Contact
CartPass counts where consumer AI sends shoppers, and tests whether an AI shopper can buy from a store. For a panel, a question, an opt-out, or anything about our crawler: hello@cartpass.ai.
About CartPassBot
CartPassBot is the browser our scans use. It visits a store the way a shopper's AI assistant would — search, product page, variant, cart, checkout — and stops at the payment screen. It never places an order.
Every request identifies itself. The user-agent is a normal Chrome string with CartPassBot/1.0.0 and this page's address appended, where the number is the scanner release: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 (compatible; CartPassBot/1.0.0; +https://cartpass.ai/contact; hello@cartpass.ai).
CartPassBot reads your robots.txt before every run. Its shopping journeys follow the rules you publish for it by name, and the rules you publish for the AI shopping agent each run stands in for — Claude-User, ChatGPT-User, Perplexity-User, Google-Extended. A wildcard User-agent: * rule written for search crawlers does not stop a shopper's assistant, so it does not stop ours either; our crawler-style checks (robots.txt, sitemap, product data) honour it in full. To keep CartPassBot out entirely:
User-agent: CartPassBot
Disallow: /
A store nobody has asked us to look at gets at most a one-off teaser: we ask the AI engines where they send shoppers (no traffic to the store at all), read its public policy pages the way a crawler does, and make at most one shopper-shaped visit. We run no recurring sweeps. That robots.txt rule, or an email to hello@cartpass.ai, keeps CartPassBot away entirely.
Consented journey runs fill forms with synthetic test identities whose email addresses end in @cartpass.ai. Exclude that domain from CRM and remarketing lists; mail sent to those addresses reaches us, is never engaged with, and is deleted.
Stop the emails
If we emailed you and you would rather we hadn’t, reply to that message or send one line to hello@cartpass.ai. No reason needed, and no form to fill in. A person reads it and you come off the list.
The same email puts your domain on our opt-out registry, so it stops the scanning as well as the email.
The opt-out registry
The opt-out registry is a list of domains our scanner refuses to touch. A domain on it gets no run of its own — no teaser, no panel, no monitoring — and no reads at all: no shopper visit, no crawler fetch, not even the public pages any search engine takes. That holds whether the domain is the store a report is about or a rival named in somebody else’s. Nothing is emailed to it either.
One thing it can’t do is unsay an assistant. If ChatGPT names your store when a shopper asks it where to buy, that answer belongs to ChatGPT, and it may still be counted in another store’s report. We stop reading you. We can’t stop them talking about you.
One email to hello@cartpass.ai adds a domain, and it stays: a list that forgets you would run against you again. The robots.txt rule above is the version that needs no email — it keeps CartPassBot out of your store’s pages. The registry goes further and stops the run before it starts.
Disputes, and a free re-scan
Think something we sent you is wrong? Tell us. A person reads the record behind the finding — the answer we got, the page we read, the date and time — and the check is run again exactly as it ran the first time.
If we were wrong, the finding is corrected where it stands, the correction is logged next to it, and the re-scan costs you nothing.
For your IT team: assistant answers and crawler-read site facts are asked again under the same pinned protocol version and compared with the stored record, so a dispute is a re-run and not a re-reading. Anything a shopper-shaped visit captured is re-taken on your live site, with consent, on the strongest profile — journey findings included.