NEW The Enterprise AI Readiness Guide 2026 is here — download the free report →
Home ChatConvert Privacy Policy

ChatConvert Privacy Policy

ChatConvert (“the App”) is an AI product-recommendation and support chat assistant for Shopify stores, built and operated by Progryss (“we”, “us”). The App adds a chat widget to a merchant’s storefront that helps shoppers find the right product from the store’s real, in-stock catalog, answers questions from the store’s own content, and can look up the status of an order the shopper placed. This policy explains what data the App collects, how we use it, who we share it with, and the choices merchants and shoppers have.

By installing ChatConvert, you agree to the collection and use of information as described here. If you do not agree, please do not install or use the App.

1. Who is responsible for what

  • The merchant is the data controller for their store’s data and for the shoppers who chat with them. They decide what to collect, how long to keep it, and how to answer requests from their own customers.
  • Progryss is the data processor. We store and process that data only to provide the App to that merchant, on their instructions.
  • Every record in our database is scoped to a single store. One merchant’s data is never readable by another merchant.

If you are a shopper who chatted on a store using ChatConvert, the store you chatted with is your point of contact. We will pass any request you send us on to that merchant.

2. What we collect from merchants

  • Store profile — shop name, myshopify domain, store email, country, currency, timezone and plan, provided by Shopify at install.
  • Product catalog — products, variants, collections, prices, images and inventory status, synced from Shopify so the assistant only recommends real, in-stock items. We also read the store’s published policies, online store pages, discount codes and metafield definitions as knowledge sources.
  • Theme status — we read only config/settings_data.json, to detect whether the chat widget is enabled on the live theme. We do not read theme code.
  • App configuration — curated answers, FAQs, recommendation rules, persona and voice settings, guardrails, business hours, handover rules, campaign content, widget appearance, and the knowledge sources you add (crawled pages from your own site, uploaded PDF/CSV files, manual Q&A, and store policies).
  • Team members — for each colleague the merchant invites into the App: name, email address and a hashed password. We never store passwords in readable form.
  • Billing status — your plan tier, subscription state and trial dates. All charges are handled by the Shopify Billing API; we never see or store payment details.
  • Operational logs — errors and warnings only, never ordinary traffic. Each entry holds a timestamp, an event code, a short message and the store it belongs to. It never stores chat message bodies or contact details, and an automated test fails our build if an email address ever appears in one. We also keep per-store daily counts of AI calls and tokens for billing and capacity; these are aggregate numbers, not content.

3. What we collect from shoppers

  • Chat messages — what the shopper types and the assistant’s replies, stored as a conversation transcript for the merchant.
  • Contact details the shopper chooses to give — name, email and/or phone, through the optional pre-chat form or during the conversation. These are optional and configured by the merchant; we never require them.
  • A session identifier — a randomly generated ID kept in the shopper’s browser so a conversation stays connected across messages. It rotates after 30 minutes of inactivity and is not tied to a Shopify account or an advertising ID.
  • Page context — which page the chat was opened on, so answers are relevant.
  • Coarse location and marketing opt-in status, where the shopper provides them, and a satisfaction rating if they answer the optional post-chat survey.
  • Usage events — first-party, aggregate widget analytics (opens, messages sent, product clicks) so merchants can see how the assistant performs.

We do not collect shopper payment details or precise location, and we use no third-party advertising trackers. Chat is free text, so a shopper may type personal information into a message; anything they type is stored as part of the transcript and is covered by the deletion rights in sections 9 and 10.

4. Order lookup and protected customer data

The App can tell a shopper where their order is. To do that the merchant grants read_orders, read_customers and write_customers, which places ChatConvert at Shopify’s Protected Customer Data level 2. We apply Shopify’s level 1 and level 2 requirements to those fields.

  • The lookup is deliberately narrow. A shopper proves ownership of an order by supplying the order number plus the email or phone already on that order. We compare, then return a minimal status subset — order number, status, fulfilment and tracking.
  • We never echo the order’s stored email, phone or shipping address back into the chat, and we do not store them.
  • write_customers is used only when the merchant explicitly converts a chat contact into a customer record on their own store.

5. Cookies, storage and consent

ChatConvert sets no cookies on the storefront. The widget uses the browser’s own localStorage (for the rotating session ID) and sessionStorage (per-tab interface state and a short-lived configuration cache). It does not track shoppers across sites, does not build advertising profiles, and carries no third-party analytics or advertising pixels.

The widget integrates with the Shopify Customer Privacy API. Where the storefront exposes it, analytics events are held until the shopper’s consent state is resolved and are not sent if analytics consent is withheld. Answering the shopper’s question is never blocked by this. Merchants can also enable a disclaimer in the chat window so shoppers know they are talking to an AI assistant and that the conversation is stored.

6. How we use it

  • To run the chat assistant — understand the shopper’s question and recommend matching in-stock products, or answer from the store’s own knowledge content.
  • To look up order status when a shopper asks, as described in section 4.
  • To show merchants their conversation transcripts, unanswered questions and analytics in the App’s dashboard.
  • To route conversations to a human agent, and to send handover notifications and team invitations by email.
  • To manage plans and billing through Shopify, provide support, diagnose errors, and keep the App secure and compliant.

We do not sell or rent any merchant or shopper data, we do not share it with advertisers or data brokers, we do not use it for our own marketing, and we never use one merchant’s data to serve another merchant.

Automated decision-making. The assistant generates suggestions and answers. It does not make decisions with legal or similarly significant effects about any individual.

7. AI processing (OpenAI)

ChatConvert uses OpenAI as its AI sub-processor. To generate a reply, we send the conversation messages together with relevant snippets of the store’s catalog and knowledge content to OpenAI’s API. The default models are gpt-4o-mini for chat and text-embedding-3-small for content matching; a merchant may select another OpenAI model from the gpt-4o or gpt-4.1 families in the App’s settings. This data is used solely to produce the assistant’s response. Under OpenAI’s API data-usage policy, data submitted via the API is not used to train OpenAI’s models. We do not send Shopify account credentials to OpenAI, and AI provider keys are held server-side only — they are never exposed to the storefront widget.

8. Sharing & sub-processors

We share data only with the services required to run the App:

  • Shopify — the platform the App runs on (install, authentication, catalog, orders, billing, and the storefront where the widget appears).
  • OpenAI — AI processing as described in section 7.
  • DigitalOcean — our hosting provider, where the App’s backend and its PostgreSQL database run and where all stored data lives.
  • Resend — our email delivery provider, used for handover notifications and team invitations. It receives the recipient address and the notification content only.

Beyond these, we disclose data only if required by law. Merchants are notified of any material change to our sub-processors via an update to this policy.

9. Retention & deletion

  • Chat transcripts and contacts — the retention window is set by the merchant in Settings → Privacy & Data Requests: 7, 30, 60 or 90 days, or Keep forever. The default is Keep forever, so a merchant who wants a shorter window must choose one. A nightly job deletes anything past the chosen window.
  • Operational logs — 14 days, then deleted.
  • Store configuration, catalog mirror and knowledge sources — kept for as long as the App is installed.
  • After uninstall — billing stops immediately, and there is a 7-day grace period so an accidental uninstall or a quick reinstall does not lose the merchant’s setup. After 7 days, every record belonging to that store is permanently deleted — conversations, messages, contacts, analytics, knowledge content and configuration. This is well inside the 30-day deadline Shopify sets for its shop/redact request.
  • GDPR data-request exports — never stored. An export is computed at the moment the merchant downloads it and exists only for the lifetime of that response; no file is written to disk.
  • Individual shoppers’ data can be deleted earlier at any time via the redaction process in section 10.

10. Shopify compliance webhooks (GDPR)

ChatConvert implements all three of Shopify’s mandatory privacy webhooks:

  • customers/data_request — we create a request the merchant can fulfil from the App’s Privacy page within Shopify’s 30-day deadline, producing an export of every contact record, conversation, full message transcript and unresolved question tied to that customer’s email.
  • customers/redact — we permanently delete that shopper’s conversations, messages, contact record and any captured email for the requesting store.
  • shop/redact — we permanently delete all of the store’s data, as described in section 9.

11. Security & data transfers

  • All data is transmitted over HTTPS/TLS and stored on DigitalOcean’s managed cloud infrastructure.
  • Every database query is scoped to a single store; cross-store access is structurally prevented and covered by an automated tenancy audit.
  • API keys and provider secrets are encrypted at rest, never returned to the browser, and never written to logs.
  • The App authenticates with Shopify session tokens; we never collect or store Shopify login credentials. Admin sessions use HttpOnly cookies, team passwords are stored only as hashes, and repeated failed logins lock the account.
  • Storefront requests are verified through Shopify’s signed app-proxy mechanism, and every Shopify webhook is HMAC-verified before any processing.
  • Data may be processed on servers outside your country (including the United States). Where required, transfers rely on recognised safeguards such as Standard Contractual Clauses.

No system is perfectly secure. If we become aware of a breach affecting personal data, we will notify affected merchants without undue delay and cooperate with them as the controller.

12. Your rights

Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict its processing.

  • Shoppers: the store you chatted with is the data controller for your conversation. Contact that store directly — they can fulfil access and deletion requests through Shopify, and we honour those requests automatically via the webhooks in section 10.
  • Merchants: contact us at the address below for any data request about your store and we will assist within the statutory deadline.

You may also lodge a complaint with your local supervisory authority.

13. Children

ChatConvert is a business tool for merchants and is not directed at children. We do not knowingly collect personal data from children. If you believe a child’s data has reached us through a chat transcript, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time; the “Last updated” date at the top will change when we do. If we make a material change — a new sub-processor, a new category of data, or a different retention window — we will notify installed merchants before the change takes effect.

15. Contact

Email: progryss@gmail.com
Business: Progryss Media Private Limited, First Floor, Workspace By Innova, H-54, H Block, Sector 63, Noida, Uttar Pradesh 201301
Governing law: India

Recent Posts

    Recent Comments

    No comments to show.

    Archives

    No archives to show.

    Categories

    • No categories