Privacy Policy
Last updated: September 1, 2026 · Version 1.3
1. Introduction and scope
This Privacy Policy explains how Vosaire (“we”, “us”), through our Shopify app, collects, uses, and protects data when a merchant installs Vosaire on their Shopify store.
This policy covers two groups: (A) Merchants — the Shopify store owners and staff who install and configure Vosaire; and (B) Shoppers— visitors to a merchant's storefront who interact with the Vosaire chat widget. For Shopper data, the Merchant is the data controller and Vosaire processes that data as a processor on the Merchant's behalf.
Section 6 below covers a third, separate case: your visit to this website (vosaire.com) to read about Vosaire, which is governed by us directly as controller — not by a merchant.
This Shopify app is a distinct product from any other Vosaire platform or product — installing it does not create or affect any account on another Vosaire product.
2. Who we are
Vosaire builds and operates this Shopify app. For privacy matters, contact privacy@vosaire.com.
3. Information we collect
When a merchant installs Vosaire, we collect and process the following, solely to deliver the app's features:
- Store information: shop name, shop owner email, store URL, and shop ID
- Products, collections, pages, blog posts, and store policies — used to train Vosaire's AI knowledge base
- Live inventory and stock levels, for real-time availability answers (on qualifying plans)
- Order data — order number, line items, and fulfillment status — for order-status lookup
- Customer email addresses associated with orders, for order lookup and coupon attribution
- Customer notes, tags, and email/SMS marketing consent, written back to Shopify only when a merchant enables that feature (on qualifying plans)
- Discount codes and draft orders created on the merchant's behalf, only when a merchant enables the Sales agent (on qualifying plans)
- Theme structure metadata, read-only, used to guide merchants through activating the storefront widget — Vosaire never writes to a theme
- Conversation transcripts between Vosaire and shoppers
- Revenue attribution linking conversations to completed orders
All data above may be transmitted to OpenAI to generate AI responses — see Section 5.
4. Gmail integration (optional)
A merchant may optionally connect a Gmail inbox from Vosaire's Channels settings so Vosaire can read incoming customer emails and draft or send AI-generated replies. This is off by default — Vosaire never accesses Gmail unless a merchant explicitly connects an account.
What we access. Once connected, we access:
- The subject, sender, and body of messages in the connected inbox, to detect customer support emails
- The ability to mark a processed message as read
- The ability to create a draft reply, or send a reply on the merchant's behalf, within the same email thread the customer started
- The connected account's name and email address, to identify the connection
We never access Sent mail, Trash, contacts, calendar, or any other Google product beyond the connected Gmail inbox, and we never send a new email outside a thread the customer started.
How we use it. Email content is used solely to generate an AI reply to that specific message, exactly as described in Section 5 (AI and LLM processing). Sending is automatic only when a merchant has explicitly enabled auto-reply for that connection; otherwise, Vosaire saves a draft in Gmail for the merchant to review and send themselves.
Limited Use disclosure.Vosaire's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data to serve advertisements, sell it, or transfer it to third parties except as needed to provide the reply-generation feature itself (see Section 5), and we do not use Gmail data to train or improve any generalized (non-personalized) AI or machine learning model.
Turning it off.A merchant can stop Vosaire reading a Gmail inbox at any time by disconnecting the channel from Vosaire's Channels settings, or by removing the connection entirely from Vosaire's Integrations settings — either immediately stops any further access. A merchant can also revoke Vosaire's access directly from their Google Account's third-party access settings. Emails already processed into a conversation are retained per Section 6 below; if Vosaire is fully uninstalled, all data including any Gmail-derived conversation content is deleted per Section 8's shop/redact process.
5. AI and LLM processing
Vosaire uses OpenAIas its LLM provider. When Vosaire answers a shopper — or, if a merchant has connected Gmail, a customer email received through that inbox — relevant store data, email content, and conversation context is sent to OpenAI's API over an encrypted connection.
We do not use your store data, Gmail content, or conversation content to train, fine-tune, or improve any AI model— including Vosaire's own systems or OpenAI's foundation models. OpenAI's API data usage terms prohibit training on API inputs by default.
AI-generated responses may occasionally be inaccurate or incomplete. Merchants and shoppers should verify important information independently.
7. Data retention
| Data category | Retention | Basis |
|---|---|---|
| Store & conversation data (including Gmail-derived replies) | Duration of install + 30 days after uninstall | Contract |
| Knowledge base content | Until re-synced or 30 days after uninstall | Contract |
| Gmail OAuth connection | Until the merchant disconnects the channel, removes the connection in Integrations, or revokes access via their Google Account, or the app is uninstalled | Contract |
| Cookie-consent decisions (vosaire.com) | 24 months from the decision, or until you change your choice | Legal compliance |
| Security / audit logs | 12 months | Legitimate interest |
| Support communications | 3 years | Legitimate interest |
Vosaire never handles payment card or billing data directly — subscription billing runs entirely through Shopify. See our Refund Policy.
8. Data storage and security
Data is stored primarily on servers in the European Union (Hetzner, Germany), with file storage in the United States (Cloudflare R2). We use TLS 1.3 in transit, AES-256 encryption at rest, and role-based access controls. Gmail OAuth credentials are encrypted at rest using the same controls.
In the event of a data breach affecting personal data, we will notify affected merchants and, where required, supervisory authorities within 72 hours of becoming aware.
9. Sub-processors
We use the following sub-processors, each bound by a data processing agreement:
| Sub-processor | Purpose | Country |
|---|---|---|
| OpenAI | AI response generation, including replies to Gmail messages | US |
| Amazon Web Services (SES) | Transactional email delivery | US |
| Cloudflare R2 | File and knowledge-base storage | US |
| Hetzner | Server infrastructure | Germany |
| Google (Analytics) | vosaire.com website traffic analytics — only after you accept in the cookie banner | US |
10. GDPR compliance webhooks
Vosaire implements all three Shopify-required GDPR compliance webhooks:
- customers/data_request — acknowledged within 30 days; we notify the merchant of all data held for that customer.
- customers/redact — customer PII is anonymized and related coupon records removed within 30 days of the request.
- shop/redact — all data tied to the merchant's store (conversations, knowledge sources, revenue records, Gmail-derived data, organization record) is permanently deleted within 30 days of uninstallation.
11. Shopify and Google API scopes
Vosaire requests only the scopes needed to deliver its features.
11.1 Shopify scopes
read_products— catalog sync for AI training and product cardsread_orders/write_orders— order lookup and adding notes/tagsread_all_orders— order lookup beyond Shopify's 60-day default windowread_customers/write_customers— resolving a shopper's identity; saving notes, tags, or consent when enabledread_content— pages and blog posts for AI trainingread_legal_policies— store policies for AI trainingread_themes— read-only, to guide widget activationread_inventory— live stock levels (qualifying plans)read_discounts/write_discounts— Sales agent discount codes (qualifying plans)read_draft_orders/write_draft_orders— Sales agent checkout links (qualifying plans)
11.2 Google scopes (Gmail integration, optional)
gmail.readonly— detect and read new customer emails in the connected inboxgmail.send— send an AI-generated reply, only when auto-reply is enabled, always within the original threadgmail.modify— mark a processed email as read, and create draft repliesuserinfo.email— identify which Google account is connected
12. Your rights
12.1 GDPR (EEA, UK, Switzerland)
You may access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time. Deletion requests are fulfilled within 30 days except where retention is legally required. Contact privacy@vosaire.com.
12.2 CCPA / CPRA (California)
California residents may know, access, correct, and delete their personal information, and opt out of sale or sharing. We do not sell or share personal information. Email privacy@vosaire.com with subject “CCPA Request”.
12.3 India DPDP Act, 2023
Where the Digital Personal Data Protection Act applies, we process personal data only on the basis of your consent (for vosaire.com cookies, see Section 6) or another lawful basis such as performance of a contract. You may withdraw consent, and may access, correct, or request erasure of your personal data, at any time. To raise a grievance or exercise these rights, contact our Grievance Officer at privacy@vosaire.com; we aim to resolve grievances within 30 days.
13. Children's privacy
Vosaire is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@vosaire.com and we will delete it promptly.
14. Business transfers
In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity. We will give reasonable notice before your data becomes subject to a different privacy policy.
15. Changes to this policy
For material changes, we will notify merchants by email at least 14 days before they take effect. The “Last updated” date above reflects the most recent revision.
16. Contact us
Questions, data requests, or complaints: privacy@vosaire.com. We aim to respond within 5 business days.