Shopify App — Privacy Policy

Emanuel — Privacy Policy

Last updated: May 14, 2026 · Version 1.1

Application handle: emanuel-advanced-ai-live-chat · Publisher: CivSec S.M.A.R.T B.V. (KvK 98045768)

1. Who we are

This Privacy Policy applies to the Emanuel application (the "App", "we", "us", "our") distributed through the Shopify App Store and operated by:

CivSec S.M.A.R.T B.V.
Chamber of Commerce (KvK): 98045768
VAT: NL868337237B01
Registered address: available on request via dpo@civsecsmart.com
Privacy contact: dpo@civsecsmart.com
Support: emanuel-support@civsecsmart.com

CivSec S.M.A.R.T B.V. is a wholly-owned subsidiary of CivSec Group B.V. (KvK 98032615) and is the data controller / processor (as applicable) for the processing activities described below.

2. Scope

This Policy describes how we process personal data in connection with:

  • The admin-facing application used by Shopify merchants (shop owners and their staff) inside the Shopify Admin;
  • The chat widget embedded in merchant storefronts and used by visitors (the merchant's end-consumers).

Different roles (merchant vs. visitor) trigger different data flows and different legal responsibilities — see §4.

3. Data we collect

3.1 From merchants (admin app)

Data Source Purpose Legal basis
Shop domain (*.myshopify.com)Shopify OAuth on installScope isolation per tenantGDPR Art 6(1)(b) Contract
Shop owner / staff name and emailShopify SessionAuthentication, supportArt 6(1)(b) Contract
Shop access token (offline)Shopify OAuthAuthenticated API access (scoped)Art 6(1)(b) Contract
Plan selection + subscription statusShopify Billing webhooksFeature gating, billingArt 6(1)(b) Contract
Widget configuration (colour, greeting, assistant name, avatar URL, knowledge-base text, optional system prompt)Merchant admin UI inputService deliveryArt 6(1)(b) Contract
Support correspondenceEmail / ticket repliesCustomer supportArt 6(1)(b) / 6(1)(f)

3.2 From visitors (widget on merchant storefront)

Data Source Purpose Legal basis
Pseudonymous visitor UUIDGenerated client-side, stored in browser localStorageConversation continuityArt 6(1)(f) Legitimate interest (merchant)
Chat messages (visitor + AI)Typed in widgetService delivery; transcript retentionArt 6(1)(f)
IP addressHTTPS requestRate limiting, abuse prevention (hashed/truncated, discarded within 24h)Art 6(1)(f)
User-agent stringHTTPS requestCompatibility & bug triageArt 6(1)(f)
Shop domain + page URLLoader forwardingContextual AI responseArt 6(1)(b) / (f)
Optional name, email, phonePre-chat form (only if merchant enables + visitor provides)Lead capture for the merchantArt 6(1)(a) Consent
GDPR consent recordTimestamp + checkbox stateProof of consentArt 6(1)(c) Legal obligation

3.3 Data we do NOT collect

  • Payment card details (Shopify handles billing end-to-end; we never see card numbers)
  • Third-party ad-tracking identifiers
  • Device fingerprinting signals
  • Special categories of data (GDPR Art. 9) such as health, biometrics, or political opinions
  • Browser cookies on storefronts (we use only localStorage, not cookies)

4. Controller / Processor roles

  • For merchant-level data (shop, access token, admin settings, merchant billing, support tickets): CivSec S.M.A.R.T B.V. is the Controller. Merchants are the data subjects.
  • For visitor-level data (messages, UUID, IP, optional pre-chat form data): CivSec S.M.A.R.T B.V. is a Processor on behalf of the merchant (Controller). The merchant is responsible for informing their visitors and relying on an appropriate legal basis on the storefront. A Data Processing Agreement (§12) governs this relationship.

5. Retention

Data categoryRetentionRationale
Conversations and messages90 days from last message (default)Storage minimisation
Support tickets and correspondence24 monthsDispute-resolution window
Merchant session tokensUntil app uninstall or token expiryService delivery
IP address (rate-limit cache)24 hours (hashed)Abuse prevention
Subscription / invoice records7 yearsDutch tax law (AWR) — 7-year retention
Pre-chat form entries90 days from last conversation, or until visitor requests erasureMinimisation

Upon app uninstall by a merchant, we delete all visitor-level data for that shop within 48 hours, triggered by Shopify's shop/redact webhook. Retention exceptions apply only where required by law (e.g. the 7-year tax window for billing records, scrubbed of visitor PII).

6. Subprocessors

We use the following third-party providers. Each is contractually obligated to process data only on our documented instructions and to apply equivalent technical and organisational measures.

SubprocessorRoleLocationPrivacy policy
Anthropic PBCAI inference (Claude API)USAlink
Google LLCAI inference (Gemini API). Pro+ multi-AI featureUSAlink
Google LLC (Analytics)App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for in-app widget tracking.USAlink
Vercel Inc.Application hosting, edge compute, CDNUSA corp; EU region fra1 (Frankfurt) for executionlink
Neon Inc.Managed PostgreSQL databaseEU region aws-eu-central-1 (Frankfurt)link
Resend Inc.Transactional email (transcripts, support)USAlink
Sentry (Functional Software, Inc.)Error monitoring (PII scrubbing enabled, EU instance de.sentry.io)EU (Germany)link
Upstash Inc.Redis-compatible rate-limit + KV cacheEU regionlink
Shopify Inc.App distribution, OAuth, Managed PricingCanadalink

We will notify merchants at least 30 days before adding a new subprocessor that processes visitor personal data. Merchants may object by uninstalling the app before the effective date.

7. International transfers

Personal data may be transferred outside the European Economic Area (EEA) — principally to the United States for Anthropic, Google (Gemini), Vercel, Resend, and Sentry. We rely on:

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) executed with each subprocessor
  • Supplementary measures including TLS 1.2+ in transit, AES-256 at rest, and minimisation
  • Regional pinning where available (Vercel fra1, Neon aws-eu-central-1)

Anthropic has committed under its Commercial Terms that API inputs and outputs are not used to train models by default. Google AI Studio API configuration similarly applies the no-training default for paid usage tiers.

8. Your rights

8.1 Under the GDPR

You have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data — "right to be forgotten" (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a structured, commonly-used format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time where consent is the legal basis (Art. 7(3))
  • Lodge a complaint with a supervisory authority: Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, The Netherlands)

Visitors typically exercise these rights via the merchant (who forwards requests through Shopify's customers/data_request webhook). Visitors may also contact us directly at dpo@civsecsmart.com.

8.2 Under the CCPA (California residents)

Californian residents have the right to:

  • Know what personal information is collected, used, and disclosed
  • Delete personal information (subject to legal exceptions)
  • Opt out of sale — we do not sell personal information and never have
  • Non-discrimination for exercising CCPA rights

To exercise these rights, email dpo@civsecsmart.com with subject line "CCPA request".

9. Security

We apply the following safeguards, consistent with GDPR Art. 32:

  • TLS 1.2+ for all network traffic
  • AES-256 encryption at rest for database content
  • Principle of least privilege for internal access; audit logs maintained
  • HMAC-SHA256 verification on all inbound Shopify webhooks
  • Scope-minimised OAuth (only the Shopify scopes documented in our app listing)
  • Automated dependency vulnerability scanning in CI
  • No secrets in client-side code — AI provider API keys reside exclusively server-side
  • Responsible disclosure channel: security@civsecsmart.com · see /.well-known/security.txt (RFC 9116)

No system is 100% secure. In the event of a qualifying personal data breach we will notify affected parties without undue delay and in any event within 72 hours of awareness, in accordance with GDPR Art. 33–34.

10. Cookies and local storage

The storefront widget uses browser localStorage — not cookies — to store:

  • A pseudonymous visitor UUID (civsec_visitor_id)
  • A 5-minute cache of the widget configuration
  • Optional pre-chat form inputs for the current session (only if the merchant enabled this feature and the visitor provided them)

The admin app uses Shopify session cookies only for authentication inside the Shopify Admin iframe, as required by Shopify App Bridge.

The Emanuel App Store listing page on apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a small set of install-funnel events to our Google Analytics 4 property: a view of the listing page, a click on the Install button, a completed install, and an arrival from a Shopify App Store ad. We use this data only to measure listing performance. Those events are governed by Shopify privacy policy on apps.shopify.com and processed by Google as described in section 6. The listing analytics flow does not involve cookies set by our app on a merchant storefront and is independent of the widget and admin processing described above.

11. Children

The App is a business-to-business service. The widget is not directed at children under 16. We do not knowingly collect data from children under 16. If a merchant's storefront targets children, that merchant is responsible for ensuring appropriate consent and protections on their side.

12. Data Processing Agreement

For visitor-level processing, merchants and CivSec S.M.A.R.T B.V. enter into a Data Processing Agreement (DPA) incorporated by reference into the Terms of Service. Key DPA provisions include:

  • Processor acts only on the Controller's documented instructions
  • Confidentiality obligations for personnel with access to data
  • List of subprocessors with 30-day change notice
  • Assistance with data-subject requests
  • Breach notification within 72 hours of awareness
  • Deletion or return of data upon termination
  • Reasonable audit rights (remote, annual)

Although CivSec S.M.A.R.T B.V. falls below the GDPR Art. 37 mandatory-DPO threshold, a designated privacy contact is available at dpo@civsecsmart.com for all data-protection matters.

13. Changes to this Policy

We may update this Policy as the service evolves or as regulation changes. Material changes are communicated to merchants by email and in-app notification at least 30 days before they take effect. The "Last updated" date at the top reflects the current version.

14. Contact

CivSec S.M.A.R.T B.V.
KvK 98045768 · VAT NL868337237B01
Postal address available on request via dpo@civsecsmart.com

Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change. Changelog 1.0 to 1.1: added Google Analytics (GA4) subprocessor row in section 6 plus listing analytics paragraph in section 10, covering the App Store listing tracking activated 2026-05-14.