Home Privacy Policy
Legal

Privacy Policy

How Sticky Add to Cart handles data when installed on your BigCommerce store. Last updated 16 June 2026.

Sticky Add to Cart (“the App”) is a BigCommerce app provided by Codinative (“we”, “us”). The App adds a customizable, persistent Add to Cart bar to a merchant's product pages. This policy explains what data the App accesses, stores, and processes.

Information we access

When a merchant installs the App via BigCommerce OAuth, we request only the permissions needed to run the sticky bar:

  • Storefront scripts — to install the script that renders the bar on your product pages.
  • Products — to read product details (title, price, image, variants) so the bar shows the right information.
  • Store information — to read your store's currency and basic settings.

The App does not access orders, customers, or payment data.

Information we store

We store the data required to operate the App, in Google Firebase (Firestore):

  • Your store hash and the OAuth access token issued by BigCommerce at install.
  • The store user(s) who installed or were granted access to the App (id, email, username).
  • Your bar configuration — the styling, layout and behaviour settings you save in the dashboard.
  • Your subscription status for billing (see Third-party processors).

The App does not collect or store any shopper personal data. The bar runs in the shopper's browser and uses the product information already present on the page.

Third-party processors

  • BigCommerce — the platform the App integrates with.
  • Google Firebase / Firestore — stores your store record and bar configuration.
  • Vercel — hosts the App and serves the storefront script.
  • Stripe — processes subscription billing.

We do not sell or share your data with advertisers, and we do not use it for any purpose other than operating the App.

Data retention & deletion

When you uninstall the App, BigCommerce notifies our uninstall endpoint and we remove your store record, access token and bar configuration, and the storefront script is removed. To request deletion at any other time, email us at info@codinative.com.

Security

All traffic uses HTTPS. Access tokens and credentials are stored server-side and are never exposed to the browser or to shoppers.

Contact

Questions about this policy? Email info@codinative.com or visit codinative.com.

Codinative · codinative.com