DobroChat — Privacy Policy

Effective date: September 24, 2026

DobroChat (“the App”, “we”, “us”) is a Shopify application that provides merchants with an omnichannel messaging inbox: it connects messaging channels (such as Telegram and Viber) to a Shopify store so the merchant can talk to their customers, sell in chat and send order updates from one place.

For the personal data of a store’s customers, the merchant is the data controller and DobroChat acts as a data processor on the merchant’s behalf. This policy describes what data the App handles, why, where it is stored and how it is deleted.

1. Information we collect

From the merchant (store):

From the store’s customers (buyers), only when they message the store:

We do not collect payment card data. Checkout happens on Shopify’s own pages.

2. How we use this data

We do not sell personal data, do not use it for advertising and do not share it with third parties except the service providers listed below.

3. Where data is stored (subprocessors)

All data is transmitted over TLS. Incoming webhooks are verified (HMAC).

3a. The optional AI agent

A merchant may connect an AI provider (OpenAI, Anthropic or Google) to draft or send replies in chat. This feature is off by default and works only after the merchant enters their own API key from that provider. The merchant’s contract for that key is with the AI provider directly; we transmit data to it on the merchant’s instruction.

When the feature is enabled, the following is sent to the chosen AI provider:

Providers used for this purpose, in addition to the subprocessors listed above: OpenAI, Anthropic and Google (USA) — whichever the merchant selects. We do not use this data to train any model, and we ask providers not to retain it beyond serving the request. Data is sent only at the moment a reply is being prepared; we do not upload conversation or order history in bulk.

Important, for Google Gemini free-tier keys. Google states that content submitted on the Gemini API free tier may be used to improve Google products. That is a term of the merchant’s own key, not of this app, and it applies to the chat text we transmit on the merchant’s behalf. A merchant who does not want customer messages used this way should use a paid (billing-enabled) Gemini key or choose another provider.

A merchant can disable the feature at any time in the app’s Settings, or remove the API key, after which nothing further is sent to the AI provider.

4. Data retention and deletion

5. GDPR and Shopify mandatory privacy webhooks

The App implements all three mandatory Shopify privacy webhooks:

6. Customer (buyer) rights

Buyers who wish to access or delete their personal data should contact the store (merchant) they messaged — the merchant controls that data and can trigger export or deletion through Shopify. You may also contact us directly at the address below and we will assist.

7. Changes to this policy

We may update this policy as the App evolves. The current version is always available at this address; the effective date above reflects the latest revision.

8. Contact

Questions about privacy or data handling: personal@matcher.store