Shoesy.AI

Privacy Policy

Effective date: 2026-07-04

This Privacy Policy explains how Shoesy AI ("Shoesy", "we", "our") collects, uses, stores, and shares information when a merchant installs the Shoesy app on their store, when a shopper interacts with the Shoesy chat widget on that store, and when a visitor uses our marketing site at shoesy.ai.

We serve merchants and shoppers worldwide. This policy is structured with primary attention to United States privacy law (CCPA / CPRA and the state-privacy laws that follow it), with regional addenda for the United Kingdom, Canada, Australia, Germany, and the rest of the European Economic Area.

1. Who we are

Shoesy AI is operated by Grzegorz Zięba, sole proprietor, registered in the Republic of Poland. This entity is the "business" under California law and the "data controller" under UK GDPR and EU GDPR. You can reach us at privacy@shoesy.ai.

2. Data we collect

2.1 From shoppers (via the chat widget)

We do not collect names, addresses, payment details, IP addresses for tracking, browser fingerprints, government identifiers, biometric data, precise geolocation, or any cookie that would identify a shopper across sites. We do not collect "sensitive personal information" as that term is defined under the CPRA, and we do not knowingly collect "special category data" as defined under the UK / EU GDPR.

2.2 From merchants (via the Shoesy app)

We do not request or store payment instruments, customer PII beyond what a shopper voluntarily types into the widget, or any access scope outside of read-only catalog, content, legal-policies, and order reads.

2.3 From visitors to shoesy.ai (the marketing site)

2.4 Cookies and device storage

The widget sets no cookies and uses no cross-site identifiers. It uses two kinds of browser storage, both scoped to the store you are shopping on and readable only by that store's pages:

3. How we use the data

We do not sell shopper or merchant data to anyone, ever. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA. We never use shopper contact information for Shoesy's own marketing or outreach, and we contact merchants only about the Service (the only marketing list we keep is the marketing-site signup form in §2.3, which visitors join themselves). We do not use merchant or customer data — in identifiable, anonymized, aggregated, or derived form — to train, fine-tune, or improve AI models, ours or anyone else's. The general-purpose language models that generate assistant replies receive data at inference time only; the third-party provider that runs them is engaged as a sub-processor under data-processing terms that prohibit training on those inputs (see §4). Shoesy's own sizing engine is deterministic — not a trained model — and its rules are built from published brand sizing data, not from merchant or customer data.

AI transparency. The chat widget discloses that it is an automated AI system through three mechanisms. First, it identifies itself as an "AI Assistant": the launcher button carries that name as its accessible label and the panel header displays it in plain text once the chat is open. Second, the panel header carries a persistent subtitle — "Automated AI · replies may be imperfect" — shown for the whole conversation and localized into every language the widget answers in. Third, if a shopper asks whether they are talking to a bot or a human, the widget answers with a fixed, truthful disclosure that it is an AI system — this answer is served deterministically, outside the AI model, and the assistant never claims to be human. When the assistant cannot answer a shopper's question, it returns an honest fallback reply: where the merchant has configured a support email it offers escalation to the merchant's human support, and otherwise it directs the shopper to contact the store directly. A sizing question the engine cannot answer confidently instead returns a "not enough data" reply that points to the merchant's own size guide where the merchant has configured one.

4. Third parties processing data on our behalf

We use a small set of sub-processors to deliver the Service. Each is bound by the processor's standard data-processing terms, and each is engaged as a "service provider" under the CCPA / CPRA and as a "processor" under the UK / EU GDPR — the contracts forbid the sub-processor from selling, sharing, or using the data for its own purposes.

Category Purpose Data shared
Edge delivery Global edge computing network in front of our origin. Encrypted HTTP traffic transits the edge network before reaching our servers.
AI model inference Generates assistant replies on our behalf. Prompt + retrieved context per request. Bound by terms that prohibit training on inputs.
Request tracing + analytics Helps us measure quality, latency, and cost of each request. Trace id, prompt, response, model, latency, cost. PII scrubbed where present.
Error monitoring Captures runtime errors so we can fix them. Stack traces, scrubbed request metadata.
Infrastructure hosting Supplies the rented servers our application and databases live on. All service data at rest, on servers we administer (the provider manages the hardware).
Offsite backups Stores backup snapshots outside our primary servers. Database, search-index, and vector-index snapshots in access-controlled private storage.
E-commerce platform The merchant's own storefront platform that the app integrates with. Order lookups; deletion / data-request signals from the platform on the merchant's behalf.

We will provide the current list of named sub-processors on request to privacy@shoesy.ai, and we do not move data to a category of sub-processor not listed above without updating this policy first.

5. Retention

Data Retention
Chat logs (shopper messages + assistant replies) Deleted no later than 90 days after your last interaction in a session.
Order-lookup pairs (email + order #) Stored only inside the chat log of the originating session, and deleted with that log.
Back-in-stock requests (shopper email + product/variant) Kept in raw form for the merchant to act on; not auto-deleted (no restock notifier sends them). Erased when a customer-deletion (redact) signal for that email arrives, and otherwise when the merchant uninstalls the app or the shop is redacted (the same shop-data cascade that clears every other tenant table).
Merchant shop configuration (FAQ, tone, support email) For the lifetime of the install.
Product catalog snapshots Refreshed continuously; previous versions discarded.
Early-access emails (marketing-site signups) Kept until you opt out or request deletion; removed within 30 days of a request.
Backups Retained 30 days in access-controlled private storage, then rotated out.

When a merchant uninstalls the app, or a shop exercises a deletion right, the e-commerce platform notifies us and we delete that shop's data within 30 days. A shopper deletion signal is also forwarded to us and logged; as explained in §6, anonymous shopper chat is not linked to a customer account we can single out, and it is deleted automatically on the schedule above (and in full when the merchant uninstalls).

6. Your privacy rights

We honor the rights granted by the law of your residence. We do not require you to create an account to exercise them, and we do not discriminate against you for exercising them.

How this works for shopper chat. Shopper conversations are stored under an anonymous per-session id (a per-tab identifier) that we never link to a named individual or to a Shopify customer account (see §2.1), and email addresses are masked in the stored chat record at the moment we receive them. So when a request keyed to a customer account reaches us — for example a deletion signal the e-commerce platform forwards to us — we log it (and respond within 30 days), but there is no account-linked shopper record in the chat data for us to single out: no stored identifier ties a person to their chat messages. The one identifiable exception is a back-in-stock request (§2.1), which stores a raw email: a customer-deletion (redact) signal for that email erases those rows, and they are disclosed in our response to a data request for that email. Independently of any request, every chat log is deleted no later than 90 days after the last interaction in its session (§5), and all shopper data for a store is deleted when the merchant uninstalls the app. To ask about data tied to a specific session, email privacy@shoesy.ai. (This note concerns the shopper chat record; the compliance request itself is retained as an audit record.)

6.1 United States — California (CCPA / CPRA)

If you are a California resident, you have the right to:

We have not received any verifiable consumer requests in the prior 12 months that would require numerical disclosure under CCPA §1798.130(a)(5)(B); when that changes we will publish the metrics here.

6.2 United States — other states

Comprehensive consumer-privacy laws in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other states that follow them grant residents access, deletion, correction, portability, and opt-out rights similar to those in §6.1, with appeal procedures and complaint channels through the relevant state attorney general. To exercise any of these rights, email privacy@shoesy.ai.

6.3 United Kingdom (UK GDPR + Data Protection Act 2018)

If you are in the United Kingdom, you have the right to:

6.4 Canada (PIPEDA + provincial laws including Quebec Law 25, Alberta PIPA, BC PIPA)

You have the right to access and correct your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada (OPC) or your provincial commissioner.

6.5 Australia (Privacy Act 1988 + Australian Privacy Principles)

You have the right to access and correct your personal information and to complain to the Office of the Australian Information Commissioner (OAIC).

6.6 Germany and the rest of the European Economic Area (EU GDPR + BDSG / national implementations)

If you are in Germany or another EEA country, you have the right to:

6.7 How to exercise these rights

Email privacy@shoesy.ai. Shoppers: route requests via the merchant whose store you used the widget on, or email us directly; the platform also forwards the data-request signal to us, and we respond within 30 days (or the period your local law requires, whichever is shorter). For how this works given that shopper chat is anonymous and not account-linked, see the shopper-chat note at the top of §6. Merchants: contact us directly. We may need to verify your identity or your authorized agent's authority before disclosing or deleting data.

We do not respond to law-enforcement or government requests without a valid legal order, and we will inform the affected merchant unless legally prohibited.

7. Security

No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay and within the timelines the applicable law requires — including the 72-hour supervisory-authority notification under GDPR Art. 33 and notice to affected individuals without undue delay under Art. 34, the UK GDPR equivalent, the Australian NDB scheme, and applicable US state breach-notification laws.

8. International transfers and data location

Our primary production servers are located in the United States. Public traffic is served from a global edge computing network (provided by Cloudflare, Inc.) before reaching those servers. Because our operating entity is based in the European Union and our processing routinely involves transfers across borders:

If your jurisdiction restricts transfers of personal information to the United States or other third countries, the safeguards above apply. We will provide copies of the relevant transfer mechanisms on request to privacy@shoesy.ai.

9. Children

Shoesy is a B2B tool used inside e-commerce storefronts. We do not knowingly collect personal information from a child:

If you believe a child has interacted with the widget, contact us and we will delete the relevant chat log.

10. Changes to this policy

We may update this policy. Material changes will be announced inside the merchant dashboard at least 14 days before they take effect, and reflected in the Effective date at the top of this page. Continued use of Shoesy after the effective date constitutes acceptance.

11. Contact

Questions, requests, or complaints: privacy@shoesy.ai.