Overview and scope
This Privacy Policy explains how Cartra AI (“Cartra,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information. It applies to our website at www.cartra.ai, our consultation request form, and the business communications we have with prospective clients, clients, and partners (together, the “Services”).
Cartra is a business-to-business company. We design, build, deploy, and maintain custom AI agents for operations teams, connected to the tools our clients already run. We do not offer a consumer app. Our Services are intended for people acting in a professional capacity.
This policy does not govern data we process on behalf of clients during an engagement. That work is governed by a separate written agreement signed with each client (a “Client Agreement”), as explained in Client data and AI systems.
Please read this policy alongside our Terms of Use. If you do not agree with it, please do not use the Services.
Information we collect
We collect only what we need to respond to you, run the website, and serve our clients.
Information you give us
- Consultation requests. When you request a consultation, we collect your name, work email, role, company name, and company annual revenue range, plus a description of what you need if you choose to add one. We also record which page you sent the request from.
- Direct communications. When you email us or message us on WhatsApp or WeChat, we receive your message, your contact details, and anything else you choose to share, such as attachments.
- Business relationship details. If you are a client contact, partner, or vendor, we collect the business contact and billing details needed to manage the relationship.
Please do not send sensitive personal information, such as health data, financial account numbers, or government ID numbers, through the form or by message unless we have asked for it under a Client Agreement.
Information collected automatically
- Log data. Our hosting provider records standard server logs, including your IP address, browser type (user agent), the pages you request, and request times.
- Usage and device data. Through cookies and similar technologies, we collect information about how you use the site, such as pages viewed, referring pages, device and browser type, approximate location derived from your IP address, and events such as clicks on consultation buttons and form submissions. See Cookies and analytics.
- Security signals. Cloudflare Turnstile runs on our consultation form and may process your IP address and device and browser signals to tell people from bots.
Information from other sources
We may receive business contact information from referrals, event organizers, partners, and publicly or commercially available business sources, such as professional directories and business contact databases. We use it to understand who we are talking to and to follow up in a relevant way.
How we use information
We use personal information to:
- Respond to consultation requests and questions, schedule calls, and assess whether we are a good fit for your needs.
- Provide and support the Services, and manage client engagements and other business relationships.
- Communicate with you about our work, including relevant updates. You can opt out of non-essential communications at any time.
- Measure and improve the website, such as which pages help visitors most.
- Protect the Services, including detecting spam, abuse, fraud, and security incidents.
- Comply with legal obligations, enforce our agreements, and establish or defend legal claims.
- Fulfill any other purpose we describe when we collect the information, or with your consent.
We may also create aggregated or de-identified information that cannot reasonably identify you. We use it to understand trends and improve our Services, and we do not attempt to re-identify it.
Client data and AI systems
When a client engages us to build or run an AI agent, we may process data from that client’s systems, such as documents, emails, and records in an ERP or CRM, including any personal information those records contain (“Client Data”).
- We act on our client’s instructions. For Client Data, we are a service provider or processor. The client decides what data an agent can access and for what purpose. If you have questions about how an organization uses an agent we built, please contact that organization first.
- The Client Agreement controls. Each engagement is governed by a Client Agreement, such as a master services agreement, statement of work, or data processing agreement. If it conflicts with this policy, the Client Agreement controls for Client Data.
- No training on your data. We do not use Client Data, form submissions, or messages you send us to train general-purpose or third-party AI models.
- Model providers are restricted by contract. When an engagement uses a third-party AI model provider, such as a large language model API, we engage that provider under terms that prohibit it from using the data to train its models, consistent with the Client Agreement.
- Access is limited. We limit access to Client Data to the people who need it to deliver the engagement, and we return or delete it as the Client Agreement requires.
No sale of personal information
We do not sell personal information, and we have not sold it in the past 12 months. We do not rent or trade contact lists, and we do not give personal information to third parties for their own marketing.
Data retention
We keep personal information only as long as we need it for the purposes in this policy, unless the law requires or permits a longer period. As a general guide:
- Consultation requests and correspondence from people who do not become clients: up to 24 months after our last contact.
- Client relationship records: for the length of the relationship, then as long as needed for legal, tax, accounting, and contractual purposes.
- Analytics data: up to 14 months, under the retention setting in our Google Analytics account.
- Server logs: for a limited period set by our hosting provider.
- Client Data: as set out in the Client Agreement.
When we no longer need information, we delete or de-identify it. Where that is not yet possible, such as for data in backups, we isolate it until it can be deleted.
Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls based on need, and careful selection of service providers. Client engagements may carry additional safeguards set out in the Client Agreement.
No method of transmission or storage is fully secure, so we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, contact us at [email protected]. If a breach affects your personal information, we will notify you as the law requires.
International data transfers
Cartra is based in the United States, and our service providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live.
When we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses and the UK addendum, or another lawful transfer mechanism. Contact us to learn more about these safeguards.
Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete your personal information.
- Object to or restrict certain processing, or withdraw consent where we rely on it.
- Opt out of marketing messages by replying to ask us to stop or by emailing us.
To make a request, email [email protected]. We will verify your identity before we act, usually by matching details you give us with details we hold, and we will respond within the time the law requires. We may keep some information where the law allows, for example to meet a legal obligation or to keep a record of your opt-out.
If your request concerns Client Data, we will refer you to the client that controls it and help that client respond.
Additional rights for California residents
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives you the rights below. This section supplements the rest of this policy.
What we collect and why
In the past 12 months, we have collected these categories of personal information:
- Identifiers, such as name, email address, messaging handle, and IP address.
- Professional or employment-related information, such as role, company name, and company revenue range.
- Internet or other electronic network activity, such as pages viewed, clicks, browser type, and security signals.
- Approximate geolocation, derived from IP address.
- Other information you choose to share, such as the description in a consultation request.
We collect these categories from the sources in Information we collect, use them for the purposes in How we use information, disclose them for business purposes to the recipients in How we share information, and keep them for the periods in Data retention.
We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes that would give you a right to limit its use.
Your California rights
- Right to know the personal information we collected about you, its sources, our purposes, and the categories of third parties we disclosed it to, and to receive a copy of specific pieces.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. Because we do neither, there is nothing to opt out of today. If that changes, we will honor opt-out requests, including Global Privacy Control signals, as the law requires.
- Right to non-discrimination. We will not deny you services, charge you a different price, or give you a different quality of service because you used these rights.
How to submit a request
Email [email protected] with the subject line “California privacy request” and tell us which right you want to use. We will confirm receipt within 10 business days and respond within 45 days. If we need up to 45 more days, we will tell you why.
Authorized agents. You may have an authorized agent submit a request for you. We will ask the agent for your signed written permission, and we may ask you to verify your identity directly with us, unless the agent holds a valid power of attorney.
Additional rights for EEA, UK, and Swiss residents
If you are in the European Economic Area, the United Kingdom, or Switzerland, Cartra is the controller of the personal information described in this policy. For Client Data, our client is the controller and we act as its processor. We rely on these legal bases:
- Legitimate interests, to respond to inquiries, run and secure the website, understand how it is used, and develop business relationships. We weigh these interests against your rights, and you can object at any time.
- Contract, to take steps you request before entering an agreement with us, and to perform that agreement.
- Consent, where we ask for it. You can withdraw consent at any time without affecting processing that happened before.
- Legal obligation, to meet tax, accounting, and other legal requirements.
Beyond the rights in Your rights and choices, you have the right to data portability and the right to object to processing based on legitimate interests, including direct marketing.
You also have the right to lodge a complaint with the data protection supervisory authority where you live or work, or where you believe a violation occurred. In the UK, that is the Information Commissioner’s Office. We would welcome the chance to address your concern first, so please contact us.
Children’s privacy
Our Services are for adults acting in a business capacity and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us at [email protected] and we will delete it.
Third-party links
The site may link to services we do not control, such as WhatsApp, WeChat, and Google. Their own privacy policies govern how they handle your information, including messages you send us through their platforms. Please review those policies before you share information.
Changes to this policy
We may update this policy as our Services, our providers, or the law change. When we do, we will post the revised policy on this page and update the “Last updated” date at the top of this page. For material changes, we will also give more prominent notice, such as a notice on the site or an email. The updated policy applies from the date it is posted.
Contact us
Questions, requests, or concerns about this policy or our privacy practices? Email [email protected] or write to us at the address below. For help with an engagement, visit our Support page.
Cartra AI2261 Market Street STE 85777
San Francisco, CA 94114
United States
[email protected]