Privacy Policy
Last Updated: May 17, 2026
1. Introduction
ZenSell.ai (“we”, “our”, “us”) operates the ZenSell.ai API and the WooCommerce ZenSellAgent plugin. This Privacy Policy explains what data we collect from merchants who install our plugin, how we use it, and their rights.
This policy does not apply to the end customers of the merchants' stores — merchants are responsible for their own store customers' data.
2. Data We Collect
During plugin setup
- WooCommerce store URL
- WordPress admin email address
- Auto-generated, read-only WooCommerce REST API credentials (generated locally by WordPress and sent to ZenSell.ai to enable product sync)
Product catalog data (for AI search)
- Product names, descriptions, prices, categories, and stock status from the merchant's WooCommerce store
- This data is processed by OpenAI's API to generate semantic search vectors (embeddings) and stored in our database
Chat conversation data
- Text messages exchanged between store visitors and the AI agent
- Conversation messages are processed by OpenAI's API (GPT-4o-mini model) to generate responses
- We store conversation logs for up to 90 days
Revenue attribution
- When a WooCommerce order is completed, the plugin sends: order total (numeric value only) and product IDs
- No customer names, email addresses, or personally identifiable information are transmitted for attribution
Billing
- Subscription and payment processing is handled entirely by Stripe, Inc. We do not store any credit card or payment data on our servers.
3. How We Use the Data
- To provision and operate the AI agent (product sync, chat responses)
- To calculate revenue attribution (which chat conversations led to completed sales)
- To manage your subscription and enforce plan conversation limits
- To send transactional emails (provisioning confirmation, billing notifications)
- We do not sell, rent, or share merchant data with third parties for advertising or marketing purposes
4. Data Storage & Security
- Merchant and conversation data is stored in Supabase (managed PostgreSQL database)
- Backend compute runs on Hetzner Cloud servers in the EU (Germany)
- All data in transit is encrypted via HTTPS/TLS
- Each merchant's data is isolated — no data is shared between stores (multi-tenant)
- API access requires a secret API key and is HTTPS-only
- Conversation logs are automatically deleted after 90 days
5. Third-Party Data Processing
When you use ZenSell.ai, your data is processed by these sub-processors:
| Sub-processor | Purpose | Privacy policy |
|---|---|---|
| OpenAI, Inc. | AI chat responses (GPT-4o-mini) & product embeddings (text-embedding-3-small) | openai.com/policies/privacy-policy |
| Stripe, Inc. | Payment processing and subscription management | stripe.com/privacy |
| Supabase, Inc. | Database hosting (managed PostgreSQL) | supabase.com/privacy |
| Hetzner Cloud GmbH | Backend server compute (EU, Germany) | hetzner.com/legal/privacy-policy |
Important note on AI processing: Product catalog data and chat messages are sent to OpenAI to generate responses and embeddings. By using ZenSell.ai, you acknowledge and accept this processing. OpenAI is contractually bound not to use API data to train their models (as per their API usage policies).
6. Merchant Rights (GDPR)
If you are based in the EU/EEA, you have the right to:
- Access — request a copy of all data we hold about your store
- Deletion — request deletion of all your data and account
- Portability — receive your data in a machine-readable format
- Objection — object to specific processing activities
To exercise these rights, email: team@zensell.ai. We process all requests within 30 calendar days.
7. Data Retention
| Data type | Retention period |
|---|---|
| Tenant account and settings | Until account deletion |
| Product embeddings | Until re-sync or account deletion |
| Conversation logs | 90 days |
| Attribution events | 12 months |
| Billing records | 7 years (legal requirement) |
8. Changes to This Policy
We may update this policy. We will notify merchants by email at least 14 days before any material change takes effect. Continued use of the service after the effective date constitutes acceptance.
9. Contact
For privacy questions or data requests:
Email: team@zensell.ai
Support: suporte@zensell.ai
Website: https://zensell.ai