PRIVACY POLICY

Your data, protected.

We believe in transparency. Here's exactly what data we collect, how we use it, and how we keep it safe.

Last updated: March 10, 2026

Data We Collect

From Merchants

  • Shopify store information (store name, domain, OAuth tokens for API access)
  • Product catalog data (titles, descriptions, prices, images, availability status)
  • App settings and configuration (persona name, accent color, welcome message, theme config, billing plan)

From Store Visitors

  • Chat conversations (stored by anonymous session ID, not linked to Shopify customer accounts)
  • Analytics events (page views, product impressions, add-to-cart actions, purchases)

What we DON'T collect

Customer names, email addresses, payment information, or browsing history outside our widget. We keep it minimal.

How We Use Data

  • 1 Product Search: Your product catalog is synced and embedded for semantic search using OpenAI's API, so customers can find products conversationally.
  • 2 Chat Responses: Chat messages are sent to OpenAI GPT-4o for generating responses. OpenAI does not use API data for training their models.
  • 3 Analytics: Analytics events are aggregated to power merchant dashboards with insights about customer engagement and product performance.
  • 4 Billing: All billing is handled exclusively through the Shopify Billing API. We never collect, store, or process payment information directly.

Third-Party Services

We use the following third-party services to operate ShopExpert AI:

OpenAI

Chat responses & semantic search embeddings

Neon

PostgreSQL database hosting

Shopify

OAuth, billing & platform integration

Data Retention

Conversations

Retained while your subscription is active. Fully deleted when you uninstall the app.

Product Catalog

Kept in sync while installed. Fully deleted within 48 hours of uninstall.

Analytics

30-day rolling window. Older data is automatically purged.

GDPR Compliance

We are committed to compliance with the General Data Protection Regulation (GDPR) and support the following rights:

  • Right of Access: Request a copy of all data we hold about you or your customers.
  • Right to Erasure: Request deletion of your data at any time.
  • Data Portability: Receive your data in a structured, machine-readable format.

Processing times: Customer data deletion requests are processed within 30 days. All shop data is erased within 48 hours of uninstalling the app.

Questions?

If you have questions about this privacy policy or want to exercise your data rights, reach out to us.

privacy@shopexpert.ai