1. Controller
supportif.ai — Manuel Sampl
Johann-Strauß-Gasse 8
1040 Vienna, Austria
E-mail: support@supportif.ai
This policy covers the website supportif.ai and the Shopify app supportif.AI (running at app.supportif.ai). For personal data of a merchant's customers that we process while providing the app, we generally act as a processor on behalf of the merchant (Art. 28 GDPR) — see our Data Processing Agreement.
2. What data we process
- Merchant & shop data — shop domain, installation and plan status, settings; shop content retrieved via the Shopify Admin API within the granted access scopes (products, collections, orders, customer records, shop policies, pages, blogs).
- Support emails — the contents of mailboxes you connect (sender, recipients, subject, body, attachments), including personal data of your customers contained in those emails, plus tickets, drafts and AI analyses derived from them.
- Credentials & tokens — IMAP/SMTP credentials, Google OAuth tokens, optional storefront password, optional Telegram bot tokens and your own AI API keys (Pro plan). All of these are stored encrypted (AES-256-GCM) and decrypted only in memory when needed.
- Crawled store website content — the page texts of the sources you approve in the Website Knowledge Sync (pages, policies, collections, products, blogs) and the knowledge entries generated from them.
- Telegram data — only if you connect a bot: bot username, linked chat ID and the notification messages exchanged.
- Usage & billing metadata — AI token counts and costs per request (for metered billing via Shopify), technical logs required to operate the service. Billing itself is handled entirely by Shopify; we never see your payment details.
- Website visitors — our marketing website is static and sets no tracking cookies. Server access logs of our hosting provider (IP address, user agent, timestamp) are used solely for security and operations.
3. Purposes and legal bases
- Providing the app (reading and sending emails, AI triage and drafting, ticketing, knowledge sync, Telegram notifications, team assignment) — performance of contract, Art. 6(1)(b) GDPR.
- Metered billing through Shopify — performance of contract, Art. 6(1)(b) GDPR.
- Security, abuse prevention and service improvement (aggregated, non-content metadata) — legitimate interest, Art. 6(1)(f) GDPR.
- Support communication with you — Art. 6(1)(b) and (f) GDPR.
We do not sell any data, we do not use your data for advertising, and we do not allow third-party AI providers to train their models on your data (API traffic is excluded from training under the providers' API terms).
4. AI processing
To analyze and answer support emails, the relevant email content and required shop context are sent to the AI model you configured: OpenAI and/or Anthropic (cloud), or a local model operated within our infrastructure. Cloud providers receive only the content needed for the specific request and process it under their API data-processing terms. If you prefer that no data leaves our infrastructure, select the local model. Automated replies are only sent within the automation rules you configure; all data-changing Shopify actions always require your explicit approval — there is no automated decision-making with legal effect within the meaning of Art. 22 GDPR.
5. Sub-processors
- Shopify — platform, app hosting frame, billing.
- Vercel — application hosting (EU region configured where available).
- Database hosting provider — encrypted storage of app data.
- OpenAI / Anthropic — AI processing, only when you use cloud models.
- Google — only for Gmail mailboxes connected via OAuth.
- Telegram — only if you enable the Telegram bot.
Where processing takes place outside the EU/EEA, it is safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
6. Retention and deletion
- Emails without tickets, resolved tickets and flushed usage records are deleted automatically after the configured retention period (default: 365 days).
- When you uninstall the app, your shop's data is deleted. Shopify's GDPR webhooks (customer data request, customer erasure, shop erasure) are implemented and honored.
- Legal retention obligations (e.g. accounting records) remain unaffected.
7. Security
All connections are encrypted in transit (TLS). Credentials, tokens, API keys and the storefront password are encrypted at rest with AES-256-GCM. Access to production systems is restricted and logged. Each shop's data is strictly separated by tenant.
8. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Contact us at support@supportif.ai — we answer within the statutory time limits. You also have the right to lodge a complaint with a supervisory authority; in Austria this is the Datenschutzbehörde (dsb.gv.at).
If you are a customer of a store that uses supportif.AI, please direct requests to the store first — the merchant is the controller of your data; we support them in fulfilling your rights.
9. Changes
We may update this policy to reflect changes in the service or the law. The current version is always available at supportif.ai/legal/privacy; material changes are announced in the app.