Tracking & Data
EasyCart Data Handling
EasyCart handles a lot of personal information for the people who visit, shop, and buy from your store. Here’s exactly what’s stored, why, and what modern data protection laws mean for your business.
The Evolution of Personal Information
Two major regulations reshaped what counts as personal data — and every online store needs to know both.
In 2018, the European Union’s General Data Protection Regulation (GDPR) redefined personal information handling for data that used to be considered fairly benign. It covers anything that can directly or indirectly identify a person — real names, screen names, ID numbers, birth dates, location data, network addresses, device IDs, and even physical, physiological, genetic, mental, commercial, cultural, or social characteristics. In practice, that’s almost any piece of information about a person that isn’t fully anonymized.
In 2020, the United States followed with the California Consumer Privacy Act (CCPA), which expands on GDPR slightly. Under the CCPA, personal information is anything that identifies, relates to, describes, or could reasonably be linked — directly or indirectly — to a particular consumer or household. That includes biometric data, browsing history, employment and education data, and any inferences drawn from that data to build a profile of someone’s preferences, characteristics, and behavior.
Who These Laws Apply To
GDPR and CCPA cast very different nets.
The EU’s GDPR applies to any company doing business within the EU — offering goods or services, paid or free, or monitoring the behavior of individuals there. California’s CCPA works differently: it currently applies to companies with annual revenue over $25 million, or that collect data on more than 50,000 people. Companies don’t need to be based in California, or even the United States, to fall under it. Most store owners won’t hit these thresholds today — but national trends may extend similar rules to everyone eventually, so it’s worth keeping an eye on.
What You Actually Need to Do
Below the CCPA thresholds? There’s not much required — but a good policy is smart regardless.
If you’re a small or mid-sized business under $25 million in annual revenue, or tracking fewer than 50,000 people, you don’t need to do much to comply today. Over that threshold, you likely already have a legal team helping you meet the requirements — typically a clear link on your site letting people delete their data or opt out of collection at any time.
More importantly: every site should have a data policy stating exactly what’s collected, how it’s used, and whether it’s shared with third parties. Under the CCPA, failing to give users clear access to that information can expose you to lawsuits. It’s a good habit to build now — broader rules along these lines may well become federal law.
What Data Does EasyCart Store?
EasyCart never stores full credit card numbers — but it does store the following, mostly to power payment, shipping, tax, and fraud-detection systems.
- Usernames & Encrypted Passwords: Saved for users who opt to save their account information during checkout or account creation.
- Email Addresses: Saved with every user order and account.
- Billing Addresses: Required on all orders for payment purposes.
- Shipping Addresses: Optional depending on your product setup — used for shipping and tax calculations.
- Order History: Saved per user, including product, option, and other cost-associated data.
- IP Information: Saved during order processing to help payment processors run fraud protection.
- Cookies & Session Data: Used for eCommerce tracking, and can carry a personally identifiable signature tying a user to their cart, account, and purchase history.
- Partial Card Data: Some payment processing saves the last 4 digits and expiration date of a card, used for authentication on terminal orders.
- Tracking Codes: Systems like Google Analytics and Facebook Pixel are implemented directly and pass order data, location, and page flow information to those platforms — not stored within EasyCart itself.
- Third-Party Extensions: Apps like QuickBooks, ShipStation, MailChimp, Stamps.com, and BlueCheck vary in what they process, but any extension you connect should be assumed to receive the data above.
💡 Keep in Mind: Other plugins, themes, and WordPress itself can and likely will collect additional data on top of what EasyCart handles. Check each one’s own policy for the full picture of what your site collects.
Next Steps
Turn this information into an actual policy for your store.
We recommend every online store build an easy-to-access policy statement covering what data you handle, how you handle it, and who you share it with. The information above should cover the EasyCart side of that policy. It’s also worth planning ahead for user data removal requests — something as simple as an ‘Opt Out’ link in your footer can go a long way, and it’s a direction more regulation is clearly heading.
Not Legal Advice
EasyCart shares this information to the best of our knowledge, but we’re not a legal authority and can’t claim full compliance on your behalf. Regulations keep evolving — consult a legal professional for guidance specific to your business.
Further Resources
Go straight to the source for the full regulatory text.
- General Data Protection Regulation: gdpr.eu
- California Consumer Privacy Act: oag.ca.gov/privacy/ccpa
Building Your Store’s Privacy Policy?
Our support team can point you to the right settings for opt-outs, data exports, and account deletion requests inside EasyCart.