Privacy Policy

Effective date: April 1, 2026  ·  Last updated: September 1, 2026

ShieldDesk ("we", "our", or "us") is an AI-powered customer support tool for Shopify merchants, operated by Approid Technologies. This Privacy Policy explains what data we collect, why we collect it, how we store and share it, and the rights available to you — whether you are a merchant (store owner) or an end customer (someone who submitted a contact form).

We do not sell personal data. We do not use customer data for advertising or model training. Data is processed solely to deliver the ShieldDesk service.

1. Roles: Data Controller vs. Data Processor

Under data protection laws such as the GDPR, it is important to distinguish between two roles:

In respect of merchant account data (shop domain, access tokens, billing information), Approid Technologies is the data controller.

Merchants are responsible for ensuring they have a lawful basis to share their customers' personal data with us, and for notifying their customers that their support messages may be processed by an AI tool.

2. Data We Collect

Merchant account data (collected when a merchant installs the App):

Customer message data (collected when a customer submits a contact form on a merchant's Shopify store):

We do not collect payment card details, passwords, or any data beyond what is listed above.

3. Legal Basis for Processing (GDPR)

For merchants and customers in the European Economic Area (EEA) or United Kingdom, we rely on the following legal bases:

Data typeLegal basis
Merchant account data (shop domain, access token)Performance of a contract — necessary to provide the service the merchant has subscribed to.
Customer message data processed on behalf of the merchantLegitimate interests of the merchant (providing customer support) and performance of the merchant's contract with their customer. The merchant is responsible for establishing their own lawful basis with their customers.
Billing and subscription dataPerformance of a contract and compliance with legal obligations.

4. Why We Collect It

All data collected is used exclusively to provide the ShieldDesk service:

We do not use this data for advertising, analytics sold to third parties, or AI model training on our end.

5. How We Store It

All data is stored in Supabase, a managed cloud database platform. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Supabase infrastructure is hosted on AWS and holds SOC 2 Type II certification.

Our application backend is hosted on Render, a cloud application platform based in the United States. Render processes data in transit but does not persist application data independently.

Merchant account data (shop domain, access tokens) is stored in a dedicated table with row-level access restricted to the ShieldDesk backend. Customer messages are stored in a separate table, always scoped to the specific shop domain to ensure strict data isolation between merchants.

5b. Features that process additional data

These capabilities are off unless a merchant turns them on, and each is limited to what the feature needs:

Customer phone numbers and shipping addresses are read only for the enquiry being handled, are shown only to the merchant's staff inside the app, and are deleted under the same retention and redaction rules as all other data.

Where messages are shown inside Shopify — ShieldDesk also surfaces messages the merchant already holds, without collecting anything further: a block on the Shopify order page listing that customer's messages, answers to questions the merchant asks Shopify's Sidekick assistant (for example "anything urgent from customers?"), triggers and actions for Shopify Flow so the merchant can build their own automations, and an optional daily digest emailed to the merchant. These read data already described above and send nothing to the end customer.

6. Sub-processors and Third-Party Sharing

We share data with the following sub-processors to deliver the service:

Sub-processorPurposeData sharedLocation
Anthropic (Claude API) AI message classification and draft reply generation Customer message content, order context United States
Supabase Database storage All data listed in Section 2 United States (AWS)
Render Application hosting and serving Data in transit only — not persisted United States
Mailgun (Sinch) Sending support replies and merchant notifications by email; receiving support email that a merchant forwards to ShieldDesk Customer email address, message content, reply content United States (EU region available)
Meta Platforms (WhatsApp Business Platform) — only when a merchant connects their own WhatsApp Business account Receiving customer WhatsApp messages and sending replies Customer phone number, WhatsApp profile name, message content Per Meta's data policy
Shopify Billing, webhook delivery, OAuth Subscription status, app events Global

Anthropic does not use API inputs to train their models by default. Their data handling is governed by Anthropic's Privacy Policy.

We do not share data with any other third party, and we do not sell data under any circumstances.

7. International Data Transfers

ShieldDesk is operated from India. Our sub-processors (Anthropic, Supabase, Render, Mailgun) are based in the United States; Meta processes WhatsApp data under its own policy when a merchant enables that channel. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, please be aware that your data will be transferred to and processed in countries that may not have the same data protection standards as your country.

We rely on the following safeguards for international transfers: standard contractual clauses (where applicable) and processing only through sub-processors who maintain appropriate certifications (SOC 2, ISO 27001). By using the App, you consent to these international transfers as described in this Policy.

8. Data Retention

Customer messages (name, email, message body, AI classification, draft reply) are retained for as long as the merchant's account is active. Merchants may request deletion of specific customer records at any time by contacting us. We aim to fulfil deletion requests within 30 days.

Merchant account data is retained for as long as the App is installed. When a merchant uninstalls the App, we revoke their access token and retain a minimal record (shop domain, uninstall date) for up to 90 days to support reinstallation. Merchants may request full deletion of all records at any time.

When a Shopify GDPR shop/redact webhook is received (typically 48 hours after uninstallation), we permanently delete all data associated with that shop, including all customer messages and the merchant account record.

9. Merchant Rights

As a merchant using ShieldDesk, you have the right to:

To exercise any of these rights, email us at support@approidtech.com. We will respond within 30 days.

10. End Customer Rights — GDPR & CCPA

If you are an end customer (a person who submitted a contact form on a Shopify store that uses ShieldDesk), your message was processed on behalf of that merchant. The merchant is the primary data controller for your data. Please contact the merchant's store directly for most data requests.

However, you may contact us directly at support@approidtech.com to exercise the following rights:

Please include your email address and the Shopify store domain where you submitted your message. We will respond within 30 days (10 business days for CCPA requests).

If you are in the EEA/UK and believe your rights have not been addressed, you have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national data protection authority in the EU).

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:

No system is perfectly secure. If you discover a potential security issue, please report it to support@approidtech.com promptly.

12. Cookies and Tracking

ShieldDesk does not use cookies, tracking pixels, or any third-party analytics. The merchant dashboard uses browser sessionStorage solely to remember whether the onboarding wizard has been shown in the current browser session. This data is never transmitted to our servers and is cleared when the browser tab is closed.

13. Children's Data

The App is not intended for use by or in connection with individuals under 16 years of age. Merchants must not use the App to process messages from individuals they know to be under 16 without appropriate verified parental consent.

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 14 days' advance notice via the App or by email to the address associated with your Shopify account. Continued use of the App after the notice period constitutes your acceptance of the updated Policy.

15. Contact

For privacy-related questions, data requests, or deletion requests, contact us at:

Approid Technologies
Email: support@approidtech.com

We will acknowledge your request within 5 business days and resolve it within 30 days.