Vendora
Legal

Privacy Policy

What we collect, why, and how we protect it.

Last updated: July 15, 2026

Vendora is an AI sales-assistant app for Shopify stores. This policy explains what information we process when a merchant installs Vendora and when a shopper interacts with the storefront widget. We act as a data processor on behalf of the merchant, who remains the controller of their shoppers’ data.

Information we process

  • Store data. When a merchant installs Vendora, we read catalog data (products, variants, collections, pages, blog articles, and store policies) through the Shopify API to power product recommendations.
  • Account data. The store domain, access token, plan, and the merchant’s app configuration (agent name, tone, colors, and similar settings).
  • Conversation data. Messages a shopper sends to the widget and the agent’s replies, so the assistant can hold a coherent conversation and add items to the cart. We also use these conversations to monitor and improve the quality of the assistant, as described in How we use chat conversations below.
  • Order and customer lookup data. When enabled for a store, Vendora may read limited order and customer information to support order-status questions after shopper verification and to link chat-captured leads to existing Shopify customers in the merchant admin. Vendora does not write customer or order data.
  • Usage events. Anonymous interaction events (for example: widget opened, message sent, product viewed, item added to cart) used for merchant-facing analytics. These events never contain message text or personal identifiers.

How we use it

  • To answer shopper questions using only the store’s real catalog.
  • To recommend products and add them to the Shopify cart.
  • To support order-status questions and assisted-order attribution when the merchant has granted the required read-only Shopify permissions.
  • To show merchants aggregate analytics about widget usage.
  • To monitor the quality of the assistant, detect and fix errors, and improve the chat experience for the merchant’s shoppers (see How we use chat conversations below).
  • To operate, secure, and improve the service.

We do not sell personal data, we do not use it for advertising, and we do not use conversations to train third-party AI models.

How we use chat conversations

Beyond powering each live conversation, we review chat activity to keep the assistant accurate and helpful. Concretely, we use conversations to:

  • run the assistant during the conversation — understanding the shopper’s request, recommending real catalog products, and adding items to the cart;
  • monitor quality automatically. An automated monitor samples recent replies to catch failure patterns — for example, the assistant saying it added something it did not, promising a discount that does not exist, or not showing products a shopper clearly asked for — so we can correct them quickly;
  • debug and improve the chat. When a problem is flagged, our team looks at the relevant message so we can reproduce and fix it, then add a regression test so it does not happen again.

Personal identifiers are hidden in these quality reviews. Before a flagged message reaches our internal alerts or logs, we automatically remove personal details such as names, email addresses, and phone numbers, replacing them with a placeholder. For quality work we only need to see the type of error and the shape of the message — not who the shopper is. This work exists to make the chat better for each merchant’s customers; we do not use it to build shopper profiles, to advertise, or to sell data.

Subprocessors

We rely on a small number of infrastructure providers to deliver the service:

  • OpenAI — generates embeddings and written chat responses for the storefront assistant.
  • Supabase — hosts our database (catalog, settings, conversations, and analytics events).
  • Railway — hosts the application runtime.
  • Shopify — the platform our app runs on and the source of catalog and cart data.

Data retention

Catalog and configuration data is kept while the app is installed. Conversations and analytics events are retained to provide history and analytics, and are removed on request or when the app is uninstalled and the store record is redacted under Shopify’s GDPR webhooks.

Your choices

  • Merchants can uninstall the app at any time, which stops all processing.
  • Data deletion requests are honored through Shopify’s mandatory privacy webhooks (customer redact, shop redact).

Contact

Questions about this policy? Email info@workrol.com.