Privacy Policy
Effective Date: June 19, 2026 Last Updated: June 19, 2026
1. Introduction
Chizy (“Chizy,” “we,” “us,” or “our”) provides the Chizy – AI Chatbot & AI Agents application (the “App” or “Service”) for merchants using the Shopify platform, with integrations into messaging channels including Meta Business Messaging Platforms (WhatsApp, Messenger, and Instagram Direct), Shopify Inbox, and other connected channels.
This Privacy Policy explains how we collect, use, share, and safeguard personal data when you install, use, or otherwise interact with the App. It outlines your privacy rights and how you may exercise them under applicable laws including the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act (“CCPA”), and other applicable regulations.
2. Scope — Who This Policy Applies To
This Policy applies to two categories of data subjects:
(a) Merchants — Shopify store owners and their staff who install and configure the App.
(b) End-Users (Shoppers) — individuals who interact with a Merchant’s storefront chatbot or messaging channels (including WhatsApp, Shopify Inbox, and other integrated channels) powered by Chizy.
Controller / Processor roles:
For data we collect directly from Merchants (account creation, configuration, billing, support), Chizy acts as the data controller.
For data we process on behalf of a Merchant about their End-Users (conversations, contact details, message content), the Merchant acts as the data controller and Chizy acts as the data processor. Merchants are responsible for ensuring they have a lawful basis to collect and process End-User data and for providing their own privacy notices to End-Users where required.
3. Information We Collect
3.1 From Shopify
When a Merchant installs the App, we receive the following from the Shopify APIs and webhooks:
Shop domain, shop name, country, primary contact email, and Shopify account email
Store settings and configuration
Product catalog data (titles, descriptions, variants, prices, images, collections)
Pages, policies, and (on Growth+ plans) blog articles
Order data, including order numbers, status, fulfillment information, and associated customer identifiers — used solely for in-chat order tracking
Customer records, where required to support order tracking and merchant-configured chatbot behavior
3.2 From Meta Business Messaging Platforms
When a Merchant connects a Meta Business Messaging channel (WhatsApp, Messenger, and/or Instagram Direct) to Chizy, we receive data from the Meta Business Platform. The exact data depends on which channel is connected.
Common across all Meta channels:
Business asset identifiers (e.g. WhatsApp Business Account ID, Facebook Page ID, Instagram Business Account ID), display name, and verification status
Message content (text, media, documents, location, contacts, reactions) exchanged between End-Users and the Merchant
Message metadata (timestamps, delivery status, read receipts, conversation IDs)
Channel-specific identifiers and data:
WhatsApp — End-User phone numbers and WhatsApp profile names; Phone Number ID; template message status and quality ratings
Messenger — End-User Page-Scoped User ID (PSID), Facebook profile name and profile picture URL
Instagram Direct — End-User Instagram-Scoped ID (IGSID), Instagram username/display name, and profile picture URL
We process this data solely to operate the chatbot, deliver replies, and provide analytics to the Merchant.
3.3 From End-Users via the Chatbot
When an End-User interacts with a Chizy-powered chatbot on the storefront or a messaging channel, we collect:
Identity data submitted via pre-chat survey (where enabled by the Merchant): email address, name, phone number, and any custom fields the Merchant has configured
Identity data auto-filled from the Shopify customer object, where the End-User is logged into the Shopify storefront: email and name
Conversation content: all messages exchanged between the End-User and the AI or human agent
Conversation metadata: timestamps, message status, AI processing metadata (model used, token counts), and Chizy-generated conversation summaries and tags
Technical data captured automatically on every conversation, regardless of pre-chat survey status:
IP address
Browser and device information (user-agent string and related fields)
Approximate geographic location derived from IP
Note for Merchants: End-Users who do not complete a pre-chat survey are still subject to automatic capture of IP, browser, and geolocation data. You should ensure your own privacy notice to End-Users reflects this.
3.4 Information You Provide Voluntarily
Information submitted when contacting our support team (name, email, screenshots, message content) via in-app live chat or email
Feedback, feature requests, and survey responses
3.5 Automatically Collected Data — Chizy Admin & Website
When you use the Chizy admin (inside Shopify) or visit our website (chizy.io, docs.chizy.io):
Browser, device, and connection information
Usage data (pages viewed, features used, error logs) for service operation and debugging
Cookies and similar technologies (see Section 9)
We do not use third-party product analytics services.
4. How We Use Your Information & Legal Basis
We process personal data for the following purposes. For data subjects in the EEA / UK, the relevant legal basis under GDPR is listed.
To operate, configure, and provide the App to Merchants
Performance of a contract (Art. 6(1)(b))
To enable AI chatbot responses, product recommendation, order tracking, and related features for End-Users
Processor — performed on instructions of the Merchant (Art. 28); Merchant’s lawful basis applies
To provide customer support and resolve technical issues
Performance of a contract; Legitimate interest (Art. 6(1)(f))
To send service announcements, transactional emails, and security notices
Performance of a contract; Legal obligation where applicable
To send product updates, feature announcements, and marketing
Consent (Art. 6(1)(a)) where required
To monitor and improve App performance, train internal classifiers, and ensure quality
Legitimate interest (Art. 6(1)(f))
To detect, prevent, and respond to fraud, abuse, security incidents, and policy violations
Legitimate interest; Legal obligation
To comply with legal, regulatory, and tax obligations
Legal obligation (Art. 6(1)(c))
We do not use End-User message content to train any third-party AI model.
5. AI Processing & Automation
The App uses third-party large language model (“LLM”) providers to generate chatbot responses. Currently:
OpenAI models
Anthropic Claude models
When an End-User sends a message:
The message content, recent conversation history, and relevant Merchant knowledge base entries are sent to the LLM provider over a secure API connection.
LLM providers process this data under their own data protection terms and do not retain it for model training in accordance with their enterprise / API terms.
End-Users are informed that they are interacting with an AI assistant via in-chat disclosure.
The App also uses automated decision-making in the following narrow ways: product recommendation ranking, language auto-detection, conversation tagging, and routing of messages to human agents (where Shopify Inbox handoff is enabled). These do not produce legal or similarly significant effects on End-Users within the meaning of GDPR Art. 22. End-Users may always request to speak with a human via the available contact channels.
6. Sharing & Sub-processors
We share personal data only with the following sub-processors, each of which is contractually required to protect the data and use it only for the purposes we instruct.
Shopify Inc.
Source platform integration (storefront, billing, admin)
Store configuration, products, orders, customer records
Global
Meta Platforms, Inc. (Business Messaging Platforms)
WhatsApp, Messenger, and Instagram Direct messaging delivery and receipt
End-User platform identifiers (phone, PSID, IGSID), profile names, message content, metadata
Global
OpenAI, L.L.C.
LLM responses, summarization, tagging
Message content, conversation context, knowledge base excerpts
United States
Anthropic, PBC
LLM responses, summarization, tagging
Message content, conversation context, knowledge base excerpts
United States
AWS/Linode
Application hosting, database, storage, search index
All processed data
United States
We do not sell personal data. We do not share End-User message content with advertisers or any other party outside the sub-processors listed above.
We will notify Merchants in advance of material changes to our sub-processor list by updating this Policy.
7. Data Storage, Security & Retention
7.1 Storage
Personal data is stored on servers operated by our hosting provider in the United States. Backups are maintained for disaster recovery and are encrypted at rest.
7.2 Security
We apply administrative, technical, and organizational measures to protect personal data, including:
TLS encryption for data in transit
Encryption at rest for databases and backups
Role-based access controls within Chizy systems
Audit logging of administrative actions
Regular review of access by employees and contractors
No method of transmission or storage is entirely risk-free, and we cannot guarantee absolute security.
7.3 Retention
We retain personal data only as long as necessary for the purposes described in this Policy:
WhatsApp message content and metadata — retained for up to 30 days from receipt, in line with Meta Cloud API terms, then removed from active systems. Backups are purged within 90 days.
Conversation logs and Merchant store data — can be deleted via Shopify admin panel, or upon Merchant uninstall, deletion is initiated within 48 hours via Shopify’s
shop/redactandcustomers/redactGDPR webhooks.Merchant account and billing records — retained for the duration of the active subscription. Invoice and transaction records may be retained for up to 7 years in pseudonymized form where required by tax and accounting law.
Aggregated and anonymized data — may be retained indefinitely as it no longer identifies any individual.
8. International Data Transfers
Chizy is based in Singapore and processes data in the United States. Sub-processors may be located in the United States, the European Union, and other jurisdictions.
Where personal data of EEA or UK residents is transferred outside the EEA / UK, we rely on one or more of the following safeguards:
The European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum
An adequacy decision under GDPR Article 45 where applicable (e.g. UK, Switzerland)
Other lawful transfer mechanisms permitted by applicable law
9. Cookies and Similar Technologies
9.1 On the Chizy admin and website (chizy.io, docs.chizy.io)
chizy.io, docs.chizy.io)We use cookies and similar technologies to:
Maintain authentication and core App functionality
Remember preferences
Measure and analyze usage to improve the App
We do not use third-party advertising or product analytics cookies.
9.2 On the storefront chat widget
The storefront chat widget uses local browser storage (not cookies) on the End-User’s device to:
Persist the conversation across page loads
Track unread message counts and dismissed banners
Preserve human-takeover state when Shopify Inbox handoff is active
This data stays on the End-User’s device and is not used for cross-site tracking. End-Users may clear it via their browser settings.
10. Your Rights
Subject to applicable law and the role Chizy plays for the data in question (controller or processor), you may have the following rights.
10.1 For all data subjects
Access the personal data we hold about you
Correct inaccurate or incomplete data
Delete your personal data (see Section 10.4 below)
Restrict or object to processing in certain circumstances
Portability of data you provided to us, in a structured, commonly used format
Withdraw consent at any time, where processing is based on consent (without affecting prior lawful processing)
Lodge a complaint with your local data protection authority
10.2 Data deletion — how to exercise
Chizy offers three deletion pathways.
(a) Manual deletion by the Merchant via the Chizy admin. Merchants can delete individual conversation logs at any time without uninstalling the App:
Open the Chizy admin inside Shopify
Go to Conversations
Open the conversation(s) you want to delete and click Delete
Deleted conversation logs — including the associated End-User messages, identity fields, and metadata — are removed from active systems within 30 days and from backups within 90 days.
(b) Automatic deletion on Merchant uninstall (Shopify-driven).
When a Merchant uninstalls the App from their Shopify store, deletion of all data associated with that store — including End-User conversations, contact information, and chatbot logs — is initiated within 48 hours via Shopify’s shop/redact and customers/redact GDPR webhooks. Removal is completed from active systems immediately. No action is required from the Merchant or End-Users.
(c) On-demand deletion for individual End-Users (shoppers). Even while a Merchant is actively using Chizy, an End-User may request deletion of their personal data at any time by emailing [email protected] with the store URL and any identifier they used (phone number, WhatsApp number, Messenger/Instagram username, or email).
We will acknowledge valid requests within 7 days, complete removal from active systems within 30 days, and from backups within 90 days, confirming completion via the same channel.
A standalone Data Deletion Instructions page is available at https://docs.chizy.io/policies/data-deletion.
11. Meta Messaging — Opt-in & Opt-out
Merchants using Meta Business Messaging Platforms (WhatsApp, Messenger, Instagram Direct) via Chizy must comply with Meta’s platform-specific messaging policies. Rules vary by channel.
11.1 WhatsApp
Merchants must obtain explicit opt-in consent from End-Users before sending proactive (template) messages, in accordance with the WhatsApp Business Messaging Policy and Meta’s Commerce Policy.
Chizy allows merchants to:
Record the opt-in source, timestamp, and consent text for each End-User
Manually mark an End-User as opted-out and block further proactive messaging to them
End-Users may opt out by blocking the Merchant on WhatsApp or contacting [email protected] to request opt-out.
11.2 Messenger
Outbound messaging on Messenger is governed by Meta’s standard 24-hour messaging window: Merchants may freely respond to an End-User within 24 hours of the End-User’s last message. Outside this window, Merchants may only send messages that fall under an approved message tag (e.g. CONFIRMED_EVENT_UPDATE, POST_PURCHASE_UPDATE, ACCOUNT_UPDATE) or a OTN (one-time notification) for which the End-User has explicitly opted in.
End-Users may opt out by blocking the Merchant’s Facebook Page or contacting [email protected] to request opt-out.
11.3 Instagram Direct
Outbound messaging on Instagram is governed by Meta’s 24-hour messaging window with Human Agent permission allowing up to 7 days for legitimate human-agent responses. Proactive notifications outside the window require an approved use case.
End-Users may opt out by blocking the Merchant’s Instagram account or contacting [email protected] to request opt-out.
12. Children’s Privacy
The App is not directed to children under 16 years of age, and we do not knowingly collect personal data from children under this age.
If we become aware that we have collected personal data from a child under the applicable age without verified parental consent, we will delete it promptly. Merchants are responsible for ensuring their use of the App complies with applicable children’s privacy laws, including COPPA in the United States and GDPR Article 8 in the EU.
If you believe a child has provided personal data to us, please contact [email protected].
13. Third-Party Links
Our App or website may include links to external websites. We are not responsible for the content, policies, or practices of those third parties. We recommend reviewing their privacy policies before sharing personal data.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:
Update the “Last Updated” date at the top of this Policy
For Merchants, send a notification via the in-App message center and / or email at least 30 days before the changes take effect
For End-Users, the Merchant remains responsible for surfacing material changes through their own privacy notice
Your continued use of the App after the effective date of an updated Policy constitutes acceptance of the changes.
15. Contact Us
If you have any questions about this Policy or wish to exercise your rights, please contact us:
Privacy & data requests: [email protected]
General support: [email protected]
⚖️ By installing or using the Chizy AI Chatbot App, you agree to this Privacy Policy. This Policy is governed by the laws of Singapore. We may update this Policy periodically, and changes will be posted here with an updated effective date.
Last updated