Privacy Policy
Effective date: 2026-07-04
This Privacy Policy explains how Shoesy AI ("Shoesy", "we", "our") collects, uses, stores, and shares information when a merchant installs the Shoesy app on their store, when a shopper interacts with the Shoesy chat widget on that store, and when a visitor uses our marketing site at shoesy.ai.
We serve merchants and shoppers worldwide. This policy is structured with primary attention to United States privacy law (CCPA / CPRA and the state-privacy laws that follow it), with regional addenda for the United Kingdom, Canada, Australia, Germany, and the rest of the European Economic Area.
1. Who we are
Shoesy AI is operated by Grzegorz Zięba, sole proprietor, registered in the Republic of Poland. This entity is the "business" under California law and the "data controller" under UK GDPR and EU GDPR. You can reach us at privacy@shoesy.ai.
2. Data we collect
2.1 From shoppers (via the chat widget)
- Chat messages — the questions a shopper types into the assistant and the assistant's replies.
- Anonymous session ids — a per-tab identifier we use to keep a single conversation coherent. We do not link this id to a named individual.
- Page-context metadata — the URL, product handle, product title, currency, and locale of the page on which the widget was opened, so the assistant can answer in context.
- Order-lookup inputs — when a shopper voluntarily provides an order number and email address to ask "where is my order?", we send that pair to the merchant's e-commerce platform to fetch the order. We do not retain the raw email afterward on our servers: it is masked in the session's chat record. The order number is kept pseudonymously in that record (no name, no account link). Both are deleted on the §5 schedule. (The shopper's own browser may keep a short-lived local copy — see §2.4.)
- Back-in-stock requests — when a shopper asks about a sold-out item and chooses to be told when it returns, we store the email address they enter together with the product and the color / size / width they asked about. Unlike the order-lookup email above, this address is kept in raw form, because its whole purpose is to let the store reach the shopper: the request appears in the merchant's dashboard (with a CSV export) and the store team follows up manually. Shoesy does not send an automated restock email — there is no automated notifier — so these records are not deleted "on send." They are erased when a customer-deletion (redact) signal for that email reaches us, and otherwise persist until the shop's data is deleted (merchant uninstall or shop-redact), per §5.
We do not collect names, addresses, payment details, IP addresses for tracking, browser fingerprints, government identifiers, biometric data, precise geolocation, or any cookie that would identify a shopper across sites. We do not collect "sensitive personal information" as that term is defined under the CPRA, and we do not knowingly collect "special category data" as defined under the UK / EU GDPR.
2.2 From merchants (via the Shoesy app)
- Shop configuration — store domain, support email, FAQ entries, assistant tone, widget on/off state.
- Product catalog metadata — product titles, descriptions, variants, inventory levels, images, and tags, fetched via the read-only access scopes the app requests on install.
- Order metadata — used only at lookup time as described above; not bulk-synced.
We do not request or store payment instruments, customer PII beyond what a shopper voluntarily types into the widget, or any access scope outside of read-only catalog, content, legal-policies, and order reads.
2.3 From visitors to shoesy.ai (the marketing site)
- Early-access signups — if you submit your email address on our "early access & launch updates" form, we store it together with a timestamp and use it solely to send occasional product-launch and feature updates for Shoesy. We do not sell or share these addresses, we do not enrich them with data from any other source, and every email we send includes a way to opt out. To be removed at any time, use the opt-out link or write to privacy@shoesy.ai; we delete the address within 30 days of a request.
- Live-demo chat messages — our
/demopage runs the real chat widget connected to our own demonstration store (shoesy-demo). If you type a message there, it is processed and stored exactly as a shopper's message is under §2.1 — the questions you type and the assistant's replies, tied to an anonymous per-tab session id, with no account or sign-in required. These messages are held under the demonstration store's data, are not linked to you as an identified individual, and are retained on the same schedule as any shopper conversation (§5). We do not use them to contact you, and — as with every conversation — never to train or improve AI models (§3).
2.4 Cookies and device storage
The widget sets no cookies and uses no cross-site identifiers. It uses two kinds of browser storage, both scoped to the store you are shopping on and readable only by that store's pages:
- Per-tab session storage — the anonymous session id from §2.1, discarded when the tab closes.
- Local storage on your device — small convenience entries the widget keeps so the assistant can pick up where you left off: your stated shoe size / width / brand preference (kept up to 30 days) and, after an order lookup, the order number and email you entered (kept up to 3 days). These entries live only in your browser — they are not a server-side copy. While they haven't expired, the widget sends them along with your chat messages so the assistant can use them; whenever the email is used, it is masked server-side per §2.1. Clearing your browser's site data removes them immediately.
3. How we use the data
- Generate AI assistant replies on the merchant's storefront.
- Look up an order at the shopper's request.
- Evaluate and debug the Service's retrieval quality and deterministic sizing rules using aggregated, deidentified logs. This diagnostic use never involves training, fine-tuning, or improving an AI or machine-learning model.
- Generate aggregate analytics for the merchant (question categories, deflection rate).
We do not sell shopper or merchant data to anyone, ever. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA. We never use shopper contact information for Shoesy's own marketing or outreach, and we contact merchants only about the Service (the only marketing list we keep is the marketing-site signup form in §2.3, which visitors join themselves). We do not use merchant or customer data — in identifiable, anonymized, aggregated, or derived form — to train, fine-tune, or improve AI models, ours or anyone else's. The general-purpose language models that generate assistant replies receive data at inference time only; the third-party provider that runs them is engaged as a sub-processor under data-processing terms that prohibit training on those inputs (see §4). Shoesy's own sizing engine is deterministic — not a trained model — and its rules are built from published brand sizing data, not from merchant or customer data.
AI transparency. The chat widget discloses that it is an automated AI system through three mechanisms. First, it identifies itself as an "AI Assistant": the launcher button carries that name as its accessible label and the panel header displays it in plain text once the chat is open. Second, the panel header carries a persistent subtitle — "Automated AI · replies may be imperfect" — shown for the whole conversation and localized into every language the widget answers in. Third, if a shopper asks whether they are talking to a bot or a human, the widget answers with a fixed, truthful disclosure that it is an AI system — this answer is served deterministically, outside the AI model, and the assistant never claims to be human. When the assistant cannot answer a shopper's question, it returns an honest fallback reply: where the merchant has configured a support email it offers escalation to the merchant's human support, and otherwise it directs the shopper to contact the store directly. A sizing question the engine cannot answer confidently instead returns a "not enough data" reply that points to the merchant's own size guide where the merchant has configured one.
4. Third parties processing data on our behalf
We use a small set of sub-processors to deliver the Service. Each is bound by the processor's standard data-processing terms, and each is engaged as a "service provider" under the CCPA / CPRA and as a "processor" under the UK / EU GDPR — the contracts forbid the sub-processor from selling, sharing, or using the data for its own purposes.
| Category | Purpose | Data shared |
|---|---|---|
| Edge delivery | Global edge computing network in front of our origin. | Encrypted HTTP traffic transits the edge network before reaching our servers. |
| AI model inference | Generates assistant replies on our behalf. | Prompt + retrieved context per request. Bound by terms that prohibit training on inputs. |
| Request tracing + analytics | Helps us measure quality, latency, and cost of each request. | Trace id, prompt, response, model, latency, cost. PII scrubbed where present. |
| Error monitoring | Captures runtime errors so we can fix them. | Stack traces, scrubbed request metadata. |
| Infrastructure hosting | Supplies the rented servers our application and databases live on. | All service data at rest, on servers we administer (the provider manages the hardware). |
| Offsite backups | Stores backup snapshots outside our primary servers. | Database, search-index, and vector-index snapshots in access-controlled private storage. |
| E-commerce platform | The merchant's own storefront platform that the app integrates with. | Order lookups; deletion / data-request signals from the platform on the merchant's behalf. |
We will provide the current list of named sub-processors on request to privacy@shoesy.ai, and we do not move data to a category of sub-processor not listed above without updating this policy first.
5. Retention
| Data | Retention |
|---|---|
| Chat logs (shopper messages + assistant replies) | Deleted no later than 90 days after your last interaction in a session. |
| Order-lookup pairs (email + order #) | Stored only inside the chat log of the originating session, and deleted with that log. |
| Back-in-stock requests (shopper email + product/variant) | Kept in raw form for the merchant to act on; not auto-deleted (no restock notifier sends them). Erased when a customer-deletion (redact) signal for that email arrives, and otherwise when the merchant uninstalls the app or the shop is redacted (the same shop-data cascade that clears every other tenant table). |
| Merchant shop configuration (FAQ, tone, support email) | For the lifetime of the install. |
| Product catalog snapshots | Refreshed continuously; previous versions discarded. |
| Early-access emails (marketing-site signups) | Kept until you opt out or request deletion; removed within 30 days of a request. |
| Backups | Retained 30 days in access-controlled private storage, then rotated out. |
When a merchant uninstalls the app, or a shop exercises a deletion right, the e-commerce platform notifies us and we delete that shop's data within 30 days. A shopper deletion signal is also forwarded to us and logged; as explained in §6, anonymous shopper chat is not linked to a customer account we can single out, and it is deleted automatically on the schedule above (and in full when the merchant uninstalls).
6. Your privacy rights
We honor the rights granted by the law of your residence. We do not require you to create an account to exercise them, and we do not discriminate against you for exercising them.
How this works for shopper chat. Shopper conversations are stored under an anonymous per-session id (a per-tab identifier) that we never link to a named individual or to a Shopify customer account (see §2.1), and email addresses are masked in the stored chat record at the moment we receive them. So when a request keyed to a customer account reaches us — for example a deletion signal the e-commerce platform forwards to us — we log it (and respond within 30 days), but there is no account-linked shopper record in the chat data for us to single out: no stored identifier ties a person to their chat messages. The one identifiable exception is a back-in-stock request (§2.1), which stores a raw email: a customer-deletion (redact) signal for that email erases those rows, and they are disclosed in our response to a data request for that email. Independently of any request, every chat log is deleted no later than 90 days after the last interaction in its session (§5), and all shopper data for a store is deleted when the merchant uninstalls the app. To ask about data tied to a specific session, email privacy@shoesy.ai. (This note concerns the shopper chat record; the compliance request itself is retained as an audit record.)
6.1 United States — California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, the categories of sources and recipients, and the business purpose.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of "sale" or "sharing" of personal information. We do not sell or share — see §3.
- Limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
- Non-discrimination for exercising any of the above.
- Designate an authorized agent to act on your behalf.
- File a complaint with the California Attorney General or the California Privacy Protection Agency (CPPA).
We have not received any verifiable consumer requests in the prior 12 months that would require numerical disclosure under CCPA §1798.130(a)(5)(B); when that changes we will publish the metrics here.
6.2 United States — other states
Comprehensive consumer-privacy laws in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other states that follow them grant residents access, deletion, correction, portability, and opt-out rights similar to those in §6.1, with appeal procedures and complaint channels through the relevant state attorney general. To exercise any of these rights, email privacy@shoesy.ai.
6.3 United Kingdom (UK GDPR + Data Protection Act 2018)
If you are in the United Kingdom, you have the right to:
- Access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time.
- Lodge a complaint with the UK Information Commissioner's Office (ICO).
6.4 Canada (PIPEDA + provincial laws including Quebec Law 25, Alberta PIPA, BC PIPA)
You have the right to access and correct your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada (OPC) or your provincial commissioner.
6.5 Australia (Privacy Act 1988 + Australian Privacy Principles)
You have the right to access and correct your personal information and to complain to the Office of the Australian Information Commissioner (OAIC).
6.6 Germany and the rest of the European Economic Area (EU GDPR + BDSG / national implementations)
If you are in Germany or another EEA country, you have the right to:
- Access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time.
- Lodge a complaint with your member-state supervisory authority — for example, the German Federal Commissioner for Data Protection and Freedom of Information (BfDI) or the relevant Land authority.
6.7 How to exercise these rights
Email privacy@shoesy.ai. Shoppers: route requests via the merchant whose store you used the widget on, or email us directly; the platform also forwards the data-request signal to us, and we respond within 30 days (or the period your local law requires, whichever is shorter). For how this works given that shopper chat is anonymous and not account-linked, see the shopper-chat note at the top of §6. Merchants: contact us directly. We may need to verify your identity or your authorized agent's authority before disclosing or deleting data.
We do not respond to law-enforcement or government requests without a valid legal order, and we will inform the affected merchant unless legally prohibited.
7. Security
- All HTTP traffic is encrypted in transit using modern TLS.
- Databases and search / vector indexes are reachable only from inside our private network; backup snapshots are held offsite in access-controlled private storage.
- Production systems are not directly reachable from the public internet; operator access runs through a zero-trust access layer, which logs each login, on top of key-based authentication.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay and within the timelines the applicable law requires — including the 72-hour supervisory-authority notification under GDPR Art. 33 and notice to affected individuals without undue delay under Art. 34, the UK GDPR equivalent, the Australian NDB scheme, and applicable US state breach-notification laws.
8. International transfers and data location
Our primary production servers are located in the United States. Public traffic is served from a global edge computing network (provided by Cloudflare, Inc.) before reaching those servers. Because our operating entity is based in the European Union and our processing routinely involves transfers across borders:
- Transfers from the United Kingdom rely on the UK International Data Transfer Agreement (IDTA) or the UK addendum to the EU Standard Contractual Clauses.
- Transfers from the EEA (including Germany) rely on the EU Standard Contractual Clauses.
- Transfers to or from Canada are made under PIPEDA's accountability principle.
- Transfers to or from Australia are made under Australian Privacy Principle 8 (cross-border disclosure).
If your jurisdiction restricts transfers of personal information to the United States or other third countries, the safeguards above apply. We will provide copies of the relevant transfer mechanisms on request to privacy@shoesy.ai.
9. Children
Shoesy is a B2B tool used inside e-commerce storefronts. We do not knowingly collect personal information from a child:
- Under 13 in the United States, in line with the Children's Online Privacy Protection Act (COPPA).
- Under 13 in the United Kingdom (Data Protection Act 2018, s. 9).
- Under 16 in the EEA (or the lower minimum age, not below 13, your member state has set for digital-services consent under GDPR Art. 8).
If you believe a child has interacted with the widget, contact us and we will delete the relevant chat log.
10. Changes to this policy
We may update this policy. Material changes will be announced inside the merchant dashboard at least 14 days before they take effect, and reflected in the Effective date at the top of this page. Continued use of Shoesy after the effective date constitutes acceptance.
11. Contact
Questions, requests, or complaints: privacy@shoesy.ai.