Back to the store ↗

KINDERAI / PRIVACY POLICY

Privacy Policy

Pre-launch draft — owner confirmation required.
This page is not a finalized statement of production practices. Clearly marked TODOs must be completed and checked against the app before public launch or submission.

Who is responsible

KinderAI is operated by Andreas Christofi, a physical person. Privacy enquiries: [email protected]. KinderAI provides tools for Shopify merchants to help shoppers and review store conversations. A merchant determines how its store uses shopper information. KinderAI’s role for each processing activity must be specified in the final policy and any data processing agreement.

TODO — CONFIRM DATA PRACTICE: Confirm postal address, controller/processor roles, effective date and applicable representative or DPO details.

Information and sources

The product includes customer messages and saved conversation history, product and store knowledge, merchant settings, leads (including contact details a shopper chooses to share), and Shopify-connected features. Depending on enabled features and permissions, records may include shopper contact details, product variants, order information and support-ticket content. Store Recommendations uses a 30-day Shopify performance window; this is not a retention period.

TODO — CONFIRM DATA PRACTICE: Confirm the exact Shopify API scopes and fields, protected customer data access, merchant account/billing fields, identifiers, IP addresses, cookies, device data, diagnostic logs and every collection source. Remove categories not processed.

Purposes and lawful basis

The intended uses are to answer shopper questions, supply store context, maintain conversation history, surface buying friction, suggest merchant actions, generate store recommendations and handle support. Merchants remain responsible for deciding what changes or offers to approve.

TODO — CONFIRM DATA PRACTICE: Map each actual processing activity to its purpose and applicable lawful basis. Identify consent-dependent features, optional data, and any automated decisions with legal or similarly significant effects.

AI processing and service providers

Messages and store context may need to be sent to an AI service to generate responses or recommendations. The final policy must identify the actual recipients and describe what they receive. No promise that customer data is excluded from model training is made in this draft.

TODO — CONFIRM DATA PRACTICE: Name AI providers and subprocessors, list data sent to each, link their applicable terms, confirm model-training settings, provider retention, abuse-monitoring exceptions, human access and contractual restrictions. Confirm hosting, database, logging, support and billing providers.

Retention, deletion and uninstall

Conversation history is part of the product. A final retention schedule must explain how long each record is kept and what happens when a merchant deletes data, uninstalls the app or closes an account.

TODO — CONFIRM DATA PRACTICE: Specify active storage periods, backups, log retention, legal-hold exceptions, deletion deadlines and Shopify privacy-webhook handling. Verify actual implementation before publishing these commitments.

Processing locations and safeguards

The final policy must explain where data is hosted and processed and any international transfers. Security measures should describe implemented controls without promising absolute security.

TODO — CONFIRM DATA PRACTICE: Confirm countries/regions, transfer mechanisms, access controls, encryption, incident procedures and relevant contractual safeguards.

Your choices and privacy requests

Shoppers should contact the merchant whose store they used for requests about that store’s records. Merchants can raise a privacy enquiry through KinderAI’s in-app support assistant. People without app access can email [email protected].

TODO — CONFIRM DATA PRACTICE: Confirm mailbox monitoring and the identity-verification process; explain applicable access, correction, deletion, restriction, objection, portability, consent withdrawal and regulator complaint rights, including response periods.

This website, cookies and changes

The homepage product interactions are illustrative local demos; they do not connect to a Shopify store. The website loads externally hosted fonts. Hosting and external services may receive request metadata when pages or resources load. The website is separate from the production app.

TODO — CONFIRM DATA PRACTICE: Audit hosting logs, external font requests, analytics and cookies; state actual providers, purposes, retention and consent controls. Add effective date and the process for notifying material policy changes.