Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how We Accelerate Inc. (“we”, “us”) handles data in connection with the agentshopper application (the “App”), an AI chat assistant installed by Shopify merchants on their stores. It covers data we process about merchants who install the App and about the shoppers who interact with the storefront chat.

1. Information we collect

When you install and use the App, we process:

  • Store & account data — your myshopify.com domain, the OAuth access token issued by Shopify, and the access scopes you grant (read_products, read_product_listings, read_inventory, read_orders). Access tokens are encrypted at rest.
  • Catalog data — product titles, descriptions, variants, pricing, and inventory levels synced from your store so the assistant can answer shopper questions. We generate vector embeddings from this catalog content.
  • Chat data — messages exchanged between your shoppers and the assistant, used to generate responses and to provide you with conversation history and analytics.
  • Order and attribution data — order identifier, status, currency, total, product identifiers, Shopify customer reference stored as a keyed one-way pseudonym, and the assistant session marker used to measure assisted conversion. We do not retain customer email, shipping or billing addresses, phone numbers, or the complete order webhook.
  • Billing data — legacy subscription status and plan information from Shopify Billing, when applicable. We do not receive or store payment-card details; billing is handled entirely by Shopify.

2. How we use information

  • To operate the storefront chat assistant and answer shopper questions about your catalog.
  • To authenticate your store and maintain your App configuration.
  • To provide analytics, conversation history, and support.
  • To reconcile or cancel legacy Shopify subscriptions, when applicable.
  • To detect, prevent, and address abuse, security incidents, and technical problems.

We do not sell personal information, and we do not use shopper chat content to train third-party foundation models.

The storefront widget checks Shopify’s Customer Privacy API. Optional analytics are sent only when analytics processing is allowed, and browser persistence for conversation, visitor, and preference state is used only when preferences processing is allowed. The assistant remains usable with in-memory identifiers when those optional purposes are not allowed.

3. Sub-processors

We rely on the following third-party service providers to operate the App. Each acts as a sub-processor and is bound by data-protection obligations:

Sub-processorPurposeData processed
Supabase (Postgres)Primary database & vector store hostingStore config, catalog embeddings, chat logs
Google (Gemini API)AI response generation & embeddingsCatalog content, shopper chat messages
OpenAIAI-assisted onboarding and optional response generationStorefront/catalog context during onboarding; shopper chat messages only for stores configured to use the OpenAI model provider
ShopifyApp platform, OAuth, billing, webhooksStore domain, catalog, subscription status
Slack (when operations alerts are enabled)Security, worker, and compliance deadline alertsStore domain and non-content operational identifiers; never webhook payloads or shopper chat text
VercelApplication hostingRequest metadata (transient)

4. Data retention

  • While the App is installed, we retain your store configuration, synced catalog, and embeddings to provide the service. Shopper chat messages, session records, and widget analytics are automatically removed after 90 days by default; minimized order-attribution rows are removed after 365 days.
  • On uninstall (Shopify app/uninstalled webhook), we disable the storefront widget, mark your connection inactive, stop syncing, and erase stored Shopify Admin, refresh, Storefront, and app-secret credentials.
  • Shop data erasure — following Shopify’s shop/redact request (sent 48 hours after uninstall), we delete the store’s configuration, catalog, embeddings, and chat logs.
  • Customer data erasure — following a customers/redact request, we delete the identified customer’s order-attribution rows and all linked chat sessions, messages, and analytics events. Any billing-usage metadata is de-linked from the erased sessions.
  • Customer data access — a Shopify customers/data_request creates a time-bound operations request so the customer’s stored order and linked chat data can be returned securely through the requesting merchant.
  • We retain non-PII compliance and webhook audit records (proof of receipt) as needed to demonstrate regulatory compliance; these records exclude the personal data being erased.
  • Operational webhook bodies are encrypted while awaiting background processing and erased after success; a dead-letter payload is kept for troubleshooting for no more than seven days. Mandatory privacy request payloads are encrypted while processing. Failed requests are retried, but their encrypted bodies are dead-lettered and erased at the seven-day limit while a non-PII audit record and an operator alert remain. A customer data-request payload remains encrypted only until fulfillment is confirmed.

5. GDPR / CCPA rights

Shoppers may request access to, correction of, or deletion of their personal data. Such requests are normally made through the merchant, who can submit them via Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact), which the App honors. You may also contact us directly at support@weaccelerate.com.

6. Security

Access tokens and other secrets are encrypted at rest. Access to production data is restricted to dedicated server database roles and a small number of authorized personnel. Browser database roles have no direct application-table access. All data transits over TLS.

7. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

8. Contact

Questions about this policy or your data can be sent to support@weaccelerate.com.

See also our Terms of Service.