01

About This Policy

This Privacy Policy explains how Indition collects, uses, discloses, retains, and protects information through the Indition AI & Live Chat Shopify application (the "App"). The App includes its embedded Shopify admin experience, storefront chat widget, live-chat and AI-assisted features, content synchronization, support functions, and related services.

This policy applies specifically to the App. The general Indition website privacy policy applies to use of indition.com and other Indition services outside this App, unless that policy says otherwise.

02

Our Relationship with Merchants and Shoppers

A Shopify merchant installs and configures the App for its store. The merchant decides whether to enable the storefront chat widget, what store content to connect, what settings and instructions to provide, and how to respond to shoppers. Depending on the information and applicable law, the merchant may act as the controller or business and Indition may act as its processor or service provider. For some operational, security, billing, legal-compliance, and support activities, Indition may determine the purposes and means of processing.

Shoppers should also review the merchant's own privacy policy. Questions about a merchant's products, orders, account, or use of chat information should usually be directed to that merchant first.

03

Information We Collect

Shopify Store and App Information

When a merchant installs or uses the App, we may receive or generate:

  • Shop identifiers and details — Shopify shop ID, shop domain, store name, installation status, authentication and permission status, and App configuration.
  • Authorized user information — information about authorized Shopify users and their role or access context when needed to provide or secure the embedded App.
  • Access credentials — encrypted access credentials and security metadata needed to connect to Shopify.
  • Product and collection information — used to answer store-related questions and keep the App's knowledge current.
  • Legal policies — the store's published legal policies, when available through the permissions granted to the App.
  • Online store page content — if the merchant separately enables the optional online-store-pages permission and chooses to synchronize those pages.
  • Widget and theme status — theme app extension or widget activation status, configuration changes, and product or collection change notices.
  • Subscription and billing information — plan, billing entitlement, and feature-availability information associated with the App.
The App currently requests Shopify permissions for products and legal policies and uses an app proxy to deliver the storefront widget. It may offer online store pages as an optional permission. The App does not currently request Shopify Admin API access to merchant orders or customer records. An inventory permission may appear as an optional declared permission, but the current App does not ingest or store Shopify inventory data through its synchronization process. We will update this policy before activating any materially different data use.

Information Provided by Merchants and Their Teams

Merchants and authorized team members may provide:

  • Assistant instructions, tone, business rules, response preferences, and escalation guidance.
  • Widget appearance, display settings, business hours, starter questions, FAQs, security settings, and usage limits.
  • Team member roles, assignments, notification recipients, and transcript recipients.
  • Files, URLs, selected web pages, manual questions and answers, and selected product or knowledge sources.
  • Support communications, issue details, test prompts, and feedback about AI responses or App behavior.

Information from Shoppers and Storefront Visitors

When a person uses the storefront chat widget, we may collect:

  • Voluntarily provided information — name, email address, telephone number, messages, uploaded content, and feedback.
  • Chat and conversation information — questions, AI-generated replies, live-agent replies, transcripts, participants, handoff status, conversation status, and timestamps.
  • Storefront page context — page URL, page title, referrer URL, navigation or visit history relevant to the chat, and public storefront context.
  • Identifiers and technical data — pseudonymous visitor, session, tab, site, and conversation identifiers; IP address; user agent; mobile indicator; viewport; browser or device characteristics; security diagnostics; and automated-bot indicators.
If a logged-in Shopify customer identifier is made available through a signed storefront request, the App uses it temporarily to create a store-specific, non-reversible pseudonymous identifier. The raw Shopify customer identifier is not intended to be stored or written to logs. We do not try to infer a person's identity from free-form message text solely to match a privacy request.

Operational, Security, and Privacy-Request Information

We may collect or generate:

  • Feature usage, synchronization state, system logs, diagnostics, error and performance information.
  • Security, access-control, audit, rate-limit, and abuse-prevention information.
  • Webhook metadata, delivery status, payload hashes, workflow status, and minimized evidence of privacy-request handling. The App is designed not to persist raw privacy webhook payloads in its internal workflow records.
  • Support ticket identifiers, billing-entitlement records, and records needed to meet legal or compliance obligations.
04

How We Use Information

We use information described above to:

Operate the App — Install, authenticate, configure, operate, and secure the App.
Sync Content — Synchronize merchant-authorized store content and keep store-specific knowledge current.
AI Features — Provide AI-assisted responses, live-chat communication, conversation continuity, search, retrieval, embeddings, and store-specific context.
Route & Notify — Display conversation history, route or assign conversations, send notifications or transcripts, and support merchant follow-up.
Apply Settings — Apply merchant settings, business hours, team permissions, usage limits, and subscription entitlements.
Security — Detect, investigate, and prevent fraud, security incidents, abuse, and technical failures.
Reliability — Monitor reliability, diagnose errors, provide support, and improve App safety and performance.
Legal & Compliance — Process privacy requests, comply with law, enforce agreements, and establish or defend legal claims.
05

AI-Assisted Features

The App can import merchant-authorized store information, divide it into searchable sections, create numerical representations called embeddings, and index it for store-specific retrieval. When a shopper or merchant submits a question, the App may retrieve relevant store content and include that content, the merchant's instructions, the question, and recent conversation context in a request to an AI service so that the service can generate a response. This retrieval-based process does not, by itself, mean that a general-purpose AI model is being trained on the merchant's data.

Information sent to an AI service may include product or policy excerpts, merchant instructions, a shopper's question, recent conversation context, and personal information that a user chooses to type into the chat. Merchants should avoid placing unnecessary sensitive information in instructions or knowledge sources, and shoppers should avoid submitting sensitive information that is not needed for support.

AI-generated responses may be incomplete, outdated, or incorrect. Merchants are responsible for configuring appropriate instructions and escalation paths, and users should verify important information with the merchant.
06

Cookies and Browser Storage

The storefront widget uses cookies and browser storage to maintain visitor, site, session, tab, upload, and user-interface state; prevent unauthorized access; and keep a shopper connected to the correct conversation. A secure, HttpOnly, partitioned visitor cookie may remain for up to 400 days unless it is deleted earlier by the user, browser, merchant, or App. Session and tab information may end sooner.

The widget may also receive page URL, page title, referrer, and recent page-visit context so it can answer questions in context and preserve continuity.

CategoryPurposeDurationConsent
NecessaryVisitor identity, session continuity, conversation access, securityUp to 400 days (visitor); session (tab/session)Not required (essential)
07

How We Disclose Information

We may disclose information to:

  • Shopify — as needed to provide the integration, verify requests, manage billing or entitlements, and comply with Shopify platform requirements.
  • AI and embedding providers — that process prompts, relevant store content, and conversation context to provide the requested features.
  • Infrastructure and service providers — hosting, database, storage, file-processing, email, notification, analytics, error-monitoring, security, and customer-support providers that help us operate the App.
  • Professional advisers — auditors, insurers, and legal representatives when reasonably necessary.
  • Authorities and regulators — government authorities, regulators, courts, or other parties when required by law or necessary to protect rights, safety, and security.
  • Business transfers — a buyer, investor, lender, or successor in connection with a proposed or completed merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
09

Data Retention and Deletion

We retain information only for as long as needed for the purposes described in this policy, to meet legal or contractual obligations, resolve disputes, and protect the App. The periods below are the proposed App-specific schedule and must be confirmed before publication.

Uninstallation, Disconnection, and Shop Deletion

When the App is uninstalled or disconnected, we revoke or invalidate the App's Shopify access and stop new synchronization and widget access as soon as reasonably practicable. Shopify ordinarily sends a shop-redaction request after uninstall. When we receive a valid shop-redaction request, we remove or de-identify App data tied to the store, invalidate store-specific knowledge, and retain only information that we are permitted or required to keep for legal, security, billing, fraud-prevention, audit, or dispute purposes.

Uninstalling the App does not automatically delete data that a merchant maintains independently in another Indition service or data that has a separate lawful purpose and retention rule.
10

Privacy Rights and Requests

Depending on location, individuals may have rights to request:

Access
Correction
Deletion
Restriction
Objection
Portability
Withdraw Consent
Appeal

These rights may be limited by law.

Shoppers should normally submit requests to the Shopify merchant that controls the store and chat experience. Merchants may submit requests through the App's support or privacy contact. We may ask for information needed to verify the requester, identify the relevant store, and protect other people from unauthorized disclosure. We use exact, verified identifiers and store-specific pseudonyms where available; we do not guess identity from message text. Some guest or legacy conversations may not be matchable without sufficient verified information.

Shopify may send us mandatory privacy webhooks for customer data requests, customer redaction, and shop redaction. We process valid requests within the period required by applicable law and Shopify, including completion within 30 days when that period applies.

11

International Data Transfers

We and our service providers may process information in countries other than the country where a merchant or shopper is located. Where required, we use appropriate safeguards for international transfers, such as contractual protections or recognized adequacy mechanisms.

12

Security

We use administrative, technical, and organizational measures designed to protect information, including:

HTTPS in transit
Controlled credential handling & encryption
Tenant & store boundaries
Access controls
Webhook signature verification
Pseudonymous identifiers
Minimized privacy-request logs
Monitoring & audit records

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13

Children's Privacy

The App is a business service for Shopify merchants and is not designed or marketed specifically to children. Merchants are responsible for determining whether their storefront and use of the chat widget are directed to children and for obtaining any consent required by law.

14

Changes to This Policy

We may update this policy to reflect changes to the App, our practices, providers, or legal requirements. We will post the updated policy at this URL and revise the last-updated date. If required, we will provide additional notice to merchants or obtain consent before a material change takes effect.

We recommend that merchants periodically review this policy to stay informed about how we process information related to their store and shoppers.

Indition Chat — AI Assist
Hi! Is the blue version still in stock?
Generating reply…
Yes! The Cobalt Blue is available in all sizes. I can add it to your cart or send you the direct link — which would you prefer?
Insert
Copy
AI Assisted · Autonomy
Ready to Get Started?

Bring trusted AI support to your Shopify store

Trained on your store, running on premium models, and governed by you. Setup in 2 mins and resolve more issues automatically or assist your agents on the rest — and stand behind every answer.

Full 14-day free trial
No credit card to install
No per-resolution fees
Implementation support included
Available on the official Shopify App Store · Reviewed by Shopify