MZ MZ SupportPilot AI AI customer support for Shopify
Privacy Terms Support
Legal and data protection

Privacy Policy

This Privacy Policy explains how MZ SupportPilot AI collects, uses, stores, shares, and protects information when merchants install the app and when customers use its storefront support features.

Effective date: August 2, 2026 Last updated: August 2, 2026
Privacy summary
  • We do not sell personal information.
  • We do not use customer data for advertising.
  • Order information requires customer verification.
  • Merchants control their store support information.
On this page
1. About this policy 2. Our privacy role 3. Information we collect 4. How information is used 5. AI and automated support 6. Order verification 7. Information sharing 8. Data retention 9. Security 10. Privacy rights 11. International processing 12. Children 13. Policy updates 14. Contact us
01

About this Privacy Policy

This Privacy Policy applies to the MZ SupportPilot AI Shopify application, its embedded merchant interface, storefront chat widget, app-proxy endpoints, support services, and related websites.

In this policy, “App,” “SupportPilot,” “we,” “us,” and “our” refer to MZ SupportPilot AI and its operator, ZJ Programmers.

“Merchant” means a Shopify store owner or authorized staff member who installs or uses the App. “Customer” means a shopper, visitor, buyer, or other individual who interacts with a merchant through the App.

02

Our role in processing personal information

Merchants generally determine why and how their customers’ personal information is processed. For customer information processed through a merchant’s store, the merchant generally acts as the data controller or business, and we act as its service provider or data processor.

We may act as an independent controller for limited information relating to merchant accounts, billing, security, service administration, legal compliance, and direct communications with merchants.

Customers should also review the privacy policy of the Shopify merchant whose storefront they are using.
03

Information we collect and process

3.1 Merchant and store information

When a merchant installs or uses the App, we may process:

  • Shopify store domain and Shopify store identifiers.
  • App installation, authorization, session, and access information.
  • App configuration, AI-agent settings, widget settings, themes, and feature preferences.
  • Billing-plan status, usage limits, and subscription verification information.
  • Merchant-created FAQs, policies, approved support content, and other knowledge-base information.
  • Synced product information such as titles, descriptions, handles, images, prices, variants, inventory, tags, vendor, and product type.
  • Communications sent to our support team.

3.2 Storefront customer information

When a customer uses the storefront widget, we may process:

  • Customer name and email address submitted through the support form.
  • Support questions, messages, merchant replies, system messages, and conversation history.
  • Conversation status, sentiment indicators, AI confidence information, handoff status, and message timestamps.
  • A randomly generated visitor identifier and public conversation identifier.
  • Browser language, current page URL, and page title.
  • Product recommendations displayed and product links clicked through the support widget.

3.3 Order-support information

When a customer chooses order tracking, we may process:

  • The order number entered by the customer.
  • The email address used during checkout.
  • Limited order information needed to provide support, such as order name, order date, payment status, fulfillment status, purchased items, total value, cancellation status, and shipment tracking.

The App is designed not to display customer addresses, phone numbers, full payment details, or other information that is unnecessary for order-status support.

3.4 Browser storage

The storefront widget may use browser local storage or session storage to remember:

  • A randomly generated visitor identifier.
  • Customer name and email, when enabled.
  • Normal-chat conversation identifiers.
  • Order-support conversation identifiers.
  • Previously handled follow-up prompts.
  • Last-seen merchant messages.
  • Whether the welcome message was dismissed.

Customers can clear this information through their browser settings. Merchants may also disable certain profile or conversation-resume features through the App.

04

How we use information

We process information only as reasonably necessary to:

  • Install, authenticate, operate, maintain, and secure the App.
  • Provide storefront customer-support conversations.
  • Answer questions using merchant-approved FAQs, products, and business knowledge.
  • Recommend relevant products and provide direct product links.
  • Verify order requests and display limited order-status information.
  • Transfer conversations to the merchant’s support team.
  • Allow merchants to review conversations, send replies, and resolve support cases.
  • Calculate conversation usage and enforce subscription limits.
  • Generate support analytics, such as conversation counts, handoffs, and product-link clicks.
  • Prevent fraud, abuse, unauthorized access, and excessive requests.
  • Diagnose errors, provide technical support, and improve reliability.
  • Comply with legal obligations and valid Shopify privacy requests.
No sale of personal information

We do not sell customer or merchant personal information. We do not use storefront customer information for third-party advertising or unrelated marketing profiles.

05

AI and automated customer support

MZ SupportPilot AI uses automated logic to analyze customer questions and retrieve relevant information from merchant-approved knowledge sources.

Automated responses may use:

  • Enabled merchant FAQs.
  • Synced Shopify product information.
  • Merchant-written policies and business knowledge.
  • Configured support and escalation rules.

Automated answers can be incomplete or inaccurate. Merchants are responsible for reviewing their knowledge sources, settings, and customer-facing information. Customers can request human assistance, and the App may transfer low-confidence or sensitive questions to the merchant’s team.

The App does not use customer information to make credit, employment, insurance, housing, legal, medical, or other decisions that produce similarly significant effects.

06

Secure order verification

Order information is not intended to be displayed solely because a visitor knows an order number. The App requires the customer to provide both:

  1. The relevant order number; and
  2. The email address used during checkout.

The submitted details are compared with the relevant Shopify order before limited order information is returned. Verification attempts may be limited to prevent abuse.

Order-support information is used only to provide the requested customer-service functionality and is not used for advertising or data resale.

07

How information is shared

We do not sell personal information. We may disclose limited information to the following parties when necessary:

Shopify

The App operates through Shopify APIs, app authentication, app proxy services, billing tools, and theme app extensions.

Hosting providers

Our hosting, database, storage, and infrastructure providers may process information only as required to operate and secure the service.

The relevant merchant

Customer conversations, submitted contact details, support status, and order-support results are made available to the merchant operating the storefront.

Professional advisers

Information may be disclosed to legal, security, accounting, insurance, or compliance advisers where reasonably necessary.

Legal authorities

We may disclose information when required by law, legal process, or a valid government request, or to protect rights, safety, and service security.

Business transfers

Information may be transferred as part of a merger, acquisition, financing, restructuring, or sale, subject to appropriate confidentiality protections.

Current service providers

  • Shopify — ecommerce platform, APIs, app authentication, billing, and app distribution.
  • Render — application hosting and production infrastructure.
  • REPLACE_ME: Add the name of your production database provider, if different from Render.
  • REPLACE_ME: Add any external AI provider if customer messages are sent to one.
08

Data retention and deletion

We retain personal information only for as long as reasonably necessary to provide the App, satisfy contractual and legal obligations, resolve disputes, and protect the service.

Our standard retention approach is:

  • Active conversations are retained while they are needed for ongoing customer support.
  • Resolved conversations and associated customer identifiers are retained for up to 90 days, unless the merchant deletes them sooner or a longer period is legally required.
  • Product and knowledge-base data remains stored while the App is installed or until the merchant deletes or resynchronizes it.
  • Security and audit records may be retained for a reasonable period needed for fraud prevention, investigation, and compliance.
  • Data is deleted or anonymized following valid Shopify customer-redaction and shop-redaction requests, subject to applicable legal exceptions.
Implementation requirement

Publish this 90-day period only if your production app actually deletes or anonymizes resolved conversations according to this schedule.

09

Security measures

We use technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, or destruction.

These safeguards may include:

  • HTTPS/TLS encryption for data in transit.
  • Encryption at rest provided by production infrastructure and storage providers.
  • Server-side storage of Shopify credentials and secret environment variables.
  • Shopify app-proxy and administrative authentication.
  • Store-level database isolation and authorization checks.
  • Input validation, request limits, and order-verification attempt controls.
  • Restricted access to production systems and personal information.
  • Strong passwords and multi-factor authentication where supported.
  • Logging and investigation of security-relevant activity.
  • Separation of development and production credentials and data.

No method of electronic transmission or storage can be guaranteed to be completely secure. Merchants and customers should avoid submitting unnecessary sensitive information through support messages.

10

Privacy rights and requests

Depending on the applicable law, individuals may have rights to:

  • Request access to their personal information.
  • Request correction of inaccurate information.
  • Request deletion of personal information.
  • Request restriction of certain processing.
  • Object to certain processing.
  • Request a portable copy of eligible information.
  • Withdraw consent where processing relies on consent.
  • Submit a complaint to an appropriate data-protection authority.

Customers should normally submit a request to the Shopify merchant from whom they purchased or whose storefront they visited. The merchant can then send the appropriate Shopify privacy request to applications connected to the store.

We process valid Shopify privacy webhooks and may request information needed to confirm the request, identify the relevant merchant, and prevent unauthorized disclosure or deletion.

We do not discriminate against individuals for exercising applicable privacy rights.

11

International data processing

Shopify, our infrastructure providers, and other approved service providers may process information in countries other than the country where the merchant or customer is located.

Where required, we rely on appropriate contractual, organizational, and technical safeguards for international transfers of personal information.

12

Children’s privacy

The App is a business customer-support service and is not directed specifically to children. We do not knowingly collect personal information directly from children for our own independent purposes.

Merchants are responsible for operating their stores, configuring age-appropriate customer experiences, and complying with laws applicable to their products and customers.

13

Changes to this policy

We may update this Privacy Policy to reflect changes to the App, our service providers, legal requirements, or security practices.

The updated version will be posted on this page with a revised “Last updated” date. Material changes may also be communicated to merchants through the App, email, or another appropriate method.

14

Contact us

Questions about this Privacy Policy, security, or data requests can be sent to:

ZJ Programmers App: MZ SupportPilot AI Privacy email: zahidjami806@gmail.com Support email: zahidjami806@gmail.com Website: See Website Business address: E11/2 , islamabad

For customer information connected to a specific Shopify store, please identify the store domain and contact the merchant first.

MZ MZ SupportPilot AI Operated by ZJ Programmers

AI customer support, product guidance, secure order assistance, and human handoff for Shopify stores.

Privacy Policy Terms of Service Support
© 2026 ZJ Programmers. All rights reserved.