Privacy Policy
keepo! (operated by keeponi, "we", "us") provides a Shopify app that helps merchants recover abandoned carts and engage customers over WhatsApp. This policy explains what personal data we collect, why, how long we keep it, and what rights individuals have.
1. Data we collect
From Shopify merchants (account holders):
- Account email + name + hashed password (if signing up via keeponi.com)
- Shopify shop domain, scopes, encrypted access token
- WhatsApp connection metadata (phone number, instance state)
From the merchant's customers (synced from Shopify):
- Customer name, email, phone, marketing consent state
- Order count + lifetime total spend, last order date
- Abandoned cart contents (line items, totals, checkout URL)
- Messages sent + delivery / read status from WhatsApp
2. Why we collect it
- To deliver the core service — sending recovery messages to customers who abandoned a cart
- To show the merchant a dashboard of who's queued, sent, converted
- To enforce send-window + opt-out rules + monthly quotas
- To bill the merchant via Shopify Billing
3. How long we keep it
We retain personal data for as long as the merchant has the app installed. When the merchant uninstalls, Shopify sends a shop/redact webhook 48 hours later; we cascade-delete the entire store record (including all customer data) within 48 hours of receipt. Individual customers can request erasure via the merchant; we process Shopify's customers/redact webhook within 30 days.
4. Who we share with
We do not sell personal data. We share it only with infrastructure providers strictly required to run the service:
- Railway (cloud hosting, EU/US regions)
- WA-API / WhatsApp (message delivery)
- Anthropic (AI agent responses; only the conversation text is sent, no customer PII beyond what's in the message body)
- Shopify (our origin source for all customer data; we read from their API)
5. Security
All access tokens and webhook secrets are encrypted at rest (AES-256-GCM). Database connections use TLS. We use bcrypt (cost 12) for merchant passwords. We log access events and review them for anomalies.
6. Your rights (GDPR / CCPA)
Individual customers have the right to access, correct, port, or delete their data. Requests should go to the merchant whose store the data belongs to (we don't have a direct relationship with end customers). Merchants can submit a request on a customer's behalf via Shopify's customer-data-request flow.
7. International transfers
Data may be processed in the United States and the European Union. Where applicable we rely on Standard Contractual Clauses to enable lawful international transfers.
8. Changes
We'll update this policy as the service evolves. Material changes will be communicated via email to the merchant's account address.
9. Contact
Questions? Email privacy@keeponi.com.