For the complete documentation index, see llms.txt. This page is also available as Markdown.

Privacy Policy

Effective Date: June 19, 2026 Last Updated: June 19, 2026


1. Introduction

Chizy (“Chizy,” “we,” “us,” or “our”) provides the Chizy – AI Chatbot & AI Agents application (the “App” or “Service”) for merchants using the Shopify platform, with integrations into messaging channels including Meta Business Messaging Platforms (WhatsApp, Messenger, and Instagram Direct), Shopify Inbox, and other connected channels.

This Privacy Policy explains how we collect, use, share, and safeguard personal data when you install, use, or otherwise interact with the App. It outlines your privacy rights and how you may exercise them under applicable laws including the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act (“CCPA”), and other applicable regulations.


2. Scope — Who This Policy Applies To

This Policy applies to two categories of data subjects:

(a) Merchants — Shopify store owners and their staff who install and configure the App.

(b) End-Users (Shoppers) — individuals who interact with a Merchant’s storefront chatbot or messaging channels (including WhatsApp, Shopify Inbox, and other integrated channels) powered by Chizy.

Controller / Processor roles:

  • For data we collect directly from Merchants (account creation, configuration, billing, support), Chizy acts as the data controller.

  • For data we process on behalf of a Merchant about their End-Users (conversations, contact details, message content), the Merchant acts as the data controller and Chizy acts as the data processor. Merchants are responsible for ensuring they have a lawful basis to collect and process End-User data and for providing their own privacy notices to End-Users where required.


3. Information We Collect

3.1 From Shopify

When a Merchant installs the App, we receive the following from the Shopify APIs and webhooks:

  • Shop domain, shop name, country, primary contact email, and Shopify account email

  • Store settings and configuration

  • Product catalog data (titles, descriptions, variants, prices, images, collections)

  • Pages, policies, and (on Growth+ plans) blog articles

  • Order data, including order numbers, status, fulfillment information, and associated customer identifiers — used solely for in-chat order tracking

  • Customer records, where required to support order tracking and merchant-configured chatbot behavior

3.2 From Meta Business Messaging Platforms

When a Merchant connects a Meta Business Messaging channel (WhatsApp, Messenger, and/or Instagram Direct) to Chizy, we receive data from the Meta Business Platform. The exact data depends on which channel is connected.

Common across all Meta channels:

  • Business asset identifiers (e.g. WhatsApp Business Account ID, Facebook Page ID, Instagram Business Account ID), display name, and verification status

  • Message content (text, media, documents, location, contacts, reactions) exchanged between End-Users and the Merchant

  • Message metadata (timestamps, delivery status, read receipts, conversation IDs)

Channel-specific identifiers and data:

  • WhatsApp — End-User phone numbers and WhatsApp profile names; Phone Number ID; template message status and quality ratings

  • Messenger — End-User Page-Scoped User ID (PSID), Facebook profile name and profile picture URL

  • Instagram Direct — End-User Instagram-Scoped ID (IGSID), Instagram username/display name, and profile picture URL

We process this data solely to operate the chatbot, deliver replies, and provide analytics to the Merchant.

3.3 From End-Users via the Chatbot

When an End-User interacts with a Chizy-powered chatbot on the storefront or a messaging channel, we collect:

  • Identity data submitted via pre-chat survey (where enabled by the Merchant): email address, name, phone number, and any custom fields the Merchant has configured

  • Identity data auto-filled from the Shopify customer object, where the End-User is logged into the Shopify storefront: email and name

  • Conversation content: all messages exchanged between the End-User and the AI or human agent

  • Conversation metadata: timestamps, message status, AI processing metadata (model used, token counts), and Chizy-generated conversation summaries and tags

  • Technical data captured automatically on every conversation, regardless of pre-chat survey status:

    • IP address

    • Browser and device information (user-agent string and related fields)

    • Approximate geographic location derived from IP

Note for Merchants: End-Users who do not complete a pre-chat survey are still subject to automatic capture of IP, browser, and geolocation data. You should ensure your own privacy notice to End-Users reflects this.

3.4 Information You Provide Voluntarily

  • Information submitted when contacting our support team (name, email, screenshots, message content) via in-app live chat or email

  • Feedback, feature requests, and survey responses

3.5 Automatically Collected Data — Chizy Admin & Website

When you use the Chizy admin (inside Shopify) or visit our website (chizy.io, docs.chizy.io):

  • Browser, device, and connection information

  • Usage data (pages viewed, features used, error logs) for service operation and debugging

  • Cookies and similar technologies (see Section 9)

We do not use third-party product analytics services.


We process personal data for the following purposes. For data subjects in the EEA / UK, the relevant legal basis under GDPR is listed.

Purpose
Legal basis (GDPR)

To operate, configure, and provide the App to Merchants

Performance of a contract (Art. 6(1)(b))

To enable AI chatbot responses, product recommendation, order tracking, and related features for End-Users

Processor — performed on instructions of the Merchant (Art. 28); Merchant’s lawful basis applies

To provide customer support and resolve technical issues

Performance of a contract; Legitimate interest (Art. 6(1)(f))

To send service announcements, transactional emails, and security notices

Performance of a contract; Legal obligation where applicable

To send product updates, feature announcements, and marketing

Consent (Art. 6(1)(a)) where required

To monitor and improve App performance, train internal classifiers, and ensure quality

Legitimate interest (Art. 6(1)(f))

To detect, prevent, and respond to fraud, abuse, security incidents, and policy violations

Legitimate interest; Legal obligation

To comply with legal, regulatory, and tax obligations

Legal obligation (Art. 6(1)(c))

We do not use End-User message content to train any third-party AI model.


5. AI Processing & Automation

The App uses third-party large language model (“LLM”) providers to generate chatbot responses. Currently:

  • OpenAI models

  • Anthropic Claude models

When an End-User sends a message:

  1. The message content, recent conversation history, and relevant Merchant knowledge base entries are sent to the LLM provider over a secure API connection.

  2. LLM providers process this data under their own data protection terms and do not retain it for model training in accordance with their enterprise / API terms.

  3. End-Users are informed that they are interacting with an AI assistant via in-chat disclosure.

The App also uses automated decision-making in the following narrow ways: product recommendation ranking, language auto-detection, conversation tagging, and routing of messages to human agents (where Shopify Inbox handoff is enabled). These do not produce legal or similarly significant effects on End-Users within the meaning of GDPR Art. 22. End-Users may always request to speak with a human via the available contact channels.


6. Sharing & Sub-processors

We share personal data only with the following sub-processors, each of which is contractually required to protect the data and use it only for the purposes we instruct.

Sub-processor
Purpose
Categories of data shared
Location

Shopify Inc.

Source platform integration (storefront, billing, admin)

Store configuration, products, orders, customer records

Global

Meta Platforms, Inc. (Business Messaging Platforms)

WhatsApp, Messenger, and Instagram Direct messaging delivery and receipt

End-User platform identifiers (phone, PSID, IGSID), profile names, message content, metadata

Global

OpenAI, L.L.C.

LLM responses, summarization, tagging

Message content, conversation context, knowledge base excerpts

United States

Anthropic, PBC

LLM responses, summarization, tagging

Message content, conversation context, knowledge base excerpts

United States

AWS/Linode

Application hosting, database, storage, search index

All processed data

United States

We do not sell personal data. We do not share End-User message content with advertisers or any other party outside the sub-processors listed above.

We will notify Merchants in advance of material changes to our sub-processor list by updating this Policy.


7. Data Storage, Security & Retention

7.1 Storage

Personal data is stored on servers operated by our hosting provider in the United States. Backups are maintained for disaster recovery and are encrypted at rest.

7.2 Security

We apply administrative, technical, and organizational measures to protect personal data, including:

  • TLS encryption for data in transit

  • Encryption at rest for databases and backups

  • Role-based access controls within Chizy systems

  • Audit logging of administrative actions

  • Regular review of access by employees and contractors

No method of transmission or storage is entirely risk-free, and we cannot guarantee absolute security.

7.3 Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

  • WhatsApp message content and metadata — retained for up to 30 days from receipt, in line with Meta Cloud API terms, then removed from active systems. Backups are purged within 90 days.

  • Conversation logs and Merchant store data — can be deleted via Shopify admin panel, or upon Merchant uninstall, deletion is initiated within 48 hours via Shopify’s shop/redact and customers/redact GDPR webhooks.

  • Merchant account and billing records — retained for the duration of the active subscription. Invoice and transaction records may be retained for up to 7 years in pseudonymized form where required by tax and accounting law.

  • Aggregated and anonymized data — may be retained indefinitely as it no longer identifies any individual.


8. International Data Transfers

Chizy is based in Singapore and processes data in the United States. Sub-processors may be located in the United States, the European Union, and other jurisdictions.

Where personal data of EEA or UK residents is transferred outside the EEA / UK, we rely on one or more of the following safeguards:

  • The European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum

  • An adequacy decision under GDPR Article 45 where applicable (e.g. UK, Switzerland)

  • Other lawful transfer mechanisms permitted by applicable law


9. Cookies and Similar Technologies

9.1 On the Chizy admin and website (chizy.io, docs.chizy.io)

We use cookies and similar technologies to:

  • Maintain authentication and core App functionality

  • Remember preferences

  • Measure and analyze usage to improve the App

We do not use third-party advertising or product analytics cookies.

9.2 On the storefront chat widget

The storefront chat widget uses local browser storage (not cookies) on the End-User’s device to:

  • Persist the conversation across page loads

  • Track unread message counts and dismissed banners

  • Preserve human-takeover state when Shopify Inbox handoff is active

This data stays on the End-User’s device and is not used for cross-site tracking. End-Users may clear it via their browser settings.


10. Your Rights

Subject to applicable law and the role Chizy plays for the data in question (controller or processor), you may have the following rights.

10.1 For all data subjects

  • Access the personal data we hold about you

  • Correct inaccurate or incomplete data

  • Delete your personal data (see Section 10.4 below)

  • Restrict or object to processing in certain circumstances

  • Portability of data you provided to us, in a structured, commonly used format

  • Withdraw consent at any time, where processing is based on consent (without affecting prior lawful processing)

  • Lodge a complaint with your local data protection authority

10.2 Data deletion — how to exercise

Chizy offers three deletion pathways.

(a) Manual deletion by the Merchant via the Chizy admin. Merchants can delete individual conversation logs at any time without uninstalling the App:

  1. Open the Chizy admin inside Shopify

  2. Go to Conversations

  3. Open the conversation(s) you want to delete and click Delete

Deleted conversation logs — including the associated End-User messages, identity fields, and metadata — are removed from active systems within 30 days and from backups within 90 days.

(b) Automatic deletion on Merchant uninstall (Shopify-driven). When a Merchant uninstalls the App from their Shopify store, deletion of all data associated with that store — including End-User conversations, contact information, and chatbot logs — is initiated within 48 hours via Shopify’s shop/redact and customers/redact GDPR webhooks. Removal is completed from active systems immediately. No action is required from the Merchant or End-Users.

(c) On-demand deletion for individual End-Users (shoppers). Even while a Merchant is actively using Chizy, an End-User may request deletion of their personal data at any time by emailing [email protected] with the store URL and any identifier they used (phone number, WhatsApp number, Messenger/Instagram username, or email).

We will acknowledge valid requests within 7 days, complete removal from active systems within 30 days, and from backups within 90 days, confirming completion via the same channel.

A standalone Data Deletion Instructions page is available at https://docs.chizy.io/policies/data-deletion.


11. Meta Messaging — Opt-in & Opt-out

Merchants using Meta Business Messaging Platforms (WhatsApp, Messenger, Instagram Direct) via Chizy must comply with Meta’s platform-specific messaging policies. Rules vary by channel.

11.1 WhatsApp

Merchants must obtain explicit opt-in consent from End-Users before sending proactive (template) messages, in accordance with the WhatsApp Business Messaging Policy and Meta’s Commerce Policy.

Chizy allows merchants to:

  • Record the opt-in source, timestamp, and consent text for each End-User

  • Manually mark an End-User as opted-out and block further proactive messaging to them

End-Users may opt out by blocking the Merchant on WhatsApp or contacting [email protected] to request opt-out.

11.2 Messenger

Outbound messaging on Messenger is governed by Meta’s standard 24-hour messaging window: Merchants may freely respond to an End-User within 24 hours of the End-User’s last message. Outside this window, Merchants may only send messages that fall under an approved message tag (e.g. CONFIRMED_EVENT_UPDATE, POST_PURCHASE_UPDATE, ACCOUNT_UPDATE) or a OTN (one-time notification) for which the End-User has explicitly opted in.

End-Users may opt out by blocking the Merchant’s Facebook Page or contacting [email protected] to request opt-out.

11.3 Instagram Direct

Outbound messaging on Instagram is governed by Meta’s 24-hour messaging window with Human Agent permission allowing up to 7 days for legitimate human-agent responses. Proactive notifications outside the window require an approved use case.

End-Users may opt out by blocking the Merchant’s Instagram account or contacting [email protected] to request opt-out.


12. Children’s Privacy

The App is not directed to children under 16 years of age, and we do not knowingly collect personal data from children under this age.

If we become aware that we have collected personal data from a child under the applicable age without verified parental consent, we will delete it promptly. Merchants are responsible for ensuring their use of the App complies with applicable children’s privacy laws, including COPPA in the United States and GDPR Article 8 in the EU.

If you believe a child has provided personal data to us, please contact [email protected].


Our App or website may include links to external websites. We are not responsible for the content, policies, or practices of those third parties. We recommend reviewing their privacy policies before sharing personal data.


14. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this Policy

  • For Merchants, send a notification via the in-App message center and / or email at least 30 days before the changes take effect

  • For End-Users, the Merchant remains responsible for surfacing material changes through their own privacy notice

Your continued use of the App after the effective date of an updated Policy constitutes acceptance of the changes.


15. Contact Us

If you have any questions about this Policy or wish to exercise your rights, please contact us:


⚖️ By installing or using the Chizy AI Chatbot App, you agree to this Privacy Policy. This Policy is governed by the laws of Singapore. We may update this Policy periodically, and changes will be posted here with an updated effective date.

Last updated