Your store's data, handled carefully
You're connecting Vosaire to real orders, customers, and — if you choose — a Gmail inbox. Here's exactly how that data is protected, in plain language, with the full legal detail linked below.
Encrypted everywhere
TLS 1.3 in transit, AES-256 at rest. Gmail OAuth credentials are encrypted at rest using the same controls.
Known data residency
Primary data on servers in the EU (Hetzner, Germany). File storage in the US (Cloudflare R2). No undisclosed regions.
Role-based access
Internal access to merchant data is scoped by role — nobody on our team has blanket access by default.
72-hour breach notice
If a data breach affects your personal data, we notify you and, where required, supervisory authorities within 72 hours of becoming aware.
GDPR webhooks, actually implemented
All three Shopify-required compliance webhooks are live — data requests, customer redaction, and full shop redaction on uninstall.
No training on your data
Your store data, Gmail content, and conversations are never used to train Vosaire's systems or OpenAI's foundation models.
Who else touches your data, and why
| Sub-processor | Purpose | Country |
|---|---|---|
| OpenAI | AI response generation, including replies to Gmail messages | US |
| Amazon Web Services (SES) | Transactional email delivery | US |
| Cloudflare R2 | File and knowledge-base storage | US |
| Hetzner | Server infrastructure | Germany |
| Google (Analytics) | vosaire.com website traffic analytics — only after you accept in the cookie banner | US |
Every sub-processor above is bound by a data processing agreement. Full detail in our Privacy Policy.
How long we keep it
| Data category | Retention | Basis |
|---|---|---|
| Store & conversation data (including Gmail-derived replies) | Duration of install + 30 days after uninstall | Contract |
| Knowledge base content | Until re-synced or 30 days after uninstall | Contract |
| Gmail OAuth connection | Until the merchant disconnects the channel, removes the connection in Integrations, or revokes access via their Google Account, or the app is uninstalled | Contract |
| Cookie-consent decisions (vosaire.com) | 24 months from the decision, or until you change your choice | Legal compliance |
| Security / audit logs | 12 months | Legitimate interest |
| Support communications | 3 years | Legitimate interest |
Security & data FAQ
Does Vosaire sell or share my store's data?+
No, never. We do not sell or share personal information — see our Privacy Policy's California/CCPA section for the specific legal commitment.
What happens to my data if I connect Gmail?+
Vosaire only reads the connected inbox to detect and draft replies to customer emails — never Sent mail, Trash, contacts, or calendar. It adheres to Google's API Services User Data Policy, including the Limited Use requirements: no ads, no selling, no training a generalized AI model on that data.
Is my data used to train OpenAI's models?+
No. OpenAI's API data-usage terms prohibit training on API inputs by default, and we don't use your store data, Gmail content, or conversations to train or fine-tune any AI model — Vosaire's own systems included.
What happens to my data if I uninstall?+
Everything tied to your store — conversations, knowledge sources, revenue records, Gmail-derived data, your organization record — is permanently deleted within 30 days, via our shop/redact GDPR webhook.
Where can I see the full legal detail?+
This page is a plain-language summary. The binding terms — including sub-processor DPAs, retention periods, and your rights under GDPR, CCPA, and India's DPDP Act — are in our Privacy Policy.
Found a security issue?
Email privacy@vosaire.comwith details — we read every report and aim to respond within 5 business days. Please don't test against merchant stores you don't own or have permission to test.