Privacy Policy
Effective date: 3rd September 2026
Introduction
Welcome to Sendvisor. Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email reply service and related features (collectively, the "Services").
Information we collect
When you use Sendvisor, we may collect the following types of information:
- Personal Information: When you sign up, we may collect your name, email address, and billing details.
- Email Data: Email threads and content you submit to the Services for AI reply generation.
- Connection Data: Information from services that you choose to connect, including store identifiers, authorised access scopes, and encrypted access credentials.
- Merchant Customer Data: When a merchant enables a Shopify connection, we may process the customer email address, order number and date, payment and fulfilment status, line items, and shipment tracking details needed to answer a customer enquiry. We do not request customer postal addresses or phone numbers for this feature.
- Usage Data: Analytics on how you interact with our Services, including IP addresses, browser type, and pages visited.
- Cookies and Tracking Technologies: We may use cookies and similar technologies to enhance user experience and analyse site traffic. Where we use non-essential cookies, we will ask for your consent first.
How we use your information
We use the information we collect to:
- Provide and improve our Services, including AI reply generation.
- Personalise your experience with configured tones, language, and locale preferences.
- Secure and maintain our platform, preventing fraud or abuse.
- Match an authenticated email sender to relevant Shopify orders and provide factual order context for a support reply.
- Communicate updates, or important service notifications.
Shopify and merchant customer data
For personal data contained in a merchant's connected store or support inbox, the merchant determines why that data is processed and instructs Sendvisor to process it to provide the Services. Merchants are responsible for having an appropriate lawful basis, providing required notices, and communicating applicable customer consent and opt-out decisions to us.
Shopify access is limited to the capabilities a merchant enables. Order data is requested only when an incoming support message requires it, and only when the sender's email authentication passes our identity checks. We use the authenticated sender address to restrict the order search to that customer. Product catalogue data may be retrieved separately because it is not customer-specific.
We use merchant customer data only to provide, secure, support, and maintain the merchant-requested Services. We do not sell merchant customer data, use it for targeted advertising, or use it to make decisions that produce legal or similarly significant effects. Sendvisor produces suggested email replies; merchants can configure review, editing, approval, and rejection controls.
Sharing your information
We do not sell your personal data. However, we may share information in the following cases:
With service providers: We work with trusted third parties (e.g. hosting providers, payment processors, AI providers) to deliver our Services.
Legal compliance: If required by law, we may disclose information to comply with legal obligations or protect Sendvisor's rights.
Business transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the new entity.
Data storage and security
We use technical and organisational safeguards designed to protect personal data. These include encrypted transport, encryption of connection credentials at rest, access controls, authenticated application sessions, sender-authentication checks before customer-specific order retrieval, and monitoring and logging used to operate and secure the Services. Production backups are encrypted and access-restricted.
Access to merchant customer data is limited to authorised personnel and service providers who need it to operate, secure, or support the Services. We review access following role changes and do not use production customer data as test fixtures. Test and production environments use separate application configuration and storage paths.
We maintain procedures for investigating, containing, documenting, and remediating suspected security incidents. Where required, we will notify affected merchants and competent authorities in accordance with applicable law. No online service can guarantee absolute security, so we recommend strong, unique passwords and two-factor authentication.
Data retention
We retain personal data only for as long as needed to provide the Services, meet legal obligations, resolve disputes, and maintain security. Our current operational retention periods are:
- Email messages, generated drafts, and associated Shopify connection context are scheduled for deletion after 30 days.
- Processed raw inbound email files are scheduled for deletion after seven days.
- Inbound email authentication records are kept for seven days when unclaimed and 30 days after association with a message.
- Encrypted backups follow a limited rotating retention schedule and expire separately from active systems.
We may retain limited records for longer where required by law, to establish or defend legal claims, or to investigate abuse or security events.
Your rights and choices
Depending on your location, you may have the following rights:
- Access & correction: Request a copy of your data or correct inaccuracies.
- Deletion: Request to delete your account and associated data.
- Opt-out: Unsubscribe from marketing communications at any time.
- Restriction, objection, and portability: Ask us to restrict or object to certain processing, or provide eligible data in a portable form.
- Cookie preferences: Manage cookies through your browser settings.
To exercise any of these rights, please contact us at [email protected].
Requests from merchant customers
If your data was provided to Sendvisor by a merchant whose store or support inbox you contacted, please contact that merchant first. We will assist the merchant with verified access, correction, deletion, restriction, consent, and opt-out requests as required by applicable law and our agreement with the merchant. Merchants may disconnect Shopify at any time to stop new retrieval through that connection.
Third-party links and connections
Sendvisor may integrate with third-party tools or contain links to external sites. We are not responsible for their privacy practices, and we encourage you to review their policies before using their services.
To provide the Services, personal data may be processed by infrastructure, email delivery, monitoring, payment, AI, and connected-service providers, including Shopify where a merchant enables that connection. We limit disclosures to what is reasonably necessary for the relevant service and require providers to protect the data under applicable contractual and legal obligations.
Automated abuse prevention
We use Cloudflare Turnstile on authentication forms to protect the Services from automated abuse. Turnstile processes limited browser and network signals on our behalf to distinguish human visitors from automated traffic. For more information, see Cloudflare's Turnstile Privacy Addendum.
International transfers
Some service providers may process data outside the country where it was collected. Where required, we use recognised transfer safeguards or rely on an applicable adequacy mechanism.
Children's privacy
Sendvisor is not intended for children under 13, and we do not knowingly collect data from minors. If you believe a child has provided us with personal information, please contact us for removal.
Changes to this policy
We may update this Privacy Policy periodically. Any changes will be posted on this page with the "Effective Date" updated accordingly. Your continued use of Sendvisor after any changes constitutes acceptance of the revised policy.
Contact us
If you have any questions about this Privacy Policy, please contact us at [email protected].