Legal
Privacy Policy
Effective date: May 10, 2026 · Last updated: September 30, 2026
This Privacy Policy explains how Zencrypt (“we,” “our,” or “us”) collects, uses, discloses, and protects information when merchants install our Shopify app (“Zencrypt Support”) and when their customers interact with the chat widget we provide.
We act as a data processor on behalf of merchants for the personal data of their customers, and as a data controller for the merchant account data we hold directly. If you are an end customer with a question about your data, please contact the merchant whose store you interacted with first; they are the controller of your data.
1. Who we are
Zencrypt
Lucknow, India
Contact: contact@zencrypt.co.in
Data protection inquiries: contact@zencrypt.co.in
2. Information we collect
2.1 Information from merchants
- Account data received from Shopify during app installation: store domain, shop ID, store owner name and email, store country and currency, and the OAuth access token (which we store encrypted at rest using AES-256-GCM).
- Configuration data entered by the merchant in the app dashboard: business hours, brand voice settings, automation preferences, refund and return policies, team member emails, and billing tier.
- Support tickets the merchant opens with us: subject, message body, and any attachments. Used solely to answer the request.
- Product usage data: which pages of the app the merchant opens and for how long, the buttons, links and tabs they click (recorded by their label), and the changes they make, such as approving an action or saving settings. We never record what is typed, and a click in a list that shows customer data is recorded only by the list's name, not its contents. We also record when a store installs or uninstalls the app.
2.2 Information from the merchant's Shopify store (processed on the merchant's behalf)
- Order data: order number, line items, totals, fulfillment status, shipping address, and tracking numbers.
- Customer data: name, email, phone number, billing and shipping addresses, and order history.
- Refund, return, and cancellation records created via our app or visible on the store.
- Shop policies and product catalog (read-only) used to ground AI responses and to suggest relevant products at the end of a chat.
- Customer profiles: learned automatically from a customer's orders, the products they ask about in the chat and the suggestions they click (for example the product types and brands they buy, the prices they usually pay and whether they prefer chat or email), plus any notes and labels the merchant adds and whether the customer should not be shown product suggestions.
2.3 Information from end customers (storefront chat widget)
- Chat content: messages typed into the widget, and any name or email the customer voluntarily provides during the conversation.
- Technical metadata: IP address, user-agent string, browser language, referring URL, and a timestamped widget session token. These are used for rate limiting, abuse detection (e.g., automated bots), and conversation continuity across page loads.
- Product suggestions: which suggested products were shown in the chat and which one the customer clicked, so the merchant can see whether suggestions help. Suggestions are based on the customer's orders, the merchant's notes and what other customers bought; browsing on the store is not tracked.
- No tracking cookies: the widget uses only first-party
localStorageon the merchant's storefront domain to remember the active conversation. No third-party cookies, no advertising pixels, no cross-site tracking.
3. How we use information
- To provide, operate, and maintain the Zencrypt Support service.
- To generate AI-assisted replies to customer inquiries on behalf of the merchant. Chat content and relevant order context are sent to large-language-model providers (see Section 5) for the duration of a single response generation.
- To execute merchant-approved actions on the Shopify store, such as issuing a refund, processing a return, or updating an address — only when explicitly authorized by the merchant or by automation rules the merchant has configured.
- To send transactional emails (e.g., installation confirmations, support replies, SLA notifications).
- To detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- To comply with legal obligations and respond to lawful requests.
- To understand which features merchants use, so we can decide what to improve. Product usage data is seen only by Zencrypt, never by other merchants.
- To improve the service's reliability and accuracy through aggregated, de-identified analytics. We do not train AI models on merchant or end-customer data.
4. Legal bases for processing (EEA/UK users)
- Contract — to deliver the service merchants subscribe to.
- Legitimate interests — operating, securing, and improving the service.
- Consent — where required (e.g., optional analytics).
- Legal obligations — tax, accounting, or law-enforcement requests.
5. Sub-processors
We use the following third-party service providers (sub-processors) to operate the service. Each processes data only as instructed by us and under contractual data protection commitments at least as protective as this Policy.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic, PBC | Primary AI model provider (Claude) — generates response drafts | United States |
| OpenAI, L.L.C. | Fallback AI model provider — used only when Anthropic is unavailable | United States |
| Neon, Inc. | Managed PostgreSQL database (encrypted at rest) | United States / EU |
| Upstash, Inc. | Redis cache for rate limiting and session continuity | United States / EU |
| Inngest, Inc. | Asynchronous job orchestration | United States |
| Resend.com | Transactional email delivery | United States / EU |
| Cloudflare, Inc. (R2) | Storage of message attachments (encrypted at rest) | Global edge |
| Functional Software, Inc. (Sentry) | Error and performance monitoring (does not receive chat content) | United States / EU |
| Railway Corp. | Application hosting | United States |
| Shopify Inc. | Source platform for orders, customers, and merchant authentication | Canada / United States / EU |
We may add or replace sub-processors as the service evolves. Material changes will be announced via the merchant dashboard at least 30 days in advance, except where a faster change is required for security or legal reasons.
6. International data transfers
Personal data may be transferred to countries outside your country of residence, including the United States. Where required, we rely on Standard Contractual Clauses approved by the European Commission and equivalent mechanisms under UK GDPR and other regional laws to protect transferred data.
7. Data retention
- Conversations and messages: retained for the lifetime of the merchant's account, and deleted within 30 days of the merchant uninstalling the app (we receive Shopify's
app/uninstalledandshop/redactwebhooks, which trigger our deletion routine). - End-customer personal data: deleted upon receipt of Shopify's
customers/redactwebhook, which Shopify dispatches when a customer requests their data be removed from a store. - Audit logs and security records: retained for up to 12 months after the merchant's uninstall to investigate incidents and comply with our legal obligations.
- Product usage data: kept for 12 months, and deleted with the rest of the store's data after an uninstall. The record that a store installed or uninstalled the app is kept without anything that identifies the store.
- Aggregated, de-identified analytics: retained indefinitely. These contain no personal data.
8. Your rights
Depending on your location, you may have rights under data protection law, including the right to access, correct, delete, or restrict processing of your personal data, the right to portability, and the right to object to certain processing.
End customers: please contact the merchant whose store you interacted with — they are the data controller for your data and can submit a deletion request to Shopify on your behalf, which we will action automatically within 30 days.
Merchants and direct contacts: email contact@zencrypt.co.in and we will respond within 30 days.
9. Security
- All data in transit is protected with TLS 1.2 or higher.
- Shopify access tokens are encrypted at rest with AES-256-GCM.
- Database storage is encrypted at rest by our infrastructure providers.
- Access to production systems is limited, multi-factor-authenticated, and audit-logged.
- We monitor errors and anomalous activity continuously via Sentry and Inngest.
No system is perfectly secure. If you become aware of a vulnerability or incident, please contact contact@zencrypt.co.in immediately.
10. Children
Zencrypt Support is intended for use by merchants and their adult customers. We do not knowingly collect personal data from children under 16. If you believe we have, please contact us at contact@zencrypt.co.in.
11. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date at the top of this page reflects the latest version. Material changes will be communicated via the merchant dashboard or email at least 30 days before they take effect.
12. Contact
For privacy questions, please email contact@zencrypt.co.in or write to the postal address in Section 1.
See also: Terms of Service