Retrics

CHAT · DATA & PRIVACY APPENDIX

What Chat
reads, and why.

The company policies below apply to everything Retrics runs. This page is the part that is specific to this product — the data it touches, and who else sees it.
BUILDING
ChatBUILDING
RUNS ONchat.retrics.ai
CUSTOMER GRAPHOutside the shared graph
DATA FLOW DECLAREDYes

THIS PAGE IS THE URL THIS PRODUCT’S APP LISTING SUBMITS

WHERE IT STANDS

The work is real. The door is not open yet.

THE DATA FLOW

Five questions, answered plainly.

WHAT IT READS
  • Order number, status, fulfilment state, totals, line items and tracking — to answer “where is my order” without a person
  • The customer email and phone attached to an order — as an identity check before anything about that order is revealed, never for marketing
  • The shipping address on an order — shown to the merchant when an address correction is proposed, so a person sees what would change before approving
  • Products, variants, prices and inventory — so the assistant answers about what is really for sale and never invents a product
  • Checkout contents, to recover an abandoned cart in the conversation
  • The messages a shopper types, and a session identifier that keeps one conversation continuous
  • Page and browser context, shown to the merchant beside the conversation: the pages visited and their titles, the referring link, browser language and time zone, screen size, and browser, operating system and device type
  • An approximate city, region and country — derived at the edge from an IP address that is never sent to us, never stored, and never written down anywhere
WHAT IT STORES
  • Conversation transcripts, and which of them were handed to a person
  • The page and browser context above, kept with the conversation it belongs to
  • A shopper identity record per conversation, and the memories kept against it
  • Merchant sign-in details and the store credentials Shopify issues on install
  • Billing is handled by Stripe — card numbers are never seen or stored
HOW IT IS PROTECTED
  • Encrypted in transit everywhere, over TLS
  • Encrypted at rest with AES-256-GCM envelope encryption: each workspace holds its own data key, itself encrypted by a master key kept outside the database
  • Searchable without being readable — email and phone are looked up through a keyed one-way index, so the plaintext is never in a queryable column
  • Every record is scoped to one workspace, and a workspace is bound to one store for life
HOW LONG IT IS KEPT
  • Webhook delivery records: 7 days
  • Rate-limit counters: 2 hours
  • Inactive chat sessions carrying no conversation: 30 days
  • Completed checkouts: 7 days; abandoned checkouts: 90 days
  • Conversations and their messages: 24 months after the last message, then deleted automatically overnight
  • Sooner on request — a shopper erasure request, or the merchant uninstalling and the store being redacted, deletes them immediately rather than waiting out the 24 months
  • A shopper erasure request erases their identity, their stored memories, their merge history and any pending action about them, within the 30-day window Shopify sets
WHO ELSE SEES IT
  • Anthropic — conversation content is sent to generate a reply, and is not used to train their models (United States)
  • Supabase — the database (United States, us-east-1)
  • Vercel — application hosting (United States)
  • Railway — background jobs: reports, erasure and syncing
  • Stripe — merchant billing only; no shopper data reaches it (United States)
  • Browser push services from Google, Apple and Mozilla — delivering a notification to a merchant's own browser
  • No advertising platform receives anything from Chat — no audience, no identifier, no event
  • Personal data is never sold, and shoppers' personal data is never used to train models

AND THE COMPANY POLICIES IT SITS UNDER

These apply to everything Retrics runs.

They are linked rather than repeated here. Twelve copies of the same policy is twelve things that drift apart.

THIS APPENDIX IS MAINTAINED WITH THE PRODUCT · EDITING IT CHANGES NOTHING ELSE