SureClerk: Privacy Policy
Last updated: 2026-08-30
Who we are
SureClerk is a Shopify app operated by Peppertree. It answers product questions on a merchant's storefront using only that merchant's own catalogue and policy pages. SureClerk is in development and is not in the Shopify App Store yet.
What we store
When a merchant installs SureClerk, we store:
- Shop domain, shop ID and access token: to identify the store and authenticate Shopify API calls
- A copy of catalogue and policy content: product titles, descriptions, handles, variants, prices, inventory levels, and the text of the store's policy and content pages. This copy is what answers are drawn from
- Merchant-approved answers and app settings: the question-and-answer pairs and widget configuration the merchant creates
From shoppers who use the chat widget, we store:
- Chat messages: the questions a shopper types and the answers returned, so the conversation survives page navigation
- An anonymous visitor identifier: a random ID held in the shopper's browser to group their messages into one conversation. It is not linked to a Shopify customer account
- An email address, only if the shopper chooses to leave one: offered when the assistant cannot answer, so the merchant can follow up. It is never required to use the chat
When an order follows a chat, we store the order ID, order number, total and currency to report how many sales followed a conversation. We do not store customer names, addresses, phone numbers, payment details or line items.
How we use data
Data is used solely to operate the app for the merchant who installed it. We do not sell data, share it with third parties for their own purposes, or use it to train machine-learning models.
AI processing
When a question cannot be answered from the merchant's approved answers or from exact catalogue facts, the question and the retrieved passages from the merchant's own store content are sent to a large language model provider (Anthropic or Google, depending on configuration) to compose a reply. The model may only restate what is in those passages. Providers are used under their API terms, which do not permit training on this data.
Data retention and deletion
- Uninstall: Shopify sends a shop/redact request 48 hours after uninstall, and we delete every record belonging to that shop
- Shopper erasure: on a customers/redact request we delete that shopper's conversations and messages and remove their email address. The question text may be retained in de-identified form so the merchant can still see the content gap
- Shopper access: on a customers/data_request we assemble everything held for that shopper and provide it to the merchant, who is responsible for delivering it
Requests are matched on the email address the shopper provided, as that is the only identifier shared between Shopify's customer records and the chat.
GDPR and CCPA
We respond to Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Merchants act as the data controller for their shoppers' data; Peppertree acts as a processor on their behalf.
Contact
Questions or data requests: [email protected]