security

We implement industry-standard security measures:

  • All data transmitted over HTTPS/TLS encryption
  • Database encryption at rest
  • Multi-tenant data isolation (separate database schemas per user)
  • Regular security audits and updates
  • Secure payment processing via PCI-DSS compliant Stripe

10. Children's Privacy

QuillCart is a business service intended for users aged 18 and older. We do not knowingly collect personal information from children under 18. If you believe we have collected data from a minor, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. Your continued use after changes constitutes acceptance.

12. Contact & Complaints

For privacy inquiries or to exercise your rights:

DATA MONTANA
60 Rue François 1er
75008 Paris, France
Email: contact@quillcart.com

If you are not satisfied with our response, you have the right to lodge a complaint with the French data protection authority (CNIL) at www.cnil.fr.