Privacy Policy
Last updated: September 28, 2026
1. Overview
Zactar ("we", "our", or "us") provides customer support workflow software for Shopify merchants through a Chrome browser extension and backend API services. This Privacy Policy describes how we collect, use, process, and protect your information and that of your customers when you install and use our services.
2. Shopify Protected Customer Data & Scope of Access
When a merchant authorizes Zactar on Shopify, we request access to orders, fulfillments, and customer contact details strictly for the purpose of Customer Support. Specifically:
- Order Context: Order number, line items, fulfillment status, tracking numbers, and delivery checkpoint events.
- Customer Details: Customer name and email address to match inbound support threads.
- Minimal Storage: Customer order details retrieved from Shopify are processed in memory to generate support drafts and context panels. We do not keep a database of your customers' personal information. The only per-customer records we hold are an encrypted one-hour draft cache and a pseudonymised access log, both described in Section 6.
3. Chrome Extension & Gmail Data Handling
Our Chrome extension runs locally in your browser. When viewing a message on mail.google.com, it identifies the sender email or order number to query context from your connected Shopify store. Zactar:
- Does NOT read, scan, or store your private personal inbox.
- Does NOT sell or monetize email data.
- Does NOT automatically send emails without your review and approval in v1.
4. AI Processing
We use Google Gemini API to generate draft replies. Customer inquiry text and order facts are sent to the model via secure, encrypted enterprise endpoints. Google's API terms state that customer data sent via API is not used to train public foundation models.
5. GDPR, CCPA & Shopify Mandatory Webhooks
We strictly honor Shopify's mandatory privacy compliance webhooks:
- customers/data_request: Reports any customer data associated with a shop. We hold no customer profile, only the pseudonymised access-log entries described in Section 6.
- customers/redact: Deletes that customer's access-log entries. Cached drafts expire within one hour on their own.
- shop/redact: Purges all merchant tokens, settings, and cache within 48 hours of app uninstall.
6. Data Retention
We keep personal data only as long as it is needed to provide the service:
- Email content: never stored. It is processed in memory to produce a draft.
- Draft cache: a generated draft and the order facts behind it are cached, encrypted, for at most 1 hour so reopening the same email is instant.
- Access log: each lookup of customer data is logged with the store, the paired browser, the action and the time. Customer emails and order IDs in the log are replaced with keyed one-way hashes. Entries are deleted automatically after 90 days, or sooner on a
customers/redactorshop/redactrequest. - Store records: the store's access token, paired browsers and settings are deleted when the app is uninstalled and on
shop/redact. Aggregate usage counts, which contain no personal data, are kept for billing and product analytics. - Backups: our hosting provider (DigitalOcean) takes automatic server backups, which are rotated out on its retention schedule (at most 4 weeks). Tokens and cached drafts inside them are already encrypted by us.
7. Security
- Encryption: all traffic uses TLS. Shopify access tokens and cached drafts are encrypted at rest (AES with HMAC authentication), so they stay encrypted in any database copy or backup.
- Separate environments: testing uses Shopify development stores, a separate database and separate encryption keys. Production data is never used for testing.
- Access control: production systems are reachable only by Zactar's operator, over SSH keys, with two-factor authentication on every account that can reach customer data. Every read of customer data is logged.
- Incident response: if we confirm a security incident affecting personal data, we contain it, rotate affected credentials, and notify affected merchants and Shopify without undue delay and within 72 hours, so merchants can meet their own notification duties.
8. Contact Us
If you have any questions or data deletion requests, contact us at: support@zactar.com.