Privacy Policy
Zappy · Last updated: 2026
Zappy ("we", "the app") is a Shopify app that adds an AI support assistant to a merchant's storefront. This policy explains what data the app accesses, why, and how it is handled. By installing Zappy, the merchant agrees to this policy.
Information we access
With the merchant's permission (granted at install), Zappy accesses:
- Store & order data — order status, fulfillment, and tracking details, used only to answer a customer's own order-status request (matched by order number and email).
- Product data — product titles, prices, and images, used to generate product recommendations in the chat.
- Customer questions — the messages customers type into the chat widget are processed to generate a reply and are logged so the merchant can view what customers ask (used for the analytics dashboard).
- Access token — an offline access token provided by Shopify, so the app can look up orders and products. It is stored encrypted at rest (AES-256-GCM) and is never shared.
Zappy does not collect payment/card details, and does not sell or rent any data to third parties.
AI processing
To generate answers and recommendations, customer questions and relevant store data (such as your saved FAQ answers or product titles) are sent to third-party AI providers (Google Gemini and/or Groq) via their APIs. These providers process the request to return a response. We send only what is needed to answer the question and do not send access tokens or payment data.
How we use the data
- To answer customer questions and provide order status.
- To recommend products from the store's own catalog.
- To show the merchant analytics (questions handled, deflection rate, unanswered questions).
Data retention & deletion
Chat logs are retained to power the merchant's analytics. When a merchant uninstalls the app, or when Shopify sends a data-deletion request on behalf of a shop or customer, the associated data is deleted. Zappy implements Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) to honor these requests.
Data storage
Data is stored using Neon (PostgreSQL) and the app is hosted on Vercel. Access tokens are encrypted before storage.
Your rights
Merchants and their customers may request access to, or deletion of, their data. Deletion requests are handled automatically via Shopify's privacy webhooks, or can be made directly using the contact below.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected on this page with an updated date.
Contact
For any privacy questions or data requests, contact us at [your-email@example.com].
This document is a general template describing Zappy's data practices and is not legal advice. Please review it against your own circumstances before publishing.