1. What we collect
We may collect account details (name, email, authentication and consent records); billing identifiers and transaction status from Stripe (we do not store full card numbers); chatbot settings and knowledge content; messages, contact details and channel identifiers processed for customers; team roles; support communications; integration tokens and identifiers; and technical records such as IP address, browser, device, security events, logs and AI-run diagnostics.
2. How we collect it
We collect information directly from account users, from people who interact with a customer’s chatbot, automatically when the service is used, and from connected services such as Meta, Shopify and Stripe. Our business customers decide what customer conversation data they submit and are generally responsible for their own privacy notices. Connecting Shopify initially enables only public shopping and theme features. If a merchant separately enables Customer sync, we send the saved name, email or phone, contact UUID, source channels, consent state, and capture/update times needed to match or create a Shopify Customer; chatbot custom answers and social usernames are not sent. If private order support is enabled, a customer-supplied order number and saved email are used only to find the matching order and return a limited status summary. We do not bulk-import Shopify customers or order history.
3. Why we use it
We use personal information only to provide and secure accounts; run chatbots and merchant-enabled integrations; answer a customer’s requested support question; process billing; measure allowances; deliver support and operational notices; detect fraud and abuse; diagnose reliability; comply with law; and establish or defend legal claims. We do not sell personal information or use Shopify customer or order data for advertising, profiling, or unrelated product development.
4. AI processing
Prompts, relevant conversation context and knowledge excerpts may be sent to the AI provider selected for a chatbot to generate a reply. Administrators should avoid placing unnecessary sensitive information in prompts or knowledge sources. AI output is stored with conversation and diagnostic records where needed to operate and audit the service.
5. Disclosure and overseas processing
We disclose information only as needed to service providers and connected platforms, professional advisers, authorities where legally required, and a successor in a business transaction. Our providers may include hosting and databases, Cloudflare R2, Redis, Qdrant, OpenAI and other configured AI providers, Stripe, Resend, browser automation providers, and customer-selected integrations. Because we operate an online service, recipients and systems may be located in Australia, the United States, the European Union, Singapore, or other countries where a selected provider operates. We take reasonable contractual and technical steps appropriate to the information and service.
6. Consent and customer choices
Saving contact details does not create marketing consent. A preference changes only when the person uses the Web Chat checkboxes or a Messenger or Instagram preference button. The same controls let a person uncheck or stop a channel; that withdrawal is recorded and forwarded to Shopify when Customer sync is enabled. Merchants remain responsible for campaign notices, lawful bases, and honoring choices in every downstream system.
7. Security
We use encrypted HTTPS and production database/cache transport, provider-managed encryption at rest and for backups, password hashing, encrypted integration tokens and temporary order summaries, multi-factor staff authentication, restricted production secrets and staff access, rate limiting, pseudonymous protected-data audit records, and incident-response and data-loss-prevention procedures. Production customer data is not used in test environments. No internet service is risk-free. Report suspected security issues to [email protected].
8. Retention
Messages, conversations, stale contacts, consent evidence, and related customer records are automatically removed after 365 days without retained activity by default; merchants may request earlier deletion. AI diagnostics are normally retained 30 days. Shopify order summaries are encrypted and expire after 24 hours. Pseudonymous protected-access and staff audit logs are retained up to 365 days. Completed Shopify privacy-request workflow records are retained 90 days. Encrypted backups expire through the provider’s documented rotation. Payment and legal records may be retained longer where required by law, tax, fraud-prevention, or dispute obligations.
9. Access, correction and deletion
You may ask to access or correct personal information, withdraw marketing consent, object to sale (we do not sell personal information), make a privacy complaint, or request deletion. Account owners can disable a protected Shopify feature, revoke its permission, or disconnect Shopify in the dashboard. See our Data Deletion page for instructions. We may verify identity and may retain information where law requires it. We generally respond within 30 days.
10. Cookies and local storage
We use essential session cookies and browser storage to keep users signed in, protect sessions, remember interface choices and run the service. See our Cookie Policy. We do not currently use advertising cookies on the service pages covered by this policy.
11. Children
The service is for businesses and adults and is not directed to children under 18. Do not intentionally submit children’s information unless lawful, necessary and covered by appropriate consent and safeguards.
12. Complaints
Contact our privacy lead first at [email protected]. Include enough detail for us to investigate. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
13. Contact
Hello Marky Chat
Privacy: [email protected]