About this Privacy Policy
This Privacy Policy applies to the MZ SupportPilot AI Shopify application, its embedded merchant interface, storefront chat widget, app-proxy endpoints, support services, and related websites.
In this policy, “App,” “SupportPilot,” “we,” “us,” and “our” refer to MZ SupportPilot AI and its operator, ZJ Programmers.
“Merchant” means a Shopify store owner or authorized staff member who installs or uses the App. “Customer” means a shopper, visitor, buyer, or other individual who interacts with a merchant through the App.
Our role in processing personal information
Merchants generally determine why and how their customers’ personal information is processed. For customer information processed through a merchant’s store, the merchant generally acts as the data controller or business, and we act as its service provider or data processor.
We may act as an independent controller for limited information relating to merchant accounts, billing, security, service administration, legal compliance, and direct communications with merchants.
Information we collect and process
3.1 Merchant and store information
When a merchant installs or uses the App, we may process:
- Shopify store domain and Shopify store identifiers.
- App installation, authorization, session, and access information.
- App configuration, AI-agent settings, widget settings, themes, and feature preferences.
- Billing-plan status, usage limits, and subscription verification information.
- Merchant-created FAQs, policies, approved support content, and other knowledge-base information.
- Synced product information such as titles, descriptions, handles, images, prices, variants, inventory, tags, vendor, and product type.
- Communications sent to our support team.
3.2 Storefront customer information
When a customer uses the storefront widget, we may process:
- Customer name and email address submitted through the support form.
- Support questions, messages, merchant replies, system messages, and conversation history.
- Conversation status, sentiment indicators, AI confidence information, handoff status, and message timestamps.
- A randomly generated visitor identifier and public conversation identifier.
- Browser language, current page URL, and page title.
- Product recommendations displayed and product links clicked through the support widget.
3.3 Order-support information
When a customer chooses order tracking, we may process:
- The order number entered by the customer.
- The email address used during checkout.
- Limited order information needed to provide support, such as order name, order date, payment status, fulfillment status, purchased items, total value, cancellation status, and shipment tracking.
The App is designed not to display customer addresses, phone numbers, full payment details, or other information that is unnecessary for order-status support.
3.4 Browser storage
The storefront widget may use browser local storage or session storage to remember:
- A randomly generated visitor identifier.
- Customer name and email, when enabled.
- Normal-chat conversation identifiers.
- Order-support conversation identifiers.
- Previously handled follow-up prompts.
- Last-seen merchant messages.
- Whether the welcome message was dismissed.
Customers can clear this information through their browser settings. Merchants may also disable certain profile or conversation-resume features through the App.
How we use information
We process information only as reasonably necessary to:
- Install, authenticate, operate, maintain, and secure the App.
- Provide storefront customer-support conversations.
- Answer questions using merchant-approved FAQs, products, and business knowledge.
- Recommend relevant products and provide direct product links.
- Verify order requests and display limited order-status information.
- Transfer conversations to the merchant’s support team.
- Allow merchants to review conversations, send replies, and resolve support cases.
- Calculate conversation usage and enforce subscription limits.
- Generate support analytics, such as conversation counts, handoffs, and product-link clicks.
- Prevent fraud, abuse, unauthorized access, and excessive requests.
- Diagnose errors, provide technical support, and improve reliability.
- Comply with legal obligations and valid Shopify privacy requests.
We do not sell customer or merchant personal information. We do not use storefront customer information for third-party advertising or unrelated marketing profiles.
AI and automated customer support
MZ SupportPilot AI uses automated logic to analyze customer questions and retrieve relevant information from merchant-approved knowledge sources.
Automated responses may use:
- Enabled merchant FAQs.
- Synced Shopify product information.
- Merchant-written policies and business knowledge.
- Configured support and escalation rules.
Automated answers can be incomplete or inaccurate. Merchants are responsible for reviewing their knowledge sources, settings, and customer-facing information. Customers can request human assistance, and the App may transfer low-confidence or sensitive questions to the merchant’s team.
The App does not use customer information to make credit, employment, insurance, housing, legal, medical, or other decisions that produce similarly significant effects.
Secure order verification
Order information is not intended to be displayed solely because a visitor knows an order number. The App requires the customer to provide both:
- The relevant order number; and
- The email address used during checkout.
The submitted details are compared with the relevant Shopify order before limited order information is returned. Verification attempts may be limited to prevent abuse.
Order-support information is used only to provide the requested customer-service functionality and is not used for advertising or data resale.
Data retention and deletion
We retain personal information only for as long as reasonably necessary to provide the App, satisfy contractual and legal obligations, resolve disputes, and protect the service.
Our standard retention approach is:
- Active conversations are retained while they are needed for ongoing customer support.
- Resolved conversations and associated customer identifiers are retained for up to 90 days, unless the merchant deletes them sooner or a longer period is legally required.
- Product and knowledge-base data remains stored while the App is installed or until the merchant deletes or resynchronizes it.
- Security and audit records may be retained for a reasonable period needed for fraud prevention, investigation, and compliance.
- Data is deleted or anonymized following valid Shopify customer-redaction and shop-redaction requests, subject to applicable legal exceptions.
Publish this 90-day period only if your production app actually deletes or anonymizes resolved conversations according to this schedule.
Security measures
We use technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, or destruction.
These safeguards may include:
- HTTPS/TLS encryption for data in transit.
- Encryption at rest provided by production infrastructure and storage providers.
- Server-side storage of Shopify credentials and secret environment variables.
- Shopify app-proxy and administrative authentication.
- Store-level database isolation and authorization checks.
- Input validation, request limits, and order-verification attempt controls.
- Restricted access to production systems and personal information.
- Strong passwords and multi-factor authentication where supported.
- Logging and investigation of security-relevant activity.
- Separation of development and production credentials and data.
No method of electronic transmission or storage can be guaranteed to be completely secure. Merchants and customers should avoid submitting unnecessary sensitive information through support messages.
Privacy rights and requests
Depending on the applicable law, individuals may have rights to:
- Request access to their personal information.
- Request correction of inaccurate information.
- Request deletion of personal information.
- Request restriction of certain processing.
- Object to certain processing.
- Request a portable copy of eligible information.
- Withdraw consent where processing relies on consent.
- Submit a complaint to an appropriate data-protection authority.
Customers should normally submit a request to the Shopify merchant from whom they purchased or whose storefront they visited. The merchant can then send the appropriate Shopify privacy request to applications connected to the store.
We process valid Shopify privacy webhooks and may request information needed to confirm the request, identify the relevant merchant, and prevent unauthorized disclosure or deletion.
We do not discriminate against individuals for exercising applicable privacy rights.
International data processing
Shopify, our infrastructure providers, and other approved service providers may process information in countries other than the country where the merchant or customer is located.
Where required, we rely on appropriate contractual, organizational, and technical safeguards for international transfers of personal information.
Children’s privacy
The App is a business customer-support service and is not directed specifically to children. We do not knowingly collect personal information directly from children for our own independent purposes.
Merchants are responsible for operating their stores, configuring age-appropriate customer experiences, and complying with laws applicable to their products and customers.
Changes to this policy
We may update this Privacy Policy to reflect changes to the App, our service providers, legal requirements, or security practices.
The updated version will be posted on this page with a revised “Last updated” date. Material changes may also be communicated to merchants through the App, email, or another appropriate method.
Contact us
Questions about this Privacy Policy, security, or data requests can be sent to:
ZJ Programmers App: MZ SupportPilot AI Privacy email: zahidjami806@gmail.com Support email: zahidjami806@gmail.com Website: See Website Business address: E11/2 , islamabadFor customer information connected to a specific Shopify store, please identify the store domain and contact the merchant first.