HeiChat Data Protection, AI, and Security Policy Policy
Last updated: 2026-08-17 Effective date: 2025-12-29
This policy describes HeiChat's data retention and deletion practices, AI data use and model training position, international data transfer safeguards, technical and organisational measures, and source references for GDPR-related documentation.
Data Retention and Deletion Policy
This section describes how HeiChat retains and deletes merchant and customer data processed through the HeiChat Shopify app.
For data marked as retained during the active subscription, HeiChat retains the data for the duration of the merchant's active subscription unless it is deleted earlier through a Shopify privacy webhook, direct merchant deletion request, or other applicable deletion process.
Retention during an active subscription
Retention after uninstall
To support reinstallation and service continuity, HeiChat may retain the merchant's basic configuration and customer chat records for up to 12 months after the merchant uninstalls the app.
After uninstall, data other than the merchant's basic configuration and customer chat records is deleted or anonymised in accordance with Shopify privacy webhook requirements and applicable Shopify requirements. This includes order data/cache, customer identifiers, IP/device/browser attribution data, analytics metrics, AI request/response records, product data, and knowledge base data, unless retention is legally required.
If the merchant does not reinstall HeiChat within 12 months, HeiChat deletes or anonymises retained data unless retention is required by law.
Deleted data may remain in AWS backup snapshots until the applicable 30-day snapshot retention cycle expires.
Shopify mandatory privacy webhooks
HeiChat processes Shopify mandatory privacy webhook requests:
customers/data_requestcustomers/redactshop/redact
HeiChat's standard process for Shopify mandatory privacy webhooks is:
- Receive the webhook as a
POSTrequest with a JSON body. - Verify that the webhook was sent by Shopify, including verification of the Shopify HMAC signature.
- Return
401 Unauthorizedfor invalid signatures. - For valid webhooks, record the request, enqueue the privacy task, and return a success response promptly after the request has been accepted for processing.
- Identify applicable records by
shop_id,shop_domain, customer ID, email, phone, and listed order IDs where provided in the webhook payload. - Delete, anonymise, export, or report applicable records according to the webhook topic.
- Keep an internal audit record of the webhook receipt and completion status.
For customers/data_request, HeiChat identifies personal data associated with the customer and provides the relevant export or response to the merchant or through the applicable Shopify privacy request process.
For customers/redact, HeiChat deletes or anonymises personal data associated with the customer identifiers and the orders_to_redact values provided in the webhook payload, unless retention is legally required.
For shop/redact, HeiChat deletes or anonymises data associated with the shop after Shopify sends the webhook following app uninstall, unless retention is legally required or covered by the limited post-uninstall retention period for merchant basic configuration and customer chat records described above.
HeiChat's operational target is to complete valid Shopify privacy webhook requests within 48 hours after receipt. If a request requires backup expiry, complex manual review, or legal retention assessment, HeiChat aims to complete the request within 30 days unless a longer period is permitted or required by applicable law.
Direct merchant deletion requests
Merchants may request deletion by contacting heicarbook@gmail.com.
HeiChat will verify the request and delete or anonymise applicable merchant and customer data within a reasonable period, unless retention is required by law. HeiChat generally aims to complete verified deletion requests within 30 days where technically and legally possible.
Backup deletion
Deleted data may remain in encrypted backups until those backups expire under HeiChat's backup retention cycle.
HeiChat stores backups in AWS. HeiChat creates daily snapshots and retains backup snapshots for 30 days. Backups are used for disaster recovery and business continuity purposes.
AI Data Use and Model Training Statement
HeiChat uses AI service providers to generate customer support responses for Shopify merchants.
AI routing and model providers
HeiChat uses OpenRouter as an AI routing provider. OpenRouter routes AI requests to the model provider selected or enabled for the merchant's configuration.
Where a merchant configures HeiChat to use Claude Sonnet 4.5, the relevant model provider is Anthropic.
HeiChat may support fallback routing and merchant-selected model providers. Fallback or merchant-selected providers may include Google Vertex, Amazon Bedrock, Azure, OpenAI, Google, Meta, Mistral, Anthropic, and other providers made available through HeiChat or OpenRouter.
The exact model provider depends on the merchant's selected configuration, provider availability, and any enabled fallback routing.
Data sent to AI providers
To generate a response, HeiChat may send the following data to OpenRouter and the selected model provider:
- the customer's chat message;
- relevant prior chat context;
- relevant merchant instructions and knowledge base material;
- relevant product, order, shipping, return, or customer context where authorised by the merchant and needed to answer the question;
- technical request metadata required to operate the AI service.
HeiChat applies data minimisation and aims to send only the context needed to generate the requested support response.
General model training
HeiChat does not use merchant customer chat messages, order information, customer data, shop content, uploaded knowledge base material, or other merchant data to train or fine-tune general-purpose AI models.
HeiChat does not sell merchant or customer data to AI model providers.
HeiChat configures available AI routing and privacy controls so that model providers are not permitted to use inputs or outputs for model training where such controls are available.
HeiChat may review operational metadata, service performance, product usage, or merchant feedback to maintain, debug, secure, and improve HeiChat. Where HeiChat uses data for product improvement, it applies access controls and data minimisation and does not use merchant customer personal data to train general-purpose AI models.
OpenRouter handling
OpenRouter acts as an AI routing provider for HeiChat. Based on OpenRouter's published privacy documentation, prompt and response retention by OpenRouter is controlled by account and routing settings, and OpenRouter may retain technical metadata such as token counts, latency, routing, and billing-related information.
HeiChat's published position is that available OpenRouter routing and privacy controls are configured so that model providers are not permitted to use inputs or outputs for model training.
Anthropic handling
For Claude Sonnet 4.5 and other AI models provided by Anthropic , customer conversations may be processed by Anthropic to generate model responses. Anthropic's published commercial offering documentation states that Anthropic does not use chats or sessions from commercial offerings such as the Anthropic API to train its models unless the customer chooses to participate in a relevant opt-in program or explicitly submits feedback for training.
Merchant configuration
Merchants can choose supported model providers through HeiChat configuration where the feature is available. Available providers may change over time based on HeiChat's supported model list, OpenRouter availability, provider availability, and service requirements.
Merchants that need stricter AI routing or data-handling controls should review their HeiChat AI configuration and contact HeiChat before enabling provider options that may affect data location or provider handling.
International Data Transfers
HeiChat may process and store personal data in the United States and other countries where HeiChat or its subprocessors operate.
HeiChat's main application infrastructure, database, and data management are hosted on Amazon Web Services (AWS) in the United States, primarily in the AWS us-east-2 region. HeiChat also uses Cloudflare and AWS CDN/DNS services, which may process request metadata through global edge locations. AI requests may be routed through OpenRouter and, where Claude Sonnet 4.5 is selected, processed by Anthropic. Fallback or merchant-selected AI providers may include Google Vertex, Amazon Bedrock, Azure, and other supported providers selected by the merchant. Merchant email communications may be processed through Google Gmail / Google Workspace, and Shopify Billing and platform data are processed through Shopify.
Transfer mechanisms
For transfers from the EEA to the United States or other third countries, HeiChat relies on appropriate safeguards under GDPR Chapter V.
Depending on the recipient, these safeguards may include the EU-U.S. Data Privacy Framework for certified U.S. recipients and/or the European Commission's Standard Contractual Clauses.
Where SCCs are used, Module 2 generally applies to transfers from the merchant as controller to HeiChat as processor, and Module 3 generally applies to onward transfers from HeiChat to subprocessors.
HeiChat also relies on vendor data processing agreements, onward transfer restrictions, and supplementary technical and organisational safeguards where applicable.
Standard Contractual Clauses
Where the European Commission's Standard Contractual Clauses are used, Module 2 generally applies to transfers from the merchant as controller to HeiChat as processor, and Module 3 generally applies to onward transfers from HeiChat as processor to its subprocessors.
Supplementary safeguards
HeiChat applies supplementary safeguards designed to protect personal data during international transfers, including:
- encryption in transit using HTTPS/TLS;
- database encryption at rest;
- access controls and least-privilege access;
- MFA for administrative access;
- production access logging;
- data minimisation, including sending only the context needed to provide support responses;
- limited retention and deletion processes;
- subprocessor contractual restrictions;
- Shopify mandatory privacy webhook handling;
- configuration controls for AI routing and model-provider data handling.
HeiChat also maintains backups and recovery testing, vulnerability remediation, and incident response processes.
United States processing
HeiChat may transfer, store, or process personal data internationally, including in the United States. HeiChat uses appropriate transfer mechanisms and safeguards for such processing where required by applicable data protection law.
Technical and Organisational Measures
HeiChat implements technical and organisational measures designed to protect personal data processed through the HeiChat Shopify app.
Security governance
- Defined owner for privacy and security requests: heicarbook@gmail.com.
- Internal access to production systems limited to authorised personnel.
- Confidentiality obligations for personnel with access to production data.
- Vendor/subprocessor review before onboarding providers that process personal data.
Access control
- Role-based or least-privilege access for administrative systems.
- Separate production access from ordinary user access where feasible.
- Multi-factor authentication is enabled for administrative access.
- Employee and administrator permissions are limited according to least-privilege principles.
- Production access logs are maintained.
- Accounts with production or administrative access are reviewed periodically.
Encryption and transport security
- HTTPS/TLS is enforced for production traffic between browsers, HeiChat, Shopify, and API providers.
- Databases are encrypted at rest.
- Object storage and backups are encrypted at rest where supported by AWS.
- Secrets and API keys are stored in HeiChat's database or configuration storage with restricted administrative access.
Data minimisation
- HeiChat sends only the context reasonably needed to provide customer support responses.
- AI prompts should exclude unnecessary personal data where feasible.
- Logs should avoid storing full chat/customer content unless necessary for service operation or debugging.
System security
- Production systems are hosted on Amazon Web Services (AWS), primarily in the
us-east-2region. - Cloudflare and AWS are used for CDN, DNS, and network services.
- Security patches are applied through HeiChat's vulnerability remediation process.
- Network access is restricted through provider-level controls where applicable.
- AWS-provided error alarms, production access logs, and application logging are used to identify service reliability and security issues.
Availability and resilience
- Backups are maintained for critical service data.
- Backups are stored in AWS as daily snapshots retained for 30 days.
- Backup and recovery testing is performed.
Incident response
- HeiChat investigates suspected security incidents affecting personal data.
- HeiChat notifies affected merchants without undue delay after becoming aware of a personal data breach involving merchant customer data.
- HeiChat maintains an incident response process.
- Incident records are maintained internally.
Deletion and retention controls
- HeiChat supports Shopify mandatory privacy webhooks.
- Merchant deletion requests can be sent to heicarbook@gmail.com.
- Data deletion is performed according to the Data Retention and Deletion Policy section above.
Testing and review
- Security controls are reviewed periodically.
- Vulnerabilities are tracked and remediated according to severity through HeiChat's vulnerability remediation process.
- HeiChat does not currently provide SOC 2, ISO 27001, penetration test, or other third-party security audit reports.
Source References
Prepared date: 2026-08-13
This section identifies regulatory and vendor materials used to structure HeiChat's GDPR-related policy documentation. It is provided for transparency and does not modify HeiChat's Terms of Service, Privacy Policy, or Data Processing Addendum.
GDPR
- GDPR Article 28: processor requirements and processing by contract or other legal act.
- GDPR Article 32: security of processing.
- GDPR Article 44: general principle for international transfers.
European Commission
- EU-U.S. Data Privacy Framework and EU-U.S. data transfers.
- European Commission Standard Contractual Clauses Q&A, including the modular structure.
OpenRouter
- OpenRouter data collection documentation.
- OpenRouter provider routing and provider data collection controls.
- OpenRouter provider logging documentation.
- OpenRouter input and output logging documentation.
Anthropic
- Anthropic Privacy Center materials regarding the use of personal data in model training.
Shopify
- Shopify privacy law webhooks and mandatory privacy webhooks documentation.
- Shopify GDPR mandatory webhooks changelog and handling expectations.
- Shopify Web Pixels API and customer privacy documentation.

