Privacy Policy
Effective 7 October 2026
This policy explains what personal data AstaDesk (“AstaDesk”, “we”) handles when merchants use our AI customer support service and when their customers contact them through it, why we handle it, and the choices and rights you have.
1. Who this policy covers and our role
- Merchants (our customers who create a AstaDesk account). For their account and billing data, we decide how the data is used (we are the “controller”).
- Shoppers (the merchant's customers who email or chat with a store that uses AstaDesk). For this data we act only on the merchant's instructions, as a “processor” or “service provider”. The merchant's own privacy policy also applies, and shoppers can contact the store directly about their data.
2. Data we collect
- Account data: name, email address, password (stored only as a secure hash), store name and settings.
- Connected store data: when a merchant connects Shopify, we read orders, fulfilment and tracking details, products and customer details needed to answer support questions. Access tokens are encrypted.
- Support conversations: emails forwarded to AstaDesk and messages sent through the store chat, including the sender's name and email if provided, plus replies, drafts and internal notes.
- Billing data: plan, subscription status and invoices, handled by Stripe. We do not store card numbers.
- Usage and technical data: counts of AI replies, error reports (with personal data removed) and basic server logs.
The store chat keeps a random identifier in the shopper's browser storage so the conversation continues across pages. We only store a one-way hash of it. We do not use advertising or tracking cookies. Our dashboard uses only the cookies needed to keep you signed in.
3. How we use data
- To provide the service: receive messages, look up store data, draft and send replies, and show them in the inbox.
- To carry out actions a merchant explicitly approves (for example a refund or cancellation in Shopify).
- To bill subscriptions, prevent abuse (for example rate limits and email loop protection) and keep the service secure.
- To fix errors and improve reliability.
- To communicate with merchants about their account and important changes.
We do not sell personal data, and we do not use support conversations to train AI models. Legal bases (where GDPR or UK GDPR applies): performance of our contract with merchants, our legitimate interests in running a secure service, and legal obligations.
4. AI processing
Replies are drafted by an AI model using only the conversation, the merchant's policies and the store data needed for the question. Merchants choose whether replies are sent automatically or reviewed first. Refunds, cancellations and address changes are never carried out without a merchant's approval. AI output can be wrong, which is why conversations can always be taken over by a person.
5. Service providers
We share data only with providers that help us run AstaDesk, under contracts that protect it:
- Supabase: Database, authentication and real-time updates
- Vercel: Application hosting
- Anthropic: AI model that drafts replies (data is not used to train its models)
- Inngest: Background job processing
- Postmark: Receiving and sending support email
- Stripe: Subscription billing and payments (AstaDesk never sees full card numbers)
- Shopify: Store data you connect (orders, products, customers)
- Sentry: Error monitoring, with personal data removed before reports are sent
Some providers process data outside your country, including in the United States and the European Union. Where required, transfers are protected by safeguards such as the EU Standard Contractual Clauses.
6. Retention and deletion
- We keep account and conversation data while the merchant's account is active.
- When a shopper asks a store to delete their data, Shopify notifies us and we delete that shopper's conversations automatically. When a store uninstalls AstaDesk, we delete its shoppers' data 48 hours later unless the store reconnects.
- Merchants can ask us to delete their whole account. We then delete their data, except what we must keep by law (for example invoices).
7. Security
Data is encrypted in transit. Each store's data is isolated at the database level, Shopify access tokens are encrypted with AES-256, every incoming webhook is verified, and access to production systems is restricted. No system is perfectly secure, but we work to protect your data and will notify affected merchants of a breach as required by law.
8. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or California privacy laws), you may have the right to access, correct, delete or export your personal data, and to object to or restrict certain processing. We do not sell or share personal data for cross-context advertising.
Shoppers: please contact the store you spoke with first. It controls your data and we will help it respond. Merchants and anyone else: contact us at the support contact shown in your AstaDesk dashboard (Settings). You may also complain to your local data protection authority.
9. Children
AstaDesk is a business service and is not directed at children under 16.
10. Changes and contact
We will update this page when our practices change and, for material changes, notify merchants by email or in the dashboard. Questions: the support contact shown in your AstaDesk dashboard (Settings).