Chat Squeeze
Chat SqueezeShopify AI Chat Agent

Privacy Policy

Last updated: March 20, 2026

Chat Squeeze ("the App") provides an AI-powered shopping assistant chatbot ("the Service") to merchants who use Shopify to power their stores. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with your Shopify-supported store.

Personal Information the App Collects

From Your Shopify Account

When you install the App, we are automatically able to access certain types of information from your Shopify account:

  • Product data (read_products, read_product_listings, read_product_feeds): Product titles, descriptions, images, pricing, variants, tags, vendor, inventory status, and collection memberships. Used to power the AI shopping assistant.
  • Order data (read_orders): Order number, fulfillment status, tracking information, and line items. Used only when a shopper requests order tracking within the chat.
  • Fulfillment data (read_third_party_fulfillment_orders): Third-party fulfillment status. Used for order tracking responses.

Note: All Shopify API access is read-only. The App does not write to or modify your Shopify store data.

From Merchants (You)

  • Account information: Email address, name, store domain (collected during installation/sign-up)
  • Bot configuration: Chatbot name, instructions, welcome message, widget appearance settings
  • Billing information: Processed entirely by Shopify Billing; we do not store payment card details

From Your Customers (Shoppers)

  • Chat messages: The full text content of messages exchanged between shoppers and the AI assistant
  • Visitor identifier: A randomly generated UUID stored in a cookie (cs_visitor_token, 60 days) and localStorage, used to maintain chat continuity across visits
  • Lead information (only if voluntarily submitted by the shopper via the lead capture form): Name, email, phone number
  • Order lookup data (only if the shopper uses order tracking): Order number and email, used to retrieve order status from Shopify and displayed in-chat only (not stored separately)
  • Attribution data: Which products a shopper clicked or added to cart from the chat widget, stored via a cookie (_cs_attribution, 7 days)
  • IP address: Used as a fallback visitor identifier only when no visitor token is available

Technologies Used

We collect personal information directly from the relevant individual, through your Shopify account, or using the following technologies:

  • Cookies: cs_visitor_token (visitor identification, 60 days) and _cs_attribution (product attribution, 7 days). These cookies respect Shopify's customer privacy consent API — they are only set when trackingAllowed() returns true. We also use localStorage for the visitor token as a fallback.
  • No tracking pixels or web beacons are injected into the shopper-facing widget.

Merchant Dashboard Analytics

On the Merchant Dashboard (app.chatsqueeze.com only):

  • Google Analytics, Facebook Pixel, and Microsoft Clarity are used to analyze merchant (not shopper) usage of the dashboard. These are not present in the customer-facing chat widget.

How Do We Use Your Personal Information?

We use the personal information we collect from you and your customers in order to provide the Service and to operate the App. Specifically:

  • Product data: Synced and indexed (including AI-generated vector embeddings) to power semantic product search within the chat assistant
  • Chat messages: Sent to OpenAI's API for AI response generation; stored in our database to maintain conversation continuity and provide chat history to merchants
  • Visitor tokens: Used to link chat sessions across visits so returning shoppers see their conversation history
  • Lead information: Stored and made available to the merchant via the dashboard; notification emails sent to the merchant via Resend
  • Order data: Retrieved from Shopify in real-time when a shopper requests order tracking; displayed in-chat and not stored separately
  • Attribution data: Used to attribute sales and add-to-cart events to chatbot-assisted interactions, displayed in merchant analytics
  • Dashboard analytics: Used to improve the merchant experience and measure marketing effectiveness

Important: We do not use shopper data for behavioral advertising, remarketing, or any purpose unrelated to providing the Service.

Sharing Your Personal Information

We share personal information with the following third-party services to operate the App:

  • OpenAI (api.openai.com): Chat messages and conversation context are sent to OpenAI for AI response generation and text embedding. OpenAI processes this data according to their API data usage policy and does not use API inputs to train their models.
  • Supabase: Our database and authentication provider. All persistent data (accounts, chat sessions, messages, products, leads) is stored on Supabase infrastructure.
  • Resend: Used to send lead notification emails and usage alert emails to merchants. Receives merchant email addresses and lead contact information.
  • Shopify: We access your store data through the Shopify API using the OAuth access token you grant during installation. Subscription billing is handled entirely through Shopify Billing.

Merchant Dashboard Analytics

On the merchant dashboard only (not the shopper widget):

  • Google Analytics, Facebook/Meta Pixel, Microsoft Clarity: Receive anonymized page view and conversion data from merchant dashboard usage.

We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful request for information we receive, or to otherwise protect our rights.

Data Retention

  • Chat sessions and messages: Automatically deleted after 60 days of inactivity
  • Visitor tokens: Expire after 60 days
  • Attribution cookies: Expire after 7 days
  • Lead data: Retained until the merchant deletes it or requests account deletion
  • Product data: Updated on each sync cycle; deleted when the merchant uninstalls the App
  • Merchant account data: Retained while the account is active; deleted upon uninstallation or request

GDPR and Your Rights

If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us at the address below.

GDPR Compliance

We implement all three mandatory Shopify GDPR webhooks:

  • Customer data request: We can export all data associated with a specific customer email
  • Customer data erasure: We delete all leads and chat sessions associated with the customer
  • Shop data erasure: Upon app uninstallation, we delete all tenant data including bots, chat sessions, messages, leads, products, and connections

Note: Your information may be transferred outside of Europe, including to the United States, where our infrastructure providers (OpenAI, Supabase) operate.

Changes to This Policy

We may update this privacy policy from time to time in order to reflect changes to our practices or for other operational, legal, or regulatory reasons. We encourage you to review this page periodically.

Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email at:

support@chatsqueeze.com

Chat Squeeze
https://www.chatsqueeze.com

TRY FREE