Privacy and Security
VerdantCart AI is designed to work inside WordPress and WooCommerce with a privacy-first approach. The goal is to keep carbon reporting close to the store environment where order, product, and reporting data already exists, and to be transparent about the few cases where data leaves that environment.
Last updated
June 2026
Who we are
VerdantCart AI is operated from Sweden. The data controller for the public website (verdantcart.ai) and the VerdantCart AI Pro plugin is the operator of VerdantCart AI. For privacy questions, please use our Contact us.
Store data used for reporting
The VerdantCart Carbon Reports plugin (free) and VerdantCart AI Pro use relevant WordPress and WooCommerce store data to generate reporting views, summaries, charts, exports, emissions estimates, product hotspots, and sustainability insights.
What data may be included
This may include order totals, order dates, product information, product weights, order status, customer or user identifiers, and calculated reporting snapshots needed to produce carbon reports.
Where reporting data is stored
Core reporting data is stored inside your WordPress database and WooCommerce environment. VerdantCart is designed so the main reporting experience runs inside your store rather than requiring a separate external dashboard for normal reporting views. Reporting data does not leave your WordPress installation as part of normal use of the free plugin.
External tracking on the website
The public VerdantCart website is designed to avoid unnecessary external visitor tracking. Outbound links to WordPress.org and to the Freemius checkout include UTM parameters so we can understand which pages led to plugin installs or trial signups, but they do not identify individual visitors.
Payment processing
VerdantCart AI Pro is sold through Freemius as Merchant of Record. When you start a Pro trial or purchase a Pro subscription, Freemius collects and processes the information needed to complete the transaction — typically email address, billing details, payment method, and any tax-relevant information required by your jurisdiction. Freemius is the seller of record for these transactions and applies its own privacy policy and terms. We receive purchase, subscription status, and license information from Freemius in order to provision and verify your Pro license.
License verification
When you activate a VerdantCart AI Pro license, the plugin sends the license key and your site URL (used as the license instance name) to the Freemius license API. A daily background check then re-verifies the license against Freemius using the stored instance identifier. These calls allow the plugin to confirm that the license is still valid, has not been disabled, and has not exceeded its site limit. No customer order data, product data, or reporting data is included in these license API calls.
Pro plugin and AI providers
VerdantCart AI Pro includes optional AI-generated executive summaries. When enabled, the plugin sends aggregated reporting metrics (such as totals, trends, and hotspots derived from your snapshots) to OpenAI or Anthropic Claude using your own API key. Because the API key is yours, you remain in control of which provider sees your data, can switch providers at any time, can review usage on your own provider account, and can disable AI summaries entirely so no data is sent to either provider. VerdantCart does not store, relay, or retain any AI request content on our infrastructure.
Sub-processors
Services involved in operating VerdantCart AI may include: a hosting provider for the public website, Freemius as payment processor and license issuer for VerdantCart AI Pro, an email forwarding provider for our contact addresses, and — only at the discretion of each Pro customer who enables AI summaries — the AI provider whose API key they have entered (OpenAI or Anthropic). Each sub-processor applies its own privacy policy and terms.
Access control
Store-level reporting is intended for authorized store administrators or users with appropriate permissions. Customer-level access is limited to the dashboard views made available to the relevant user account.
Exports and sharing
If you export reports as CSV, PDF, or another format, you control where those files are stored, downloaded, sent, or shared. Store owners are responsible for protecting exported files and deciding who can access them.
Data accuracy and minimization
VerdantCart aims to use only the data needed to generate useful reporting outputs. The accuracy of reports depends on the quality and completeness of the data available in your WooCommerce store, including product and order information.
Site owner responsibility
Each store owner remains responsible for their own privacy practices, customer data handling, legal disclosures, cookie notices, data retention practices, and compliance obligations related to their WordPress site and WooCommerce store. Installing VerdantCart Carbon Reports or VerdantCart AI Pro does not transfer those obligations to us.
Data retention and deletion
Reporting data generated by the plugins remains in the WordPress database while the plugin is active or while the store owner keeps the related records. Pro license records stored at Freemius follow Freemius's own retention policies. Store owners are responsible for managing data retention, deletion, backups, and exported files according to their own policies and legal requirements.
Your rights
Depending on where you live, you may have rights regarding the personal data we hold about you — including the right to access, correct, or request deletion of that data. To exercise any of these rights, or to ask a question about how VerdantCart AI handles your information, please contact us. Where personal data was collected by Freemius as Merchant of Record, those requests may need to be directed to Freemius as well.
Policy updates
This Privacy page may be updated over time as VerdantCart AI evolves, as features change, or as new connected services are introduced. The "Last updated" date at the top of this page reflects the most recent revision.