Privacy policy
How we handle the data that flows through AskRoo, and the choices you and your shoppers have.
Template — a working draft to review with legal counsel before launch. Last updated July 2026.
This policy explains how AskRoo (AskRoo Pty Ltd) handles personal information. It covers two groups: Shopify merchants who install AskRoo, and the shoppers who talk to it on a merchant's store. For a merchant's store, the merchant is the data controller and AskRoois a processor acting on the merchant's instructions.
Who this covers
It applies whenever a merchant connects a Shopify store to AskRoo, and whenever a shopper interacts with the AskRoo widget on that store. Shoppers do not have a direct account with us. Their questions are answered on behalf of the merchant whose store they are visiting.
What we collect
We collect only what is needed to answer support questions:
- Shopper chat messages and the conversation history for a given support thread.
- Order, fulfilment and contact context needed to answer a question, read from the merchant's Shopify store at the time it is asked.
- The merchant's account details and the configuration they set up, including guardrails, policies and connected channels.
- The minimal Shopify permissions (scopes) required to do the job, and nothing broader.
Protected customer data
AskRoorequests the minimum Shopify scopes required to answer support questions and has completed Shopify's Level 2 protected customer data access requirements. We treat customer personal information as protected data and limit who and what can reach it.
How we use data
We use the data we hold to:
- Answer support questions grounded in the merchant's live store data, and show the source behind an answer.
- Route escalations to the right person when a question needs a human.
- Monitor and improve the reliability and accuracy of the service.
We do not sell personal information. We do not use shopper or merchant data to train third-party foundation models.
Retention
Personally identifiable information (PII) is retained for 90 days by default, after which it is deleted or de-identified. A merchant may ask us to remove specific data sooner. Aggregated, de-identified operational data may be kept longer to measure reliability.
Where data is held
AskRoo is hosted in an Australian region. Some sub-processors may process limited data elsewhere to deliver their part of the service; where that happens we put appropriate safeguards in place.
Legal framework
For Australian merchants, our handling of personal information is aligned to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For merchants who serve customers in the EU or EEA, we are designed to support their obligations under the General Data Protection Regulation (GDPR), with the merchant acting as controller and AskRoo as processor.
Sub-processors
We use a small set of sub-processors to run the service. We keep these to what is necessary:
- LLM providers— used to generate answers. Where a merchant brings their own key (BYOK), that key is encrypted at rest, validated before use and never logged. The merchant's content is not used to train the provider's models.
- Cloud hosting — infrastructure that runs the application and stores data, in an Australian region.
- Transactional email — to send account and support notifications.
Sub-processors are bound by contract to protect the data they handle and to use it only to provide their service to us.
Security
We design AskRoo to protect data in practical ways: encryption in transit and at rest, access controls that limit who and what can reach customer data, and logging of the actions the agent takes. Security is a commitment we build into the product, not a claim of perfect protection.
Cookies
We keep cookies to a minimum. The AskRoo widget uses only what is needed to run a support conversation, such as keeping a session going. We do not use it for advertising.
Your rights and choices
You can ask to access, correct or delete personal information, and you can make a complaint about how we handle it. Merchants can raise a request at connect@askroo.io. If you are a shopper, please contact the merchant whose store you were on first, as they are the data controller for their store. We will support the merchant in responding to your request.
Changes to this policy
We may update this policy as the product develops or the law changes. When we make a material change, we will update the date at the top of this page and, where appropriate, let merchants know.
Contact us
For any privacy question or request, contact us at connect@askroo.io. Our postal contact is 8 Hadenfeld Ave, Macquarie University, New South Wales 2109, Australia.