Flycart

India · www.flycart.org · 14 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 14 sub-vendors.

Insights

Last updated 2026-06-18 · revision 1

14 direct vendors, 252 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Flycart demonstrates medium migration readiness. The primary challenge lies in its foundational technology stack, which is built on WordPress, WooCommerce, PHP, and MySQL. While this stack is well-understood and has extensive community support, it is a traditional architecture and not inherently cloud-native, containerized, or microservices-based. This means that a transformative migration towards a modern, highly scalable cloud architecture would likely be a complex and resource-intensive undertaking, requiring significant re-architecting rather than a simple lift-and-shift. Key information gaps also impede a full readiness assessment, as data on regulatory environment, data residency requirements, financial stability (ability to fund a migration), and specific vendor lock-in risks is not available. Dependencies on specific third-party plugins and services (e.g., Freemius for licensing, Interakt for WhatsApp API, Intercom for support) could introduce integration complexities during a migration. On the positive side, the use of standard and widely adopted technologies means there is a large pool of expertise and managed services available in cloud environments, which could facilitate a lift-and-shift migration of the existing WordPress setup. The adoption of modern front-end technologies like React for Gutenberg integration also indicates some internal capability for modern development practices. The geographic diversity of its vendor base, while not directly impacting technical lock-in, could simplify some aspects of vendor management during a migration project.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework but is increasingly expected by enterprise customers of SaaS and cloud service providers. Flycart provides cloud-connected WooCommerce plugins and the Retainful product (email/SMS/WhatsApp marketing automation with a SaaS component at retainful.com), which involves storing and processing customer data on Flycart's infrastructure. Risk is MEDIUM because: (1) Flycart's 200,000+ customer base includes businesses that may contractually require SOC 2 compliance from their vendors; (2) The Retainful SaaS product processes customer behavioral and contact data, raising expectations for formal security assurance; (3) Absence of SOC 2 certification may limit enterprise sales opportunities; (4) However, Flycart appears to be a small company (estimated <50 employees) targeting SMB WooCommerce merchants, where SOC 2 is less commonly mandated. The risk is not 'High' because SOC 2 is voluntary and Flycart's primary market (SMB WooCommerce stores) rarely mandates it.

Evidence: https://www.flycart.org/privacy-policy, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

PCI DSS (source) — Assessment Required

Flycart processes payment transactions for plugin purchases, collecting billing addresses and payment-related information. The privacy policy states 'When you purchase the Services, we will also collect transaction information, which may include your billing and mailing address, and other payment-related information.' Risk is MEDIUM because: (1) If Flycart uses third-party payment processors (Stripe is listed as an integration partner) and does not store raw card data, PCI DSS scope may be limited to SAQ A or SAQ A-EP; (2) However, the extent of card data handling is not publicly disclosed; (3) Non-compliance with PCI DSS can result in fines from card networks, increased transaction fees, and loss of ability to process card payments; (4) The risk is not 'High' because modern payment processors (Stripe, PayPal) typically handle card data directly, minimizing merchant PCI scope.

Evidence: https://www.flycart.org/privacy-policy, https://www.flycart.org, https://www.pcisecuritystandards.org/document_library/

India DPDP Act — Assessment Required

India's Digital Personal Data Protection Act (DPDP Act) 2023 was enacted in August 2023 and applies to processing of digital personal data within India and to processing of personal data outside India if it relates to offering goods or services to individuals in India. As an Indian company (Cartrabbit Technologies Pvt Ltd, Coimbatore), Flycart is directly subject to the DPDP Act as a 'Data Fiduciary.' Risk is HIGH because: (1) The DPDP Act is India's primary data protection law and directly applies to Flycart as an Indian entity; (2) Implementing rules and the Data Protection Board are still being established, creating compliance uncertainty; (3) Penalties under the DPDP Act can reach ₹250 crore (~$30M USD) per violation; (4) Flycart processes personal data of Indian customers and employees; (5) The company's privacy policy (last updated May 2018) significantly predates the DPDP Act and does not address its requirements. Risk is 'High' due to direct applicability and the significant gap between current privacy policy and DPDP Act requirements.

Evidence: https://www.flycart.org/privacy-policy, https://www.meity.gov.in/writereaddata/files/Digital%20Personal%20Data%20Protection%20Act%202023.pdf, https://www.flycart.org/about-us

Financials

Three-year financials

Financial Resilience Score: 6/10

Flycart, operating as Cartrabbit Technologies Pvt Ltd, appears to be a financially resilient bootstrapped SaaS business with a diversified product portfolio of six WooCommerce plugins addressing various parts of the e-commerce funnel. Its flagship product, Discount Rules for WooCommerce, has 100,000+ active installs and strong ratings, providing a meaningful moat in the freemium WordPress ecosystem. The recurring subscription model with multi-year prepay options supports cash-flow visibility, and the low-cost India operating base in Coimbatore enables favorable unit economics versus US/EU SaaS peers. However, the company faces meaningful risks including 100% platform concentration on the WooCommerce/WordPress ecosystem, intense competition from established plugin vendors and Automattic's own first-party features, and limited transparency as a private founder-led entity. FX exposure exists since most customers pay in USD/EUR while the cost base is in INR (currently a tailwind). Revenue is estimated in the single-digit-million USD range based on install counts and typical freemium conversion rates, though no audited figures are publicly available in the sources consulted. Overall, the bootstrapped status with no debt pressure and steady organic growth supports a moderate resilience score.

Key strengths: Diversified portfolio of six WooCommerce plugins, Flagship product with 100,000+ active installs and 4.8-star rating, Recurring subscription revenue with multi-year prepay options, Low-cost India operating base supports favorable unit economics, Bootstrapped/founder-led with no dilutive funding or external debt, 200,000+ aggregate active store installs across portfolio, 9+ years of operating history in WordPress ecosystem

Risk factors: 100% platform concentration on WooCommerce/WordPress ecosystem, Intense competition from YITH, WPDesk, StoreApps, Booster, Klaviyo, Risk from Automattic's first-party feature expansion, Limited transparency as small private operator, Key-person risk concentrated in founders, FX/cross-border collection exposure (USD/EUR revenue vs INR costs), Low freemium conversion rates with high support load from free users, Potential merchant shift toward Shopify/BigCommerce

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report