sellbot.org/privacy

Privacy Policy

Last updated: 6 September 2026

SellBot is made by CurrencyWiki Technologies LLC. This page explains what the SellBot Shopify app and the SellBot phone app collect, why, and how to get it deleted. Installing the app means you agree to this policy.

What we collect

  • Your store domain and Shopify access token
  • Your product catalogue, so the AI answers from real stock
  • Chat messages between shoppers and the AI or your team
  • A random visitor ID per chat — not a name, email, or IP
  • A shopper's email only if they type one in themselves
  • For each paired phone: its device name and a push token

What we never do

  • Sell your data, or anyone's, to anybody
  • Train third-party AI models on your store's data
  • Track shoppers across other websites
  • Touch card numbers — checkout stays entirely on Shopify
  • Ask Shopify for customer records or order history

1. Merchant data

Through Shopify's OAuth flow we receive your store domain and an access token, and we read your product catalogue and store locale. We also store the settings you choose in the admin — design, triggers, business hours, feature toggles — plus each team member's name and role so replies carry the right person's name. Paid-order webhooks are used for sales attribution in aggregate; they carry no personal details.

2. Shopper data

When someone chats on your storefront we store the messages so you can read and correct them in the Inbox, a random visitor ID to group those messages, and a snapshot of their cart so the AI can answer sensibly. A shopper's email is stored only when they choose to leave one — for a back-in-stock alert, or when nobody was available to reply. It is never required to use the chat.

On paid plans the Live tab shows who is browsing right now. That is the same anonymous visitor ID plus the page they are on, held in server memory for a few minutes and never written to the database.

We do not ask shoppers for names, addresses, or phone numbers. Anything a shopper types into the chat is kept in the transcript so you can answer it — nothing more.

3. The phone app

Pairing a phone stores two things: the phone's own device name, which Android and iOS report automatically and which often contains a person's name, and a push token so alerts can reach that handset. Both are used only to deliver alerts to that phone, and both are deleted the moment the phone is unpaired or revoked.

The reply box has a dictation button. Tapping it hands the microphone to your phone's own speech recogniser — Android's or Apple's. On Android that normally means the audio goes to Google's speech service to be turned into text. That audio never reaches SellBot's servers; we only ever receive the finished text, and only once you send the message. If you would rather it never left the handset, don't use the microphone button — type instead.

4. Who else sees data

Shopify (OAuth, billing, webhooks). Your chosen AI provider — Anthropic, OpenAI, or Google — receives conversation messages and product context to write replies; none of them train public models on it. Amazon SES sends transactional email. Expo, with Apple and Google's push services, delivers phone alerts, which means it sees the push token and the alert text. Railway hosts the application and database.

On paid plans you can bring your own AI key, in which case requests go straight from SellBot to the provider you chose, and your own email service, in which case shopper emails leave through your provider instead of ours.

5. How long we keep it

  • Chat transcripts auto-delete after 30 days. Export anything you want to keep from the Inbox first.
  • Store settings and the catalogue cache last as long as your subscription.
  • Aggregate counts — how many chats, how many escalations — outlive the 30 days, but carry no message content.
  • A shopper's email stays until you delete it or they unsubscribe.
  • Phone device names and push tokens go the moment a phone is unpaired or revoked.
  • Everything else goes when you uninstall, via Shopify's shop_redact webhook — about 48 hours later.

6. Deleting your data

You can do all of this yourself, today, without asking us:

  • A paired phone's data. In the phone app open Settings and tap Unpair this device. Or, from the SellBot admin, open the Team tab and choose Revoke next to that phone. Either one deletes the device record and its push token immediately.
  • A shopper's email. Delete it from the waitlist in the SellBot admin, or the shopper can use the unsubscribe link in any email we send them.
  • A conversation. Transcripts delete themselves after 30 days. To remove one sooner, ask us at the address below.
  • Everything. Uninstall SellBot from your Shopify admin. Shopify sends us a redaction webhook and all of your store's data is deleted, normally within 48 hours.

You can also just email contact@sellbot.org and ask us to delete it, and we will. Tell us your store domain so we can find the right records.

7. Your rights

If you are in the EU or UK, we process data to provide the app you installed, and you may ask for access, correction, erasure, or a portable copy at any time. We are the processor for your merchant data and a joint controller for shopper data you choose to collect. If you are in California, we do not sell personal information, and you may ask what we hold and have it deleted. We honour Shopify's GDPR webhooks automatically, so uninstalling is enough on its own.

8. Security

Everything travels over HTTPS. If you bring your own AI key it is encrypted at rest with AES-256-GCM and the decryption key never leaves the application server. Phone pairing uses single-use QR codes that are burned on first scan and expire shortly if never used. Database backups are encrypted, engineer access is least-privilege, and access logs are kept for 90 days.

9. Contact

Questions, or a request about your data: contact@sellbot.org.

CurrencyWiki Technologies LLC · sellbot.org