Privacy Policy
Reslo: AI Order Replies — last updated 2026-07-21
Who we are
Reslo: AI Order Replies (“the App”) is operated by Sumate Chimyindee. For any question or data request, contact us at sumaet@gmail.com.
What data we process
- Shop data: your shop domain and an encrypted Shopify access token, required to operate the App.
- Order data: order number, financial and fulfillment status, tracking numbers and URLs, and order timestamps — synced via Shopify webhooks. We deliberately do not store customer names, emails, phone numbers, or addresses from order data.
- Issue data you provide: the customer messages a merchant pastes into the App, plus an optional customer name/address a merchant may supply so we can remove them before AI processing.
How we use AI (important)
To classify issues and draft reply suggestions, the App sends data to Anthropic (the Claude API, anthropic.com), our AI sub-processor:
- What is sent: the pasted customer message after personal data has been removed — names, emails, phone numbers, and addresses are replaced with placeholders (for example
{{CUSTOMER_NAME}}) before the API call — plus non-personal order facts (order number, statuses, tracking numbers). - What is not sent: raw customer names, emails, phone numbers, addresses, payment details, or your Shopify access token.
- Placeholders are mapped back to real values only on our servers, after the AI responds.
No automated decisions with legal effect
The App only produces draft suggestions. The merchant reviews and sends every reply and makes every decision — the App never contacts customers and makes no automated decision that has legal or similarly significant effects on a customer.
Billing
All charges are handled through the Shopify Billing API. We never collect or see payment card details.
Data retention
Customer messages and related issue data are retained for up to 12 months, or until the merchant deletes them or uninstalls the App — whichever comes first. On uninstall (the shop/redact webhook, sent 48 hours later) we permanently delete all data we hold for the shop.
Your rights and data deletion
customers/data_request: we identify the issue records that reference a customer so the merchant can fulfil the request.customers/redact: matching issues are anonymized and their drafts deleted.shop/redact: all shop data — orders, issues, drafts, sessions — is permanently deleted.
Security
- Shopify access tokens are encrypted at rest (AES-256-GCM).
- Every merchant’s data is isolated with PostgreSQL Row-Level Security.
- All data is encrypted in transit over TLS.
We do not sell your data
We do not sell customer or merchant personal data, and we do not use it for advertising.
Sub-processors
- Anthropic (Claude API) — AI classification and drafting.
- Hosting and infrastructure providers used to run the App (application hosting, database, and queue), each under their own security and privacy terms.
Contact
Questions or data requests: sumaet@gmail.com.