Privacy Policy
How AskRoo collects, uses, shares and protects personal information — across the askroo.io website, the AskRoo merchant dashboard, and the AskRoo AI agent running on a merchant’s Shopify store.
Plain-language first
Every section opens with what actually happens to data, before the detail. No hidden clauses.
Merchant data stays the merchant’s
For shopper conversations on a store, the merchant is the controller. AskRoo processes on their instructions.
Never sold
We do not sell personal information, and we do not use shopper conversations to train third-party public models.
01Who we are and what this covers
AskRoo (“AskRoo”, “we”, “us”, “our”) provides an AI commerce agent for Shopify stores that combines product discovery, shopping guidance, offer guidance and customer support in one conversation. We serve Shopify merchants globally.
This Privacy Policy explains how we handle personal information across:
- The AskRoo website — askroo.io and its subdomains, including marketing pages and enquiry forms.
- The AskRoo merchant dashboard — the account area where merchants configure, monitor and manage the agent.
- The AskRoo agent — the assistant that runs on an installed merchant’s Shopify storefront and converses with shoppers.
It does not cover the practices of the Shopify merchants who install AskRoo, of Shopify itself, or of any third-party site we link to. Those organisations have their own privacy policies, and a merchant’s policy governs the store you are shopping on.
02Our role: controller and processor
Our obligations depend on whose data we are handling and why. Under the EU/UK GDPR and equivalent laws, we act in two distinct roles.
| Context | Our role | What it means |
|---|---|---|
| Website visitors, enquiries, merchant accounts and billing | Controller | We decide why and how the data is processed, and this policy governs it directly. |
| Shopper conversations and store data on an installed store | Processor | The merchant is the controller. We process on their documented instructions under our Data Processing Agreement, and the merchant’s own privacy policy applies to shoppers. |
| Aggregated, de-identified service metrics | Controller | We use non-identifying aggregates to operate, secure and improve the service. |
Shopping on a store that uses AskRoo? Start with Information for shoppers. For access or deletion requests, contact the merchant you shopped with — we will assist them in responding.
03Information we collect
We collect only what the service needs to function, and we keep identifying data out of the agent’s working context wherever it is not required to answer.
a. Information you provide directly
- Merchant account details — name, business name, work email address, phone number, store URL and role.
- Enquiries and support requests — the content of emails, demo requests and founding-cohort applications you send us.
- Configuration you set — agent tone, policies, escalation rules, business hours and any custom answers you supply.
- Billing details — handled by Shopify Billing or our payment processor. We receive confirmation and invoice records, not full card numbers.
b. Shopper conversation data
- Message content — what a shopper types or says to the agent, and the agent’s replies.
- Session context — the page the conversation started on, the products viewed, cart contents and browsing signals shared by the store.
- Order lookups — where a shopper asks about an order, the order number, email or phone used to verify identity, and the resulting order and fulfilment status.
- Feedback — thumbs up or down ratings, escalation events and handover notes.
c. Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system, language and referring URL.
- Usage data — pages viewed, features used, timestamps, session duration and error diagnostics.
- Security logs — authentication events, rate-limit triggers and abuse-prevention signals.
d. Information from other sources
- Shopify — store and catalogue data made available through the permissions you grant at install (see section 04).
- Service providers — delivery, bounce and error signals from our email and infrastructure providers.
Please do not share sensitive information with the agent. AskRoo is not designed to collect health, biometric, financial account, government identifier or other special-category data. Do not enter card numbers or passwords into a conversation; we will never ask for them.
04Shopify store data and permissions
When a merchant installs AskRoo from the Shopify App Store, Shopify asks them to approve a specific set of access scopes. We request only what the agent needs to answer accurately, and we can operate with a reduced scope set if a merchant prefers.
- Products, collections and inventory — so the agent can recommend items that exist and are in stock.
- Store policies and pages — shipping, returns, warranty and FAQ content, so answers match the merchant’s published terms.
- Discounts and price rules — so the agent surfaces only offers that are actually live and applicable.
- Orders and fulfilment — so the agent can answer “where is my order” questions, only after identity verification.
- Customer records — used strictly to match a verified shopper to their own order history. Never used for profiling or marketing by us.
Merchants can review these permissions at any time in their Shopify admin and revoke them by uninstalling the app. On uninstall, Shopify notifies us and we begin the deletion process described in section 11. We also honour Shopify’s mandatory GDPR webhooks — customers/data_request, customers/redact and shop/redact — which route data requests from a merchant’s store to us automatically.
05How we use information
We use personal information for the following purposes and no others without telling you first.
- To run the agent — retrieve relevant store information, generate replies, surface products and offers, and verify identity before revealing private order details.
- To provide the merchant dashboard — account creation, authentication, configuration, conversation review and reporting.
- To support merchants — respond to enquiries, onboard new stores, troubleshoot issues and provide the hands-on support included with the founding cohort.
- To keep the service safe — detect and prevent abuse, spam, prompt injection, fraud and unauthorised access, and enforce rate limits.
- To improve quality — measure answer accuracy, resolution and escalation rates, and diagnose failures. Where a merchant has enabled it, review a sample of conversations to tune retrieval and confidence thresholds for that store.
- To communicate — send service, security and billing notices. Product and marketing emails go only to merchants and prospects who have opted in, and every one carries an unsubscribe link.
- To meet legal obligations — tax and accounting records, responding to lawful requests, and establishing or defending legal claims.
What we never do: sell personal information; share it with data brokers; use shopper conversations for cross-merchant advertising; or make solely automated decisions that produce legal or similarly significant effects about an individual.
06AI processing and model training
AskRoo uses large language models to understand questions and compose replies. Understanding that pipeline matters, so here is exactly what happens.
- Retrieval, not memorisation. The agent retrieves relevant passages from the merchant’s own catalogue, policies and content, then answers from that retrieved context. Store content is indexed per merchant and never pooled across stores.
- Minimised context. We pass the model the least data needed to answer. Private order details are retrieved only after identity verification and are not retained by the model provider beyond the request.
- No training on your data by model providers. We use enterprise API tiers under agreements that prohibit our model providers from using inputs or outputs to train their models, and that impose zero or short-term retention limited to abuse monitoring.
- Improvement within a store. Where a merchant enables it, we use conversations from their store to tune retrieval, confidence thresholds and gap analysis for their store. Merchants can disable this in the dashboard.
- Aggregate insight only across stores. Any cross-merchant analysis uses de-identified, aggregated statistics — question categories, resolution rates, latency — not conversation content.
- Human oversight. When the agent’s confidence is low, or a question falls outside merchant policy, it escalates to a human rather than guessing.
07Legal bases for processing
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under Article 6 GDPR.
| Purpose | Legal basis |
|---|---|
| Providing the service to a merchant, account management, billing | Performance of a contract |
| Responding to enquiries and demo requests | Steps prior to entering a contract; legitimate interests |
| Security, abuse prevention, service reliability | Legitimate interests in protecting the service and its users |
| Quality measurement and product improvement | Legitimate interests, balanced against your rights; consent where required |
| Non-essential cookies and marketing email | Consent, withdrawable at any time |
| Tax, accounting and lawful requests | Compliance with a legal obligation |
Where we act as a processor for a merchant, the merchant determines the legal basis for shopper data and is responsible for providing notice to their shoppers.
09Subprocessors
We use a small, deliberately limited set of vendors. Each is bound by a data processing agreement, is assessed before onboarding, and is reviewed periodically.
| Category | Purpose | Typical location |
|---|---|---|
| Cloud hosting and databases | Running the application and storing store and conversation data | EU, United States |
| Large language model providers | Generating agent replies under no-training, limited-retention terms | United States, EU |
| Commerce platform | Shopify app distribution, authentication and billing | Canada, United States |
| Transactional email | Service, security and account notifications | United States, EU |
| Error monitoring and analytics | Diagnosing failures and measuring reliability | United States, EU |
Merchants can request our current, named subprocessor list and subscribe to change notifications by emailing connect@askroo.io. We give notice before adding a new subprocessor that processes merchant data, so merchants have an opportunity to object.
10International transfers
AskRoo serves merchants globally, so personal information may be transferred to and processed in countries other than your own, including the United States and the European Union.
- For transfers out of the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where applicable.
- For transfers to any other country, we put appropriate contractual safeguards in place and satisfy ourselves that the recipient will handle the information consistently with this policy before any disclosure is made.
- We assess the laws of destination countries and apply supplementary technical measures — encryption in transit and at rest, access controls and data minimisation — where appropriate.
Merchants with data residency requirements should contact us before install so we can confirm what we can support.
11How long we keep data
We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires.
| Data | Retention |
|---|---|
| Shopper conversation transcripts | Merchant-configurable, 90 days by default; deleted or de-identified after the configured period |
| Verified order lookup results | Not stored beyond the session, except as a record that a lookup occurred |
| Merchant account and configuration | For the life of the account, then deleted within 90 days of closure |
| Indexed store catalogue and policy content | Deleted within 30 days of uninstall |
| Security and audit logs | Up to 12 months |
| Billing and tax records | As required by applicable tax and accounting law, generally 7 years |
| Aggregated, de-identified metrics | Retained indefinitely; no longer personal information |
Backups are encrypted and rotate on a fixed schedule, so deleted data may persist in backup for a short additional period before being overwritten.
12Security
We apply technical and organisational measures appropriate to the risk. No system is perfectly secure, but these are the controls we hold ourselves to.
- Encryption — TLS 1.2 or higher in transit, encryption at rest for databases and backups.
- Access control — least-privilege access, role-based permissions, multi-factor authentication on administrative accounts, and access logging.
- Tenant isolation — each merchant’s store content and conversations are logically separated; retrieval is scoped to a single store.
- Identity verification — private order data is released only after the shopper verifies ownership of the order.
- Secure development — code review, dependency scanning, secrets management and staged deployment.
- Breach response — a documented plan. Where a data breach is likely to result in serious harm, we notify affected merchants without undue delay and, where required, the relevant supervisory or regulatory authority — within 72 hours under the GDPR.
To report a suspected vulnerability, email connect@askroo.io with the subject “Security report”. We will acknowledge within two business days and will not pursue good-faith researchers who follow responsible disclosure.
13Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal information.
- Access — obtain a copy of the personal information we hold about you.
- Correction — have inaccurate or incomplete information corrected.
- Deletion — ask us to erase your personal information, subject to legal retention obligations.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Restriction and objection — limit or object to processing based on legitimate interests, including direct marketing.
- Withdraw consent — at any time, without affecting processing already carried out.
- Non-discrimination — we will not deny service, charge different prices or provide a lesser quality of service because you exercised a privacy right.
How to exercise them
Email connect@askroo.io with the subject “Privacy request”. We will verify your identity in proportion to the sensitivity of the request and respond within 30 days, or within the shorter period your local law requires. There is no fee unless a request is manifestly unfounded or excessive. You may use an authorised agent where your local law allows it.
Regional notes
- EEA, UK and Switzerland — you may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner’s Office.
- California — you have rights to know, delete, correct and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising, and we do not knowingly process the data of consumers under 16 for those purposes.
- Other regions — where local law grants broader rights, we honour the broader standard.
14Information for shoppers
If you chatted with AskRoo on a store, this section is for you.
- The store you shopped with controls your data. AskRoo processes your conversation on that merchant’s behalf, under their instructions and their privacy policy.
- What the agent sees. Your messages, the pages and products in your session, and — only if you ask about an order and verify your identity — that order’s details.
- Verification. The agent will not reveal order, address or delivery information until you confirm ownership of the order. It will never ask for a password or a full card number.
- Escalation. If you ask for a person, or the agent is not confident, your conversation is handed to the merchant’s team, who will see the transcript.
- Your requests. To access or delete your data, contact the store you shopped with. If you contact us directly, we will forward your request to that merchant and assist them in fulfilling it.
16Children’s privacy
AskRoo is a business tool sold to merchants and is not directed to children. We do not knowingly collect personal information from children under 16, or under the age of digital consent in your jurisdiction where that age is higher. If you believe a child has provided personal information to us through a store conversation, contact us at connect@askroo.io and we will delete it promptly.
17Changes to this policy
We update this policy as the product and the law evolve. The “Last updated” date at the top of this page always reflects the current version.
For material changes — a new purpose of processing, a new category of data, or a change in how we share information — we will notify merchants by email or in the dashboard at least 14 days before the change takes effect, so there is time to review it or object. Continued use of the service after the effective date constitutes acceptance of the updated policy. Previous versions are available on request.
18Contact and complaints
Questions about this policy, or about how your data is handled, come straight to us. We answer them ourselves.
If you are not satisfied with our response, you may complain to the data protection authority for your country or region. In the EEA or the UK, that is your national supervisory authority or the UK Information Commissioner’s Office.
Back to top