Privacy Policy
Last Updated: July 5, 2026
1. Introduction
ZenSell.ai ("we", "our", "us", operated by ZenSell.ai, located at C. Alejandro Dumas, 17, Carretera de Cádiz, 29004 Málaga) operates the ZenSell.ai API, the WooCommerce ZenSellAgent plugin, and the ZenSell AI Shopify app. This Privacy Policy explains what data we collect from merchants who install our plugin or app, how we use it, and their rights.
While merchants act as the Data Controllers for their store's end customers, ZenSell.ai acts as a Data Processor for the chat conversation logs and order data processed by our plugin/app. We offer a Standard Contractual Clauses (SCCs)-based Data Processing Addendum (DPA) for merchants upon request by contacting team@zensell.ai.
2. Data We Collect
During WooCommerce plugin setup
- WooCommerce store URL
- WordPress admin email address
- Auto-generated, read-only WooCommerce REST API credentials (generated locally by WordPress and sent to ZenSell.ai to enable product sync)
During Shopify app installation
- Shopify shop domain and storefront domain
- Merchant admin email address and shop name
- A Shopify API access token with read-only scopes (read_products, read_orders), stored encrypted at rest (AES-256)
Product catalog data (for AI search)
- Product names, descriptions, prices, categories, variants, and stock status from the merchant's WooCommerce or Shopify store
- This data is processed by OpenAI's API to generate semantic search vectors (embeddings) and stored in our database
Chat conversation data
- Text messages exchanged between store visitors and the AI agent
- Conversation messages are processed by OpenAI's API (GPT-4o-mini model) to generate responses
- We store conversation logs for up to 90 days
Revenue attribution
- When a WooCommerce order is completed, the plugin sends: order total (numeric value only) and product IDs
- On Shopify, the orders/create webhook sends us the order ID, order total, line items, and an anonymous chat-session token stored in the cart attributes — this token is what links a sale back to an AI conversation
- No customer names, addresses, or phone numbers are transmitted for attribution
Order status lookups (chat feature)
- When a store visitor asks the chat about their order, they may type their order number or the email address used at checkout; we use it only to look up that order's status in the merchant's store and show the answer in the chat
- The email address is not stored beyond the conversation log and is never used for marketing
Billing
- Subscription and payment processing is handled entirely by Stripe, Inc. We do not store any credit card or payment data on our servers.
3. How We Use the Data
- To provision and operate the AI agent (product sync, chat responses)
- To calculate revenue attribution (which chat conversations led to completed sales)
- To manage your subscription and enforce plan conversation limits
- To send transactional emails (provisioning confirmation, billing notifications)
- We do not sell, rent, or share merchant data with third parties for advertising or marketing purposes
4. Cookies and Local Storage
We use strictly necessary cookies and local storage (such as HTML5 LocalStorage) to operate our services:
- On the Merchant's Storefront: The ZenSell chat widget uses local storage to maintain the active chat session and conversation history as visitors navigate between store pages (on both WooCommerce and Shopify storefronts). No marketing or tracking cookies are set by the widget.
- On our Website and Dashboard: We use session cookies and tokens to authenticate merchants logging into the ZenSell dashboard or the Shopify embedded admin, and lightweight analytics to monitor platform performance.
5. Data Storage & Security
- Merchant and conversation data is stored in Supabase (managed PostgreSQL database)
- Backend compute runs on Hetzner Cloud servers in the EU (Germany)
- All data in transit and at rest is encrypted (HTTPS/TLS for transit, AES-256 for data at rest); platform access tokens are additionally encrypted with a dedicated key (Fernet)
- Each merchant's data is isolated — no data is shared between stores (multi-tenant)
- API access requires a secret API key and is HTTPS-only
- Conversation logs are automatically deleted after 90 days
- For Shopify stores, we honor Shopify's mandatory GDPR webhooks: customer contact data is redacted on customers/redact requests, and all shop data (catalog, conversations, attribution) is permanently deleted approximately 48 hours after the app is uninstalled (shop/redact)
6. Third-Party Data Processing
When you use ZenSell.ai, your data is processed by these sub-processors:
| Sub-processor | Purpose | Privacy policy |
|---|---|---|
| OpenAI, Inc. | AI chat responses (GPT-4o-mini) & product embeddings (text-embedding-3-small) | openai.com/policies/privacy-policy |
| Stripe, Inc. | Payment processing and subscription management (WooCommerce merchants) | stripe.com/privacy |
| Shopify Inc. | Billing API for subscription management (Shopify merchants) | shopify.com/legal/privacy |
| Supabase, Inc. | Database hosting (managed PostgreSQL) | supabase.com/privacy |
| Hetzner Cloud GmbH | Backend server compute (EU, Germany) | hetzner.com/legal/privacy-policy |
Important note on AI processing and Data Transfers: Product catalog data and chat messages are sent to OpenAI to generate responses and embeddings. By using ZenSell.ai, you acknowledge and accept this processing. OpenAI is contractually bound not to use API data to train their models. For transfers of EU/EEA data to US-based processors (OpenAI, Stripe, Supabase, Shopify), we rely on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms to ensure compliance.
7. Merchant Rights (GDPR & US State Laws)
If you are based in the EU/EEA or certain US states (such as California), you have rights regarding your personal data:
- Access & Portability — request a copy or machine-readable transfer of all data we hold about your store
- Deletion — request deletion of all your data and account
- Objection & Restriction — object to or restrict specific processing activities
- Do Not Sell/Share — We do not sell or share your personal data with third parties for advertising or marketing purposes.
To exercise these rights, email: team@zensell.ai. We process all requests within 30 calendar days.
For Shopify stores, data-subject and shop deletion requests are also handled automatically through Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) — no email needed.
8. Children's Privacy
Our services are not directed to children under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal data from children. If we learn we have collected personal data from a child, we will delete it immediately.
9. Data Retention
| Data type | Retention period |
|---|---|
| Tenant account and settings | Until account deletion |
| Product embeddings | Until re-sync or account deletion |
| Conversation logs | 90 days |
| Attribution events | 12 months |
| Billing records | 7 years (legal requirement) |
| Shopify shop data (catalog, conversations, attribution) | Purged ~48h after app uninstall (shop/redact webhook) |
| Customer email typed in chat | Redacted on customers/redact request; otherwise follows conversation log retention |
10. Changes to This Policy
We may update this policy. We will notify merchants by email at least 14 days before any material change takes effect. Continued use of the service after the effective date constitutes acceptance.
11. Contact
For privacy questions, DPA requests, or data rights:
Email: team@zensell.ai
Support: suporte@zensell.ai
Website: https://zensell.ai