LEGAL

Privacy Policy

KwikKart Technologies ("KwikKartBot," "we," "us") provides an AI shopping assistant for Shopify stores. This policy sets out exactly what we store, what we deliberately do not collect, who else receives data, how long we keep it, and how to exercise your rights.

It covers two groups: merchants who install the app, and shopperswho interact with the assistant on a merchant's storefront. Where a merchant is the controller of their customers' data, we act as their processor.

1. Data we collect from merchants

On installation, Shopify shares store data with us according to the access scopes you approve during OAuth. Depending on those scopes this may include store details (name, domain, contact email, currency, plan), product and collection data, order and fulfilment data, and customer records needed to answer a shopper's questions about their own orders. If your team creates dashboard logins, we store their name, email, and credentials.

2. Data we collect from shoppers

Stored on our servers:

Shopper data stored server-side
DataStoreWhen
Session token, IP address, user-agent, OS, browser, device type, screen size, countrysessionsEvery widget load
Email address / phone numbersessionsOnly when the shopper types it, or when the store theme supplies it for a logged-in shopper who is subscribed to marketing
Chat messages (encrypted at rest, AES-256-GCM)conversationsEvery chat turn
Chat events, cart adds, purchases, search queriesactivitiesPer event
Products viewedproduct_viewsAssistant-surfaced views, or any view by an identified shopper
Aggregate view counts (not linked to any shopper)product_view_countsEvery product view
Cart contentscart_snapshotsOnly if the shopper used the assistant, or is identified
Queued emailsemail_triggersWhen an abandonment or restock email is scheduled

Stored only in the shopper's own browser and never transmitted to the merchant or to us: days visited, recently viewed products, last cart count, last question asked, chat transcript, and session token.

3. What we deliberately do not collect

  • No scraping of logged-in customer data. The widget never reads __st.em, ShopifyAnalytics.meta, or window.__shopify_customer.
  • Email requires consent.Either the shopper types it, or the theme passes it only when the shopper's email_marketing_consent.state is subscribed.
  • No payment data. Ever. Card and payment details never reach us.
  • Order lookup is privacy-gated.It requires an order number plus a matching email or phone number. A mismatch returns "not found" identically to a non-existent order, so orders cannot be enumerated by guessing.

4. How we use data

  • To answer shopper questions about products, orders, shipping, and store policies.
  • To recommend products from the merchant's live catalogue.
  • To send the automations a merchant has enabled, such as cart-abandonment and restock emails.
  • To give merchants analytics and revenue attribution for assisted conversations.
  • To operate, secure, debug, and improve the service.
  • To meet legal obligations.

We do not sell personal information, and we do not use merchant or shopper data to train our own models.

5. AI processing, in plain language

Shopper messages are sent to Anthropic to generate a reply. They are not used to train AI models. We retain them for 90 days so the assistant can follow the conversation, then delete them.

Alongside the message we send the store context needed to answer it — for example matching product details, or policy text the merchant has supplied. OpenAI may be used as a fallback provider if the primary provider is unavailable. Voyage AI processes store content and search queries to power catalogue search.

6. Sub-processors

These providers receive data in order to operate the service. Each is bound by confidentiality and data-protection obligations.

Sub-processors and what each receives
ProcessorReceivesPurpose
AnthropicChat messages, store contextGenerating assistant replies
OpenAIChat messages, store contextFallback reply provider
Voyage AIStore content, search queriesEmbeddings and reranking
SupabaseAll stored dataDatabase
RenderAll data in transitBackend hosting
VercelMerchant dashboard trafficDashboard hosting
Resend / SMTP providerShopper email address, product detailsTransactional and automation email
SentryError diagnosticsMonitoring
ShopifyCatalogue, orders, webhooks

7. Retention

  • Chat messages — deleted after 90 days.
  • Cart snapshots — deleted after 90 days.
  • Session personal data (email, phone, IP, device) — cleared after 90 days.
  • Activity payloads — sensitive fields scrubbed after 90 days.
  • Aggregate counts — kept indefinitely, as they contain no personal data.

The session retention window is configurable per deployment. When a merchant uninstalls, shop data is deleted as described in the next section.

8. Your rights

We implement Shopify's mandatory privacy webhooks, so requests routed through Shopify are honoured automatically:

  • customers/data_request — returns everything we hold about that shopper.
  • customers/redact — deletes that shopper's identity from our session records.
  • shop/redact — deletes all data for a shop 48 hours after uninstall.

Every marketing email carries an unsubscribe link, honoured before any further send.

Depending on where you live — including under the GDPR, UK GDPR, and US state privacy laws such as the CCPA — you may also have rights to access, correct, delete, port, or object to the processing of your personal data. Shoppers should contact the store they were shopping with first, since merchants control their own customer relationships. You can also contact us directly at support@kwikkartbot.in and we will respond within a reasonable period and as applicable law requires.

9. Security

We use administrative, technical, and physical safeguards appropriate to the data we handle:

  • Chat message content and merchant credentials — including Shopify access tokens and API secrets — are encrypted at rest with AES-256-GCM.
  • Encryption is fail-closed: if the key is unavailable, writes are refused rather than stored as plaintext.
  • Per-tenant isolation — every query is scoped by shop_id, with row-level security enabled.
  • Webhook requests are verified by HMAC signature.
  • Data is encrypted in transit using TLS.
  • We are approved by Shopify for Protected Customer Data access.

To be precise about scope: encryption at rest currently covers chat content and merchant credentials. Shopper contact details held in session records are not yet encrypted at rest, and we are closing that gap. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International transfers

We and our sub-processors may process data in countries other than your own, including India, the United States, and the European Union. Where required, we rely on appropriate safeguards such as standard contractual clauses.

11. Children

The service is built for merchants and their adult customers. We do not knowingly collect personal information from children under 16. If we learn that we have, we delete it promptly.

12. Changes to this policy

We may update this policy to reflect changes in our practices or for legal, operational, or regulatory reasons — including adding or replacing a sub-processor. We post the updated policy here with a revised effective date, and give merchants additional notice where changes are material.

13. Contact

For any privacy question, or to exercise your rights, contact support@kwikkartbot.in.