Privacy Policy
AItalk customer-support assistant · Last updated: 2026-08-31
AItalk is a customer-support assistant installed by merchants on their
online stores. This policy describes what data the service touches, why, for
how long, and how it is removed. The merchant who installs AItalk is the data
controller for their customers' data; AItalk processes it on the merchant's
behalf.
What we process, and why
- Order data (order status, shipment and tracking
information, line items, shipping address): read from the merchant's store
platform at the moment a customer asks about their order, to answer that
question. Order data is fetched on demand and is not copied into a
standing database of orders.
- Customer email address: used as the key that matches a
chat visitor to their orders. For logged-in customers it is asserted by
the store platform; guests type it into the chat widget.
- Conversation content (messages, the assistant's
replies, satisfaction ratings): stored so a conversation can continue
across page loads, so the merchant can review it in their support inbox,
and so a human agent receives context on handoff.
- Merchant configuration (wording rules, handoff
triggers, support mailbox): stored to run the merchant's assistant. Store
API credentials are encrypted at rest (AES-256-GCM).
AI processing
Customer messages are processed by large-language-model services to
classify the question and compose replies, under contracts that do not permit
training on this data. Model output is constrained by merchant-configured
wording rules before it reaches a customer.
What we do not do
- No sale of personal data, no advertising use, no cross-merchant
profiles.
- No payment card data: AItalk never sees checkout or payment
credentials.
- No tracking scripts in the chat widget; it stores a conversation id in
the visitor's browser and nothing else.
Retention and deletion
- Conversations are retained while the merchant's installation is active,
so the merchant's support team can reference history.
- When a merchant uninstalls, service stops immediately; stored data is
deleted when the platform sends its deletion request
(
shop/redact), which Shopify issues 48 hours after
uninstall.
- Customer-level deletion requests (
customers/redact) remove
that customer's conversations for that store only.
- Data-access requests (
customers/data_request) are logged
and answered within 30 days.
Security
All traffic is TLS. Requests between the store and AItalk are
authenticated by platform signature (HMAC-SHA256); store API tokens are
encrypted at rest; each merchant's data is isolated by store id at the
database layer.
Contact
Privacy questions and data requests: use the support contact on our app
listing, or the merchant you purchased from.