Effective August 30, 2026
Privacy Policy
Shopkeeper helps merchants manage support conversations and customer context. This policy explains what information we collect, how we use it, and the choices available to customers and merchants.
Information We Collect
We collect account and workspace information, including names, email addresses, organization names, team membership, authentication identifiers, billing status, and settings chosen by a merchant.
Merchants may connect email, Shopify, Instagram, and other support channels. Those integrations can send us customer names, email addresses, social account identifiers, order context, message content, attachments, and conversation metadata needed to provide support workflows.
We also collect product usage, device, log, and diagnostic data such as request metadata, error reports, webhook delivery status, and security events. Payments are processed by Stripe; we store payment status and identifiers, not full payment card numbers.
We use PostHog for limited product analytics. Shopkeeper sends server-side events tied to a pseudonymous internal workspace identifier, such as onboarding progress, integration connection status, and whether key support workflows succeeded. We do not send names, email addresses, message content, prompts, integration credentials, or connected-platform payloads to PostHog, and we do not use PostHog browser tracking, cookies, session replay, or person profiles.
How We Use Information
We use information to provide the service, authenticate users, route and display support messages, generate AI-assisted drafts and summaries, send merchant-approved replies, process billing, prevent abuse, troubleshoot issues, and improve reliability.
We do not sell personal information. We do not use merchant customer message content to train general purpose AI models.
Google Workspace API Data
When a merchant connects Gmail, Shopkeeper uses Google Workspace APIs to identify the connected account, read inbox messages and attachments addressed to the merchant's configured support address, create and continue visible support tickets, and send merchant-approved replies from the connected account. Shopkeeper stores the normalized message content, attachments, delivery metadata, and Gmail identifiers needed to provide those support features, prevent duplicate tickets, preserve conversation threading, and recover delayed synchronization.
Google Workspace API data is shared only with infrastructure and AI service providers as necessary to provide and secure these user-facing support features, and with authorized members of the merchant's workspace. It is not sold, used for advertising, or used to create, train, or improve a general-purpose AI model. Shopkeeper's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Meta Platform Data (Instagram)
When a merchant connects an Instagram professional account, Shopkeeper requests two permissions. Instagram Business Basic (instagram_business_basic) identifies the connected account so the merchant can confirm which account is linked and so incoming messages route to the correct workspace. Instagram Business Manage Messages (instagram_business_manage_messages) receives the direct messages people send to that account and delivers merchant-approved replies back to the sender. Shopkeeper does not request access to a merchant's posts, comments, insights, followers, or advertising data.
From those permissions Shopkeeper stores the message text, accepted media attachments, the Instagram-scoped sender identifier, the sender's Instagram name, username, and profile picture, and the provider timestamps and message identifiers returned by Meta. That data creates the visible support ticket, prevents duplicate tickets, preserves conversation threading, and records that a reply was delivered. Attachments are stored privately and can be opened only by authenticated members of the merchant's workspace.
Meta Platform Data is shared only with the infrastructure and AI service providers needed to provide and secure these user-facing support features, and with authorized members of the merchant's workspace. It is not sold, not used for advertising or ad targeting, not used to build profiles of people independently of the merchant relationship, and not used to create, train, or improve a general-purpose AI model. Shopkeeper's use of Meta Platform Data follows the Meta Platform Terms and Developer Policies.
A merchant can disconnect Instagram at any time from Settings, then Integrations, which revokes Shopkeeper's access and unsubscribes the account so no further messages are delivered. Deleting data Shopkeeper has already received is covered by our data deletion instructions.
How We Share Information
We share information with service providers that help operate Shopkeeper, including hosting, database, email, product analytics, observability, billing, authentication, and AI infrastructure providers. These providers may only use information to deliver services to us.
We may share information with connected platforms as directed by a merchant, to comply with law, to protect rights and safety, or as part of a merger, financing, or sale of business assets.
Retention and Deletion
We retain account, workspace, support, and integration data while the merchant account is active or as needed for legitimate business, legal, security, and compliance purposes. Merchants can request export or deletion by contacting hello@useshopkeeper.com. Our data deletion instructions explain who may request deletion, what is removed, and how long it takes.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including tenant-scoped access controls, signed webhooks, production secret separation, encryption in transit, and operational monitoring. No system is perfectly secure, and merchants should keep their own account credentials and connected platform access secure.
Your Choices
Depending on where you live, you may have rights to access, correct, export, delete, or object to certain processing of personal information. Merchants are responsible for responding to customer privacy requests, and Shopkeeper helps merchants complete those requests for data stored in the service.
Contact
Questions or requests can be sent to hello@useshopkeeper.com.