Privacy Policy

Account Editor Chatbot for Shopify · Operated by ITGeeks · Effective: 19 July 2026

This policy explains what personal data the Account Editor Chatbot app ("the App", "we") processes, why, where it is stored, how long it is kept, and the rights available to merchants and their customers. It applies to merchants who install the App on their Shopify store and to the shoppers ("customers") who interact with the App on those stores.

We act as a data processor on behalf of the merchant, who is the data controller for their customers' personal data. Our processing is governed by our Data Processing Addendum.

1. Personal data we process

CategoryDataSource
Customer identity Shopify customer ID; name, email address, phone number (mirrored from the merchant's Shopify store when needed to deliver a reply or notification) Shopify APIs, via the merchant's authorization
Order data Order contents, totals, status, shipping method, delivery address (when the customer edits it), refund and cancellation details Shopify APIs
Conversation content Chat messages, voice conversation transcripts, support ticket threads, live-agent chat threads, feedback and ratings. Voice audio is never stored — it is transcribed in real time and discarded. Provided by the customer while using the App
Cart and browsing context Cart contents, the storefront page a chat was opened from, market/currency context The merchant's storefront
Channel data WhatsApp phone number and message content (only when the customer contacts the store on WhatsApp); email address and message content for transactional emails Provided by the customer
Merchant data Store domain, store settings, support-agent names and email addresses configured by the merchant The merchant

We practice data minimization: the storefront widget sends only an opaque customer ID; contact details are resolved server-side only at the moment they are needed (for example, to deliver a support reply). Internal audit and compliance logs store identifiers and counts, never copies of contact data.

2. Why we process it (purposes)

We do not sell personal data, use it for advertising, build cross-store profiles, or use one merchant's data for any other merchant. Processing is limited to the purposes above.

3. Sub-processors

We share personal data only with the sub-processors needed to run the App, under their respective data protection terms:

Sub-processorPurposeData involved
ShopifyCommerce platform; source of truth for customer and order dataAll commerce data
OpenAILanguage model responses; real-time voice conversation and transcriptionConversation content; customer first name in voice sessions
MongoDB AtlasPrimary encrypted databaseAll stored data listed above
Fly.ioApplication hosting and private networking (US region)Data in transit through the App
Meta Platforms (WhatsApp Business)WhatsApp message delivery, only when the customer uses WhatsAppPhone number, message content
Email delivery provider (SMTP, e.g. AWS SES)Transactional email deliveryEmail address, message content
Google (Places API)Address autocomplete during address correction, when usedAddress text typed by the customer

4. Storage, security, and retention

Retention periods

DataRetention
Chat conversation history90 days, then deleted automatically
Request metrics90 days
WhatsApp send/delivery logs90 days
Support photo uploads30 days
Automated agent event log30 days
Cart snapshots (cache)10 days
Webhook deduplication records7 days
Chat session state (cache)~30 minutes
Contact-change verification codes15 minutes
Customer profile mirror, support tickets, cart recovery records, analytics events For as long as the App is installed on the store; deleted on uninstall or on a customer deletion request (below)
Deletion audit logRetained as legal proof that deletions were performed; contains identifiers and counts only, no personal contact data

5. Consent

6. Your rights (customers)

Customers can exercise their privacy rights through the merchant whose store they shopped at, or through Shopify's built-in privacy tools. The App implements Shopify's mandatory privacy webhooks:

7. International transfers

Data is hosted in the United States (Fly.io region IAD; MongoDB Atlas). Where data is transferred from other regions, it is protected by the safeguards in our Data Processing Addendum and the sub-processors' own transfer mechanisms.

8. Changes and contact

We will update this policy when our processing changes and revise the effective date above. Questions or privacy requests: support@accounteditor.com.