Legal

Privacy Policy

Last updated: June 22, 2026

Providara AI Concierge Service (“Providara,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices available to you. It applies to merchants who purchase a Providara setup package or install our Shopify app, and, where relevant, to end customers who interact with the AI concierge on a merchant's Shopify storefront.

1. Who we are

Providara AI Concierge Service is a Shopify app that provides an AI concierge for merchants—delivering product recommendations and storefront chat to help shoppers find products and get support on your store. Our marketing website is providara.com; the embedded merchant admin is at app.providara.com. For privacy inquiries, please contact us.

2. Data we collect

We collect personal data in the categories below. We collect only what is needed to operate Providara AI Concierge Service.

Merchant data (account and business). When you create an account, purchase a setup package, or install our app, we may collect:

  • Your name, email address, and business name
  • Your Shopify store domain and store identifier
  • Billing information for setup packages and subscriptions, processed by Paddle (our merchant of record). We do not store full payment card numbers
  • Account credentials and support communications with our team
  • AI provider API keys and related configuration you choose to connect (for example, Grok, Groq, or Together AI). Usage and charges from your AI provider are between you and that provider

Shopify store data (via granted app permissions only). With your authorization through Shopify OAuth, we access store data only through the scopes you approve at installation: read_products, write_products, and write_app_proxy. This may include:

  • Product catalog data: titles, descriptions, variants, prices, images, and inventory quantities as they appear on product and variant records returned by the Products API
  • Shop metafields we write using write_products: widget configuration such as welcome message, widget token, and related theme preferences. We do not modify your product listings, prices, or catalog content through this scope

We do not access order history or Shopify Admin customer records. We do not request read_orders, read_customers, read_content, or read_inventory scopes. Storefront add-to-cart actions use the Shopify Ajax Cart API in the shopper's browser session; we do not access carts through Admin API scopes.

Storefront shopper data (via chat widget). When end customers use the AI concierge on your storefront, we process:

  • Chat messages and session identifiers
  • Conversation context needed to respond (for example, products discussed or viewed during the session)
  • Optional email address or profile fields if the shopper voluntarily provides them

For storefront shopper data, the merchant is the data controller. Providara acts as a data processor, handling this data on the merchant's behalf to operate the AI concierge.

Technical data. We collect logs, IP addresses, browser and device information, and security and abuse-prevention signals to operate, secure, and improve the service.

Website visitors. If you visit providara.com without installing the app, we may collect contact form submissions and standard website analytics as described in the Cookies and analytics section below.

3. How we use data

We use personal data to:

  • Operate the AI concierge, including storefront chat and product recommendations
  • Sync product catalog data and apply your widget configuration
  • Process setup and subscription payments through Paddle
  • Provide customer support and respond to inquiries
  • Maintain security, prevent abuse, and improve reliability and product features
  • Send service-related communications (for example, setup instructions, billing receipts, and product updates)
  • Comply with legal obligations, Shopify partner requirements, and enforce our terms

We do not sell your personal data. We do not use merchant store data to train public-facing AI models in a way that identifies your business without your consent, except as needed to deliver the service you purchased.

4. Shopify app integration

Providara is installed on your Shopify store through OAuth. We access Shopify data only with the scopes you approve during installation, as described in Section 2.

Storefront chat and related requests from the theme app embed (“Providara AI Service”) are routed to our API through the Shopify app proxy (/apps/providara/*). App proxy requests are verified using Shopify-signed requests.

We subscribe to Shopify mandatory privacy webhooks, including customers/data_request, customers/redact, and shop/redact. We also handle app/uninstalled to begin removal of associated shop data when you uninstall the app.

When you uninstall Providara, we delete or anonymize associated shop and customer interaction data within a reasonable timeframe. A shop/redact webhook completes erasure in accordance with Shopify's required timeline for partner apps.

Merchants may export or delete customer chat data through privacy tools in the embedded admin at app.providara.com, where those features are available.

5. Legal bases (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process personal data under the following legal bases:

  • Contract: to provide Providara and fulfill our agreement with you
  • Legitimate interests: to secure our service, prevent abuse, and improve functionality, balanced against your rights
  • Consent: where required, such as for optional marketing emails (you may withdraw consent at any time)
  • Legal obligation: where we must comply with applicable law, including Shopify data-protection requirements

6. How we share data

We share data only as needed to operate Providara:

  • Shopify — app installation, OAuth, product sync, app proxy requests, and storefront integration
  • Paddle — payment processing for setup packages and subscriptions (merchant of record)
  • Cloud and AI providers — hosting, infrastructure, and AI inference. AI providers receive chat content and catalog context only as needed to generate responses for a given session, under contractual safeguards. This includes third-party AI providers whose API keys you supply
  • Professional advisors — legal, accounting, or security services when necessary
  • Authorities — when required by law or to protect rights and safety

We require subprocessors to handle data only on our instructions and with appropriate security measures. A list of key subprocessors is available on request.

7. International transfers

Providara may process data in the United States and other countries where we or our providers operate. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an adequacy decision applies.

8. Data retention

We retain merchant account and shop configuration data while you use the service and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements.

Chat logs and related usage data are retained for a limited period for support and analytics, then deleted or anonymized unless a longer retention period is required by law.

When you uninstall Providara, when we receive a valid deletion request, or when we process Shopify privacy webhooks such as shop/redact or customers/redact, we delete or anonymize applicable data within a reasonable timeframe, subject to backup cycles and legal retention requirements.

9. Your rights

Depending on your location, you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with your local supervisory authority

Merchants can exercise many rights through privacy tools in the embedded admin or by contacting us.

Storefront shoppers who interact with a merchant's AI concierge should contact the merchant first, because the merchant is the data controller for that data. We will assist merchants in fulfilling valid requests where applicable, including requests routed through Shopify compliance webhooks.

10. Cookies and analytics

Our marketing website may use cookies and similar technologies for essential functionality, preferences, and analytics. You can control cookies through your browser settings. The Providara Shopify app and theme app embed (“Providara AI Service”) may use session storage and similar technologies required for the concierge to function on your storefront.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. App proxy requests to our API are verified using Shopify-signed requests. No method of transmission or storage is completely secure; we encourage you to use strong passwords, protect your AI provider API keys, and limit account access to trusted team members.

12. Children

Providara is a business service not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us so we can delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post changes on this page and update the “Last updated” date. Material changes will be communicated by email or in-app notice where required by law.

Questions?

If you have questions about this policy, please contact us. Related policies: Terms of Service, Privacy Policy, Refund Policy, Service Agreement.