Privacy policy
This policy explains how Always Awake processes information when a Shopify merchant installs the app and when a visitor uses its storefront sales guide.
Information we process
- Shop domain, app configuration, granted access scopes and Shopify authentication sessions.
- Published store information the merchant authorises us to read, including products, inventory, pages, articles, policies, menus, public metaobjects, markets, locales and delivery configuration.
- Anonymous storefront identifiers, page context, chat messages, recommendation events, experiment assignment and cart interactions needed to provide and measure the service.
- Human handover requests, replies from the store team, team display labels, conversation status and related timestamps. Chat transcripts can include information a shopper or staff member chooses to type; please do not include payment credentials or unnecessary sensitive information. Authorised merchant staff can review the conversation in the app inbox.
- Merchant notification preferences and activity records, including whether an alert has been read. If a merchant connects a browser for device notifications, we store its push endpoint, subscription encryption keys, browser description and connection and last-used timestamps. Connection links use a hashed, single-use pairing token that expires after ten minutes.
- When a merchant enables lifecycle capture, a visitor can choose to submit an email address and buying preferences directly to the merchant's Klaviyo account. Always Awake records that a capture succeeded but does not retain the submitted email address in its own database.
- When order measurement is enabled, we process only the Shopify order identifier, anonymous Always Awake conversation reference, paid total, currency, payment timestamp and paid, cancelled or refunded state. We do not retain the customer name, email, phone, address, line items or payment details for attribution.
- Brand images uploaded by the merchant, plus filenames, media types and sizes.
- Token counts, model name, error and operational records needed to monitor reliability and control cost. We hash network addresses for short-lived abuse prevention and do not store the original address in the app database.
How we use information
We use information to authenticate the merchant, answer shopper questions, recommend relevant products, restore recent conversations, let the store team take over a chat, deliver selected merchant alerts, display analytics, connect eligible paid orders to assisted conversations, remove cancelled or refunded revenue, prevent abuse, provide support and comply with law. We do not sell personal information or use merchant or shopper data to train our own general-purpose model.
AI processing and service providers
Relevant shopper questions, conversation history and selected store context are sent to Google’s Gemini API to generate an answer. Shopify provides store access, authentication, billing and app delivery. Netlify provides hosting, managed database and object storage. When a merchant enables the optional integration, Klaviyo receives information a visitor expressly chooses to submit for the merchant's email marketing and lifecycle flows. These providers process data under their own contractual security and privacy commitments.
Opt-in device notifications are delivered through the browser's push provider, such as Google, Mozilla, Apple or Microsoft. Notification payloads are encrypted in transit to the subscribed browser. They contain a general activity description and a link to the authenticated merchant inbox, not chat text, product details or customer details. Browser and operating-system permissions control where alerts appear.
Retention and deletion
Merchants choose retention periods between 30 and 365 days for conversation and journey data. The default is 90 days for conversations and 365 days for aggregated journey events. Merchants can delete interaction data immediately from Settings. Uploaded brand assets are retained until replaced, removed with the app’s shop data, or deletion is requested. Shopify shop-redaction requests delete all shop-owned app records.
Human replies and handover records follow the conversation retention period. Activity notifications use the same retention setting. Browser subscriptions remain until a merchant removes the connection, the push provider reports it has expired, or the app is uninstalled or its shop data is redacted. Expired pairing records are removed during routine cleanup. Deleting interaction data in Settings also deletes its activity feed, but does not disconnect browsers; those connections can be removed separately in Activity.
Security and access
We use signed Shopify app-proxy requests, server-side credentials, per-store data isolation, encrypted HTTPS transport, managed infrastructure, rate limits and least-privilege Shopify access. No internet service can guarantee absolute security.
Your choices
Merchants can change retention, export conversation data, disable lifecycle capture, disable the storefront widget or uninstall the app. Device notifications require a separate browser opt-in. Merchants can pause browser delivery or remove a connected browser in Activity, and can revoke notification permission in their browser or device settings. Lifecycle capture is optional for visitors and its consent box is not pre-selected. Store visitors should contact the merchant first because the merchant controls the storefront and marketing relationship. We will support lawful access, correction or deletion requests.
International processing and changes
Providers may process information outside the United Kingdom. Appropriate contractual and technical safeguards are used where required. We may update this policy as the service or law changes; the effective date will show the latest version.
Service operator
Always Awake is a Shopify app operated by Neat Digital in the United Kingdom. This operator disclosure identifies the organisation responsible for the service; Always Awake remains the product and customer-facing brand.
Email the Always Awake privacy team with your store domain and the nature of the request.