Privacy Policy
Last updated September 10, 2026
kwebbel (“kwebbel”, “we”, “us”) provides an AI sales & support agent for Shopify stores. This policy explains what personal data we process on behalf of the merchants who install our app (“Merchants”), and for their shoppers, and how we protect it.
1. Data we process
- Merchant account data. The name and email you use to create a kwebbel dashboard account, your store domain, and billing details (handled by Stripe — we never store card numbers).
- Store data. Your product catalog, store pages, and knowledge content, which we use to ground the agent’s answers. This is business data, not personal data.
- Shopper conversations. Messages exchanged with the storefront agent, keyed to an anonymous visitor identifier — not to a shopper’s Shopify customer account. A shopper may voluntarily type personal information (e.g. an email or order number) into chat when asking for support.
- Order data for support. When a shopper asks about an order, we read that order’s status, tracking, items, and email from Shopify in real time to verify the shopper (order number + matching email). We do not store this order or its personal data; it is used only to answer that shopper and then discarded.
- Usage & conversion signals. Anonymous visit counts and whether a chat preceded a purchase, for the Merchant’s analytics. No shopper is personally identified.
2. How we use it
Solely to provide the service to the Merchant: answering shopper questions, recommending products, offering the Merchant’s configured discounts, verifying and reporting order status, proactively engaging shoppers, and reporting analytics to the Merchant. We do not sell personal data, and we do not use it for advertising or for training third-party models.
3. Sub-processors
We share data only with the infrastructure providers needed to run the service:
- Shopify — the platform your store runs on.
- Vercel — application hosting.
- Neon — database (encrypted at rest).
- Anthropic (Claude) — the AI model that generates replies. Conversation content is sent to generate answers; Anthropic does not train on it.
- Stripe — subscription billing.
- Cloudflare — DNS and bot protection.
- Resend — transactional email (e.g. password resets).
4. Retention & deletion
Order lookups are ephemeral and never stored. Demo data expires within 24 hours. Conversations are retained to provide support history and analytics to the Merchant. On a Shopify customers/redact request we delete any conversation containing that customer’s data; on shop/redact (48 hours after a Merchant uninstalls) we delete all of that store’s data.
5. Security
Data is encrypted in transit (TLS/HTTPS with HSTS) and at rest (including database backups). Access is limited, authentication uses hashed credentials and signed, revocable sessions, and requests are rate-limited and logged. Order lookups require identity verification (order number + matching email) before any detail is shared, and we never expose a shopper’s address or phone number.
6. Your rights
Shoppers may exercise their rights (access, deletion) through the Merchant, who can trigger deletion via Shopify. Merchants can access, export, or delete their data by contacting us or uninstalling the app. We honor GDPR and CCPA requests.
7. Contact
Questions or requests: privacy@kwebbel.ai.