Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how We Accelerate Inc. (“we”, “us”) handles data in connection with the agentshopper application (the “App”), an AI chat assistant installed by Shopify merchants on their stores. It covers data we process about merchants who install the App and about the shoppers who interact with the storefront chat.
1. Information we collect
When you install and use the App, we process:
- Store & account data — your myshopify.com domain, the OAuth access token issued by Shopify, and the access scopes you grant (
read_products,read_product_listings,read_inventory,read_orders). Access tokens are encrypted at rest. - Catalog data — product titles, descriptions, variants, pricing, and inventory levels synced from your store so the assistant can answer shopper questions. We generate vector embeddings from this catalog content.
- Chat data — messages exchanged between your shoppers and the assistant, used to generate responses and to provide you with conversation history and analytics.
- Order and attribution data — order identifier, status, currency, total, product identifiers, Shopify customer reference stored as a keyed one-way pseudonym, and the assistant session marker used to measure assisted conversion. We do not retain customer email, shipping or billing addresses, phone numbers, or the complete order webhook.
- Billing data — legacy subscription status and plan information from Shopify Billing, when applicable. We do not receive or store payment-card details; billing is handled entirely by Shopify.
2. How we use information
- To operate the storefront chat assistant and answer shopper questions about your catalog.
- To authenticate your store and maintain your App configuration.
- To provide analytics, conversation history, and support.
- To reconcile or cancel legacy Shopify subscriptions, when applicable.
- To detect, prevent, and address abuse, security incidents, and technical problems.
We do not sell personal information, and we do not use shopper chat content to train third-party foundation models.
The storefront widget checks Shopify’s Customer Privacy API. Optional analytics are sent only when analytics processing is allowed, and browser persistence for conversation, visitor, and preference state is used only when preferences processing is allowed. The assistant remains usable with in-memory identifiers when those optional purposes are not allowed.
3. Sub-processors
We rely on the following third-party service providers to operate the App. Each acts as a sub-processor and is bound by data-protection obligations:
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Supabase (Postgres) | Primary database & vector store hosting | Store config, catalog embeddings, chat logs |
| Google (Gemini API) | AI response generation & embeddings | Catalog content, shopper chat messages |
| OpenAI | AI-assisted onboarding and optional response generation | Storefront/catalog context during onboarding; shopper chat messages only for stores configured to use the OpenAI model provider |
| Shopify | App platform, OAuth, billing, webhooks | Store domain, catalog, subscription status |
| Slack (when operations alerts are enabled) | Security, worker, and compliance deadline alerts | Store domain and non-content operational identifiers; never webhook payloads or shopper chat text |
| Vercel | Application hosting | Request metadata (transient) |
4. Data retention
- While the App is installed, we retain your store configuration, synced catalog, and embeddings to provide the service. Shopper chat messages, session records, and widget analytics are automatically removed after 90 days by default; minimized order-attribution rows are removed after 365 days.
- On uninstall (Shopify
app/uninstalledwebhook), we disable the storefront widget, mark your connection inactive, stop syncing, and erase stored Shopify Admin, refresh, Storefront, and app-secret credentials. - Shop data erasure — following Shopify’s
shop/redactrequest (sent 48 hours after uninstall), we delete the store’s configuration, catalog, embeddings, and chat logs. - Customer data erasure — following a
customers/redactrequest, we delete the identified customer’s order-attribution rows and all linked chat sessions, messages, and analytics events. Any billing-usage metadata is de-linked from the erased sessions. - Customer data access — a Shopify
customers/data_requestcreates a time-bound operations request so the customer’s stored order and linked chat data can be returned securely through the requesting merchant. - We retain non-PII compliance and webhook audit records (proof of receipt) as needed to demonstrate regulatory compliance; these records exclude the personal data being erased.
- Operational webhook bodies are encrypted while awaiting background processing and erased after success; a dead-letter payload is kept for troubleshooting for no more than seven days. Mandatory privacy request payloads are encrypted while processing. Failed requests are retried, but their encrypted bodies are dead-lettered and erased at the seven-day limit while a non-PII audit record and an operator alert remain. A customer data-request payload remains encrypted only until fulfillment is confirmed.
5. GDPR / CCPA rights
Shoppers may request access to, correction of, or deletion of their personal data. Such requests are normally made through the merchant, who can submit them via Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact), which the App honors. You may also contact us directly at support@weaccelerate.com.
6. Security
Access tokens and other secrets are encrypted at rest. Access to production data is restricted to dedicated server database roles and a small number of authorized personnel. Browser database roles have no direct application-table access. All data transits over TLS.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
8. Contact
Questions about this policy or your data can be sent to support@weaccelerate.com.
See also our Terms of Service.