Trust
Data and security
What we read, how your data is separated, and — more usefully — which security claims we are not yet able to make.
What we read, and why
The agent answers questions about your products, stock and orders, which means it has to be able to look them up. It reads through the Shopify API with scopes you approve at install, and then within per-agent permission groups you choose.
- Products and inventory — so "do you have this in a medium?" is answered from your real variants and stock.
- Orders and fulfilments — so "where is my order?" is answered from the live record rather than a guess. Granted deliberately, because this touches personal data.
- Customers — only if you grant it, and only so the agent can recognise a returning buyer.
How your data is separated
The app is multi-tenant by store. Your conversations, leads, templates and catalogue index are scoped to your account, and your product index is a private search collection for your store alone. Conversations are stored so that you and your team can read and continue them.
What we do not claim
This section exists because the alternative is a merchant finding out during a procurement review. Being straight about it now costs us some enterprise deals and saves everyone a wasted quarter.
- No SOC 2 attestationWe are not certified and have not completed an audit. If your process requires a report today, we cannot supply one.
- Automated deletion is incompleteShopify's mandatory privacy webhooks are honoured, but fully automated data deletion is unfinished. Deletion requests may need manual action from us. We will do it, and we will not pretend it is automatic.
- Webhook verification is being hardenedThere is outstanding work on verifying inbound webhook authenticity. It is tracked internally, and specific findings are shared with buyers who ask rather than published here as a map.
- No availability guaranteeThe agent answers when our backend, the language model provider and the Meta connection are all healthy. There is no failover and no SLA. We do not describe the service as 24/7.
What to do if you need assurance
Ask us directly at [email protected]. We will tell you the current state of each item above, share our internal findings register where it helps, and tell you plainly if we cannot meet a requirement rather than working around the question.
If your review needs certified artefacts now, an unregulated vertical such as fashion, beauty, food or home is a better fit than a regulated one. We are not a good choice for pharmacy, clinical or financial data today.
Security questions
What does the app read from my Shopify store?
Products, variants, inventory levels, orders, customers and fulfilments, through the Shopify API, limited to the permission groups you grant each agent. 101 operations are available across orders, customers, products and inventory.
Can the agent change my store data?
Agent access is granted in groups centred on reading store data so it can answer questions accurately. Treat the agent as an assistant that looks things up rather than an automation that alters your orders.
Is my data mixed with other merchants'?
No. The app is multi-tenant by store: your conversations, leads and catalogue index are scoped to your account. Your product index is a private collection for your store alone.
Are you SOC 2 certified?
No, and we do not claim to be. We are not certified, and we have not completed an attestation. If a procurement process requires a SOC 2 report today, we are not the right choice yet — and we would rather say so now than during your review.
Are you GDPR compliant?
We do not describe ourselves as fully compliant. The app honours Shopify's mandatory privacy webhooks, but automated data deletion is incomplete, so deletion requests may require us to act manually. Do not treat this as a compliance artefact.
What happens to data when I uninstall?
Uninstalling cleans up the session and access associated with your store. Full removal of conversation and lead data on uninstall is part of the same incomplete deletion work described above — ask us and we will do it manually.
Do you train AI models on my customer conversations?
No. Conversations are processed to answer the customer's question and stored so you and your team can read them. We do not use merchant conversation data to train models.
Is the WhatsApp connection secure?
The connection uses Meta's own Embedded Signup flow with tokens issued by Meta. We have hardening work outstanding on webhook verification, and it is tracked internally rather than described in detail here.
See also what the plans cost and the full list of product limits.
Start with the free plan
Free: 1 agent, 100 messages a month and up to 100 products indexed. No credit card required, billed through Shopify, cancel any time.