Privacy Policy
AgentInStore helps online stores answer shopper questions using the merchant’s own catalog and knowledge. This policy explains what we collect, why, and how merchants and shoppers can request access or deletion.
1. Who we are
AgentInStore is operated by the service provider running this deployment. Contact the workspace owner or support email configured for your installation for privacy requests.
2. Data we process
- Merchant account data , name, email, workspace settings, plan/billing identifiers.
- Store connection data , store URL/domain, OAuth/API tokens needed to sync products and inject the chat widget.
- Catalog & knowledge , products, crawled pages, uploaded files/text used to answer questions.
- Chat messages , shopper conversations with the AI assistant (web widget and channels you enable).
- Leads , name/email/phone when a shopper (or the assistant) captures contact details.
- Technical logs , connection health, sync/job status, security events.
3. Why we process data
- Provide the AI sales assistant, product sync, and admin dashboard.
- Secure accounts, prevent abuse, and operate billing.
- Comply with legal requests (including Shopify GDPR webhooks when the Shopify app is used).
4. Store platforms
When you connect WooCommerce or Shopify, AgentInStore processes catalog data and connection credentials from that platform. Shopify merchants may also receive mandatory customer data-request / redact / shop-redact webhooks which we fulfill by locating and anonymizing or deleting matching lead and catalog records for that shop.
5. Sharing
We do not sell personal data. We use subprocessors only as needed to run the product (for example hosting, database, email delivery, LLM/embedding providers, and payment processing such as Stripe). Each merchant’s workspace data is isolated by tenant.
6. Retention
Data is kept while the workspace is active. Merchants can disconnect stores, delete knowledge/products/leads from the admin panel, or request account deletion. Disconnecting a store stops new sync; previously synced catalog may remain until deleted.
7. Security
Access is protected with authenticated admin sessions, signed webhooks where applicable, and HTTPS in production. Merchants should keep API secrets and session secrets private.
8. Your rights
Depending on your region, you may request access, correction, or deletion of personal data. Shoppers should contact the store merchant first. Merchants can open Integrations / Leads in AgentInStore or email support for workspace-level requests.
9. Children
AgentInStore is not directed at children under 16.
10. Changes
We may update this policy. The “Last updated” date above will change when we do. Continued use of the service after an update means you accept the revised policy.
11. Contact
For privacy questions about this AgentInStore deployment, contact the operator of this instance or use your workspace support channel.
