Privacy policy
The German version is authoritative. This English text is provided for convenience.
ShopGeist ("the App", "we", "us") is operated by DCMB GmbH, Baarermattstrasse 8b, 6340 Baar, Switzerland (CHE-290.198.733), which is the controller responsible for the data described below. The App provides an AI-powered chat assistant that merchants embed in their Shopify storefronts. This policy explains what data the App processes, why, and how it is protected. It applies to the merchants who install ShopGeist and to the shoppers who interact with the chat widget.
1. Data we collect
From the merchant's store. When the App is installed we access store data via the Shopify Admin API under the scopes you grant: product listings, store content and pages, published legal policies, and theme data. We use this only to build the knowledge base the assistant answers from.
From shoppers using the chat widget. We store the chat messages exchanged between a shopper and the assistant, along with a randomly generated session identifier, the detected language, and timestamps. The chat is anonymous: we do not collect a shopper's name, email, address, payment details, or Shopify customer identifier, and we do not link conversations to a specific customer account. We ask shoppers not to enter personal or sensitive information into the chat.
From email support, if the merchant enables it. If a merchant forwards their support inbox to us, we process the incoming messages: sender address and name, subject, body, attachments and headers, together with the reply drafts we generate. Unlike chat, this data is not anonymous, it contains whatever the shopper wrote, including order numbers and contact details. The merchant remains responsible for that inbox; we process it on their behalf.
Merchant account data. Standard Shopify session data (shop domain, access token, granted scopes) needed to operate the App.
2. How we use data
- To generate relevant answers in the chat widget.
- To build and refresh the store's knowledge base from public store content.
- To show merchants their conversation history and usage in the App dashboard.
- To classify incoming support email and suggest a reply draft to the merchant. Nothing is sent until the merchant approves it.
- To operate, secure, and improve the service.
3. Sub-processors and data location
To deliver the service we share the minimum necessary data with the following providers:
- Amazon Web Services (AWS), runs substantially the whole service: application hosting and delivery, the database, file and vector storage, sending and receiving email, and, through Amazon Bedrock, the language and embedding models that generate chat answers and email drafts. Message content is sent to Bedrock at request time. AWS is contractually bound not to use that content to train models and not to share it with third-party model providers.
- Shopify, the platform the App runs on.
We do not sell personal data and do not use chat or email content for advertising.
Where data is stored: Frankfurt. Everything the service keeps (chat history, merchant configuration, the knowledge base and its vector index, support email and attachments) is stored only in the AWS Frankfurt region (eu-central-1). Moving that location would be a change to this policy.
Where the AI runs: Europe. Model calls go through Amazon Bedrock's European inference profiles, which distribute an individual request across European data centres for capacity, the EEA plus London and Zurich, both covered by European Commission adequacy decisions. Only the content of that request is processed, and nothing is stored there. This is why we say "data in Frankfurt, AI processing in Europe" rather than claiming that a request never leaves Frankfurt.
4. Data retention
Chat sessions, messages and support email are retained while the App is installed so merchants can review their history, but no longer than 365 days from the last activity, after which they are deleted automatically from both the database and file storage. The forwarded original email is deleted after 30 days. When a store uninstalls the App, Shopify sends us a redaction request and we delete all data associated with that store (chat messages, chat sessions, indexed pages, the vector index, support email and attachments, and configuration) within 48 hours, in line with Shopify's mandatory data-protection webhooks.
5. Your rights (GDPR / CCPA)
Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Because shopper chat is anonymous, we are usually unable to associate a conversation with an individual. Support email is different: it is identifiable by sender address, and an access or deletion request about it is best addressed to the merchant you wrote to, we carry it out on their behalf. If you believe we hold data about you, contact us using the details below and we will respond as required by law. Merchants can also exercise these rights through Shopify's customer data request and redaction flows, which we support.
6. Security
Data is transmitted over encrypted connections (HTTPS) and held in an access-controlled database and in encrypted object storage. Access to merchant and shopper data is limited to what is required to operate the service.
7. Children
The App is not directed to children and we do not knowingly collect data from children under the age required by local law.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
For privacy questions or data requests, contact us at louis@shopgeist.ch, or by post at:
DCMB GmbH
Baarermattstrasse 8b
6340 Baar
Switzerland