Privacy Policy & Data Protection

Last updated: February 2, 2026

1. Introduction

SupportPilot AI ("we", "our", "us") is committed to protecting the privacy of merchants and their customers using our Shopify application. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with GDPR and Shopify's data protection requirements.

Data Controller: SupportPilot AI
Contact: privacy@support-pilot-ai.com

2. Data Collected

2.1 Merchant Data

2.2 Customer Data (Protected)

We access the following customer data only when processing support tickets:

2.3 Communication Data

3. How We Use Your Data

We use collected data exclusively for:

We DO NOT: Sell personal data, use it for marketing, share it with advertisers, or access it outside of support ticket processing.

4. Data Sharing

We share data only with the following third parties, necessary for service operation:

ProviderPurposeData Shared
Anthropic (Claude AI)AI response generationTicket content, customer context (processed, not stored)
SupabaseDatabase hostingAll app data (SOC 2 Type II compliant)
Google (Gmail API)Email synchronizationEmail content when Gmail is connected
Meta (Instagram API)Instagram Direct Message supportDM content, sender username, conversation history
Microsoft (Outlook API)Email synchronizationEmail content when Outlook is connected

4b. Instagram & Meta Data

When a merchant connects their Instagram Business Account, we access the following data through the Meta/Instagram API:

Data Collected

How Instagram Data is Used

Data Deletion

5. Data Security

5.1 Technical Measures

5.2 Organizational Measures

6. Data Retention

7. Your Rights (GDPR)

Under GDPR, you have the following rights:

RightHow to Exercise
AccessRequest a copy of your data via email
RectificationUpdate your data through the app or contact us
ErasureUninstall the app or request manual deletion
RestrictionContact us to limit processing
PortabilityRequest data export in JSON format
ObjectionOpt out of automated decision-making via Settings

To exercise any of these rights, contact: privacy@support-pilot-ai.com

8. Security Incident Response

In the event of a data security incident, we follow this procedure:

  1. Detection & Containment: Immediately isolate affected systems
  2. Assessment: Evaluate scope and severity within 24 hours
  3. Notification: Notify affected merchants within 72 hours per GDPR
  4. Regulatory Report: Report to relevant authorities if required
  5. Remediation: Fix vulnerabilities and prevent recurrence
  6. Documentation: Maintain detailed incident records

Security Contact: security@support-pilot-ai.com

9. Contact Us

For any questions about this Privacy Policy or our data practices:

Shopify Data Protection Compliance

SupportPilot AI complies with Shopify's Protected Customer Data requirements: