Effective date: August 29, 2026 (updated September 2, 2026)
This policy explains what data the Busymate AI for Shopify app ("the App", "we") collects, why, how long we keep it, and the rights you have. It covers two groups of people: merchants who install the App, and shoppers who interact with the assistant on a merchant's storefront. It is written to satisfy the EU/UK GDPR and the California CCPA/CPRA.
The App is the integration layer between a Shopify store and its Busymate AI white-label assistant ("bro"). It reaches the Busymate AI platform only through official APIs and holds the minimum data needed to run the integration.
Contact: mr.serebano@gmail.com.
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Shopify store domain, shop + tenant identifiers | Run the integration; map the store to its assistant | Contract |
| Shopify offline access token (encrypted at rest) | Call the store's Admin API for the assistant's tools and knowledge-base training | Contract |
| Staff name/email from the Shopify session | Account operation, support | Contract / legitimate interest |
| Billing status + plan (no card data) | Plan and usage billing via Shopify App Pricing | Contract |
| Data | Purpose | Legal basis |
|---|---|---|
| Signed-in customer identifier (from Shopify) | Scope order lookups to the shopper's own orders | Controller (merchant): contract/legitimate interest |
| Order/fulfilment details requested in a chat | Answer "where is my order", process a return/refund/cancellation you confirm | As above |
| Conversation content | Provide the assistant; improve grounding for that store | As above |
We do not sell personal information, and we do not use shopper data for cross-context behavioural advertising. We do not store shopper order history, addresses, or payment details in the App's database — order data is read live and scoped to the signed-in shopper.
busymate.ai) — the AI assistant + control plane, reached only via the Busymate AI MCP APIs.A current sub-processor list is available on request.
| Data | Kept for | Deleted when |
|---|---|---|
| Session / access token | While the App is installed | On uninstall (immediate purge) |
| Store↔tenant + billing records | While installed, then ≤ 48 hours | On Shopify shop/redact (full purge) |
| Assistant tenant data (conversations, KB) | While installed | Uninstall → suspended; shop/redact → deleted |
| A shopper's data in the tenant | Until erased | On a customers/redact request |
Full detail: see the App's data-retention notes.
GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority. Shoppers should contact the merchant (the controller); the App executes the merchant's export/erase instructions through Shopify's mandatory data-request, customer-redact, and shop-redact webhooks.
CCPA/CPRA (California): the right to know, delete, correct, and to limit use of sensitive personal information, and the right not to be discriminated against for exercising them. We do not sell or "share" personal information as those terms are defined by the CPRA.
To exercise a right, contact the merchant you interacted with, or mr.serebano@gmail.com.
Data may be processed outside your country. Where required, transfers rely on appropriate safeguards (e.g. the EU Standard Contractual Clauses).
The App is not directed to children and does not knowingly collect data from them.
We will update this policy as the App evolves and post the new effective date here.
Busymate AI — mr.serebano@gmail.com (we answer privacy requests within 30 days).
Merchants: the Terms of Service & Data Processing Addendum sets out our processor obligations to you (roles, security, sub-processors, breach notification, deletion, audit).