Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how SYS INFORMATION TECHNOLOGY LTDA (Brazilian company registration/CNPJ 49.780.808/0001-28), headquartered in Ribeirão Preto, SP, Brazil, collects, uses, stores, and protects personal data in connection with WapShopAI — an AI shopping consultant chat installed on Shopify stores.
We process personal data in accordance with Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) and, where applicable to visitors or merchants located in the European Union, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Our two roles: who is the data controller
The merchant who installs WapShopAI is the controller of their own customers' and visitors' data — they are the one who decided to sell online and collect data from people visiting their store. SYS INFORMATION TECHNOLOGY acts, in that case, as a processor: we handle that data only to provide the service the merchant contracted, following their instructions and this policy.
As for the merchant's ACCOUNT data (store domain, billing data, app settings), SYS INFORMATION TECHNOLOGY is the controller, since we decide how and why that data is processed to operate the platform.
2. What data we collect
Store and catalog data: store domain, products, variants, prices, images, and stock, obtained via the Shopify API to power the AI's recommendations. We do not collect data about the store's registered customers (name, email, address) beyond what is strictly described below.
Conversation data: messages exchanged between the visitor and the AI agent, tied to an anonymous session token (not a real identity), unless the visitor themselves types personal data into the conversation.
Order data for revenue attribution: only the conversation identifier (wapshop_cid) and the value of the order line tied to it — never the buyer's name, email, address, or phone number.
Order tracking (optional feature, off by default): when enabled by the merchant, the email provided on the order is used once to verify the identity of whoever is asking about order status — it is not stored by the agent beyond that one-time check.
Billing data: processed directly by Stripe, our payment processor. We do not store credit card numbers on our servers.
Super admin and merchant account access data: authentication credentials (password and two-factor secret always encrypted).
3. What we use the data for
We use the data described above for the following purposes:
- Generating real product recommendations and answering operational questions (shipping, payment, contact, location) inside the chat.
- Automatically configuring the agent's persona (name, tone of voice, greeting) from the store's own catalog.
- Measuring and billing usage of the service per conversation, according to the merchant's chosen plan.
- Calculating revenue attributed to the chat (conversion attribution), based only on the conversation identifier and the order line value.
- Preventing abuse, fraud, and misuse of the platform (rate limits, anomalous usage-spike detection).
- Complying with legal and tax obligations.
4. Who we share data with
We do not sell personal data. We only share data with service providers that help us operate WapShopAI, always limited to what's necessary for the contracted purpose:
- Anthropic (provider of the Claude AI models) — receives the conversation message content to generate the agent's replies.
- Shopify — the e-commerce platform WapShopAI is installed on; we exchange catalog, order, and authentication data within the scopes authorized by the merchant.
- Stripe — subscription payment processing and billing.
- Infrastructure provider (hosting and database) that runs our servers.
- Email service (SMTP) used only for internal administrative notifications.
5. International data transfers
Because Anthropic is headquartered in the United States, conversation content is transferred internationally to generate AI responses. We rely on the contractual clauses and safeguards required by LGPD (art. 33) and GDPR (art. 46) for that transfer.
If you need specific details about server locations or sub-processors for audit or compliance purposes, contact us through the channel in section 11.
6. How long we keep data
Store and catalog data is kept for as long as the app is installed and the license is active, so the AI keeps responding based on current information.
Conversation data is kept for as long as needed to provide the service (including support continuity) and, for stores in the cosmetics/health segment, may contain sensitive information voluntarily shared by the visitor — in those cases, we apply reduced retention and backups with an aligned retention period.
When the app is uninstalled, store data is removed as described on our Data Deletion page. You may also request earlier deletion at any time through the contact in section 11.
7. How we protect data
Access tokens and sensitive credentials are encrypted at rest (AES-256-GCM). Each store's data is isolated automatically and centrally in our database — there is no code path that mixes data across different stores.
Our team's access (super admin) requires its own authentication with a second factor (TOTP), separate from the merchant's and the visitor's sessions.
8. Your rights as a data subject
Under LGPD (art. 18) and, where applicable, GDPR (arts. 15–22), you may request:
- Confirmation that processing exists and access to your data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary data or data processed unlawfully.
- Portability of your data to another service provider.
- Deletion of personal data processed with your consent.
- Information about the third parties we share your data with.
- Withdrawal of consent, when processing is based on it.
- Objection to processing based on other legal grounds, where the law is not being complied with.
9. Cookies and local identifiers
The chat widget uses a session token stored in the visitor's browser to keep the conversation history. That token is only persisted durably when Shopify's own Customer Privacy API signals the store doesn't require additional explicit consent, or when that consent was given; otherwise, the token is ephemeral and only lasts for the session.
We do not use third-party advertising or tracking cookies.
10. Minors
WapShopAI is not directed at children and does not knowingly collect data from minors. If a store serves that audience, responsibility for any additional consent controls belongs to the merchant, as the controller of their own customers' data.
11. Data protection contact
To exercise your rights, ask questions about this policy, or report a privacy concern, contact us at now@sysflow.me. We respond to GDPR requests within one month (art. 12(3)) and to LGPD requests within a reasonable time, without undue delay.
12. Changes to this policy
We may update this policy to reflect changes in the service or in the law. The date at the top of this page always indicates the latest version. Material changes will be communicated to merchants through the app dashboard or by email.