Privacy Policy
Effective date: August 4, 2026
1. Introduction
InsiGage ("we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our customer experience platform.
InsiGage is distributed both directly and as an app on the Shopify App Store. Sections 5 to 8 describe how we handle data belonging to Shopify merchants and their shoppers.
2. Our Two Roles
We are a controller of data about the merchants and staff who hold InsiGage accounts — the account, usage, and technical data described in section 3.
We are a processor of data about the shoppers who talk to a merchant through InsiGage. That data belongs to the merchant, who decides why it is collected and how long it is kept. We act on the merchant's instructions. If you are a shopper and you want to access or delete your data, contact the store you were talking to; you may also contact us and we will route your request to that merchant.
3. Information We Collect
Account information: Name, email address, company name, and website URL provided during registration.
Usage data: Pages visited, features used, and interaction patterns within the platform.
Customer data: Chat messages, tickets, and knowledge base content you create through the Service.
Technical data: IP address, browser type, device information, and cookies for session management.
Shopper data: When a shopper uses the chat widget on a merchant's storefront, we process their messages, the page they are viewing, and their cart contents. Where the merchant's storefront provides it, we also process the shopper's name, email address, phone number, and Shopify customer identifier.
4. How We Use Your Information
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To send transactional emails (verification codes, notifications)
- To provide customer support
- To analyze usage patterns and improve performance
- To generate AI-assisted replies to shopper messages, as described in section 6
We do not use shopper conversations to train our own machine learning models, and we do not sell personal information.
5. Shopify Store Data
When a merchant installs InsiGage from the Shopify App Store, the merchant grants the app a set of permissions. We request only the following, and use them only as stated:
- read_customers — to show an agent who they are talking to
- read_orders — to show an agent a verified shopper's recent orders alongside the conversation
- read_themes, write_themes — to install and configure the chat widget in the merchant's theme
- read_own_subscription_plans, write_own_subscription_plans — to manage the merchant's InsiGage subscription through Shopify Billing
Order data is retrieved only for shoppers whose identity the merchant's storefront has cryptographically verified to us. For all other shoppers, no order data is requested or displayed.
6. AI Processing
InsiGage uses Google's Gemini API to draft replies to shopper messages and to index knowledge base articles for search. To do this, the content of a shopper's message, recent conversation history, and relevant help article text are sent to Google as a processor on our behalf. No account credentials or payment details are sent.
An AI-handled conversation is passed to a human agent when the shopper asks to speak to a person, or when the conversation exceeds a configured number of AI turns.
7. Sub-processors
We rely on the following providers to operate the Service. Each is bound by contract to protect the data it handles:
- Neon — managed PostgreSQL database hosting (Singapore region)
- Railway — application and API hosting
- Vercel — hosting for this website, including bot-detection on form submissions
- Cloudflare — content delivery, object storage, and DNS
- Google (Gemini API) — AI reply generation and text embeddings
- Google (Google Ads) — advertising conversion measurement on this website
- PostHog — product analytics and session recording (EU region)
- Pusher — real-time message delivery
- Resend — transactional email delivery
- Cal.com — scheduling for booked calls
- Slack — internal notification of website enquiries and booked calls
- Sentry — error monitoring
- Axiom — application logging
- Shopify — app distribution, authentication, and billing for merchants who install via the Shopify App Store
We will update this list before adding a sub-processor that handles personal data.
8. Shopify Data Requests and Deletion
As required of every Shopify App Store app, we implement Shopify's mandatory privacy webhooks and respond to them automatically:
- customers/data_request — when a shopper asks a merchant for their data, we return the shopper's stored profile together with their conversations and messages.
- customers/redact — when a shopper's erasure is requested, we anonymize their profile, delete their custom attributes, visitor and session records, page views, article feedback, and analytics events, and remove their name from stored messages.
- shop/redact — sent by Shopify 48 hours after a merchant uninstalls the app. We delete all of that store's data across every part of the platform, including conversations, messages, tickets, knowledge base articles, customer records, and the organization itself.
Each request is verified against Shopify's HMAC signature before it is acted on, and each deletion runs as a single atomic transaction.
9. Data Storage and Security
Your data is stored on secure servers with encryption at rest and in transit. We use industry-standard security measures including TLS encryption, role-based access controls, tenant isolation, and encrypted storage of third-party credentials.
Our primary database is hosted in Singapore (ap-southeast-1). If you are located in the European Economic Area or the United Kingdom, your data is transferred outside that area; we rely on the European Commission's Standard Contractual Clauses as the transfer mechanism.
10. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers: The sub-processors listed in section 7
- Legal requirements: When required by law or to protect our rights
- Business transfers: In connection with a merger, acquisition, or sale of assets, subject to this policy
11. Your Rights (GDPR)
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Export your data in a portable format
- Withdraw consent for data processing
- Lodge a complaint with your local supervisory authority
We rely on the following legal bases: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (for non-essential cookies), and legal obligation (where retention is required by law).
12. Your Rights (California)
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request its deletion, to request correction, and to be free from discrimination for exercising those rights.
We do not sell personal information. This website uses advertising conversion measurement; where that constitutes sharing for cross-context behavioral advertising, you may opt out by declining non-essential cookies in the consent banner. To exercise any of the rights above, use the contact address in section 17.
13. Cookies
We use the following cookies on this site: a strictly-necessary consent cookie (records your privacy preference; set immediately without prior consent; expires in 6 months), analytics cookies from PostHog (session replay and event tracking to help us understand how visitors use the site), and ads-measurement cookies from Google(conversion tracking via Google Ads / gtag). For visitors in the UK and EEA, PostHog and Google analytics/ads cookies are only set after you explicitly accept via the consent banner shown on first visit — they are never fired before consent is granted. Outside the UK and EEA, these cookies are enabled automatically on page load. You may decline at any time using the consent banner; if you decline, only the strictly-necessary consent cookie is set. You can also manage cookie preferences through your browser settings.
14. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law.
For merchants who installed through Shopify, uninstalling the app causes Shopify to send theshop/redact request 48 hours later, and all store data is deleted at that point rather than after 30 days.
15. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
16. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or through the Service.
17. Contact
For privacy-related questions or to exercise your rights, contact us at privacy@insigage.com.