Privacy Policy — Statiq Support Agent
Last updated: 17 July 2026
Statiq Support Agent (“the App”) is provided by Statiq Labs (“we”, “us”). This policy explains what personal data the App processes when a merchant installs it on their Shopify store, why we process it, and how long we keep it.
Contact: srichakraborty1111@gmail.com
1. Who does what
The merchant who installs the App is the data controller for their customers’ personal data. We act as a data processor on the merchant’s behalf, processing data only to provide the App’s customer support functionality and only on the merchant’s instructions.
2. What we process
From the merchant’s store, when a store visitor asks a support question, the App reads the following through Shopify’s Admin API in order to answer it:
- Order information (order number, status, fulfillment and shipping status, line items)
- Customer name and email address, used only to locate the correct order
- Product and inventory information
This data is read from Shopify at the time of the request and used to generate an answer. We do not copy customer records or order records into our own database.
From the merchant, on install:
- The store’s myshopify domain
- An encrypted Shopify API access token
Store visitor conversations:
- The text of messages exchanged with the support assistant, stored so a conversation can continue across messages
Conversation records are not linked to a customer ID or customer account. We do not maintain customer profiles.
3. Why we process it
To provide AI-powered customer support on behalf of the merchant: answering questions about order status, products, and store policies. We do not use personal data for any other purpose. We do not sell personal data, and we do not use it to train AI models.
4. Sub-processors
The App shares data with the following service providers, strictly to deliver the service:
| Sub-processor | Purpose |
|---|---|
| Google (Gemini API) | Generates support responses from message content |
| Supabase | Database hosting |
| Vercel | Application hosting |
These providers process data on our instructions as processors. They do not use it for their own purposes.
5. How long we keep it
- Conversation messages: deleted automatically 90 days after they are created, by a scheduled daily purge job.
- Store credentials and configuration: kept while the App is installed. When a merchant uninstalls, Shopify sends a
shop/redactrequest and we delete the store’s record and all associated conversations and messages. - Order and customer data: not retained. It is read live from Shopify for each request and is not stored.
- Compliance request logs: we keep a record of privacy requests received, for audit purposes.
6. Merchant and customer rights
We support Shopify’s mandatory compliance webhooks:
customers/data_request— a customer’s request for their datacustomers/redact— a customer’s request for erasureshop/redact— deletion of all store data after uninstall
Because the App does not store customer identifiers or customer records, there is generally no customer personal data held to return or erase; we log every such request and act on it within the timeframes Shopify requires.
Store visitors who wish to make a request should contact the merchant whose store they used. Merchants can contact us at the address above.
7. Security
- All data is transmitted over HTTPS/TLS.
- Data is encrypted at rest.
- Shopify API access tokens are additionally encrypted using AES-256-GCM.
- Access to production systems is limited to authorised personnel.
8. International transfers
We are based in India, and our service providers operate infrastructure in various countries. Where personal data is transferred internationally, we rely on appropriate safeguards, including standard contractual clauses where required.
9. Automated processing
The App uses a large language model to generate support responses. It does not make automated decisions that produce legal effects or similarly significant effects concerning any individual.
10. Changes
We may update this policy. The “last updated” date above will change, and material changes will be communicated to merchants.
11. Contact
Questions or requests: srichakraborty1111@gmail.com