Shopify App — Privacy Policy
Last updated: May 14, 2026 · Version 1.1
Application handle: emanuel-advanced-ai-live-chat · Publisher: CivSec S.M.A.R.T B.V. (KvK 98045768)
This Privacy Policy applies to the Emanuel application (the "App", "we", "us", "our") distributed through the Shopify App Store and operated by:
CivSec S.M.A.R.T B.V. is a wholly-owned subsidiary of CivSec Group B.V. (KvK 98032615) and is the data controller / processor (as applicable) for the processing activities described below.
This Policy describes how we process personal data in connection with:
Different roles (merchant vs. visitor) trigger different data flows and different legal responsibilities — see §4.
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
Shop domain (*.myshopify.com) | Shopify OAuth on install | Scope isolation per tenant | GDPR Art 6(1)(b) Contract |
| Shop owner / staff name and email | Shopify Session | Authentication, support | Art 6(1)(b) Contract |
| Shop access token (offline) | Shopify OAuth | Authenticated API access (scoped) | Art 6(1)(b) Contract |
| Plan selection + subscription status | Shopify Billing webhooks | Feature gating, billing | Art 6(1)(b) Contract |
| Widget configuration (colour, greeting, assistant name, avatar URL, knowledge-base text, optional system prompt) | Merchant admin UI input | Service delivery | Art 6(1)(b) Contract |
| Support correspondence | Email / ticket replies | Customer support | Art 6(1)(b) / 6(1)(f) |
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Pseudonymous visitor UUID | Generated client-side, stored in browser localStorage | Conversation continuity | Art 6(1)(f) Legitimate interest (merchant) |
| Chat messages (visitor + AI) | Typed in widget | Service delivery; transcript retention | Art 6(1)(f) |
| IP address | HTTPS request | Rate limiting, abuse prevention (hashed/truncated, discarded within 24h) | Art 6(1)(f) |
| User-agent string | HTTPS request | Compatibility & bug triage | Art 6(1)(f) |
| Shop domain + page URL | Loader forwarding | Contextual AI response | Art 6(1)(b) / (f) |
| Optional name, email, phone | Pre-chat form (only if merchant enables + visitor provides) | Lead capture for the merchant | Art 6(1)(a) Consent |
| GDPR consent record | Timestamp + checkbox state | Proof of consent | Art 6(1)(c) Legal obligation |
localStorage, not cookies)| Data category | Retention | Rationale |
|---|---|---|
| Conversations and messages | 90 days from last message (default) | Storage minimisation |
| Support tickets and correspondence | 24 months | Dispute-resolution window |
| Merchant session tokens | Until app uninstall or token expiry | Service delivery |
| IP address (rate-limit cache) | 24 hours (hashed) | Abuse prevention |
| Subscription / invoice records | 7 years | Dutch tax law (AWR) — 7-year retention |
| Pre-chat form entries | 90 days from last conversation, or until visitor requests erasure | Minimisation |
Upon app uninstall by a merchant, we delete all visitor-level data for that shop within 48 hours, triggered by Shopify's shop/redact webhook. Retention exceptions apply only where required by law (e.g. the 7-year tax window for billing records, scrubbed of visitor PII).
We use the following third-party providers. Each is contractually obligated to process data only on our documented instructions and to apply equivalent technical and organisational measures.
| Subprocessor | Role | Location | Privacy policy |
|---|---|---|---|
| Anthropic PBC | AI inference (Claude API) | USA | link |
| Google LLC | AI inference (Gemini API). Pro+ multi-AI feature | USA | link |
| Google LLC (Analytics) | App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for in-app widget tracking. | USA | link |
| Vercel Inc. | Application hosting, edge compute, CDN | USA corp; EU region fra1 (Frankfurt) for execution | link |
| Neon Inc. | Managed PostgreSQL database | EU region aws-eu-central-1 (Frankfurt) | link |
| Resend Inc. | Transactional email (transcripts, support) | USA | link |
| Sentry (Functional Software, Inc.) | Error monitoring (PII scrubbing enabled, EU instance de.sentry.io) | EU (Germany) | link |
| Upstash Inc. | Redis-compatible rate-limit + KV cache | EU region | link |
| Shopify Inc. | App distribution, OAuth, Managed Pricing | Canada | link |
We will notify merchants at least 30 days before adding a new subprocessor that processes visitor personal data. Merchants may object by uninstalling the app before the effective date.
Personal data may be transferred outside the European Economic Area (EEA) — principally to the United States for Anthropic, Google (Gemini), Vercel, Resend, and Sentry. We rely on:
fra1, Neon aws-eu-central-1)Anthropic has committed under its Commercial Terms that API inputs and outputs are not used to train models by default. Google AI Studio API configuration similarly applies the no-training default for paid usage tiers.
You have the right to:
Visitors typically exercise these rights via the merchant (who forwards requests through Shopify's customers/data_request webhook). Visitors may also contact us directly at dpo@civsecsmart.com.
Californian residents have the right to:
To exercise these rights, email dpo@civsecsmart.com with subject line "CCPA request".
We apply the following safeguards, consistent with GDPR Art. 32:
No system is 100% secure. In the event of a qualifying personal data breach we will notify affected parties without undue delay and in any event within 72 hours of awareness, in accordance with GDPR Art. 33–34.
The storefront widget uses browser localStorage — not cookies — to store:
civsec_visitor_id)The admin app uses Shopify session cookies only for authentication inside the Shopify Admin iframe, as required by Shopify App Bridge.
The Emanuel App Store listing page on apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a small set of install-funnel events to our Google Analytics 4 property: a view of the listing page, a click on the Install button, a completed install, and an arrival from a Shopify App Store ad. We use this data only to measure listing performance. Those events are governed by Shopify privacy policy on apps.shopify.com and processed by Google as described in section 6. The listing analytics flow does not involve cookies set by our app on a merchant storefront and is independent of the widget and admin processing described above.
The App is a business-to-business service. The widget is not directed at children under 16. We do not knowingly collect data from children under 16. If a merchant's storefront targets children, that merchant is responsible for ensuring appropriate consent and protections on their side.
For visitor-level processing, merchants and CivSec S.M.A.R.T B.V. enter into a Data Processing Agreement (DPA) incorporated by reference into the Terms of Service. Key DPA provisions include:
Although CivSec S.M.A.R.T B.V. falls below the GDPR Art. 37 mandatory-DPO threshold, a designated privacy contact is available at dpo@civsecsmart.com for all data-protection matters.
We may update this Policy as the service evolves or as regulation changes. Material changes are communicated to merchants by email and in-app notification at least 30 days before they take effect. The "Last updated" date at the top reflects the current version.
CivSec S.M.A.R.T B.V.
KvK 98045768 · VAT NL868337237B01
Postal address available on request via dpo@civsecsmart.com
Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change. Changelog 1.0 to 1.1: added Google Analytics (GA4) subprocessor row in section 6 plus listing analytics paragraph in section 10, covering the App Store listing tracking activated 2026-05-14.