Privacy Policy
Last updated: October 8, 2026
This policy explains how [TODO: your company or legal name] ("we") handles data in our Shopify app (the "App"). The App sends a store owner alerts about new orders and low stock in their own WhatsApp chat, and lets the owner ask about and (on paid plans) manage the store by chatting with an AI assistant. The App is not affiliated with or endorsed by WhatsApp or Meta.
Data we store
- Your shop domain and the Shopify access token Shopify gives us when you install the App.
- The WhatsApp agent API key you paste into the App, encrypted (AES-256-GCM).
- The AI provider API keys you paste into the App, encrypted (AES-256-GCM).
- The WhatsApp identifier of the agent's creator (you), used as the only recipient of messages.
- Your settings: alert switches, low-stock threshold, AI provider and model, your extra AI instructions, and a message cursor so the same WhatsApp message is not handled twice.
We do not store your customers' personal data, orders or products in our database.
Data we process but do not store
- Order alerts. When an order is created, Shopify sends us the order. We format a message with the order number, total, items, and the customer's name, phone and shipping address, and send it to your own WhatsApp chat through the WhatsApp Agent Platform. We then discard it.
- Low-stock alerts. We read inventory levels and product names to tell you when stock is low.
- AI store manager (Pro). Messages you send to your agent, and the store data needed to answer them (for example products, orders or customers you ask about), are sent to the AI provider you selected, using your own API key. The last few messages of the conversation are kept in server memory only, and are lost on restart.
We use this data only to provide these features to you. We do not sell or rent it, and do not use it for advertising or to train AI models.
Who receives data (subprocessors)
- Shopify: source of store data, and billing.
- WhatsApp / Meta: delivers messages between the App and your WhatsApp agent. Agent chats are not end-to-end encrypted.
- The AI provider you choose (for example OpenAI, Anthropic, Google, OpenRouter, xAI, DeepSeek, Groq or Mistral), only if you use the AI store manager. Their own terms and privacy policy apply to your key.
- Our hosting provider: [TODO: VPS provider name and country], where the App and its database run.
Security
All traffic uses HTTPS. API keys are encrypted at rest. Access to the server is limited to our staff who need it. Backups are encrypted.
Retention and deletion
- Your settings and keys are kept while the App is installed.
- When you uninstall, we delete your settings, keys and Shopify session right away. Shopify also sends a shop deletion request (shop/redact) 48 hours later, and we delete anything left for your shop.
- Encrypted backups are kept for up to 30 days and then deleted.
- Because we do not store customer data, customer data and deletion requests (customers/data_request, customers/redact) have nothing for us to return or delete; we still answer every request.
Your rights (GDPR, UK GDPR, CCPA/CPRA and similar laws)
You can ask to access, correct, export or delete your data, or object to its processing, by emailing us. For customer data, the merchant is the controller and we act as a processor on the merchant's behalf; customers should contact the store first. We respond within 30 days. You can also complain to your local data protection authority.
Changes
We will update this page when our practices change and change the date at the top.
Contact
[TODO: your company or legal name], [TODO: business address]. Email: management.sunskilltechs@gmail.com