Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Tapcart is a no code mobile app builder for Shopify stores that creates native iOS and Android apps and uses device identifiers, push tokens and analytics SDKs that require consent for non essential tracking.
Tapcart is a no code mobile app builder for Shopify stores, headquartered in Santa Monica California. It lets merchants turn their Shopify catalog into a fully native iOS and Android shopping app without writing code, syncing products, pricing and customer data from Shopify. Because it powers the full mobile storefront, the app processes shopper and customer personal data on Tapcart infrastructure. It also supports push notifications and a wide range of marketing and analytics integrations.
Because Tapcart builds native apps rather than websites, its tracking relies on mobile SDKs, device identifiers, push notification tokens and in app analytics events rather than browser cookies. Merchants can connect tools such as Google Analytics, the Facebook SDK, Heap, Klaviyo and attribution providers, which collect additional behavioral and advertising data. The processed data includes account details, order history, device information, app usage events and marketing identifiers. The privacy impact depends on which optional SDKs the merchant enables.
Core app functions such as accounts, cart and checkout can be based on performance of a contract, but analytics, advertising and attribution SDKs require consent under the GDPR and the ePrivacy rules that apply to storing or reading information on a device. On iOS, Apple App Tracking Transparency requires a separate permission prompt before cross app tracking identifiers are used, and Android exposes an advertising identifier that needs a lawful basis. The merchant is the controller and Tapcart and its sub processors handle the data on their behalf.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The app should present a consent mechanism that loads only essential functionality by default and waits for an explicit opt in before activating analytics and marketing SDKs. On iOS this works alongside the App Tracking Transparency prompt, and on both platforms users must be able to refuse and later withdraw consent without losing core app features. Push notifications also require the user to grant the system permission. Merchants must keep a record of the consent collected.
Tapcart is a United States company and processes app and customer data on United States infrastructure, so data from European users is transferred to a third country. These transfers should rely on the EU US Data Privacy Framework where Tapcart or its sub processors are certified, supported by Standard Contractual Clauses and a transfer impact assessment. Any connected analytics or advertising SDK may add further transfers, which the merchant should map and disclose to app users.
To deploy a Tapcart app compliantly, sign a data processing agreement with Tapcart, publish an app privacy policy and complete the platform privacy labels for the App Store and Google Play. Implement an in app consent flow that gates non essential SDKs, integrate the iOS tracking prompt and document the lawful basis for each processing activity. Map every SDK and its transfers, set retention periods and review the configuration whenever you add a new integration.
Websites using Tapcart must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is advisable because a Tapcart app collects device identifiers, push tokens, purchase behavior and analytics events, and can integrate marketing and attribution SDKs. Assess which third party SDKs the merchant enables, the transfers to the United States, and the use of iOS App Tracking Transparency and Android advertising identifiers. Document the lawful basis for core app functions versus optional tracking and the retention of customer and analytics data.
Sample consent text
This app is built with Tapcart and uses essential data such as your account and order details to run the store. With your consent we also use analytics and marketing tools that rely on device identifiers and may transfer data to the United States. You can manage these tracking choices at any time in the app settings.
Third-party domains contacted
tapcart.comapi.tapcart.comcdn.tapcart.commyshopify.comgoogle-analytics.comgraph.facebook.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| device_id | Functional | Persistent | Identifies the device so the app can maintain session and sync the cart and account |
| push_token | Functional | Persistent | Stores the push notification token so the merchant can deliver app notifications |
| tapcart_session | Functional | Session | Maintains the authenticated app session during use of the store |
| analytics_id | Analytics | 13 months | Optional in app analytics identifier that measures usage and shopper behavior |
| idfa_gaid | Marketing | Persistent until reset | Mobile advertising identifier used for attribution and marketing when the user consents |
| attribution_id | Marketing | 13 months | Optional identifier used by attribution SDKs to link installs and purchases to campaigns |
Tapcart uses cookies for user preferences — inform visitors with a consent banner.
Because Tapcart builds native apps, it relies on device identifiers, push notification tokens and in app analytics events rather than browser cookies. Core identifiers keep the session, cart and account working, while optional analytics and advertising SDKs add identifiers such as the mobile advertising ID for measurement and attribution. What is collected depends on which SDKs the merchant enables.
Consent is required for analytics, advertising and attribution tracking, though core app functions can rely on contract performance. On iOS the App Tracking Transparency prompt must be shown before cross app tracking identifiers are used, and on Android the advertising identifier needs a lawful basis. Essential features may run without consent, but any non essential SDK must wait for an opt in.
Core functionality such as accounts, cart and checkout is generally based on performance of a contract under Article 6(1)(b) of the GDPR. Analytics, marketing and attribution depend on consent under Article 6(1)(a) and the rules on accessing information stored on a device. The merchant should document the basis for each processing activity.
Yes. Tapcart is a United States company based in Santa Monica and processes app and customer data on United States infrastructure, so European user data is transferred to a third country. These transfers rely on the EU US Data Privacy Framework and Standard Contractual Clauses. Connected SDKs may add further transfers that you should disclose.
A data protection impact assessment is advisable because the app collects device identifiers, push tokens, purchase behavior and analytics events and can integrate advertising SDKs. Assess the enabled SDKs, the United States transfers and the use of mobile tracking identifiers. A minimal app using only essential functions carries lower risk.
Sign a data processing agreement with Tapcart, publish an app privacy policy and complete the App Store and Google Play privacy labels. Add an in app consent flow that gates non essential SDKs, integrate the iOS tracking prompt and document the lawful basis for each activity. Review the SDK configuration whenever you add a new integration.
Alternatives include other Shopify mobile app builders such as Vajro, Plobal Apps and Shopney, or a custom app built on the Shopify Mobile Buy SDK. Each has its own SDK and tracking profile and its own hosting location. Compare which third party SDKs they bundle and where they process data before choosing.
Re check the active SDKs and integrations whenever you change the app configuration, because adding a marketing or analytics tool introduces new identifiers and data flows. Update your app privacy policy and the store privacy labels to match what is actually collected. Refresh your consent flow if the scope of tracking changes.