Sellena ("we", "us") provides an AI shopping assistant that Shopify merchants embed in their storefront. This policy explains what personal data the Sellena app processes, why, on what legal basis, who receives it, how long it is kept, and the choices available to merchants and to their customers. The marketing site sellena.co has its own, separate privacy policy.
Data controller: Individual Entrepreneur Ivan Gubochkin, trading as Sellena, registered under the laws of Georgia, Identification Number 345814372. Registered address: available on request for legal notices at help@sellena.co. Contact: help@sellena.co. We have not appointed a Data Protection Officer; this address is the contact for every privacy matter.
| Data | Whose | Why | Stored by Sellena? | Retention |
|---|---|---|---|---|
| Shop domain, owner name, store email, plan and usage | Merchant | Operate the app, support, billing | Yes | While the app is installed; erased by Shopify's shop/redact request 48 hours after uninstall |
| Product catalog (titles, variants, prices, images) | Merchant | Feed the assistant's recommendations | Yes, mirrored | While installed; erased with the shop's data |
| Shopify API access token | Merchant | Call Shopify on the merchant's behalf | Yes | Deleted on uninstall |
| Customer name, email and phone | The merchant's customers | Tell the assistant who it is talking to (returning customer, order history) | No. Looked up from Shopify when the chat opens, passed to our conversation system, never written to our database | Not retained by the app |
| Chat messages | The merchant's customers | Generate the assistant's replies | Held in our self-hosted conversation system; sent to our AI provider to generate each reply | Until the shop's data is erased on shop/redact; also present in operational logs and traces for 30 days (see "Operational logs") |
| Order attribution (order id and name, net sales amounts, currency) | Derived from the merchant's orders | Commission billing on plans that carry a commission | Yes, without any buyer identifier | Billed records purged 365 days after billing |
| Storefront widget events (IP address, user agent, referrer) | Storefront visitors | Usage statistics and conversation counting | In memory only, at most 10,000 events, cleaned daily, never on disk | Hours |
| Web-server access logs (masked IP, user agent, URL, time) | Visitors, merchants | Security and troubleshooting | Yes | 30 days, then deleted |
| Trial record: a keyed hash of the shop domain, no clear identifier | Merchant (pseudonymised) | Prevent free-trial reset by uninstalling and reinstalling | Yes | 365 days after the last activation. Deliberately survives shop/redact (legitimate interest: fraud prevention) |
The app requests only the Shopify permissions these purposes need; read_customers
is the only customer-data permission, and it backs exactly the lookup described
above. Merchants can switch that lookup off entirely; the assistant then sees a
numeric id instead of a name.
Where the GDPR or the UK GDPR applies: performance of a contract (providing the app to the merchant); our legitimate interests in operating, securing and improving the service, counting usage for billing, and preventing free-trial abuse; legal obligations (tax and accounting records, responding to lawful requests). For end-customer data processed as the merchant's processor, the merchant is responsible for the lawful basis.
We use the data to run the assistant, keep the merchant's catalog in sync, route conversations to the merchant's inbox, bill the merchant through Shopify, and measure usage. Each reply is generated by sending the conversation and the relevant catalog context to our AI provider, OpenAI, whose API terms exclude the data from model training. We do not sell personal data, do not use customer conversations to train models, and do not place advertising or retargeting pixels in storefronts. The assistant recommends and replies; it makes no decision with legal or similarly significant effect on anyone.
chatwoot_contact_identifier,
quail_triggered_conversations) together with the conversation system's own
session identifier. These are strictly necessary for the chat to work and
identify the session, not the person. No analytics or marketing cookies are set
by Sellena. The merchant's own storefront cookie notice should mention the
assistant.| Recipient | Role | Data | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI provider generating the assistant's replies | Chat messages and catalog context | United States |
| Hetzner Online GmbH | Hosting of all Sellena servers, including our self-hosted conversation system (Chatwoot), catalog service, logs and traces | Everything above, at rest | Germany and Finland (EU) |
| Shopify | Platform, app distribution, OAuth, billing | Shop identity, subscription and usage charges | Under Shopify's own terms |
Hosting stays in the EU; OpenAI is the only recipient outside the EEA. A current sub-processor list is available on request, and merchants get reasonable notice of additions under the DPA.
Transfers of chat content to OpenAI in the United States rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies). Copies of the safeguards are available on request at help@sellena.co. The controller is established in Georgia; the same safeguards apply when we access data from there.
All traffic to and from the app, Shopify, our AI provider and our conversation system is encrypted with TLS. Customer names, emails and phone numbers are never written to our database, so the data at rest is limited to what the table above lists. Our web-server logs mask the client IP and drop cookies and authentication headers before anything is written. Each shop's data is logically isolated. Access to servers and logs is limited to the people who operate Sellena. Shopify webhooks are verified by signature.
shop/redact 48 hours later, and we erase the
shop's data across the app's tables, its conversation inbox and its stored
sessions.customers/redact request deletes the
customer's order-attribution rows. Names, emails and phones are not stored, so
there is nothing further to delete in the app.customers/data_request is answered with the
order-attribution rows we hold for the named orders.shop/redact to
prevent free-trial abuse and is purged 365 days after the last activation.Depending on where you are (EEA and UK GDPR, CCPA/CPRA, the Law of Georgia on Personal Data Protection), you may have the right to access, correct, delete, restrict or port your data, to object to processing, to withdraw consent, and not to be discriminated against for exercising these rights. We do not sell or share personal data, so there is no sale to opt out of.
Customers of a store should contact the merchant first; the merchant can trigger Shopify's data-request and redaction flows, which reach us automatically. Merchants and anyone else can write to help@sellena.co or use the contact form on sellena.co. We may ask you to confirm your identity. We respond within one month under the GDPR and UK GDPR and within 45 days under the CCPA, extendable once as each law allows, and we will tell you if we extend.
You may lodge a complaint with your data protection authority: in the EEA, the authority where you live or work; in the UK, the Information Commissioner's Office; in Georgia, the Personal Data Protection Service. We would appreciate the chance to resolve the matter first.
The app is a business tool and is not directed to individuals under 16. We do not knowingly collect their personal data; if you believe a minor's data was provided, contact help@sellena.co and we will delete it.
We process the merchant's customers' data as the merchant's processor: only on documented instructions, logically isolated per shop, never used to train shared AI models, and deleted or returned on termination. The Data Processing Agreement applies to every merchant that installs the app; merchants who need a signed copy can request one at help@sellena.co.
We may update this policy; the "Last updated" date shows the current version, and earlier versions are available on request. Material changes are announced through the app or the App Store listing.
help@sellena.co. For legal notices, ask us for our registered postal address at the same email and we will provide it within five business days.