Savant ("the app") is a Shopify app built and operated by Coduzion Technologies ("we", "us"). It adds an AI shopping assistant to a merchant's storefront and a reporting dashboard inside Shopify admin.
This policy explains what the app collects, why, who it is shared with, and how long it is kept. It covers two groups of people: merchants who install the app, and shoppers who talk to the assistant on a merchant's storefront.
If you are a shopper: the merchant whose store you were using is the controller of your personal information. We process it on their behalf. Requests about your data are normally best made to that store, and Shopify passes them to us automatically. You can also contact us directly using the details at the end of this page.
When a shopper opens the assistant on a storefront, the app reads what it needs from the merchant's Shopify store (products, inventory, prices, policies) and holds a conversation with the shopper. It can answer questions about the catalogue, recommend products, and, where the merchant has enabled it, discuss price and issue a discount code. It also remembers a shopper between visits so the conversation can pick up where it left off.
| What | Why |
|---|---|
| Messages sent to and from the assistant | To hold the conversation and to let the merchant review it |
| An anonymous device token stored in the browser | To recognise the same browser on a later visit so the conversation can continue. It is set by the app, not by an advertising network, and is not shared with anyone. |
| Shopify customer ID and email address, when known | Only available when the shopper is logged in to the store or has checked out. Used to connect a conversation to a returning customer. |
| A name or preferred form of address, if the shopper offers one | To address the shopper naturally |
| Preferences and characteristics inferred from the conversation, such as categories, brands, sizes, colours, budget signals, gift recipients and occasions, and descriptive tags | To make recommendations relevant on this visit and on later visits |
| Browsing context for the current visit: the page being viewed, products opened, basket contents, visit duration | To answer questions about what is on screen and to check discount conditions against the real basket |
| Aggregate interaction signals: intent, sentiment, what was asked about, questions the assistant could not answer, products asked for but not stocked | To produce the merchant's reporting dashboard |
The app does not collect payment card details, passwords, or government identifiers. It does not send marketing email or push notifications to shoppers. It does not sell personal information, and it does not share it with advertising networks or data brokers.
On install, the app stores the store's myshopify domain, the access token Shopify issues, and the app settings the merchant chooses. With the merchant's granted permissions it reads product, inventory, order, customer and theme data from the Shopify Admin API, and can write discounts. It reads only what is needed to answer shoppers and to produce reporting, and it does not copy the store's full customer list.
The assistant's replies are generated by a large language model. To produce a reply, the app sends the conversation, the relevant catalogue and policy information, and the shopper memory described above to our model provider, Groq, Inc., over an encrypted connection.
We send this only to generate a response for that conversation. Under our arrangement with the provider, this content is not used to train their models.
Automated decisions made by the assistant, such as whether to offer a discount, operate inside limits the merchant sets. They have no legal or similarly significant effect on a shopper, and a shopper can always ignore the assistant and buy at the listed price.
| Recipient | Purpose | Location |
|---|---|---|
| Shopify Inc. | The platform the app runs on and reads store data from | Canada / United States |
| Groq, Inc. | Generating the assistant's replies | United States |
| Amazon Web Services | Hosting the app server and its database | United States (us-east-1) |
We also disclose information where we are legally required to, and to professional advisers where necessary. We do not sell personal information.
Conversations and shopper profiles are stored in a database on our application server, hosted with Amazon Web Services in the United States. Traffic to and from the app is encrypted in transit using TLS.
If you are in the United Kingdom, European Economic Area or Switzerland, your information is transferred outside your region. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies.
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to how it is used, or ask for it in a portable form. You may also lodge a complaint with your local data protection authority.
customers/data_request, customers/redact and shop/redact requests, which are handled within 30 days and normally much sooner.Access to the app's server and database is restricted to named administrators using key-based authentication. All traffic is served over TLS. Storefront requests are verified against Shopify's request signature, and webhooks are rejected unless their HMAC signature validates. Access tokens are stored server side and are never exposed to the storefront or to a shopper's browser.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires.
The app stores one first-party token in the shopper's browser so it can recognise the same device on a later visit. It is functional, not advertising related, and it is not shared with third parties. Clearing site data removes it, and the assistant will then treat the visit as a new one.
The app is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child has provided information through the assistant, contact us and we will delete it.
If we make a material change we will update the date at the top of this page and, where the change significantly affects merchants, notify them in the app.
Coduzion Technologies
Email: support@coduzion.com
For privacy questions, please put "Privacy" in the subject line so it reaches the right person quickly.