1. Scope and roles
This policy applies to the AI Pocket Pal Shopify application, storefront assistant, merchant administration experience and this marketing website. For shopper data processed through a merchant’s store, the merchant generally acts as controller and AI Pocket Pal processes data on the merchant’s instructions. AI Pocket Pal acts as controller for merchant account, billing, support, security and marketing-site data.
2. Data we process
Merchant and account data
We process shop identifiers and domain, authorized Shopify user identifiers, app configuration, enabled markets, billing and subscription status, support contacts and communications.
Store and catalog data
With Shopify authorization, we process product and variant information, prices, availability, collections, articles, pages, legal policies, markets, locales, promotions and other content the merchant chooses to make available to the assistant.
Shopper and conversation data
We process chat messages, conversation and session identifiers, country and locale, cart context, product interactions, support status and information a shopper voluntarily provides in a support or order-status request. Recent order email lookup is compared server-side and is not included in the AI generation prompt.
Analytics and technical data
When applicable consent permits, we process page and product interactions, chat engagement, cart and checkout events, attributed purchases, device or browser information and pseudonymous visitor identifiers. Consent-dependent product and AI telemetry can include conversation text and tool request or result context, including information the shopper entered during the conversation. Security logs can include request identifiers, timestamps, IP-derived rate-limit keys and operational diagnostics.
3. Why we process data
- Provide product discovery, knowledge answers, cart actions and order-status assistance.
- Operate live support, email tickets and localized confirmations.
- Synchronize merchant-authorized catalog and knowledge content.
- Provide conversation, product, support and sales analytics.
- Manage subscriptions, usage allowances, top-ups and merchant support.
- Secure, troubleshoot and improve the service.
- Meet legal, tax, fraud-prevention and Shopify platform obligations.
4. Legal bases
Depending on the context and applicable law, processing relies on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent. Storefront analytics remains disabled while the required Shopify customer-privacy permission is unknown or denied.
5. AI processing
Conversation context and relevant merchant content can be sent to the configured Anthropic or OpenAI model to generate responses, translations, proactive teaser text and conversation classifications. OpenAI also processes merchant-authorized content to create vector embeddings for search. We minimize context to what is required for each task and use controlled server-side tools for current commerce information. Merchants remain responsible for reviewing their configuration and the content they make available.
6. Service providers and disclosures
We use service providers for Shopify platform access and billing, hosting, database and vector search, AI processing, email delivery and optional analytics. They process data under contractual or platform terms for the purposes described here. The current provider categories are listed on the Subprocessors page. We may also disclose data when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards.
7. International transfers
Our providers may process data in countries outside the merchant’s or shopper’s country. Where required, transfers rely on recognized safeguards such as adequacy decisions, standard contractual clauses or provider-specific lawful transfer mechanisms.
8. Retention
We retain service data while the merchant account is active and as needed to deliver configured features. Retention can differ by category: operational logs are kept for limited security and troubleshooting periods; purchase and compliance audit records can be retained where legally necessary; terminal compliance proof records are scheduled for deletion after the configured retention period. On uninstall or a verified privacy request, data is deleted or de-identified according to Shopify requirements and documented legal exceptions.
9. Security
Controls include Shopify authentication, tenant-scoped queries, rate limiting, origin validation, least-purpose data access, structured logging safeguards and durable compliance workflows. No method of storage or transmission can be guaranteed completely secure.
10. Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and may complain to a supervisory authority. Shoppers should normally contact the Shopify merchant first because the merchant controls the storefront relationship. Merchants and website visitors can contact us directly.
11. Children
The service is intended for Shopify merchants and general-commerce storefronts, not knowingly directed to children. Merchants are responsible for ensuring their storefront and use of the assistant meet age-related requirements applicable to their products and markets.
12. Changes and contact
We may update this policy as the product, providers or law changes. Material revisions will be reflected by the updated date and communicated where required. Privacy requests and questions can be sent to support@mg.aipocketpal.com.