Privacy Policy
This policy explains what data the AI Customer Service app processes on behalf of merchants who install it, and how buyers' data is handled.
Who we are
The app acts as a data processor for the Shopify merchant who installs it. The merchant remains the data controller for their buyers' personal data.
What we collect
- Chat messages exchanged between a buyer and the AI assistant on the merchant's storefront.
- Buyer email addresses, when a buyer provides one to verify their identity for an order lookup.
- Order information retrieved from the Shopify Admin API (status, fulfillment state, tracking numbers) in order to answer the buyer's question. Order data is read on demand and is not copied into long-term storage.
- Shop details (shop domain, shop name, contact email) needed to operate the app and notify the merchant.
We do not collect payment card data, and we never ask buyers for passwords or payment details.
How we use it
Chat messages and the verified buyer email are used to answer the buyer's question, to look up their own order, and to notify the merchant when a conversation is escalated to a human. Conversations are visible to the merchant inside the app.
Subprocessors
- DeepSeek — chat messages are sent to the DeepSeek language model API to generate replies. Messages are transmitted over TLS.
- Shopify — order and shop data are read from the Shopify Admin API.
- Our email provider (SMTP) — escalation notifications, including a transcript excerpt, are emailed to the merchant.
Retention
Conversations and their messages are retained for 90 days and then deleted automatically. Shop records are deleted when the app is uninstalled and the shop redaction request arrives from Shopify.
Your rights (GDPR)
The app implements Shopify's mandatory compliance webhooks: customers/data_request (we compile the buyer's stored conversations for the merchant to relay), customers/redact (we delete that buyer's conversations) and shop/redact (we delete all data for the shop). Buyers should direct access, correction and deletion requests to the merchant whose store they contacted; merchants can contact us at the address below.
Security
Data is transmitted over TLS and stored in an access-controlled database. Storefront chat requests are verified through Shopify's signed app proxy, and order details are only disclosed after the buyer's email matches the order.
Contact
Questions about this policy: support@shoptofly.com