Your data, protected.
We believe in transparency. Here's exactly what data we collect, how we use it, and how we keep it safe.
Last updated: March 10, 2026
Data We Collect
From Merchants
- •Shopify store information (store name, domain, OAuth tokens for API access)
- •Product catalog data (titles, descriptions, prices, images, availability status)
- •App settings and configuration (persona name, accent color, welcome message, theme config, billing plan)
From Store Visitors
- •Chat conversations (stored by anonymous session ID, not linked to Shopify customer accounts)
- •Analytics events (page views, product impressions, add-to-cart actions, purchases)
What we DON'T collect
Customer names, email addresses, payment information, or browsing history outside our widget. We keep it minimal.
How We Use Data
- 1 Product Search: Your product catalog is synced and embedded for semantic search using OpenAI's API, so customers can find products conversationally.
- 2 Chat Responses: Chat messages are sent to OpenAI GPT-4o for generating responses. OpenAI does not use API data for training their models.
- 3 Analytics: Analytics events are aggregated to power merchant dashboards with insights about customer engagement and product performance.
- 4 Billing: All billing is handled exclusively through the Shopify Billing API. We never collect, store, or process payment information directly.
Third-Party Services
We use the following third-party services to operate ShopExpert AI:
OpenAI
Chat responses & semantic search embeddings
Neon
PostgreSQL database hosting
Shopify
OAuth, billing & platform integration
Data Retention
Retained while your subscription is active. Fully deleted when you uninstall the app.
Kept in sync while installed. Fully deleted within 48 hours of uninstall.
30-day rolling window. Older data is automatically purged.
GDPR Compliance
We are committed to compliance with the General Data Protection Regulation (GDPR) and support the following rights:
- •Right of Access: Request a copy of all data we hold about you or your customers.
- •Right to Erasure: Request deletion of your data at any time.
- •Data Portability: Receive your data in a structured, machine-readable format.
Processing times: Customer data deletion requests are processed within 30 days. All shop data is erased within 48 hours of uninstalling the app.
Questions?
If you have questions about this privacy policy or want to exercise your data rights, reach out to us.
privacy@shopexpert.ai