Shopify App — Privacy Policy
Emanuel — Privacy Policy
Last updated: May 14, 2026 · Version 1.1
Application handle: emanuel-advanced-ai-live-chat
· Publisher: CivSec S.M.A.R.T B.V. (KvK 98045768)
1. Who we are
This Privacy Policy applies to the Emanuel application (the "App", "we", "us", "our") distributed through the Shopify App Store and operated by:
Chamber of Commerce (KvK): 98045768
VAT: NL868337237B01
Registered address: available on request via dpo@civsecsmart.com
Privacy contact: dpo@civsecsmart.com
Support: emanuel-support@civsecsmart.com
CivSec S.M.A.R.T B.V. is a wholly-owned subsidiary of CivSec Group B.V. (KvK 98032615) and is the data controller / processor (as applicable) for the processing activities described below.
2. Scope
This Policy describes how we process personal data in connection with:
- The admin-facing application used by Shopify merchants (shop owners and their staff) inside the Shopify Admin;
- The chat widget embedded in merchant storefronts and used by visitors (the merchant's end-consumers).
Different roles (merchant vs. visitor) trigger different data flows and different legal responsibilities — see §4.
3. Data we collect
3.1 From merchants (admin app)
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
Shop domain (*.myshopify.com) | Shopify OAuth on install | Scope isolation per tenant | GDPR Art 6(1)(b) Contract |
| Shop owner / staff name and email | Shopify Session | Authentication, support | Art 6(1)(b) Contract |
| Shop access token (offline) | Shopify OAuth | Authenticated API access (scoped) | Art 6(1)(b) Contract |
| Plan selection + subscription status | Shopify Billing webhooks | Feature gating, billing | Art 6(1)(b) Contract |
| Widget configuration (colour, greeting, assistant name, avatar URL, knowledge-base text, optional system prompt) | Merchant admin UI input | Service delivery | Art 6(1)(b) Contract |
| Support correspondence | Email / ticket replies | Customer support | Art 6(1)(b) / 6(1)(f) |
3.2 From visitors (widget on merchant storefront)
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Pseudonymous visitor UUID | Generated client-side, stored in browser localStorage | Conversation continuity | Art 6(1)(f) Legitimate interest (merchant) |
| Chat messages (visitor + AI) | Typed in widget | Service delivery; transcript retention | Art 6(1)(f) |
| IP address | HTTPS request | Rate limiting, abuse prevention (hashed/truncated, discarded within 24h) | Art 6(1)(f) |
| User-agent string | HTTPS request | Compatibility & bug triage | Art 6(1)(f) |
| Shop domain + page URL | Loader forwarding | Contextual AI response | Art 6(1)(b) / (f) |
| Optional name, email, phone | Pre-chat form (only if merchant enables + visitor provides) | Lead capture for the merchant | Art 6(1)(a) Consent |
| GDPR consent record | Timestamp + checkbox state | Proof of consent | Art 6(1)(c) Legal obligation |
3.3 Data we do NOT collect
- Payment card details (Shopify handles billing end-to-end; we never see card numbers)
- Third-party ad-tracking identifiers
- Device fingerprinting signals
- Special categories of data (GDPR Art. 9) such as health, biometrics, or political opinions
- Browser cookies on storefronts (we use only
localStorage, not cookies)
4. Controller / Processor roles
- For merchant-level data (shop, access token, admin settings, merchant billing, support tickets): CivSec S.M.A.R.T B.V. is the Controller. Merchants are the data subjects.
- For visitor-level data (messages, UUID, IP, optional pre-chat form data): CivSec S.M.A.R.T B.V. is a Processor on behalf of the merchant (Controller). The merchant is responsible for informing their visitors and relying on an appropriate legal basis on the storefront. A Data Processing Agreement (§12) governs this relationship.
5. Retention
| Data category | Retention | Rationale |
|---|---|---|
| Conversations and messages | 90 days from last message (default) | Storage minimisation |
| Support tickets and correspondence | 24 months | Dispute-resolution window |
| Merchant session tokens | Until app uninstall or token expiry | Service delivery |
| IP address (rate-limit cache) | 24 hours (hashed) | Abuse prevention |
| Subscription / invoice records | 7 years | Dutch tax law (AWR) — 7-year retention |
| Pre-chat form entries | 90 days from last conversation, or until visitor requests erasure | Minimisation |
Upon app uninstall by a merchant, we delete all visitor-level data
for that shop within 48 hours, triggered by Shopify's
shop/redact webhook. Retention exceptions apply only where required by
law (e.g. the 7-year tax window for billing records, scrubbed of visitor PII).
6. Subprocessors
We use the following third-party providers. Each is contractually obligated to process data only on our documented instructions and to apply equivalent technical and organisational measures.
| Subprocessor | Role | Location | Privacy policy |
|---|---|---|---|
| Anthropic PBC | AI inference (Claude API) | USA | link |
| Google LLC | AI inference (Gemini API). Pro+ multi-AI feature | USA | link |
| Google LLC (Analytics) | App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for in-app widget tracking. | USA | link |
| Vercel Inc. | Application hosting, edge compute, CDN | USA corp; EU region fra1 (Frankfurt) for execution | link |
| Neon Inc. | Managed PostgreSQL database | EU region aws-eu-central-1 (Frankfurt) | link |
| Resend Inc. | Transactional email (transcripts, support) | USA | link |
| Sentry (Functional Software, Inc.) | Error monitoring (PII scrubbing enabled, EU instance de.sentry.io) | EU (Germany) | link |
| Upstash Inc. | Redis-compatible rate-limit + KV cache | EU region | link |
| Shopify Inc. | App distribution, OAuth, Managed Pricing | Canada | link |
We will notify merchants at least 30 days before adding a new subprocessor that processes visitor personal data. Merchants may object by uninstalling the app before the effective date.
7. International transfers
Personal data may be transferred outside the European Economic Area (EEA) — principally to the United States for Anthropic, Google (Gemini), Vercel, Resend, and Sentry. We rely on:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) executed with each subprocessor
- Supplementary measures including TLS 1.2+ in transit, AES-256 at rest, and minimisation
- Regional pinning where available (Vercel
fra1, Neonaws-eu-central-1)
Anthropic has committed under its Commercial Terms that API inputs and outputs are not used to train models by default. Google AI Studio API configuration similarly applies the no-training default for paid usage tiers.
8. Your rights
8.1 Under the GDPR
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data — "right to be forgotten" (Art. 17)
- Restrict processing (Art. 18)
- Data portability — receive your data in a structured, commonly-used format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time where consent is the legal basis (Art. 7(3))
- Lodge a complaint with a supervisory authority: Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, The Netherlands)
Visitors typically exercise these rights via the merchant (who forwards requests
through Shopify's customers/data_request webhook). Visitors may
also contact us directly at
dpo@civsecsmart.com.
8.2 Under the CCPA (California residents)
Californian residents have the right to:
- Know what personal information is collected, used, and disclosed
- Delete personal information (subject to legal exceptions)
- Opt out of sale — we do not sell personal information and never have
- Non-discrimination for exercising CCPA rights
To exercise these rights, email dpo@civsecsmart.com with subject line "CCPA request".
9. Security
We apply the following safeguards, consistent with GDPR Art. 32:
- TLS 1.2+ for all network traffic
- AES-256 encryption at rest for database content
- Principle of least privilege for internal access; audit logs maintained
- HMAC-SHA256 verification on all inbound Shopify webhooks
- Scope-minimised OAuth (only the Shopify scopes documented in our app listing)
- Automated dependency vulnerability scanning in CI
- No secrets in client-side code — AI provider API keys reside exclusively server-side
- Responsible disclosure channel: security@civsecsmart.com · see /.well-known/security.txt (RFC 9116)
No system is 100% secure. In the event of a qualifying personal data breach we will notify affected parties without undue delay and in any event within 72 hours of awareness, in accordance with GDPR Art. 33–34.
10. Cookies and local storage
The storefront widget uses browser localStorage — not
cookies — to store:
- A pseudonymous visitor UUID (
civsec_visitor_id) - A 5-minute cache of the widget configuration
- Optional pre-chat form inputs for the current session (only if the merchant enabled this feature and the visitor provided them)
The admin app uses Shopify session cookies only for authentication inside the Shopify Admin iframe, as required by Shopify App Bridge.
The Emanuel App Store listing page on
apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a
small set of install-funnel events to our Google Analytics 4 property: a view of the
listing page, a click on the Install button, a completed install, and an arrival
from a Shopify App Store ad. We use this data only to measure listing performance.
Those events are governed by Shopify privacy policy on apps.shopify.com and processed
by Google as described in section 6. The listing analytics flow does not involve
cookies set by our app on a merchant storefront and is independent of the widget and
admin processing described above.
11. Children
The App is a business-to-business service. The widget is not directed at children under 16. We do not knowingly collect data from children under 16. If a merchant's storefront targets children, that merchant is responsible for ensuring appropriate consent and protections on their side.
12. Data Processing Agreement
For visitor-level processing, merchants and CivSec S.M.A.R.T B.V. enter into a Data Processing Agreement (DPA) incorporated by reference into the Terms of Service. Key DPA provisions include:
- Processor acts only on the Controller's documented instructions
- Confidentiality obligations for personnel with access to data
- List of subprocessors with 30-day change notice
- Assistance with data-subject requests
- Breach notification within 72 hours of awareness
- Deletion or return of data upon termination
- Reasonable audit rights (remote, annual)
Although CivSec S.M.A.R.T B.V. falls below the GDPR Art. 37 mandatory-DPO threshold, a designated privacy contact is available at dpo@civsecsmart.com for all data-protection matters.
13. Changes to this Policy
We may update this Policy as the service evolves or as regulation changes. Material changes are communicated to merchants by email and in-app notification at least 30 days before they take effect. The "Last updated" date at the top reflects the current version.
14. Contact
CivSec S.M.A.R.T B.V.
KvK 98045768 · VAT NL868337237B01
Postal address available on request via dpo@civsecsmart.com
- Privacy / GDPR / DPO: dpo@civsecsmart.com
- Security disclosures: security@civsecsmart.com
- Legal / contractual: legal@civsecsmart.com
- App support: emanuel-support@civsecsmart.com
Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change. Changelog 1.0 to 1.1: added Google Analytics (GA4) subprocessor row in section 6 plus listing analytics paragraph in section 10, covering the App Store listing tracking activated 2026-05-14.