Privacy Policy

Last updated: August 26, 2026

rezlo ("we", "us") provides AI customer-support software for Shopify stores. This policy explains what data we process, why, and the choices merchants and their customers have. Questions: support@rezlo.app.

Data we process, and why

  • Merchant account data — your store's domain, name, and the configuration you set (store description, answers, rules, greetings). Used to run your agent.
  • Store content you connect — catalog, policies, and pages read via Shopify's APIs or, when you run Auto-setup, from your own public storefront. Used to ground the agent's answers in your store's real facts.
  • Conversations — chat messages and phone-call transcripts between your customers and the agent, including details a customer volunteers (such as an order number, ZIP code, email, or phone number). Stored so you can review every transcript, handle handoffs, and see usage.
  • Order data — when a customer asks about their order and verifies themselves, the agent reads that order's status from Shopify to answer. We display order details in your admin inbox; we do not sell or share them.
  • Usage metrics — conversation and call counts per store, used for plan limits and your dashboard.

Subprocessors

Data flows only through the services needed to provide the product:

  • Shopify — store data via the APIs you authorize at install.
  • DeepSeek — the language model that generates answers; conversation content is sent for processing to produce a reply.
  • Twilio — telephony for the phone line (call routing and audio transport).
  • Deepgram — speech-to-text and text-to-speech for phone calls.
  • OVHcloud — the servers where the application and its database run.

We do not sell personal data, and we do not use one store's data to serve another store.

Retention and deletion

  • Conversation transcripts are retained for at most 13 months; configuration is retained while the app is installed.
  • Uninstalling the app triggers deletion of your store's data from our systems, in line with Shopify's data-removal requirements.
  • Merchants can request earlier deletion of any data at support@rezlo.app.
  • Customer data requests (access or erasure) forwarded by Shopify's GDPR webhooks are honored.

Security

All traffic is encrypted in transit (TLS). Access tokens and secrets are stored server-side and never exposed to browsers or third parties. Each store's data is isolated per tenant; one store can never read another's conversations, orders, or settings.

Your customers

The chat widget and phone agent identify themselves as your store's assistant. Customers should only be asked for the minimum needed to help them (for example, an order number and ZIP code to check an order). Merchants are responsible for disclosing the use of automated support in their own store policies where local law requires it.

Changes

We'll update this page when the policy changes and note the date above. Material changes will be announced inside the app.