Last updated: 27 August 2026
Gökhan Doğu TAN ("we") provides SellMind, an AI sales assistant that Shopify merchants install on their storefront. This policy explains what SellMind does with personal data.
We act as a data processor on behalf of the merchant, who is the data controller for their shoppers' data.
| Data | Why | Consent required |
|---|---|---|
| A random visitor id we generate | Keeps a conversation together across page loads | No — functional |
| Messages typed into the chat | To answer the question | No — functional |
| Cart snapshot: token, item count, total, item titles | To recommend add-ons and offer to help finish an order | No — functional |
| Shopify customer id (only when signed in) | Recognise a returning shopper; match a later order | Yes |
| Email address (from the order) | Match an order to an earlier conversation when no other identifier exists | Yes |
| Order id, order number, total, currency, date | Show the merchant the revenue the assistant produced | Yes |
| Search terms that returned nothing | Tell the merchant what shoppers looked for and could not find | No — the term alone, not who typed it |
| Questions the shop had no answer for | Tell the merchant what is worth writing an answer for | No — the question alone, not who asked it |
| An email address, and optionally a name, typed into the assistant's own form | So the merchant can reply about what the shopper asked | Yes — the shopper enters it themselves |
| Whether that shopper also agreed to marketing | Decide what the merchant may send to that address | Yes — a separate box, never pre-ticked |
| The storefront language the shopper is browsing in | Answer in their language and show the merchant's translated wording | No — functional |
When a shopper asks about their own order, the assistant reads that order's status, items and tracking from Shopify and shows it back to them. It is released only to someone who has proved they are entitled to it: either Shopify has signed them in, or they supplied both the order number and the email address on that order. The details are shown in the chat and are not stored.
The merchant can read the conversations from their own storefront inside the app. That is the point of the product — it is how they see what shoppers ask and answer anyone who needs a person.
Where the shopper has not allowed analytics tracking, SellMind still answers their questions, but stores no customer id or email and never links their order to their conversation. We read that decision from Shopify's Customer Privacy API on every request.
A merchant can switch this on. When they have, the assistant may offer a form — a real field the shopper types into, with an unticked box beside it — where there is a reason to follow up, such as an item that is out of stock. It asks at most once per conversation, never before it has helped, and never as a condition of answering. The address is read from that field only: the assistant is not permitted to take one out of a chat message, and none is written into the transcript.
Agreeing to be replied to is not agreeing to be marketed to. The two are stored separately and shown separately to the merchant, and an address given without the box ticked is marked "reply only" everywhere it appears. SellMind does not send email of any kind; the merchant follows up from their own tools.
The shopper can decline the form, and the address is erased with the rest of their conversation — by the retention sweep, or immediately on a Shopify customers/redact webhook, which matches an address given here as readily as one Shopify already knew.
A merchant can let shoppers have replies read aloud, and dictate instead of typing. Both are off unless the merchant turns them on.
Reading aloud uses the browser's own speech synthesis and never leaves the shopper's device. Dictation is different: it uses the browser's speech recognition, and in most browsers — Chrome and Edge among them — the audio is sent to the browser vendor to be turned into text. That processing is the browser's, not ours, and is governed by the browser vendor's privacy policy. We never receive the audio, never store it, and nothing is recorded until the shopper presses the microphone button themselves. The transcribed text is put into the message box for them to read and send, exactly as if they had typed it.
Neither feature is required to use the assistant with a screen reader. The chat log is a live region, so a screen reader announces every reply whether these are switched on or not.
We do not collect postal addresses or phone numbers, and we ask for a name only alongside the email form. We do not use cookies for advertising, and we do not sell personal data.
Shop domain, shop contact email, currency, plan and subscription status.
We do not use personal data for any other purpose, and we do not use shopper data to train AI models.
SellMind uses these sub-processors:
| Sub-processor | Purpose | Data |
|---|---|---|
| Anthropic (Claude API) | Generating the assistant's replies | The shopper's message, the running conversation, product titles and prices, and a summary of the cart |
| Railway | Hosting and database | All data described above |
| Shopify | Store platform | Order and customer data, via the APIs the merchant authorised |
| Cloudflare (R2) | Storing encrypted backups | The nightly database backup, encrypted with AES-256-GCM before it leaves our servers. Cloudflare cannot read it |
Shopper messages are sent to Anthropic to produce a reply. We do not send email addresses, customer ids or order data to Anthropic. Anthropic does not train models on data submitted through its API.
We share personal data with no one else, and we never sell it.
| Data | Retention |
|---|---|
| Conversations, messages, chat events | 90 days after the shopper's last message, then deleted automatically |
| Webhook delivery records | 30 days |
| Attributed order figures (order number, total, currency) | Kept for the merchant's reporting. Once the conversation expires, this record no longer identifies anyone |
| Merchant account data | Until the app is uninstalled and Shopify's shop/redact webhook arrives, then erased |
The conversation window is configurable per deployment via DATA_RETENTION_DAYS.
Shoppers exercise their rights through the merchant whose store they visited. When a merchant or Shopify sends us a request, we act on it:
customers/data_request webhook. We report the records held and provide an export within 30 days.customers/redact webhook. Every conversation belonging to that customer is deleted, along with its messages and events.shop/redact webhook. All data for that shop is deleted.Requests can also be sent directly to <sellmindai@gmail.com>.
read_products and read_ordersSee Incident Response for how we handle a breach.
The database and application run in EU West (Amsterdam, Netherlands). Shopper messages are sent to Anthropic in the United States to generate a reply — that is the only transfer of personal data outside the EEA, and it covers chat messages only, never email addresses, customer ids or order data. That transfer relies on the Standard Contractual Clauses in Anthropic's data processing addendum.
We will update this page when our processing changes, and update the date above.
Gökhan Doğu TAN sellmindai@gmail.com
For written correspondence, request a postal address at the email above.