Last updated: [PLACEHOLDER: publish date]
Who we are
This Privacy Policy explains how [PLACEHOLDER: legal entity name] (“Company”, “we”, “us”) handles data in connection with WooCommerce AI Chat (the “Service”) — a WordPress/WooCommerce plugin that adds an AI-powered shopper chat widget and catalog-content generation to a merchant’s store, plus the merchant dashboard used to manage a subscription, license, and billing.
For most of the data this policy covers, the merchant who installs the Service is the data controller of their own shoppers’ data, and we act as a data processor on the merchant’s behalf. We are not a liability-free intermediary: our infrastructure sits directly in the data path (your product catalog and chat content pass through our servers and our AI providers to generate answers), and this relationship is governed by a Data Processing Agreement (DPA) between us and the merchant.
What data we process
From merchants (store owners): account and billing information (via WooCommerce/Stripe — we do not store your card details ourselves), license key and subscription status, and usage metrics (chat replies, memory items, and AI Tasks consumed against your plan).
From your store: your product catalog and store content, indexed so the chat widget can answer shopper questions grounded in what you actually sell. This indexed content is stored in our vector database (Qdrant) for as long as your license is active.
From shoppers: the questions they ask the chat widget and the AI-generated replies. Chat logs are redacted for personal information at the point they are written, before long-term storage.
AI use and disclosure
The chat widget always displays a persistent, non-removable notice that shoppers are chatting with an AI assistant, not a person — required under the EU AI Act and built into the widget itself, not an optional setting. AI Tasks (auto-generated product descriptions, category descriptions, tags, summaries, and image alt text) are produced by third-party AI models and should be reviewed by the merchant before publishing, like any AI-generated content.
Who we share data with (sub-processors)
We use the following third-party sub-processors to operate the Service. Each is named in our DPA:
- OpenAI — generates embeddings for catalog indexing and AI chat/content-generation replies. Catalog content and chat questions are sent to OpenAI’s API to produce responses.
- Stripe — processes subscription payments through WooCommerce. We do not receive or store full payment card details.
- Sentry (EU region) — error tracking for the Service’s backend, with personal data scrubbed before any error report is sent.
- A transactional-email relay — sends license-key delivery emails and account notifications.
Our vector database (Qdrant), application database, and cache are self-hosted infrastructure operated by us, not a third-party managed service.
How long we keep your data
Your store’s indexed catalog data is retained for as long as your license is active, plus a 30-day grace period after cancellation or expiry. Backup snapshots of the vector database are retained for 7 days on a rolling basis. Chat logs are retention-bounded and personal information is redacted from them before storage.
What happens when you cancel
When your subscription is cancelled, a purge of your store’s indexed catalog data, chat logs, and related cached data is scheduled at the end of your grace period. This erasure is logged in an append-only record and is automatically re-applied even if we ever restore a system from backup, so cancelled data does not silently reappear.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or request erasure of your personal data. Merchants can request erasure of their store’s data at any time by cancelling their subscription (see above) or by contacting us directly. Shoppers with questions about a store’s use of the Service should contact that store directly, as the merchant is the data controller for their own shoppers.
Accessibility
We aim for the merchant dashboard and chat widget to meet WCAG 2.1 AA, consistent with our obligations under the European Accessibility Act.
Contact
Questions about this Privacy Policy or our Data Processing Agreement can be directed to [PLACEHOLDER: contact email]. See also our Terms and Conditions and Data Processing Agreement.