Privacy Policy
Last updated: 2026-09-13
This Privacy Policy explains what data Any Store AI ("we", "the Service") collects and how it is used, when a merchant connects a Shopify store or a customer interacts with the chat widget.
1. Data we collect
- Merchant account data: name, email, and hashed password when you create an account.
- Store connection data: your store's domain and an access token obtained via Shopify's OAuth flow, used solely to read your product catalog and manage carts/checkouts on your behalf. Access tokens are encrypted at rest.
- Conversation data: messages exchanged between your customers and the chat widget, stored so conversation history can be displayed and so the assistant has context across a session.
2. Cookies and local storage
The chat widget uses your browser's local/session storage (not third-party tracking cookies) to remember which conversation you're in, a random anonymous visitor id, and whether you've already dismissed its proactive prompt. This is all so the widget doesn't lose context or repeat itself on the same visit. The merchant dashboard sets a session cookie so you stay signed in between visits. Neither is used for advertising or cross-site tracking.
3. How we use data
Data is used to operate the Service: authenticating merchants, querying your store's catalog, generating chat responses via a third-party AI provider, and maintaining conversation history. We do not sell merchant or customer data.
4. Legal basis for processing
Where the EU/UK GDPR applies, we process merchant account data on the basis of contractual necessity (operating the account you created), and conversation/store data on the basis of our legitimate interest in providing the chat and cart features you installed the Service for, balanced against your rights as described in this policy.
5. Third parties
Chat responses are generated using a third-party large language model provider. Store catalog and cart data is read from Shopify's APIs. Infrastructure (hosting, error monitoring, backups) is provided by standard cloud service providers under their own data-processing terms. The full current list is published as our Subprocessor List. Merchants processing EU/UK personal data may also request our Data Processing Agreement.
6. Data retention
Conversation and store data is retained for as long as your account remains active, plus a limited backup retention window, after which it is deleted or anonymized.
7. Security
Store access tokens are encrypted at rest. Access to production systems is restricted, and backups are encrypted before leaving our infrastructure.
8. Your rights
You may request deletion of your account and associated data, or disconnect a store to revoke the Service's access to it, at any time. When a merchant uninstalls the Service from their store, Shopify's mandatory compliance webhooks (customer data request, customer redaction, and shop redaction) are honored automatically. A shop redaction permanently deletes that store's data from our systems. If you are a California resident, you may have additional rights under applicable law; contact us below to exercise them.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above.
10. Contact
Privacy questions can be sent to [email protected].
