Privacy Policy
Version 3.1 · effective May 22, 2026
This Privacy Policy explains how Shopxare, LLC ("Shopxare", "we", "us") collects, uses, shares and protects personal data when you visit shopxare.com, use our apps, contact us, or use the Shopxare Services as a customer or teammate. It also explains the rights you have.
1. Who is responsible
Controller: Shopxare, LLC, 2318 Garden Rd, Shopxare Park, Monterey, CA 93940, United States · [email protected] · +1 862 727 7373.
When we are a processor. Our customers use Shopxare to talk to their customers. Messages, contact records, files and similar data that a customer's End Users send through a Shopxare Messenger, email channel, Telegram bot or call belong to that customer, who is the controller. We process that data only on the customer's instructions under our Data Processing Addendum. If you are an End User of one of our customers, please read that customer's privacy notice and send requests to them first; we will help them answer.
2. Data we collect
2.1 Visitors of shopxare.com
- Technical data: IP address, browser and device type, pages viewed, referring page, time of visit and similar log data.
- Preferences: the language you choose (stored in a cookie, see the Cookie Policy).
- Visit statistics measured by our own Messenger script, without third-party analytics pixels.
2.2 People who contact us
- Name, email address, company, phone number, website and the content of your message when you use our contact form, chat with us or email us.
- Requests you submit through our legal forms (privacy, copyright, abuse, security reports, DPA requests).
2.3 Account holders and teammates
- Account data: name, email address, password (stored only as a salted hash), profile photo, job title, bio, languages, email signature, interface preferences and language.
- Security data: two-step verification settings, trusted devices, sign-in history, IP addresses and approvals made in the mobile app.
- Billing data: company name, billing address, tax ID and the last four digits and expiry of a card. Full card numbers are handled by Stripe and never reach our servers.
- Usage data: features used, settings changed and audit-log entries in your Workspace.
- Communications with our support team.
2.4 Desktop and mobile apps
- Device data: device model, operating system, app version and a push-notification token issued by Apple, Google or Expo.
- Notification preferences, such as which events notify you and which sound is played.
- If you choose to sign in by scanning a QR code, we process the one-time code and the device it was used on. We do not access your camera roll; the camera is used only while you scan.
2.5 Customer Data processed on our customers' behalf (as a processor, see section 1): End User names, emails, phone numbers, messages, files, page visits, events, device and location information that the customer's Messenger collects, call signalling data, and attributes the customer sends us.
3. Why we use it and our legal bases
| Purpose | Data | Legal basis (EEA/UK) |
|---|---|---|
| Provide the Services, accounts and apps | 2.3, 2.4, 2.5 | Contract; for Customer Data, the customer's instructions |
| Secure the Services, prevent fraud and abuse, verify sign-ins | 2.1, 2.3, 2.4 | Legitimate interests (keeping accounts and the platform safe) |
| Answer enquiries and support requests | 2.2, 2.3 | Contract or legitimate interests |
| Billing, accounting and tax | 2.3 billing data | Contract; legal obligation |
| Send service, security and billing messages | 2.3, 2.4 | Contract; legitimate interests |
| Send product news (you can opt out at any time) | Email address | Consent or legitimate interests, as local law requires |
| Improve the Services and produce aggregated statistics | 2.1, Usage Data | Legitimate interests |
| Comply with law and enforce our terms | Any relevant data | Legal obligation; legitimate interests |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use Customer Data to train AI models.
4. AI features
When a customer enables AI features (Are AI, Copilot, live translation, mood detection, knowledge-gap suggestions), the relevant parts of conversations and knowledge content are sent to the AI provider that the customer's Workspace uses: Google (Gemini) when Shopxare's platform key is used, or the provider whose API key the customer added (OpenAI, Anthropic or Google). These providers process the data under their API terms to return a result; we choose providers whose API terms do not allow them to train their models on the data sent. See the AI Terms.
5. Who we share data with
- Sub-processors and service providers that host, deliver and secure the Services, listed with their location on the Sub-processors page, such as our hosting provider, Cloudflare and Stripe.
- Providers chosen by a customer, such as a Telegram bot, an AI provider with the customer's own key, or e-commerce platforms the customer connects. The customer decides to use them.
- Professional advisers (lawyers, accountants, auditors) under confidentiality.
- Authorities, when the law requires it, following our Law Enforcement Guidelines.
- A successor, if we are involved in a merger, acquisition or sale of assets, subject to this policy.
6. Where data is stored and international transfers
Our primary servers are operated for us by Veriup Bulut İnternet Hizmetleri A.Ş. in Türkiye. Cloudflare, Inc. routes and protects traffic through its global network. Shopxare, LLC is a US company, and some providers process data in the United States or other countries.
When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision (including Türkiye and the United States), we use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or the Swiss equivalent, together with additional safeguards such as encryption in transit and strict access control. You can ask for a copy of the relevant safeguards at [email protected].
7. How long we keep data
| Data | Retention |
|---|---|
| Website and server logs | Up to 90 days, longer only when needed to investigate an incident |
| Visit statistics (shopxare.com and Messenger visits) | Up to 13 months |
| Contact form and sales enquiries | Up to 24 months after the last contact |
| Account data | For the life of the account, then deleted within 30 days of closure |
| Customer Data | For the life of the Workspace (customers can delete contacts earlier, and can ask us to delete other data); deleted within 30 days after the Workspace is closed; daily backups roll off after 35 days |
| Billing records | As long as tax and accounting law requires (generally 7 years) |
| Security and audit logs | Up to 12 months |
| Push tokens | Until you sign out of the app or the token expires |
8. Security
We protect personal data with technical and organisational measures, including encryption in transit (TLS), hashed passwords, two-step verification and app approvals, role-based access, tenant isolation, monitoring and backups. See our Security overview. If you find a vulnerability, please follow our Responsible Disclosure Policy.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data;
- restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- data portability;
- withdraw consent at any time, without affecting earlier processing;
- not be subject to decisions based solely on automated processing that significantly affect you (we do not make such decisions about you);
- lodge a complaint with your data protection authority.
California and other US states: see our US State Privacy Notice.
Türkiye (KVKK): under Article 11 of Law No. 6698 you may learn whether your data is processed, request information, learn the purpose and recipients, request correction or deletion, object to results arising from automated analysis, and claim compensation for unlawful processing.
To exercise a right, use the privacy request form or email [email protected]. We will verify your identity before acting and answer within the time the law sets (usually one month; 45 days in California; 30 days under the KVKK). If the data is Customer Data, we will pass your request to the customer concerned.
10. Global Privacy Control and Do Not Track
We honour Global Privacy Control signals as an opt-out of sale and sharing. As we do not sell or share personal data, no further change is needed. We do not respond to "Do Not Track" signals, which have no agreed standard.
11. Children
The Services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
12. Representatives
Where the law requires us to appoint a representative in the European Union or the United Kingdom, we will publish their details on this page.
13. Changes
We will post changes to this policy on this page with a new version number and date. If changes are material, we will also notify account holders by email or in the Services.
14. Contact
Shopxare, LLC · 2318 Garden Rd, Shopxare Park, Monterey, CA 93940, United States · [email protected] · +1 862 727 7373