Privacy Policy
Proposed Effective Date: August 3, 2026 | Last Updated: August 3, 2026
1. Who We Are
ShopAssist is an AI shopping assistant for eCommerce stores. It helps shoppers discover, compare, understand, and buy products through a conversational interface.
The company responsible for the processing described in this Privacy Policy is:
Kremic Ventures UG (haftungsbeschränkt)
trading as ShopAssist
Liselotte-Herrmann-Straße 12
10407 Berlin, Germany
Managing Director: Tim Kremic
Commercial Register: HRB 237823, Amtsgericht Berlin-Charlottenburg
2. When ShopAssist Is Controller and When It Is Processor
ShopAssist acts as an independent Controller for personal data used to operate its website, respond to inquiries, manage Merchant accounts and contracts, process billing, provide support, and run its own business operations.
When a shopper uses ShopAssist on a Merchant's eCommerce store, the Merchant generally determines why and how the shopper data is used. The Merchant is the Controller, and ShopAssist acts as the Merchant's Processor under the ShopAssist Data Processing Agreement.
ShopAssist supports production integrations with Shopify, WooCommerce, BigCommerce, and Magento. Integrations are installed and managed directly by ShopAssist or an authorised ShopAssist reseller partner, including through custom API implementation and a signed sales contract.
3. Personal Data We Process as Controller
3.1 Inquiries, demos, and communications
When a person contacts us, books a demo, or communicates with ShopAssist, we may process:
- name and business contact details;
- company, role, and store information;
- communication content and attachments;
- meeting, scheduling, and follow-up information; and
- technical metadata associated with the communication.
We process this information to respond to requests, take steps toward a contract, manage business relationships, and protect our legitimate business interests. The legal bases are Article 6(1)(b) and Article 6(1)(f) GDPR and, where applicable, consent under Article 6(1)(a) GDPR.
3.2 B2B prospecting and sales intelligence
ShopAssist uses Apollo.io and other lawful business sources to identify and contact potentially relevant business customers. We may obtain:
- name and business contact details, including business email address and telephone number;
- employer, job title, professional role, responsibilities, and office location;
- professional social-media profile and employment history;
- company, industry, and business information; and
- prospecting, enrichment, verification, engagement, and inferred-interest information.
We process this information to identify relevant B2B prospects, verify and enrich business contact records, conduct permitted sales outreach, and manage our sales pipeline. The legal basis is our legitimate interest in marketing ShopAssist to relevant business customers under Article 6(1)(f) GDPR. Where consent or another requirement applies to a particular communication channel, we will contact a prospect only where that requirement is satisfied.
Individuals may object to direct marketing at any time by contacting privacy@getshopassist.com or using the opt-out method in the relevant communication.
Apollo may obtain business contact information from public sources, professional profiles, customers, contributors, and third-party data providers. Apollo may act as an independent Controller for its B2B contact database and as ShopAssist's Processor for information ShopAssist uploads or processes through Apollo's prospecting and outreach features.
3.3 Merchant accounts and contracts
For Merchant accounts, onboarding, integration, support, and contract administration, we may process:
- authorised-user names, business email addresses, roles, and login information;
- company, billing, address, country, VAT, and eCommerce-platform information;
- subscription, plan, invoice, payment-status, and support information;
- integration configuration and technical contact details; and
- account activity and security logs.
The legal bases are contract performance and pre-contractual steps under Article 6(1)(b) GDPR and legitimate interests in account security, service administration, and business operations under Article 6(1)(f) GDPR.
3.4 Payments
Starter, Standard, and Premium subscriptions may be paid by bank transfer or credit card through Stripe. Enterprise subscriptions are paid annually by bank transfer. Stripe may process payment-card, transaction, fraud-prevention, device, and billing information under its applicable terms and privacy documentation. ShopAssist does not store complete payment-card details when Stripe processes the card payment.
The legal bases are Article 6(1)(b) GDPR, Article 6(1)(c) GDPR for tax and accounting obligations, and Article 6(1)(f) GDPR for fraud prevention and payment security.
3.5 Website and service security data
When someone visits the ShopAssist website or accesses ShopAssist services, Vercel, Cloudflare and ShopAssist may process:
- IP address;
- request time, requested URL, referrer, and response information;
- browser, device, operating-system, and network information;
- security events and identifiers; and
- application and error logs.
We process this information to deliver, secure, troubleshoot, and maintain the website and Service. The legal basis is Article 6(1)(f) GDPR.
4. Personal Data Processed for Merchants
Depending on the Merchant's platform, configuration, and shopper input, ShopAssist may process the following personal data on the Merchant's behalf.
4.1 Conversation data
- complete shopper messages;
- AI-generated responses;
- product questions, preferences, feedback, and interaction history; and
- information a shopper voluntarily includes in free-text messages.
ShopAssist does not require shoppers to provide their name, email address, delivery address, or payment-card details to use the shopping assistant. However, shoppers may voluntarily include personal or sensitive information in a message. Merchants should instruct shoppers not to enter payment-card details, special-category data, or other unnecessary personal information.
4.2 Session and technical data
- a ShopAssist guest identifier and conversation/session identifiers;
- for a logged-in shopper, an identifier containing the Merchant's platform customer ID;
- IP addresses processed transiently by infrastructure;
- browser, device, request, page, product, interaction, security, and error metadata;
- prompt, response, trace, score, model, token, latency, and observability data; and
- cart, feedback, order-attribution, and analytics events.
The widget also stores chat history, favourites, and widget settings in local storage to provide user-selected functionality. The Merchant dashboard uses a first-party login session cookie for Merchant staff.
4.3 Cart, order, and attribution data
Where configured, ShopAssist supports cart actions and order lookup for Shopify, WooCommerce, BigCommerce, and Magento.
Order lookup uses the shopper's order number and postcode. These values can constitute personal data when they relate to an identifiable order or household. ShopAssist uses them to request the relevant order-status information from the Merchant's eCommerce platform.
Conversations that generate or assist orders may be associated with the corresponding order so the Merchant can open a link from the ShopAssist dashboard to the order in its eCommerce platform. The shopper's name, delivery address, and complete order details remain in the Merchant's eCommerce platform and are not displayed or stored as part of the confirmed ShopAssist order-linking flow.
4.4 Analytics and Merchant-specific prompt maintenance
ShopAssist processes conversation, interaction, cart, order-attribution, and technical data to provide analytics to the relevant Merchant and to monitor Service quality.
ShopAssist does not use Customer Personal Data to train machine-learning models. Authorised ShopAssist personnel may manually review raw shopper conversations to update and maintain the prompt for the Merchant whose store generated the conversations and for support, security, or troubleshooting. ShopAssist does not use one Merchant's raw conversations to update another Merchant's prompt.
Access to raw conversations is restricted to the Merchant's authorised dashboard users, partner staff expressly granted access to that Merchant's store, and a limited number of authorised ShopAssist personnel acting under role-based permissions for support, security, or troubleshooting purposes.
5. AI Processing
ShopAssist currently uses:
OpenAI API
to generate shopper-chat responses and perform prompt analysis, categorisation, and summarisation. The data sent can include the complete current message, conversation history, the Merchant's system prompt and identifier, product information, and items selected through chat. Production processing uses an approved Zero Data Retention configuration and eligible stateless endpoints. OpenAI does not retain Customer Content in abuse-monitoring logs or application state for those requests. Limited operational, billing and security information may be processed separately.
Google Gemini API (paid tier)
to process Merchant catalogue, product data, brand information and knowledge base content. Under the paid service terms, Google does not use this data to train its models. Google may retain prompts and responses for a limited period for abuse monitoring and policy enforcement.
Cloudflare Workers AI
to embed and rerank shopper query text against product catalogue embeddings.
ShopAssist does not use Customer Personal Data to train machine-learning models and has verified that the OpenAI API and paid Gemini service do not use this business/API data for model training under the active service terms. Complete prompts and outputs are nevertheless stored in ShopAssist systems for the periods described in Section 10. Where a service provider retains prompts and responses under its own terms, as described above for the Google Gemini API, that retention is governed by the provider's applicable retention period rather than by Section 10.
AI Disclosure
The ShopAssist widget informs shoppers that they are interacting with an AI system at or before the first interaction. Merchants cannot remove this disclosure.
AI responses are probabilistic and may be incomplete or inaccurate. Shoppers should verify important product, health, safety, legal, financial, compatibility, and purchasing information with the Merchant or another appropriate source.
6. Local Storage, Cookies, and Similar Technologies
The local-storage technologies are described in Section 4.2. Browser local storage is distinct from a traditional cookie but is covered by the terminal-equipment access rules in § 25 TDDDG. Storage or access that is strictly necessary to provide a function requested by the shopper may be used without consent.
7. Purposes and Legal Bases for Merchant-Controlled Processing
The Merchant determines the lawful basis for shopper-data processing through ShopAssist. Depending on the Merchant's use case, this may include legitimate interests under Article 6(1)(f) GDPR, consent under Article 6(1)(a) GDPR, or steps connected with a contract under Article 6(1)(b) GDPR.
ShopAssist processes the data only on the Merchant's documented instructions, including the Terms, Data Processing Agreement, Order Form, platform configuration, and Merchant support requests, unless Union or Member State law requires otherwise.
8. Recipients and Service Providers
ShopAssist uses service providers to operate and support the Service. The exact legal entity, region, and transfer mechanism depend on the contracted account and configuration.
8.1 Service subprocessors for Merchant shopper data
| Provider | Processing purpose | Location |
|---|---|---|
| Cloudflare | Cloud Service Provider and content delivery network | Europe |
| OpenAI OpCo, LLC | AI research and deployment company | United States |
| Google Cloud EMEA Limited | AI research and deployment company | United States |
| Langfuse | LLM observability and prompt management | Europe |
| PostHog | Product analytics | Europe |
| Vercel | Merchant-dashboard | United States |
| Resend | Email delivery | United States |
The applicable eCommerce platform (Shopify, WooCommerce, BigCommerce, or Magento) also processes information under the Merchant's platform account and instructions. Its role is determined by the Merchant's direct relationship with that platform and the integration arrangement.
8.2 Business-operation providers
| Provider | Processing purpose | Location |
|---|---|---|
| Clarify, Inc. | Customer relationship management | United States |
| ZenLeads, Inc. (Apollo.io) | B2B prospecting, sales intelligence | United States |
| Stripe | Payment processing | Europe |
| Cal.com | Scheduling | United States |
| Google Workspace | Collaboration | United States |
| MailerLite | Email marketing | Europe |
| Finom | Banking | Europe |
ShopAssist does not sell or rent personal data.
9. International Data Transfers
Some providers or their subprocessors process or may access data outside the EU/EEA. A lawful Chapter V GDPR mechanism may include an adequacy decision, the EU-US Data Privacy Framework for an eligible certified recipient, the European Commission's Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where required.
10. Retention
ShopAssist retains Personal Data only for as long as necessary for the purposes for which it was collected, or for a longer period as is required by Union or Member State law, or as is necessary for the establishment, exercise or defence of legal claims. Where a retention period stated below expires, the relevant Personal Data is deleted or irreversibly anonymised, unless a statutory retention obligation, a documented legal hold, or an active legal claim requires continued storage. Data retained on that basis is restricted to the purpose requiring its retention and deleted when that requirement ceases.
- ShopAssist product-related retention: ShopAssist doesn't retain data beyond necessary and as described in our DPA.
- Contact and sales inquiries: ordinarily up to 12 months after the last substantive interaction, unless a longer period is required for an active relationship or legal claim.
- B2B prospecting data: ordinarily up to 12 months after the last meaningful interaction or the decision not to pursue the prospect, unless a shorter period is required following an objection or deletion request. Limited suppression information may be retained for longer to ensure that an opt-out continues to be respected.
- Invoices and accounting records: for the applicable German statutory retention period.
- Anonymised aggregate statistics: may be retained for longer where the data is genuinely anonymous and no person can reasonably be reidentified.
ShopAssist provides Merchant data export upon request.
11. Data-Subject Rights
Subject to the GDPR's conditions and exceptions, individuals may have the right to:
- access their personal data under Article 15;
- correct inaccurate data under Article 16;
- request deletion under Article 17;
- restrict processing under Article 18;
- receive portable data under Article 20;
- object to processing under Article 21; and
- withdraw consent at any time under Article 7(3), without affecting earlier processing.
If personal data is processed for direct marketing, the individual may object at any time. ShopAssist will stop using the data for direct marketing and may retain limited suppression information solely to ensure that the objection continues to be respected.
To exercise these rights:
- For Merchant account, billing, website, or direct-contact data: contact privacy@getshopassist.com.
- For shopper data processed through a Merchant's store: contact the Merchant first because the Merchant is the Controller. ShopAssist will assist the Merchant using available manual processes.
12. Security
Confirmed measures include TLS in transit, Cloudflare D1 encryption at rest, separate production and development databases, no production data in development, role-based operator/Merchant/partner permissions, MFA on Cloudflare, OpenAI and Vercel accounts, and no deliberate logging of message bodies, authentication secrets, order numbers, or postcodes in service logs.
13. AI and Children
ShopAssist-powered stores may be accessible to people under 18. ShopAssist does not intentionally ask shoppers to provide their age or unnecessary identifying information. Merchants remain responsible for determining whether their products, store, and legal basis are appropriate for minors and for implementing any legally required age, parental-authorisation, or content controls.
14. Complaints
Individuals may complain to a data protection supervisory authority. The supervisory authority responsible for ShopAssist in Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
15. Changes to This Policy
We may update this Privacy Policy when our Service, providers, processing, or legal obligations change. We will publish the updated version with a new effective date and provide additional notice where required.
16. Contact
Kremic Ventures UG (haftungsbeschränkt)
trading as ShopAssist
Liselotte-Herrmann-Straße 12
10407 Berlin, Germany
Managing Director: Tim Kremic