Privacy Policy
Last updated: April 21, 2026
ShopSifu(“we”, “our”, “us”) operates an AI-powered chatbot and live-chat service for Shopify merchants, available through the Shopify App Store and at https://shopsifu.com. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices and rights you have. By installing or using ShopSifu you agree to this policy.
1. Who this policy applies to
- Merchants — Shopify store owners and staff who install ShopSifu on their store and use our dashboard.
- Shoppers— customers of those stores who interact with the chatbot widget on a merchant's storefront.
2. Information we collect
From Shopify (when a merchant installs the app)
- Shop domain, shop ID, shop name, plan, country and timezone.
- An encrypted OAuth access token that lets us call the Shopify Admin API on the merchant's behalf, scoped to
read_products,read_orders, andread_customers. - Product catalog, order, and customer data only when queried liveto answer a shopper's question (e.g. “where is my order?”). We do not create a persistent mirror of the merchant's catalog.
From merchants (dashboard usage)
- Account details via Clerk (email, name, authentication metadata).
- Chatbot configuration, tone, custom instructions, and branding choices.
- Knowledge-base documents the merchant uploads to train the bot.
From shoppers (chat widget)
- Messages the shopper types into the chat widget.
- A session identifier stored in the browser (local storage) to keep the conversation coherent across page loads.
- Email address and order number only if the shopper voluntarily provides them (e.g. to look up an order or open a support ticket).
- Technical data: IP address, user agent, the page the widget is on, timestamps. We use this for rate limiting, abuse prevention, and debugging.
3. How we use this information
- Power the chatbot: generate answers, look up products, check order status, open support tickets.
- Show merchants their conversations, analytics, and support queue in the dashboard.
- Enforce usage limits, detect abuse, and rate-limit traffic.
- Provide customer support and respond to inquiries.
- Comply with legal obligations, including Shopify's mandatory privacy webhooks.
- Improve the product — we do not use merchant or shopper data to train third-party foundation models.
4. Sub-processors and sharing
We share data only with the sub-processors needed to operate the service. Each is bound by a data-protection agreement.
| Sub-processor | Purpose | Data region |
|---|---|---|
| Microsoft Azure OpenAI | LLM inference and embeddings | United States / EU |
| Neon (Postgres) | Primary database | United States |
| Cloudflare R2 | Knowledge-base file storage | Global edge |
| Clerk | Merchant authentication | United States |
| Resend | Transactional email (support tickets) | United States |
| Shopify | OAuth, Admin API, Storefront MCP | Global |
We do not sell personal data. We do not share personal data for behavioral advertising.
5. Tenant isolation & security
- Each merchant's data is stored in an isolated Postgres schema (
tenant_<id>) so one merchant cannot access another's data. - Shopify OAuth tokens are encrypted at rest with AES-256.
- All traffic is served over HTTPS with HSTS enabled.
- Chat widget requests are authenticated via a per-merchant publishable API key and Origin validation.
- Access to production systems is restricted to a limited number of authorized personnel on a need-to-know basis, requires multi-factor authentication, and all privileged access is recorded in an audit log.
- Staff with access to merchant or shopper personal data are bound by written confidentiality obligations and receive periodic security training.
- Our staff cannot view merchant–shopper conversations by default. Conversation content is only exposed to our support team when the merchant explicitly opens a support ticket linked to that conversation, and every such escalation is recorded in our audit log.
6. Data retention
- Conversations and messages: retained while the merchant's account is active, unless the merchant configures a shorter retention period.
- Support tickets: 24 months after resolution.
- Audit logs: 12 months.
- When a merchant uninstalls the app, the account enters a 30-day grace period. After that, or upon a
shop/redactwebhook from Shopify (whichever comes first), the merchant's entire tenant schema is deleted.
7. Shopify mandatory webhooks
We honor Shopify's privacy compliance webhooks:
customers/data_request— within 30 days of receipt we compile an export of the shopper's chat data, support tickets, and any other personal information we hold, and make it available to the merchant on request at [email protected].customers/redact— we delete conversations, messages, and support tickets associated with the identified shopper.shop/redact— Shopify fires this webhook 48 hours after a merchant uninstalls. On receipt we drop the merchant's tenant schema and all associated files in object storage. If the merchant reinstalls within the 30-day grace period described in §6, their data is restored; onceshop/redactis received, deletion is permanent.
8. Your rights
Depending on where you live (GDPR in the EU/UK, CCPA/CPRA in California, LGPD in Brazil, and similar laws elsewhere) you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to be forgotten”).
- Port your data in a machine-readable format.
- Object to or restrict certain processing.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with your local data protection authority.
Shoppers should contact the merchant whose store they were chatting with — the merchant is the data controller. Merchants can contact us directly at [email protected].
9. International data transfers
Our infrastructure is primarily in the United States. If you access the service from outside the US, your information will be transferred to and processed in the US and other jurisdictions where our sub-processors operate. We rely on Standard Contractual Clauses where required.
10. Cookies and local storage
The chat widget stores a small session identifier in the browser's local storage so the conversation continues across page loads. The dashboard uses cookies set by Clerk for authentication. We do not use advertising or tracking cookies.
11. Children
ShopSifu is not directed at children under 13 (or the equivalent age in your jurisdiction) and we do not knowingly collect data from them. If you believe a child has provided us personal data, please contact [email protected] and we will delete it.
12. AI disclosure
The chatbot uses large language models (currently provided by Azure OpenAI) to generate responses. AI-generated answers may occasionally be inaccurate. Shoppers should treat chatbot replies as informational and verify anything important — especially order, shipping, or refund details — with the merchant directly.
13. Changes to this policy
We will update this page when our practices change. If the changes are material, we will notify merchants by email and update the “Last updated” date at the top of this page.
14. Data breach notification
In the event of a personal data breach that affects merchant or shopper data, we will notify affected merchants without undue delay and, where feasible, within 72 hours of becoming aware of the breach, consistent with GDPR Article 33. Notifications will describe the nature of the breach, the categories and approximate number of records affected, likely consequences, and the measures taken or proposed to address it. Merchants are responsible for notifying their shoppers and, where applicable, their local data protection authority.
15. Contact
Privacy questions: [email protected]
General support: [email protected]