Privacy

Privacy policy for Shopify merchants

How the Clind.ai app for Shopify handles your store’s data and your customers’ data.

Last updated: October 8, 2026

1. Who we are and when this applies

This policy applies when a Shopify merchant installs the Clind.ai app. Clind is operated by VORTERA TECNOLOGIA LTDA (CNPJ 58.768.606/0001-51), Brazil.

The merchant is the controller of their customers’ data. Clind processes that data on the merchant’s behalf, only to provide the service. For anything not covered here, our general privacy policy (in Portuguese) applies.

2. What we read through Shopify’s APIs

With the permissions requested at install:

  • Store details: name, domain, contact e-mail, country, currency and language.
  • Products and collections, so the assistant can answer product questions.
  • Orders and fulfillments: order number, status, items, tracking, and the customer’s name, e-mail, phone and shipping address on the order, so the assistant and the merchant’s team can answer order questions.
  • Customer records, to recognize the shopper in a conversation.

Only with a separate permission the merchant grants: orders older than 60 days, files attached to products, theme settings (to place the chat widget and forms), and editing of products, orders and draft orders when the merchant’s team asks the Clind Copilot to do it.

Orders and customer records are read on demand to answer a question. The app does not keep a copy of the store’s full order or customer lists.

3. What we store

From the merchant

  • Names and e-mails of the account owner and team members.
  • The assistant’s settings and the knowledge documents the merchant uploads.
  • Billing status and a usage ledger (account, conversation numbers, amounts). Payment itself is handled by Shopify.

From the merchant’s customers (shoppers)

  • The messages and attachments they send through the store chat and, when the merchant connects them, e-mail, WhatsApp or Instagram.
  • The contact details they give in those conversations or in the store’s contact forms, and those that come with their order.
  • Carts and paid orders linked to a conversation, so the merchant’s team sees the context.

4. How we use it

Only to answer the merchant’s customers on the merchant’s behalf, hand conversations to the merchant’s team, show order and cart context to that team, report results to the merchant, and bill the merchant through Shopify.

Clind does not sell shopper data, share it for advertising, or use it to profile shoppers across stores.

5. AI and model training

Shopper data is never used to train AI models, neither by Clind nor by our AI provider.

Messages are sent to OpenAI only to generate the assistant’s answer. OpenAI processes this data under its API terms, which do not use API data to train its models.

The knowledge documents a merchant uploads configure that merchant’s own assistant. They are not used to train any model and are not shared with other merchants.

6. Service providers (subprocessors)

ProviderPurpose
ShopifyThe platform the app runs on; store data source and merchant billing.
OpenAIGenerates the assistant’s answers from the conversation.
RailwayCloud hosting of the Clind applications and their data.
LangfuseTraces of the assistant’s answers, used for quality and debugging.
SentryError reports.
E-mail delivery providerSends notifications and data-export links to the merchant.
Meta (WhatsApp, Instagram)Only when the merchant connects these channels.

7. How long we keep it

DataKeptDeleted when
Shoppers’ conversations, messages, attachments and contactsWhile the merchant’s account is activeThe merchant deletes them; a Shopify customer erasure request; or store removal, 48 hours after uninstall (see section 8)
Carts and paid orders linked to conversationsWhile the merchant’s account is activeSame as above, and on removal of that store
AI conversation memory3 days after the last messageExpiry, or a customer erasure request
Messages waiting in the AI processing queueFailed jobs up to 24 hoursQueue expiry
AI quality records (handoff decisions, short excerpts of blocked messages, statistics)While the merchant’s account is activeA customer erasure request, or account erasure
AI traces (Langfuse)A limited period, for quality and debuggingRetention expiry, a customer erasure request, or account erasure
Assistants, knowledge documents and promptsWhile the merchant’s account is activeAccount erasure
Store install data (session, settings, account link)While installed; the link until 48 hours after uninstallStore removal (Shopify’s shop/redact)
Billing ledger (account, conversation numbers, amounts; no shopper data)5 yearsTax and accounting obligations end
App usage events24 months; the store domain is replaced by a hash at store removalAfter 24 months
Privacy request log (no shopper data once completed)Kept as proof of compliance—
Error reports (Sentry)Per the provider’s retentionRetention expiry

8. Shopify privacy requests

Shopify sends us the requests a shopper or merchant makes. We start each one when it arrives (usually done within minutes), retry hourly if a step fails, and complete it within 30 days.

  • Customer data request (customers/data_request): we find the shopper in the merchant’s account by e-mail, phone or Shopify customer id and prepare an export of their contact details, conversations, messages, attachment names, and the carts and paid orders of that store. The merchant’s administrators receive a download link by e-mail, valid for 7 days, to send to the shopper. The export file is deleted after 30 days.
  • Customer erasure (customers/redact): we delete the shopper’s contact in the merchant’s account with their conversations, messages and attachments, the carts and paid orders of that store, and the AI memory, records and traces of those conversations. Sales the shopper made stay in the merchant’s reports as “Deleted customer”, with no personal data.
  • Store removal (shop/redact, sent by Shopify 48 hours after uninstall): if the account was used only for that Shopify store, the whole account is deleted, with its assistants and knowledge. Otherwise the store’s shopper contacts are anonymized and their messages removed, the store’s carts, orders and chat widget are deleted, and the account’s other channels are kept. The store’s install data is then removed. If the store reinstalled the app before the request arrives, nothing is deleted.

Every request is limited to the merchant account that owns the store. A request never touches another merchant’s data.

9. International transfers

Clind is based in Brazil. Our providers process data on servers outside Brazil, including in the United States. These transfers are made to provide the service, with providers bound by contractual data protection commitments, as allowed by the LGPD and, for merchants in the European Economic Area, the GDPR.

10. Security

Data is encrypted in transit. Access is limited by account, every privacy operation is scoped to the account that owns the store, and access to production systems is restricted to authorized staff.

11. Contact and requests

Shoppers should first contact the store they bought from, which controls their data. Merchants and shoppers can also write to diego@clind.ai, our data protection contact.

We may update this policy. The date at the top shows the latest version.