Privacy Policy
SolveBotic LLC (“SolveBotic,” “we,” “us,” or “our”) operates the SolveBotic service — an AI-powered customer support platform for ecommerce brands. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights.
SolveBotic LLC is a Colorado limited liability company.
If you have questions about this policy or want to make a data request, contact us at solvebotic.com/contact.
1. The Two Data Relationships
SolveBotic handles two different kinds of personal information, and the relationships are different for each:
Merchant data — we are the controller.When a business (the “merchant”) signs up for SolveBotic, we collect and decide how to use their account information directly. They are our customer.
End-customer data — we are a processor.When a merchant installs the SolveBotic widget on their store, that widget collects information from the merchant's own customers (the “end-customers”): the messages they type, the email addresses and order numbers they provide, and the conversation history. SolveBotic processes that information on the merchant's behalf. The merchant — not SolveBotic — is the controller of their end-customers' personal data.
If you are an end-customer with a question about how your data is handled, please contact the merchant whose store you were interacting with. They can in turn contact us if they need our help.
2. Information We Collect
From merchants (data we control):
- Account information: name, email address, business name
- Brand and store configuration: brand name, slug, platform (Shopify or WooCommerce), and the FAQ / knowledge-base content the merchant provides
- Integration credentials: API tokens for Shopify or WooCommerce, used to read order data from the merchant's connected store
- Billing information: processed by Stripe — we receive subscription status, plan, and a Stripe customer ID, but we do not store full payment card numbers
- Notification preferences: email address and Slack webhook URL for escalation alerts
From end-customers (data we process on the merchant's behalf):
- The text of support messages typed into the widget
- Email addresses and order numbers provided during the conversation
- Conversation session history
- Return-request details: reason, category, and resolution status
- Order data fetched from the merchant's connected Shopify or WooCommerce store when an end-customer asks about a specific order
Automatically collected:
- Standard technical and usage data such as IP addresses, browser type, and request logs, used for security, debugging, and service operation
3. How We Use Information
We use the information described above to:
- Operate the service and respond to customer support inquiries
- Generate AI responses to end-customer messages
- Process return requests and route escalations to the merchant
- Send notification emails and Slack messages
- Process payments and manage subscriptions through Stripe
- Communicate with merchants about their account
- Maintain security and prevent abuse
- Improve the service through aggregated, non-identifying analysis
4. AI Processing and Sub-processors
To run the service, we share information with the following sub-processors. Each is bound to handle the data only as needed to provide their service.
Anthropic (AI processing). Support conversation content — the end-customer's messages and conversation context — is transmitted to Anthropic's API (Claude) to classify the message and generate a suggested response. The merchant's FAQ / knowledge-base content is also included in the prompt sent to Anthropic so that responses reflect the merchant's policies. Anthropic processes this data under its own commercial terms of service and privacy policy, which you can review at anthropic.com. We use Anthropic's API in a manner intended to keep your data confidential and out of model training, consistent with Anthropic's commercial terms.
Supabase (database and infrastructure). All account, conversation, order, and return-request data is stored in a managed Postgres database hosted by Supabase.
Resend (transactional email). Used to send escalation notifications, return-request notifications, and other transactional emails on behalf of merchants.
Stripe (payment processing). Handles all subscription billing, payment card storage, and the merchant billing portal. SolveBotic does not store full card numbers.
Vercel (hosting and infrastructure). Hosts the SolveBotic application and serves the embedded widget.
Shopify and WooCommerce (merchants' connected stores).When an end-customer asks about a specific order, SolveBotic retrieves order data from the merchant's connected Shopify or WooCommerce store using credentials the merchant has provided. We act on the merchant's behalf when making these requests.
Slack (a merchant-configured destination, not a SolveBotic sub-processor).Separately from the sub-processors above, a merchant may configure a Slack webhook for escalation or return alerts. When they do, the content of those notifications — which can include an end-customer's conversation summary and email address — is sent to the merchant's own Slack workspace. This happens only when the merchant enables it; the destination, and the data-processing relationship with Slack, are the merchant's, not ours.
5. Data Retention and Deletion
We retain your account information and the associated support-conversation, order, and return-request data for as long as your account is active. When you ask us to close your account or delete your data, we delete it from our production systems within thirty (30) days — except for any records we are required to retain to comply with our legal obligations, resolve disputes, or enforce our agreements.
After data is deleted from our production systems, residual copies may remain in our encrypted, access-controlled backups for a limited period. These backups are rotated on a schedule, and deleted data is purged from them within fourteen (14) days.
You can ask us to close your account or delete your data at any time by contacting us at solvebotic.com/contact, or by emailing us directly at privacy@solvebotic.com.
6. Legal Basis for Processing (GDPR)
For individuals in the European Economic Area and the United Kingdom, our legal bases for processing personal data are:
- Merchant data: performance of our contract with the merchant (to provide the service and manage the account), and our legitimate interests in securing the service and preventing abuse.
- End-customer data: we process this only as a processor, on the instructions and lawful basis of the merchant, who is the controller of their end-customers' personal data.
We do not intentionally process special-category personal data (as defined in Article 9 of the GDPR); if end-customers voluntarily include such information in support conversations, it is processed only as described in Section 4.
7. Cookies and Local Storage
The SolveBotic dashboard sets strictly-necessary cookies to keep merchants signed in (managed by our authentication provider, Supabase). The embedded chat widget uses your browser's sessionStorage to hold a conversation session and does not set cookies. Our landing site sets no analytics or advertising cookies, and we do not use third-party tracking cookies anywhere.
Because we use only strictly-necessary storage, no cookie-consent banner is required. You can clear cookies and local storage at any time through your browser settings; doing so will sign you out of the dashboard.
8. Data Sharing
We do not sell personal data.
We share personal data only with the sub-processors listed in Section 4, who use it solely to provide services to us. We may also disclose information if we are required to do so by law, court order, or to protect the rights, property, or safety of SolveBotic, our users, or others.
We do not share personal data with advertisers and do not use it for advertising purposes.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of the personal data we hold about you, and to object to or restrict certain processing.
End-customers:If you interacted with a SolveBotic widget on a merchant's store and want to exercise any of these rights, please contact the merchant first — they are the controller of your data and will direct any necessary requests to us. We will assist the merchant in responding to verified requests.
Merchants: You can exercise these rights by contacting us at solvebotic.com/contact, or by emailing us directly at privacy@solvebotic.com.
We acknowledge the rights granted under the General Data Protection Regulation (GDPR) in the European Union and United Kingdom, and the California Consumer Privacy Act (CCPA), to the extent they apply.
10. Security
We use reasonable technical and organizational measures to protect personal data. These include transport-layer encryption (HTTPS), access controls on our database, scoped API credentials, and the security controls provided by our sub-processors (Supabase, Stripe, Vercel, Anthropic, Resend).
No security measure is perfect, and we cannot guarantee absolute security. We do not hold third-party security certifications and we do not claim any.
11. International Transfers
SolveBotic is based in the United States and our sub-processors operate in the United States and other jurisdictions. By using SolveBotic, you acknowledge that information may be transferred to and processed in countries outside your own, which may have different data-protection rules. Where applicable, we and our sub-processors rely on standard contractual safeguards for international transfers.
12. Children
SolveBotic is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us so that we can delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will revise the Effective Date above and, where reasonable, provide additional notice through the service. Your continued use of SolveBotic after the changes become effective indicates your acceptance of the revised policy.
14. Contact
For any questions about this policy or to exercise any of the rights described above, please contact us at solvebotic.com/contact.