Privacy Policy

We appreciate that you trust us with your personal information. Here we provide an overview of of what personal information we collect from you and why, how we handle it, and your rights and choices.

Carted and its affiliates and subsidiaries (hereinafter collectively referred to as “Carted,” “us,” “we,” “our,” or “Company”) has created this Privacy Policy to apply to all users of this website, www.carted.com, any affiliate website(s), software applications, and all digital assets contained or offered therein (collectively, our “Services”).

This Privacy Policy describes, among other things, the types of Information we collect from users when you use our Services, how we use it, and how you can access your Information.This Privacy Policy is integrated into our Terms & Conditions of Use (“Terms & Conditions”).  By using the Services and providing us with Information (defined below), you agree to the practices described in this Privacy Policy and to the updates to these policies posted here from time to time.

If you are based in the European Union (EU), the European Economic Area (“EEA”), which includes all EU countries, or the United Kingdom (UK), this Privacy Policy serves as notice of how we process your Personal Data (defined below) for which we are a Controller (defined below). Please see the Notice to Individuals in the European Economic Area and the UK below for your EU privacy rights, which supplements the Privacy Policy as to users located in the EU, EEA, or UK only. If we require your consent, we will request it formally, in adherence to applicable data protection laws.

By using the Services and providing us with your Information (defined below), you agree to the practices described in this Privacy Policy and Terms & Conditions referenced below and to the updates to these policies posted here from time to time.  By using our Services, you consent to these policies. If you have any privacy or data use concerns, please contact us as set out below under the heading “How to Contact Us.”

To make sure you stay informed of all changes, you should check these policies periodically.  Updates will be referenced by the “Last Updated” date shown above.

1. Information we collect about you

We may collect the following types of personal data about you which are described in more detail below: (A) Information you provide to us; (B) Information we may automatically collect; and (C) Information we may receive from third parties. The Information listed in (A)-(C) above, is detailed below, and hereinafter referred to as “Information.”

A. Information you provide to us

In using our Services, you may provide us with Information, including, without limitation:

  • Contact information such as name, email address, postal address, and telephone number(s);
  • Communication, product preferences, and opinions in online forms you share with us or when you communicate with us through email;
  • Account personal information and log in credentials, including unique identifiers such as username and password; and
  • Additional Information as otherwise described to you at the point of collection or pursuant to your consent.

B. Information we may automatically collect about you

Our Services may automatically collect certain Information about you. We use this Information to help us design our Services to better suit our users’ needs. This Information may include:

  • IP address, which is the number associated with the service through which you access the internet, like your ISP (internet service provider);
  • Date and time of your visit or use of our Services;
  • Domain server from which you are using our Services;
  • Type of computer, web browsers, search engine used, operating system, or platform you use;
  • Data identifying the web pages you visited prior to and after visiting our website or use of our Services;
  • Your movement and activity within the website, which is aggregated with other information;
  • Geographic data such as country or region; and
  • Mobile device information, including the type of device you use, operating system version, and the device identifier (or “UDID”).

i. Cookies and technologies used to collect information about you

We collect the above Information directly and through the use of third parties. We collect this Information by using certain technologies, such as cookies, web beacons, and other technologies. Third-party service providers, advertisers, and/or partners may also view, edit, or set their own cookies or place web beacons.

  1. Cookies (or browser cookies). Cookies are small digital files that are transferred to your computer or smartphone’s hard drive when you visit a website or click on a URL. Most web browsers automatically accept cookies. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of our Services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Services.
  2. Flash Cookies. We may use local shared objects, also known as Flash cookies, to store your preferences such as volume control or display content based upon what you view on our site to personalize your visit. Third parties, with whom we partner to provide certain features or to display advertising based upon your browsing activity, use Flash cookies to collect and store Information. Flash cookies are different from browser cookies because of the amount of, type of, and how data is stored. Cookie management tools provided by your browser will not remove Flash cookies.
  3. Web Beacons. Website pages may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages and for other related statistics (for example, recording the popularity of certain content and verifying system and server integrity). We also use these technical methods to analyze the traffic patterns, such as the frequency with which our users visit various parts of the Services. These technical methods may involve the transmission of Information either directly to us or to a third party authorized by us to collect Information on our behalf. Our Services may use retargeting pixels from Google, Facebook, and other ad networks. We may also use web beacons in HTML emails that we send to determine whether the recipients have opened those emails and/or clicked on links in those emails.
  4. Analytics. Analytics are tools we use, such as Google Analytics, to help provide us with Information about traffic to our website and use of our Services, which Google may share with other services and websites who use the collected data to contextualize and personalize the ads of its own advertising network. Learn more about Google’s Privacy Policy here: https://policies.google.com/privacy?hl=en-US.
  5. Mobile Application Technologies. If you access our website and Services through a mobile device, we may automatically collect Information about your device, your phone number, and your physical location.

C. Information we may receive from third parties

We may collect additional Information about you from third-party websites, social media platforms, such as but not limited to, Facebook, X (formerly Twitter), TikTok, or Instagram (“Social Media Platforms”), and/or sources providing publicly available Information (e.g., from the U.S. postal service) to help us provide Services to you, help prevent fraud, and for marketing and advertising purposes.

This Privacy Policy only applies to Information collected by our Services. We are not responsible for the privacy and security practices of those other websites or Social Media Platforms or the Information they may collect (which may include IP address). You should contact such third parties directly to determine their respective privacy policies. Links to any other websites or content do not constitute or imply an endorsement or recommendation by us of the linked website, Social Media Platform, and/or content.

2. How we use your information

A. Use and purpose of processing your information

We use and process your Information for things that may include, but are not limited to, the following:

  • To respond to your inquiries and provide you with requested information and other communications, including by email;
  • To send you our newsletter and other correspondence you request;
  • For general or targeted marketing and advertising purposes, including sending you promotional material or special offers on our behalf or on behalf of our marketing partners and/or their respective affiliates and subsidiaries and other third parties, provided that you have not already opted-out of receiving such communications;
  • To fulfill contracts we have with you;
  • To manage, improve, and foster relationships with third-party service providers, including vendors, suppliers, and parents, affiliates, subsidiaries, and business partners;
  • To maintain, improve, customize, or administer the Services, perform business analyses, or other internal purposes to improve the quality of our business, the Services, resolve technical problems, or improve security or develop other products and services;
  • To comply with our Terms & Conditions;
  • For analytics for business purposes and business intelligence;
  • To comply with any applicable laws and regulations and respond to lawful requests; and/or
  • For any other purposes disclosed to you at the time we collect your Information and/or pursuant to your consent.

We grant you a limited, revocable, non-exclusive, non-transferable right to review and in some instances print content, from our Services (e.g., our website) for your personal and educational purposes as long as they do not violate any aspect of these Terms & Conditions or applicable law, including our intellectual property and other proprietary rights in and to the Services or the intellectual property rights of another party. 

We reserve the right to terminate or limit your access to our Services and/or the licenses granted herein for any reason (or no reason) and in our sole discretion.  We reserve the right to, at any time, temporarily or permanently, modify or discontinue any features associated with the Services with or without notice and for any reason, including performing maintenance, repairs, or upgrades.  We (and our licensors) remain the sole owner of all rights, title, and interest in the Services.  We will not be liable if for any reason all or any part of the Services are unavailable at any time or for any period.

B. Sharing your information

We may disclose anonymized aggregated Information about our users, that does not identify any individual, without any restriction.  

We may share your Information as set forth in the Privacy Policy and in the following circumstances:

  • Third-Party Service Providers.  We may share your Information with third-party service providers or data processors that perform certain functions or services on our behalf (such as to host the Services, store or manage the data, perform analyses, process payments, provide customer service, or send communications for us). These third-party service providers will process this data only for purposes specified by us. In some instances, we may aggregate Information we collect so third parties do not have access to your identifiable Information to identify you individually.
  • Disclosure of Information for Legal and Administrative Reasons.  We may disclose your Information without notice: (i) when required to by law or to comply with a court order, subpoena, search warrant, or other legal process; (ii) to cooperate or undertake an internal or external investigation or audit; (iii) to comply with legal, regulatory, or administrative requirements of governmental authorities (including, without limitation, requests from the governmental agency authorities to view your Information); (iv) to protect and defend the rights, property, or safety of us, our subsidiaries and affiliates, and any of their officers, directors, employees, attorneys, agents, contractors, and partners, and the website Service users; (v) to enforce or apply our Terms & Conditions; and (vi) to verify the identity of the user of our Services.
  • Business Transfers. Your Information may be transferred, sold, or otherwise conveyed (“Conveyances”) to a third party where we: (i) merge with or are acquired by another business entity; (ii) sell all or substantially all of our assets; (iii) are adjudicated bankrupt; or (iv) are liquidated or otherwise reorganize. You agree to any and all such Conveyances of your Information.
  • Information Shared with our Subsidiaries, Parents, and Affiliates. We may share your Information with our subsidiaries and affiliates, including but not limited to,Dream Big Labs Pty Ltd. If you do not want to share your information with our subsidiaries and affiliates, please contact us at [email protected].
  • Aggregate and Deidentified Data. We may share general Information, aggregated data, or publish Information based on aggregated data. However, we will only do so in a way that your personal identity is protected.
  • Online Communications. Any Information you submit in a public forum (e.g., a blog or social network) may be read, collected, or used by us and other participants, and could be used to personalize your experience. You are responsible for the Information you choose to submit in these instances.
  • With Your Consent. We may share Information consistent with this Privacy Policy with your consent.

Except as provided in this Privacy Policy, we will not sell, exchange, trade, or disclose your Information we have collected without your consent.

3. Links to other websites

Portions of our Services may involve linking to or using websites or services belonging to third parties (“Third-Party Websites”), including those of third-party vendors or retailers. All use of third-party applications or services is at your own risk and subject to such third party's privacy policies.

In addition, from our Services you may be able to interact with social media sites (“Social Media Platforms”), for example, by “liking” or “following” us on a social media platform. If you choose to click on a link to one of these Third-Party Websites or choose to interact with or through a Social Media Platform, your activities are not governed by this Privacy Policy and will be governed by the privacy policy on that Third-Party Website or Social Media Platform. Please review their privacy policies and terms of service before disclosing any Information there. We do not review, do not endorse, and are not responsible for the privacy practices of these Third-Party Websites and Social Media Platforms.

We may also maintain pages on Social Media Platforms. Those pages and your interaction with them are governed by the privacy policies of the relevant Social Media Platform, and not our Privacy Policy. As with other Third-Party Websites, we do not endorse and are not responsible for the privacy practices of these forums, although we may have a presence on them.

4. Information security

We use commercially reasonable measures to provide our Services. However, you should assume that no data transmitted over the internet or stored or maintained by us or our third-party service providers can be 100% secure. Therefore, although we believe the measures implemented by us reduce the likelihood of security problems to a level appropriate to the type of data involved, we do not promise or guarantee, and you should not expect, that your Information or private communications will always remain private or secure. We do not guarantee that your Information will not be misused by third parties.  We are not responsible for the circumvention of any privacy settings or security features. You agree that we will not have any liability for misuse, access, acquisition, deletion, or disclosure of your Information.

If you believe that your Information has been accessed or acquired by an unauthorized person, you shall promptly contact us via the How to Contact Us section so that we can quickly take necessary measures.

5. Data retention

We will retain your Information for as long as needed to provide you Services. If you wish to request that we no longer use your Information to provide you Services, please contact us at [email protected].  We will retain and use your Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. In accordance with our routine record keeping, we may delete certain records that contain Information you have submitted to us. We are under no obligation to store such Information indefinitely and disclaim any liability arising out of, or related to, the destruction of such Information.

6. Your choices

A. Email

By using our Services, you agree that we may contact you by email as set forth herein. If you do not want to receive marketing and promotional emails from us, you may click on the “unsubscribe” link in the email to unsubscribe and opt-out of marketing email communications by contacting us via the How to Contact Us section.

B. Text messages

You may sign up to receive text messages from us (e.g., on-site chats or text message marketing).  By signing up for text messaging services or otherwise opting in to receive text messages (opting in via short code or entering your phone number into an on-site collection widget), you agree that you have provided Carted with prior express written consent to be contacted by text message, including recurring automated promotional and personalized marketing text messages (e.g., discounts, cart reminders).

  • By providing prior express and/or prior express written consent, you agree to receive text messages under the Telephone Consumer Protection Act and related state laws, including by the use of an automatic telephone dialing system (ATDS) to deliver text messages to the mobile phone number which you provided to Carted.  While you consent to receive messages sent using an autodialer, the foregoing shall not be interpreted to suggest or imply that any or all of Carted’s mobile messages are sent using a ATDS (or “autodialer”). We will use the Information provided by you in connection with the text messaging services in accordance with this Privacy Policy.  Your consent is not a condition of any purchase or use of our Services and your consent to be contacted as described is voluntary.  The number of text messages you receive may vary based upon the text messaging service(s) you sign up for. Message and data rates may apply.
  • You may revoke your consent and opt-out to discontinue test messages at any time.  If you no longer want to receive text messages from us, reply STOP (or as otherwise instructed) in the text message or refer to the How to Contact Us section.

C. Cookies

If you want to delete any cookies that are already on your computer, please refer to your file management software to locate the file or directory that stores cookies. Other information on deleting or controlling cookies is available at www.allaboutcookies.org. Please note that by deleting cookies or disabling future cookies, you may not be able to access certain areas or features of our Services.

D. Opting out of direct marketing

To exercise choices regarding the marketing information you receive, you may also review the following links:

7. Notice to individuals in the European Economic Area and the UK

This section applies only to individuals coming to our Services from within the European Union (EU), the European Economic Area (EEA), and the UK, and only if we collect through the Services any Information from you that is considered “Personal Data,” as defined in the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

Personal Data includes any Information relating to an identified or identifiable natural person, who could be identified either directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person (which may include some or all of your Information as defined in this Privacy Policy).

A. Identity and contact details of controller and EU representative

Unless otherwise stated, we are the Data Controller for the Information we process.

Contact Details:
Email: [email protected]

B. Your data protection rights

To the extent the GDPR and Data Protection Act 2018 apply, and we hold your Information in our capacity as a Data Controller as defined under those laws, you may request that we:

  • Restrict the way that we process and share your Information;
  • Transfer your Information to a third party;
  • Provide you with access to your Information;
  • Remove your Information if no longer necessary for the purposes collected;
  • Update your Information so it is correct and not out of date; and/or
  • Object to our processing of your Information.

You may also revoke your consent for processing of your Information.  If you wish to object to the use and processing of your Information or withdraw consent to this Privacy Policy, you can contact us in the following ways:

Email: [email protected]

The requests above will be considered and responded to in the time-period stated by applicable law.  Note, certain Information may be exempt from such requests.  We may require additional Information from you to confirm your identity in responding to such requests.  You have the right to lodge a complaint with the supervisory authorities applicable to you and your situation, although we invite you to contact us with any concern as we would be happy to try and resolve it directly. Please contact us at:

Email: [email protected]

C. Lawful basis for processing your information

The lawful basis for our processing of your Personal Data will depend on the purposes of the processing.  For most Personal Data processing activities covered by this Privacy Policy, the lawful basis is that the processing is necessary for our legitimate business interests.  Where we process Personal Data in relation to a contract, or a potential contract, with you, the lawful basis is that the processing is necessary for the performance of our contract with you or to take steps at your request prior to entering into a contract.  If we are required to share Personal Data with law enforcement agencies or other governmental bodies, we do so on the basis that we are under a legal obligation to do so.  We will also use consent as the legal basis where we deem appropriate or to the extent required by applicable law, for example, before we collect precise location data from your mobile device.

Depending on what Personal Data we collect from you and how we collect it, we may also rely on various grounds for processing your Personal Data, including the following reasons:

  • Processing on the basis of legitimate business interests.  When we process Personal Data on the basis that the processing is necessary for our legitimate business interests, such interests include: (i)  providing, improving, and promoting our Services, Apps, and products and services; (ii) communicating with current and potential customers, other Business Partners, and their individual points of contact; (iii) managing our relationships with our customers and other Business Partners, and their individual points of contact; (iv) other business development purposes; (v) sharing Information within the Company, as well as with service providers and other third parties; and (vi) maintaining the safety and security of our products, Services, and employees, including fraud protection.
  • Processing on the basis of performance of a contract.  Examples of situations in which we process Personal Data as necessary for performance of a contract include e-commerce transactions in which you purchase a service from us.
  • Processing on the basis of consent.  Examples of processing activities for which we may use consent as its legal basis include: (i) collecting and processing precise location Information from your mobile device; (ii) sending promotional emails when consent is required under applicable law; and (iii) processing Personal Data on Company Services through cookies and similar technologies when consent is required by applicable law.
  • Processing because we are under a legal obligation to do so. Examples of situations in which we must processes Personal Data to comply with our legal obligations include: (i) providing your Personal Data to law enforcement agencies and other governmental bodies when required by applicable laws; (ii) retaining business records required to be retained by applicable laws; and (iii) complying with court orders or other legal processes.

If the processing of your Information is based on your consent, the GDPR and Data Protection Act 2018 also allow users the right to access, revoke, or modify your consent at any time.  Please see the How to Contact Us section below to review or modify your consents.

D. Consent to transfer

We are operated in the United States and Australia, and we may use service providers based in the United States and Australia to operate our business and our relationship with you. Please be aware that Information, including your Personal Data, that we collect will be transferred to, stored, and processed in the United States, a jurisdiction in which the privacy laws may not be as comprehensive as those in the country where you reside and/or are a citizen. We maintain measures to address the transfer of your Personal Data between our group companies and between us and our third-party providers in accordance with applicable data protection laws and regulations.

E. Retention

We will retain your Information for as long as needed for the purposes described in this Privacy Policy. More specifically, the time we maintain your Information depends on the following factors:

  • Whether we need the Information to provide the Services. We will maintain any data needed to provide you with the Services, such as contact information and payment or transaction information, for as long as needed for us to provide you with the Services, respond to your questions and requests, and/or administer your account (if applicable).
  • Whether we need the Information to comply with our legal obligations. We may have legal obligations to maintain your Information where a legal or regulatory body may ask for it in the future, for example in response to a data subject request or complaint. This Information may include contact information and location information.
  • Whether we need the Information for a legitimate business interest. We may store Information like contact information, cookies, and location information in order to perform analytics, troubleshoot errors, or improve our Services. In any event, we delete the Information when it is no longer needed for our legitimate interest.

Regardless of our reason for retaining your Information, we delete all Information in accordance with our routine record keeping policies.

8. Geographic location of data storage and processing

Our Services collect Information and processes and stores that Information in databases located in the United States. As such, we may store and process Information on servers located outside of the country where you originally deposited the data. If you are visiting the Services from a country outside the United States, you should be aware that you may transfer personally identifiable Information about yourself to the United States, and that the data protection laws of the United States may not be as comprehensive as those in your own country. By visiting our Services and submitting Information, you consent to the transfer of such Information to the United States.

9. Accessing, correcting, or deleting your information

To the extent other data privacy laws provide users with additional data subject rights, those rights may be honored by the Company following proper authentication and verification. Please see the How to Contact Us section below for more information.

10. Children's information

The Services are intended only for users over the age of eighteen (18). If we become aware that a user is under thirteen (13) (or a higher age threshold where applicable) and has provided us with Information, we will take steps to comply with any applicable legal requirement to remove such Information. Contact us if you believe that we have mistakenly or unintentionally collected Information from a child under the age of thirteen (13).

11. Changes to this Privacy Policy

We reserve the right to change, modify, or amend this Privacy Policy at any time to reflect changes in our products and service offerings, accommodate new technologies, regulatory requirements, or other purposes. If we modify our Privacy Policy, we will update the “Last Updated” date below and such changes will be effective upon posting. It is your obligation to check our current Privacy Policy for any changes.

12. How to contact us

If you have any questions about these Terms & Conditions, please contact us at the following:

Email: [email protected]

Last updated 15 February 2024