ShopAI Logo

Privacy Policy

Last updated: January 1, 2025

1. Data Collection Principles

ShopAI Assistant is designed with privacy-by-default architecture:

2. Types of Information Processed

2.1 Session Data

  • Chat conversation history (retained only until browser session ends)
  • Temporary cart contents (discarded after checkout or session timeout)
  • Authentication tokens (valid only for active sessions)

2.2 Shopify Data

  • Product information fetched in real-time via API (never stored)
  • Inventory levels checked live during conversations
  • Store configuration details cached temporarily (max 24 hours)

2.3 Checkout Data

  • Shipping information collected only to generate Shopify checkout links
  • Payment details are handled exclusively by Shopify's secure checkout
  • No order history or customer profiles maintained

3. Data Security Measures

3.1 Technical Protections

  • End-to-end encryption for all chat communications (TLS 1.3+)
  • Regular security audits of our API integrations
  • OAuth 2.0 authentication with minimal required scopes
  • Automatic data purging after order processing

3.2 Operational Practices

  • No third-party data sharing or selling
  • Regular penetration testing of our systems
  • Employee training on privacy best practices
  • GDPR-compliant data processing agreements

4. Your Rights & Choices

As we don't store personal data, most privacy rights are inherently respected:

For Shopify store owners, you may revoke API access at any time through your Shopify admin panel.

5. Changes & Contact

We may update this policy to reflect changes in our practices. Significant changes will be notified via email to registered users. For questions, contact suport.shopai@gmail.com.