Legal
Privacy Policy
Last updated July 2026
1. Information We Collect
We collect information you provide directly — your name, email address and store details when you create an account or connect a Shopify store — plus the customer support content (emails, chats, tickets) that flows through the Service so the AI can act on it.
2. How We Use Your Information
We use your information to provide, maintain and improve the Service, including training your store's AI agent on your products, policies and writing style. We do not sell your data to third parties, and we never use your customers' data to train models for other merchants.
3. Shopify Data Access
When you install PhilDesk on your store, we request only the OAuth scopes needed to read orders, products and policies and to act on support requests you've authorized (for example, issuing a refund). We store this data securely and use it solely to power your store's automation — see our Security page for details.
5. Data Security
We use industry-standard technical and organizational measures to protect your information, including encryption in transit and at rest for sensitive credentials — see our Security page for specifics.
6. Data Retention
We retain account and conversation data for as long as your account is active, plus a limited period afterward for legal, accounting and fraud-prevention purposes. You can request earlier deletion at any time — see Your Rights below.
7. Third-Party Services
We rely on a small number of trusted providers to run the Service — for example Stripe for payment processing, our cloud infrastructure host, and AI model providers for generating replies. These providers only access what they need to perform their function on our behalf and are bound by their own confidentiality and security obligations.
8. Your Rights (GDPR / CCPA)
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
To exercise any of these rights — including a full account and data deletion request — email us at [email protected] and we'll respond within a reasonable timeframe, consistent with GDPR, CCPA and other applicable privacy laws.
9. International Data Transfers
Our infrastructure is primarily hosted in the EU (see Security). Where data is transferred internationally — for example to a service provider outside the EU — we rely on appropriate safeguards such as standard contractual clauses.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We'll post any material changes on this page with a new "last updated" date.
11. Contact Us
Questions about this Privacy Policy or your data? Email [email protected].