Privacy Policy

Last updated: December 19, 2024

1. Introduction

MerchantsAI ("we", "our", "us") operates the Sigma AI application for Shopify stores. This Privacy Policy explains how we collect, use, and protect your data when you use our service.

By installing Sigma AI, you agree to the collection and use of information in accordance with this policy.

2. Data We Collect

2.1 Merchant Data

When you install Sigma AI, we collect:

  • Shop information: Your Shopify store domain and basic store details
  • Access tokens: Encrypted OAuth tokens to access your Shopify data (products, orders, customers)
  • Configuration: Agent personality settings, prompt customizations, and campaign information
  • Usage metrics: Session counts and feature usage for billing and analytics

2.2 Customer Data (Store Visitors)

When customers interact with the Sigma AI chat widget, we collect:

  • Chat conversations: Messages exchanged with the AI agent
  • Session information: Anonymous session identifiers, timestamps
  • Device information: Browser type, device category (mobile/desktop)
  • Shopping behavior: Products viewed, cart actions during the chat session
  • Satisfaction scores: Optional feedback provided by customers

2.3 Analytics Data

We collect aggregated analytics including:

  • Total sessions and message counts
  • Conversion rates and revenue attribution
  • Response time metrics
  • Customer satisfaction averages

3. How We Use Your Data

We use collected data to:

  • Provide the service: Power AI chat functionality and product recommendations
  • Generate embeddings: Create semantic search vectors for your product catalog
  • Deliver analytics: Provide insights and reports in your merchant dashboard
  • Improve the service: Analyze usage patterns to enhance features
  • Billing: Track usage for subscription billing purposes

4. Third-Party Services

We use the following third-party services to provide Sigma AI functionality:

Service Purpose Data Region
OpenAI Text embeddings for semantic product search United States
Anthropic (Claude) / Google (Gemini) AI chat response generation United States
Supabase Primary database hosting EU (Frankfurt)
Qdrant Vector database for semantic search EU

These providers process data according to their respective privacy policies and data processing agreements.

5. Data Retention

  • Chat sessions: Retained for 90 days, then automatically anonymized
  • Analytics data: Retained in anonymized/aggregated form
  • Product embeddings: Updated on each sync, deleted when products are removed

6. Data Deletion

Immediate deletion: When you uninstall Sigma AI, ALL your data is deleted immediately - not after 48 hours.

Upon app uninstallation, we immediately delete:

  • All shop configuration and settings
  • All chat sessions and conversation history
  • All customer data associated with your store
  • All product embeddings and search vectors
  • All prompt configurations and customizations

Shopify also sends a backup deletion request 48 hours after uninstall (shop/redact webhook), which we handle as a safety net, though data is typically already deleted.

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Object: Object to processing of your data
  • Restrict: Request restriction of processing

For merchants: You can exercise these rights by uninstalling the app (for deletion) or contacting us at the email below.

For store customers: Please contact the store owner directly, or contact us and we will coordinate with the merchant on your behalf.

8. Data Security

We implement appropriate security measures including:

  • Encryption of access tokens using secure vault storage
  • Multi-tenant data isolation (each shop's data is separated)
  • HTTPS encryption for all data transfers
  • Regular security audits and updates

9. Children's Privacy

Sigma AI is not intended for use by children under 16. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

For privacy inquiries, data requests, or questions about this policy:

MerchantsAI
Email: hello@umerkhan.eu