Privacy Policy
This Privacy Policy describes how Jcodi Chatbot ("we", "us", or "our") collects, uses, and protects information when you install and use our Shopify application (the "App").
By installing or using the App, you agree to this Privacy Policy. If you do not agree, please uninstall the App.
1. Who this policy applies to
- Merchants — Shopify store owners who install the App in Shopify Admin.
- Store customers — visitors who use the storefront chat widget or optional messaging channels configured by the merchant.
2. Information we collect
From merchants
- Shop domain, Shopify session tokens, and app installation status.
- App settings you save, such as widget text, colors, language options, store rules, FAQ content, and subscription/billing status synced from Shopify.
- Product and collection data from your Shopify store (including titles, descriptions, prices, variants, and metafields) when you run catalog sync for AI features.
- OpenAI API credentials you provide (stored encrypted). If you use optional WhatsApp or Instagram features, related channel configuration and access tokens you save (stored encrypted).
From store customers
- Messages submitted through the storefront chat widget are processed to generate replies. We also store those messages on our servers so merchants can review conversations and chat analytics in the App admin (Inbox). We use an anonymous visitor identifier in the shopper's browser — not the customer's name, email, or Shopify customer ID. Voice input is processed to generate replies and is not kept as an audio recording.
- Chat history may also be kept in the shopper's browser (local storage) when the merchant enables that option.
- If a signed-in shopper asks to track an order, we look up that customer's orders through Shopify (order number, status, and tracking links). We do not store full order records; a short summary may appear in the merchant Inbox if the chat is saved.
- If a merchant enables WhatsApp or Instagram, message content and identifiers needed to route replies may be processed and temporarily stored for that conversation.
- Standard technical data such as IP address, browser type, and request metadata in server logs for security and operations.
3. How we use information
- Provide, operate, and improve the App and AI assistant features.
- Look up a signed-in shopper's orders and tracking when they ask in chat.
- Show merchants conversation transcripts and chat analytics in the App admin.
- Sync your catalog and generate store-specific AI rules and responses.
- Process billing through the Shopify Billing API.
- Send AI requests to configured providers (OpenAI, Anthropic, or Google) on your behalf.
- Deliver optional messaging channel replies when enabled by the merchant.
- Maintain security, prevent abuse, troubleshoot issues, and comply with law.
4. Third-party services
We rely on trusted service providers to run the App, including:
- Shopify — app hosting inside Shopify Admin, OAuth, webhooks, product data, and billing.
- OpenAI — chat (when selected), transcription, text-to-speech, and catalog/rule generation when you connect an API key or use a configured server key.
- Anthropic — chat replies when you select Claude and connect an API key.
- Google — chat replies when you select Gemini and connect an API key.
- Meta (optional) — WhatsApp Business and Instagram messaging when a merchant configures those channels.
- Hosting and database providers — to host the App and store merchant configuration securely.
These providers process data according to their own privacy policies and only as needed to deliver the App.
5. Data retention and deletion
- Merchant configuration and catalog cache are kept while the App is installed and as needed to provide the service.
- When the App is uninstalled or Shopify sends a shop redaction request, we delete persisted shop data from our systems, including sessions, shop settings, and stored storefront conversations.
- Storefront conversation transcripts are retained for up to 90 days while the App is installed, then removed automatically. Optional channel conversation data is retained only as needed to continue a support thread.
We honor Shopify's mandatory compliance webhooks for customer data requests and redaction where applicable.
6. Security
We use industry-standard measures to protect data, including HTTPS in transit and encryption for sensitive credentials such as API keys and messaging tokens. No method of transmission or storage is 100% secure, but we work to safeguard your information.
7. Your choices
- Uninstall the App from Shopify Admin to stop new data collection.
- Remove or rotate API keys and channel tokens in the App settings at any time.
- Disable the storefront widget or optional channels in App settings.
- Control whether chat history is stored on a shopper's device via the widget persistence setting. Storefront conversations saved for the merchant Inbox are still stored on our servers while the App is installed (up to 90 days).
8. International transfers
Data may be processed in countries where we or our service providers operate. We take steps to ensure appropriate safeguards when data is transferred internationally.
9. Children
The App is intended for merchants running online stores and is not directed at children under 13. Merchants are responsible for their store's compliance with applicable laws regarding minors.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date above. Continued use of the App after changes means you accept the updated policy.
11. Contact us
For privacy questions or requests about Jcodi Chatbot, contact Jcodi support through the support contact listed on the Shopify App Store.