Cartage
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Lower concern: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
States adherence to a third-party API services data policy including Limited Use requirements, and restricts sharing of user data obtained via that API with third parties except to provide services explicitly requested by the user — user-favorable restriction on data sharing.
Restricts the operator from knowingly collecting personal identifiable information from children under 13, and establishes a procedure for parents to request prompt removal of any such data inadvertently collected.
Provides an exception permitting disclosure of user data when required to comply with applicable laws or regulations.
How to read this page: Overall risk rates what Cartage's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 21 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 21 citationsLast captured 2026-07-19
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Explains that user-authorized third-party integrations may access, store, and modify account data; disclaims operator responsibility for third-party integration practices and places responsibility on the user to review permissions granted.
" You may connect third-party integrations to your Cartage account, which may ask for certain permissions to access data or send information to your Cartage account. It is your responsibility to review any third-party integrations you author..."
States adherence to a third-party API services data policy including Limited Use requirements, and restricts sharing of user data obtained via that API with third parties except to provide services explicitly requested by the user — user-favorable restriction on data sharing.
" Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the user (e.g., sharing data with an integration explicitly authorized by the user)."
States adherence to a third-party API services data policy including Limited Use requirements, and restricts sharing of user data obtained via that API with third parties except to provide services explicitly requested by the user — user-favorable restriction on data sharing.
AI-generated interpretation, not legal advice.
" Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity. Cartage (cartage.ai) does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records."
Restricts the operator from knowingly collecting personal identifiable information from children under 13, and establishes a procedure for parents to request prompt removal of any such data inadvertently collected.
AI-generated interpretation, not legal advice.
" When required to comply with applicable laws or regulations."
Provides an exception permitting disclosure of user data when required to comply with applicable laws or regulations.
AI-generated interpretation, not legal advice.
" Under the terms of this Privacy Policy, users of Cartage have the right to: Request that Cartage delete any personal data about the consumer that Cartage has collected.T"
Grants users the right to request deletion of any personal data collected about them by the operator.
AI-generated interpretation, not legal advice.
" he right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service."
Grants users the right to request copies of their personal data, with a note that a small fee may be charged for this service.
AI-generated interpretation, not legal advice.
" The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete."
Grants users the right to request correction of inaccurate personal data and to request completion of incomplete personal data held by the operator.
AI-generated interpretation, not legal advice.
" Understand and analyze how you use our website and related services"
Permits the operator to use collected information to understand and analyze how users use the website and related services.
AI-generated interpretation, not legal advice.
" This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in cartage.ai. This policy is not applicable to any information collected offline or via channels other than this website."
Defines the scope of the Privacy Policy, specifying it applies only to online activities and data collected via the cartage.ai website, explicitly excluding offline or other-channel data collection.
AI-generated interpretation, not legal advice.
" By using our website, you hereby consent to our Privacy Policy and agree to its terms."
States that by using the website the user consents to the Privacy Policy and agrees to its terms, establishing consent as the legal basis for data processing.
AI-generated interpretation, not legal advice.
" When you register for an Account, we may ask for your contact information, including items such as name, company name, address, email address, and telephone number.If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide."
Defines the categories of personal information collected at account registration (name, company name, address, email, telephone) and when users contact the company directly (name, email, phone, message contents, attachments, and any other provided information).
AI-generated interpretation, not legal advice.
" We use the information we collect in various ways, including to:"
Introduces a list of purposes for which collected information is used, establishing the operator's obligations and permitted uses of user data.
AI-generated interpretation, not legal advice.
" Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the website, and for marketing and promotional purposes"
Permits the operator to use collected information to communicate with users directly or through partners for customer service, updates, and marketing and promotional purposes.
AI-generated interpretation, not legal advice.
" We implement a variety of security measures to maintain the safety of your personal information when you enter, submit, or access your personal information. These measures include: Encryption of sensitive data both in transit and at rest using industry-standard encryption protocols."
Obligates the operator to implement security measures including encryption of sensitive data in transit and at rest using industry-standard protocols to maintain the safety of personal information.
AI-generated interpretation, not legal advice.
" Regular security assessments and audits to ensure our systems remain secure."
Obligates the operator to conduct regular security assessments and audits to ensure systems remain secure.
AI-generated interpretation, not legal advice.
" Access controls to ensure only authorized personnel have access to sensitive data."
Obligates the operator to maintain access controls ensuring only authorized personnel have access to sensitive data.
AI-generated interpretation, not legal advice.
" Cartage (cartage.ai) follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this as part of hosting services' analytics. The information collected by log files includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demographic information."
Defines the standard use of log files to collect technical data including IP addresses, browser type, ISP, timestamps, and referring/exit pages, and states these are not linked to personally identifiable information and are used for trend analysis and site administration.
AI-generated interpretation, not legal advice.
" Like any other website, Cartage (cartage.ai) uses 'cookies'. These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information."
Defines the operator's use of cookies to store visitor preferences and page visit information, which is used to customize web page content and optimize user experience.
AI-generated interpretation, not legal advice.
" If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us."
Establishes a procedure requiring the operator to respond to user rights requests within one month, and directs users to contact the operator to exercise their rights.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Cartage's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Cartage's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Cartage's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Cartage requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Cartage's published policies yet.
What the policies actually cover
0 topicsNone of Cartage's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the user (e.g., sharing data with an integration explicitly authorized by the user).”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the user (e.g., sharing data with an integration explicitly authorized by the user).”Open source citation
The clause permits using submitted content for training, development, or model/service improvement.
“Any data accessed through Google APIs will not be used to develop or improve general-purpose AI/ML models.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | training use | worsens | HIGH | 1 |
| Api | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on subprocessors data sharing
“Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the user (e.g., sharing data with an integration explicitly authorized by the user).”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Cartage’s use of Google API services adheres to Google API Services User Data Policy, including Limited Use requirements. We do not sell or share Google user data with third parties, except: To provide services explicitly requested by the user (e.g., sharing data with an integration explicitly authorized by the user).”Open timeline citation
Latest stance: training permitted on training use
“Any data accessed through Google APIs will not be used to develop or improve general-purpose AI/ML models.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
22 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Cartage's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Cartage's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Cartage's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.