Effective date: 26 June 2026

Last updated: 26 June 2026

This Privacy Policy explains how Liquify AI (“Liquify AI”, “we”, “us”, or “our”) collects, uses, shares, and protects information in connection with the Liquify AI Shopping Assistant application (the “App”) — an AI chat assistant that merchants embed on their Shopify storefronts.

Liquify AI is a product operated by Digital Angels Ltd, a company registered in England and Wales.
Registered address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ
Contact: hello@liquify.design

1. Who this policy is for

The App is used by two different groups of people, and we treat their data differently:

  • Merchants — Shopify store owners and staff who install and configure the App. For data about merchants and their stores, we are the data controller.
  • Shoppers — visitors and customers of a merchant’s store who interact with the chat widget. For shopper data, the merchant is the data controller and Liquify AI acts as a data processor, handling that data on the merchant’s behalf and under their instructions.

If you are a shopper and want to exercise privacy rights over your data, please contact the store you interacted with. We will support that store in responding to your request (see Section 8).

2. Information we collect

2.1 From merchants (when you install and use the App)

  • Store identifiers and account data: Shopify store domain, store name, Shopify shop ID, and installation date.
  • Shopify authorization: OAuth access tokens issued by Shopify, which the App uses to make API calls to your store on your behalf (e.g. read products, orders, policies, and customer context). We request only the access scopes the App needs to function.
  • App configuration: Your widget and assistant settings — welcome messages, colors and styling, enabled features, custom instructions, synonyms, shopping guides, guardrails, contact-form fields, and similar configuration you create.
  • Billing and usage data: Your selected plan, subscription status, trial dates, conversation/usage counts for metering, and the Shopify charge identifiers associated with your subscription. We do not collect or store your payment card details — billing is processed by Shopify through the Shopify Billing API.

2.2 From shoppers (collected on the merchant’s behalf via the widget)

Depending on which features a merchant enables, the App may process:

  • Chat content: The messages a shopper types (or speaks, where voice input is used) and the assistant’s replies, including the conversation history within a session.
  • Contact form submissions: Name, email address, phone number (if enabled), order number (if enabled), the shopper’s message, an AI-generated summary of the conversation, and any custom fields the merchant defines.
  • Newsletter / subscriber sign-ups: Name, email address, and phone number where the shopper opts in.
  • Order-tracking lookups: The email address and/or order number a shopper provides to look up an order, which is used to retrieve order status, fulfillment, and tracking details from Shopify.
  • Logged-in customer context: Where a shopper is signed in to the store, their Shopify customer ID, name, and saved assistant preferences may be used to personalize responses.
  • Session and technical context: A visitor identifier (stored in the browser), the page or product being viewed, current cart contents (items, quantities, subtotal), and locale signals such as country, currency, and time zone — used to give accurate, localized answers.
  • IP address (transient): Where a merchant enables bot protection, the shopper’s IP address is sent to Cloudflare Turnstile to verify the request is not automated. We do not store the IP address in our own systems for this purpose.

We do not intentionally collect special categories of personal data, and we ask merchants not to configure the App to solicit them.

3. How we use information

We use the information above to:

  • Provide and operate the App — power the chat assistant, search the merchant’s live catalog, recommend products, handle variant selection and add-to-cart, track orders, and route contact-form submissions.
  • Generate AI responses — process chat messages and relevant context through our AI provider to produce helpful answers (see Section 4).
  • Deliver merchant features — forward contact-form submissions to the merchant, sync opted-in subscribers to the merchant’s Shopify customer list, and surface promotions and recommendations.
  • Meter usage and bill — count conversations to apply plan limits and overages.
  • Secure the service — detect and prevent abuse, spam, and automated traffic.
  • Maintain and improve the App — debug issues, monitor quality, and evaluate and improve assistant responses (see Section 4.4).
  • Comply with legal obligations and enforce our agreements.

Legal bases (where GDPR/UK GDPR applies): for merchants, we rely on performance of our contract with you and our legitimate interests in operating and improving the service. For shoppers, the merchant determines the legal basis as data controller; we process on their documented instructions.

4. How we share information — sub-processors and third parties

We do not sell personal information, and we do not use shopper or merchant data for advertising. We share data only with the service providers needed to run the App, and only as described below.

4.1 Shopify

The App is built on Shopify and exchanges data with the Shopify platform to read catalog, order, policy, and customer information, to route contact-form submissions through Shopify automations (Flow), to sync opted-in subscribers, and to process billing. Your use of Shopify is governed by Shopify’s own privacy policy.

4.2 AI provider — OpenAI

Chat messages and the relevant context needed to answer them (such as conversation history, the product or page being viewed, cart summary, store policies, and country/currency) are sent to OpenAI to generate the assistant’s responses. Order numbers or an email address are included only when a shopper provides them to look up an order. OpenAI processes this data as our sub-processor; under OpenAI’s API terms, data submitted through the API is not used to train their models.

4.3 Bot protection — Cloudflare

Where a merchant enables bot protection, a verification token and the shopper’s IP address are sent to Cloudflare (Turnstile) to confirm requests are legitimate.

4.4 Quality evaluation — Anthropic

To monitor and improve the quality of assistant responses, a copy of conversation transcripts may be processed through an automated evaluation pipeline that uses Anthropic as a sub-processor. This is used for internal quality measurement only and not to make decisions about individual shoppers.

4.5 Infrastructure and hosting

The App and its databases are hosted with our infrastructure and database providers (currently Replit for application hosting and Neon for our analytics datastore), who process data on our behalf under appropriate data-processing terms.

4.6 Legal and corporate

We may disclose information if required by law, to protect our rights or users’ safety, or in connection with a merger, acquisition, or sale of assets (in which case we will notify affected merchants).

A current list of sub-processors is available on request at hello@liquify.design.

5. International data transfers

The providers above may process data in the United States and other countries. Where we transfer personal data internationally, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses, and the UK equivalents) as required by applicable law.

6. Cookies and local storage

The chat widget uses browser local storage — not advertising or tracking cookies — to function. Specifically, it stores:

  • a visitor identifier, so a returning shopper’s conversation and usage are recognized across sessions; and
  • chat state, so an in-progress conversation persists if the page reloads.

The admin (merchant) interface also stores a small preference value for the selected admin language and a sidebar state cookie. The App does not use third-party advertising cookies, tracking pixels, or cross-site profiling.

7. Data retention

  • Merchant account, configuration, and billing data are retained for as long as the App is installed and for a reasonable period afterward to meet legal, accounting, and audit obligations.
  • Shopper conversations and related data are retained for as long as needed to provide the service to the merchant and to maintain and improve the App, and in any case for no longer than 36 months, after which they are deleted or anonymized.
  • On uninstall, Shopify sends us a shop/redact request and we delete the merchant’s record and associated data from our systems.

We honor deletion requests as described in Section 8.

8. Your rights and how to exercise them

Depending on where you live (e.g. the EEA, UK, or California), you may have the right to access, correct, delete, or restrict processing of your personal data, to object to processing, and to data portability. You also have the right to lodge a complaint with your local data protection authority. In the United Kingdom, the relevant authority is the Information Commissioner’s Office (ICO, ico.org.uk).

  • Merchants can exercise these rights, or ask questions, by emailing hello@liquify.design.
  • Shoppers should contact the store they interacted with (the data controller). We support merchants in fulfilling these requests through Shopify’s mandatory privacy webhooks:
    • customers/data_request — when a shopper asks a merchant for their data, we return the relevant records (subscriber entries, chat sessions, messages, and stored preferences) we hold for that shopper.
    • customers/redact — we delete the shopper’s stored subscriber records and saved preferences for that store.
    • shop/redact — when a merchant uninstalls, we delete that store’s data.

We do not charge for reasonable requests and will respond within the timeframe required by applicable law.

9. Security

We use technical and organizational measures designed to protect personal data, including encryption of data in transit (TLS), access controls, and limiting access to authorized personnel. Shopify access tokens are used only to make API calls on a merchant’s behalf. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children’s privacy

The App is intended for use by merchants and adult shoppers. It is not directed to children, and we do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify merchants through the App or by email. Your continued use of the App after an update means you accept the revised policy.

12. Governing law

This Privacy Policy and any dispute relating to it are governed by the laws of England and Wales, without prejudice to any mandatory data-protection rights you have under your local law.

13. Contact us

Questions, requests, or complaints about this policy or your data:

Digital Angels Ltd (Liquify AI)
Email: hello@liquify.design
71-75 Shelton Street, Covent Garden, London WC2H 9JQ