DobroChat — Privacy Policy
Effective date: September 24, 2026
DobroChat (“the App”, “we”, “us”) is a Shopify application that provides merchants with an omnichannel messaging inbox: it connects messaging channels (such as Telegram and Viber) to a Shopify store so the merchant can talk to their customers, sell in chat and send order updates from one place.
For the personal data of a store’s customers, the merchant is the data controller and DobroChat acts as a data processor on the merchant’s behalf. This policy describes what data the App handles, why, where it is stored and how it is deleted.
1. Information we collect
From the merchant (store):
- Store domain and Shopify access tokens required for the App to operate;
- API credentials of messaging channels the merchant connects (e.g. a Telegram bot token or Viber auth token). These are stored encrypted at rest (AES-256-GCM);
- Billing plan status, app settings, quick replies and operator notes.
From the store’s customers (buyers), only when they message the store:
- Messenger identifiers and profile data provided by the channel (user ID, name or username, avatar);
- The content of chat messages, including attachments the customer sends;
- A phone number or e-mail address, if the customer shares one or if the merchant links the conversation to an existing Shopify customer;
- Order and delivery data from Shopify (order number, status, tracking number) used to send order updates into the same chat.
We do not collect payment card data. Checkout happens on Shopify’s own pages.
2. How we use this data
- Displaying and delivering chat conversations between the merchant and customers;
- Linking a conversation to the corresponding Shopify customer and their orders;
- Sending automatic order and delivery status updates to the customer’s chat;
- Providing in-chat selling tools (product cards, checkout links);
- Creating a Shopify draft order for the customer when a merchant’s agent clicks “Create order” in a conversation (only if the merchant granted the optional draft-order permission). The draft order is stored in the merchant’s own Shopify store — with the items, any discount the agent applied, the linked Shopify customer or, for B2B buyers, their company, company location and that location’s billing and shipping address — and its invoice link is sent to the customer in the same chat. DobroChat does not keep its own copy of the draft order;
- Operating AI-assist features inside Shopify admin (Shopify Sidekick), which read conversation data only at the merchant’s request and within Shopify admin;
- Operating the optional AI agent, if the merchant enables it — see section 3a below for exactly what is sent, to whom, and how to turn it off;
- Billing, support and abuse prevention.
We do not sell personal data, do not use it for advertising and do not share it with third parties except the service providers listed below.
3. Where data is stored (subprocessors)
- Vercel — application hosting (serverless, USA);
- Neon — PostgreSQL database where conversations and settings are stored (USA, us-east region);
- Shopify — store, customer and order data within the merchant’s own Shopify account;
- Messaging platforms the merchant connects (Telegram, Viber, etc.) — message delivery according to their own privacy policies.
- OpenAI, Anthropic or Google (USA) — only if the merchant enables the optional AI agent and supplies their own API key. See section 3a.
All data is transmitted over TLS. Incoming webhooks are verified (HMAC).
3a. The optional AI agent
A merchant may connect an AI provider (OpenAI, Anthropic or Google) to draft or send replies in chat. This feature is off by default and works only after the merchant enters their own API key from that provider. The merchant’s contract for that key is with the AI provider directly; we transmit data to it on the merchant’s instruction.
When the feature is enabled, the following is sent to the chosen AI provider:
- recent messages of the conversation being answered, with email addresses, phone numbers and anything resembling a credential removed before sending;
- a small extract of the store catalogue (product titles, prices, availability) relevant to the question;
- data about the customer in that conversation: their recent orders — order number, date, total, payment and delivery status, ordered items, tracking number and order status link — and the name of their B2B company and its locations, where applicable. This is what allows the agent to answer “where is my order”. The customer’s email address and phone number are not sent.
Providers used for this purpose, in addition to the subprocessors listed above: OpenAI, Anthropic and Google (USA) — whichever the merchant selects. We do not use this data to train any model, and we ask providers not to retain it beyond serving the request. Data is sent only at the moment a reply is being prepared; we do not upload conversation or order history in bulk.
Important, for Google Gemini free-tier keys. Google states that content submitted on the Gemini API free tier may be used to improve Google products. That is a term of the merchant’s own key, not of this app, and it applies to the chat text we transmit on the merchant’s behalf. A merchant who does not want customer messages used this way should use a paid (billing-enabled) Gemini key or choose another provider.
A merchant can disable the feature at any time in the app’s Settings, or remove the API key, after which nothing further is sent to the AI provider.
4. Data retention and deletion
- Chat history is retained according to the merchant’s billing plan: 180 days on plans with limited retention, or without a time limit on the unlimited plan. Older messages are deleted automatically; contacts, customer links, tags and notes are kept.
- After a plan change, a 7-day grace period applies before the new retention policy is enforced.
- When the App is uninstalled, channel connections are deactivated immediately and the store’s data is permanently deleted after a short reinstall grace period of about 14 days — in any case within the 30-day window required by Shopify. Reinstalling within that period restores connections and history.
5. GDPR and Shopify mandatory privacy webhooks
The App implements all three mandatory Shopify privacy webhooks:
customers/data_request— the merchant receives a downloadable JSON export of everything the App stores about the requested customer (available in the App’s Settings);customers/redact— the customer’s conversations, messages, attachments and identifiers are deleted, and personal data is scrubbed from any remaining records;shop/redact— after a store uninstalls the App, all of that store’s data is permanently erased.
6. Customer (buyer) rights
Buyers who wish to access or delete their personal data should contact the store (merchant) they messaged — the merchant controls that data and can trigger export or deletion through Shopify. You may also contact us directly at the address below and we will assist.
7. Changes to this policy
We may update this policy as the App evolves. The current version is always available at this address; the effective date above reflects the latest revision.
8. Contact
Questions about privacy or data handling: personal@matcher.store