Skip to main content

Privacy Policy

Last updated: September 1, 2026 · Version 1.3

1. Introduction and scope

This Privacy Policy explains how Vosaire (“we”, “us”), through our Shopify app, collects, uses, and protects data when a merchant installs Vosaire on their Shopify store.

This policy covers two groups: (A) Merchants — the Shopify store owners and staff who install and configure Vosaire; and (B) Shoppers— visitors to a merchant's storefront who interact with the Vosaire chat widget. For Shopper data, the Merchant is the data controller and Vosaire processes that data as a processor on the Merchant's behalf.

Section 6 below covers a third, separate case: your visit to this website (vosaire.com) to read about Vosaire, which is governed by us directly as controller — not by a merchant.

This Shopify app is a distinct product from any other Vosaire platform or product — installing it does not create or affect any account on another Vosaire product.

2. Who we are

Vosaire builds and operates this Shopify app. For privacy matters, contact privacy@vosaire.com.

3. Information we collect

When a merchant installs Vosaire, we collect and process the following, solely to deliver the app's features:

  • Store information: shop name, shop owner email, store URL, and shop ID
  • Products, collections, pages, blog posts, and store policies — used to train Vosaire's AI knowledge base
  • Live inventory and stock levels, for real-time availability answers (on qualifying plans)
  • Order data — order number, line items, and fulfillment status — for order-status lookup
  • Customer email addresses associated with orders, for order lookup and coupon attribution
  • Customer notes, tags, and email/SMS marketing consent, written back to Shopify only when a merchant enables that feature (on qualifying plans)
  • Discount codes and draft orders created on the merchant's behalf, only when a merchant enables the Sales agent (on qualifying plans)
  • Theme structure metadata, read-only, used to guide merchants through activating the storefront widget — Vosaire never writes to a theme
  • Conversation transcripts between Vosaire and shoppers
  • Revenue attribution linking conversations to completed orders

All data above may be transmitted to OpenAI to generate AI responses — see Section 5.

4. Gmail integration (optional)

A merchant may optionally connect a Gmail inbox from Vosaire's Channels settings so Vosaire can read incoming customer emails and draft or send AI-generated replies. This is off by default — Vosaire never accesses Gmail unless a merchant explicitly connects an account.

What we access. Once connected, we access:

  • The subject, sender, and body of messages in the connected inbox, to detect customer support emails
  • The ability to mark a processed message as read
  • The ability to create a draft reply, or send a reply on the merchant's behalf, within the same email thread the customer started
  • The connected account's name and email address, to identify the connection

We never access Sent mail, Trash, contacts, calendar, or any other Google product beyond the connected Gmail inbox, and we never send a new email outside a thread the customer started.

How we use it. Email content is used solely to generate an AI reply to that specific message, exactly as described in Section 5 (AI and LLM processing). Sending is automatic only when a merchant has explicitly enabled auto-reply for that connection; otherwise, Vosaire saves a draft in Gmail for the merchant to review and send themselves.

Limited Use disclosure.Vosaire's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data to serve advertisements, sell it, or transfer it to third parties except as needed to provide the reply-generation feature itself (see Section 5), and we do not use Gmail data to train or improve any generalized (non-personalized) AI or machine learning model.

Turning it off.A merchant can stop Vosaire reading a Gmail inbox at any time by disconnecting the channel from Vosaire's Channels settings, or by removing the connection entirely from Vosaire's Integrations settings — either immediately stops any further access. A merchant can also revoke Vosaire's access directly from their Google Account's third-party access settings. Emails already processed into a conversation are retained per Section 6 below; if Vosaire is fully uninstalled, all data including any Gmail-derived conversation content is deleted per Section 8's shop/redact process.

5. AI and LLM processing

Vosaire uses OpenAIas its LLM provider. When Vosaire answers a shopper — or, if a merchant has connected Gmail, a customer email received through that inbox — relevant store data, email content, and conversation context is sent to OpenAI's API over an encrypted connection.

We do not use your store data, Gmail content, or conversation content to train, fine-tune, or improve any AI model— including Vosaire's own systems or OpenAI's foundation models. OpenAI's API data usage terms prohibit training on API inputs by default.

AI-generated responses may occasionally be inaccurate or incomplete. Merchants and shoppers should verify important information independently.

6. Cookies and tracking technologies (vosaire.com)

This section is about this website— vosaire.com, which you are reading right now to learn about Vosaire — not about a merchant's Shopify storefront. It sits alongside, not instead of, the rest of this policy.

We use browser storage here in two categories only:

  • Essential (always on, no consent required).The Vosaire chat widget embedded on this site uses your browser's local/session storage to remember your chat session across page views. Nothing here is used for advertising or analytics, and it cannot be disabled without disabling the widget itself.
  • Analytics (only if you accept).If you click “Accept” in the cookie banner shown on your first visit, we load Google Analytics 4 to understand aggregate site traffic — pages viewed, referring site, approximate location, device type — and, if you arrived here from one of our Google Ads campaigns, to measure whether that visit later led to installing the app, so we know which campaigns are worth running. This uses the same Google Analytics client identifier already covered by this category, stored a little longer so an install that happens after you leave this site (over on Shopify's own install flow) can still be matched back to the visit that led to it. The Google Analytics script is not present on the page and no data reaches Google until you accept. If you click “Decline”, or simply close the banner without choosing, none of this loads.

We do not run any retargeting or session-recording tracker on this site — no Meta/Facebook Pixel, no Microsoft Clarity, Hotjar, or similar tools. We do run Google Ads campaigns, and the Analytics category above (only active once you accept) is used solely to measure which campaigns lead to installs — never to build an advertising profile of you, retarget you elsewhere, or share your data with any other advertiser.

You can change your choice at any time using the “Cookie Preferences” link in the footer of every page. As proof of consent, we keep a record of each decision — a randomly generated visitor identifier, your IP address, browser user agent, a timestamp, and the policy version shown to you — in a compliance log. This record is used only to demonstrate that consent was properly requested and honored; it is not linked to any Vosaire account and is not shared with Google or any other third party.

7. Data retention

Data categoryRetentionBasis
Store & conversation data (including Gmail-derived replies)Duration of install + 30 days after uninstallContract
Knowledge base contentUntil re-synced or 30 days after uninstallContract
Gmail OAuth connectionUntil the merchant disconnects the channel, removes the connection in Integrations, or revokes access via their Google Account, or the app is uninstalledContract
Cookie-consent decisions (vosaire.com)24 months from the decision, or until you change your choiceLegal compliance
Security / audit logs12 monthsLegitimate interest
Support communications3 yearsLegitimate interest

Vosaire never handles payment card or billing data directly — subscription billing runs entirely through Shopify. See our Refund Policy.

8. Data storage and security

Data is stored primarily on servers in the European Union (Hetzner, Germany), with file storage in the United States (Cloudflare R2). We use TLS 1.3 in transit, AES-256 encryption at rest, and role-based access controls. Gmail OAuth credentials are encrypted at rest using the same controls.

In the event of a data breach affecting personal data, we will notify affected merchants and, where required, supervisory authorities within 72 hours of becoming aware.

9. Sub-processors

We use the following sub-processors, each bound by a data processing agreement:

Sub-processorPurposeCountry
OpenAIAI response generation, including replies to Gmail messagesUS
Amazon Web Services (SES)Transactional email deliveryUS
Cloudflare R2File and knowledge-base storageUS
HetznerServer infrastructureGermany
Google (Analytics)vosaire.com website traffic analytics — only after you accept in the cookie bannerUS

10. GDPR compliance webhooks

Vosaire implements all three Shopify-required GDPR compliance webhooks:

  • customers/data_request — acknowledged within 30 days; we notify the merchant of all data held for that customer.
  • customers/redact — customer PII is anonymized and related coupon records removed within 30 days of the request.
  • shop/redact — all data tied to the merchant's store (conversations, knowledge sources, revenue records, Gmail-derived data, organization record) is permanently deleted within 30 days of uninstallation.

11. Shopify and Google API scopes

Vosaire requests only the scopes needed to deliver its features.

11.1 Shopify scopes

  • read_products — catalog sync for AI training and product cards
  • read_orders / write_orders — order lookup and adding notes/tags
  • read_all_orders — order lookup beyond Shopify's 60-day default window
  • read_customers / write_customers — resolving a shopper's identity; saving notes, tags, or consent when enabled
  • read_content — pages and blog posts for AI training
  • read_legal_policies — store policies for AI training
  • read_themes — read-only, to guide widget activation
  • read_inventory — live stock levels (qualifying plans)
  • read_discounts / write_discounts — Sales agent discount codes (qualifying plans)
  • read_draft_orders / write_draft_orders — Sales agent checkout links (qualifying plans)

11.2 Google scopes (Gmail integration, optional)

  • gmail.readonly — detect and read new customer emails in the connected inbox
  • gmail.send — send an AI-generated reply, only when auto-reply is enabled, always within the original thread
  • gmail.modify — mark a processed email as read, and create draft replies
  • userinfo.email — identify which Google account is connected

12. Your rights

12.1 GDPR (EEA, UK, Switzerland)

You may access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time. Deletion requests are fulfilled within 30 days except where retention is legally required. Contact privacy@vosaire.com.

12.2 CCPA / CPRA (California)

California residents may know, access, correct, and delete their personal information, and opt out of sale or sharing. We do not sell or share personal information. Email privacy@vosaire.com with subject “CCPA Request”.

12.3 India DPDP Act, 2023

Where the Digital Personal Data Protection Act applies, we process personal data only on the basis of your consent (for vosaire.com cookies, see Section 6) or another lawful basis such as performance of a contract. You may withdraw consent, and may access, correct, or request erasure of your personal data, at any time. To raise a grievance or exercise these rights, contact our Grievance Officer at privacy@vosaire.com; we aim to resolve grievances within 30 days.

13. Children's privacy

Vosaire is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@vosaire.com and we will delete it promptly.

14. Business transfers

In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity. We will give reasonable notice before your data becomes subject to a different privacy policy.

15. Changes to this policy

For material changes, we will notify merchants by email at least 14 days before they take effect. The “Last updated” date above reflects the most recent revision.

16. Contact us

Questions, data requests, or complaints: privacy@vosaire.com. We aim to respond within 5 business days.