DobroChat — Privacy Policy
Effective date: July 16, 2026
DobroChat (“the App”, “we”, “us”) is a Shopify application that provides merchants with an omnichannel messaging inbox: it connects messaging channels (such as Telegram and Viber) to a Shopify store so the merchant can talk to their customers, sell in chat and send order updates from one place.
For the personal data of a store’s customers, the merchant is the data controller and DobroChat acts as a data processor on the merchant’s behalf. This policy describes what data the App handles, why, where it is stored and how it is deleted.
1. Information we collect
From the merchant (store):
- Store domain and Shopify access tokens required for the App to operate;
- API credentials of messaging channels the merchant connects (e.g. a Telegram bot token or Viber auth token). These are stored encrypted at rest (AES-256-GCM);
- Billing plan status, app settings, quick replies and operator notes.
From the store’s customers (buyers), only when they message the store:
- Messenger identifiers and profile data provided by the channel (user ID, name or username, avatar);
- The content of chat messages, including attachments the customer sends;
- A phone number or e-mail address, if the customer shares one or if the merchant links the conversation to an existing Shopify customer;
- Order and delivery data from Shopify (order number, status, tracking number) used to send order updates into the same chat.
We do not collect payment card data. Checkout happens on Shopify’s own pages.
2. How we use this data
- Displaying and delivering chat conversations between the merchant and customers;
- Linking a conversation to the corresponding Shopify customer and their orders;
- Sending automatic order and delivery status updates to the customer’s chat;
- Providing in-chat selling tools (product cards, checkout links);
- Operating AI-assist features inside Shopify admin (Shopify Sidekick), which read conversation data only at the merchant’s request and within Shopify admin;
- Billing, support and abuse prevention.
We do not sell personal data, do not use it for advertising and do not share it with third parties except the service providers listed below.
3. Where data is stored (subprocessors)
- Vercel — application hosting (serverless, USA);
- Neon — PostgreSQL database where conversations and settings are stored (USA, us-east region);
- Shopify — store, customer and order data within the merchant’s own Shopify account;
- Messaging platforms the merchant connects (Telegram, Viber, etc.) — message delivery according to their own privacy policies.
All data is transmitted over TLS. Incoming webhooks are verified (HMAC).
4. Data retention and deletion
- Chat history is retained according to the merchant’s billing plan: 180 days on plans with limited retention, or without a time limit on the unlimited plan. Older messages are deleted automatically; contacts, customer links, tags and notes are kept.
- After a plan change, a 7-day grace period applies before the new retention policy is enforced.
- When the App is uninstalled, channel connections are deactivated immediately and the store’s data is permanently deleted after a short reinstall grace period of about 14 days — in any case within the 30-day window required by Shopify. Reinstalling within that period restores connections and history.
5. GDPR and Shopify mandatory privacy webhooks
The App implements all three mandatory Shopify privacy webhooks:
customers/data_request— the merchant receives a downloadable JSON export of everything the App stores about the requested customer (available in the App’s Settings);customers/redact— the customer’s conversations, messages, attachments and identifiers are deleted, and personal data is scrubbed from any remaining records;shop/redact— after a store uninstalls the App, all of that store’s data is permanently erased.
6. Customer (buyer) rights
Buyers who wish to access or delete their personal data should contact the store (merchant) they messaged — the merchant controls that data and can trigger export or deletion through Shopify. You may also contact us directly at the address below and we will assist.
7. Changes to this policy
We may update this policy as the App evolves. The current version is always available at this address; the effective date above reflects the latest revision.
8. Contact
Questions about privacy or data handling: personal@matcher.store