Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how Kulova ("Kulova", "we", "us") collects, uses, stores, and protects data in connection with the Kulova app for Shopify ("the App") and the website kulova.com. Kulova is operated from Finland, and this policy is governed by Finnish law and the EU General Data Protection Regulation (GDPR).
Contact for any privacy question or request: hello@kulova.com
1. Who this policy is for
The App is installed by Shopify merchants ("Merchants") and adds an AI-powered customer support chat to their storefronts. Two groups of people are relevant:
- Merchants — the store owner who installs and configures the App.
- Store visitors / customers ("Customers") — people who use the chat widget on a Merchant's store.
We act as a data processor on behalf of the Merchant for Customer data handled through the chat, and as a data controller for the Merchant's own account information.
2. What data we collect
From Merchants (when the App is installed and configured):
- Store domain (myshopify.com address) and public store information (store name, contact email, description, currency) retrieved from the Shopify Admin API to configure the assistant.
- Configuration you enter: business description, opening hours, support email, and custom bot instructions.
- Billing status via Shopify's Billing API (we do not receive or store your payment card details — Shopify handles all payments).
From Customers (when they use the chat):
- The messages they send to and receive from the assistant.
- A randomly generated session identifier used to keep a single conversation continuous.
- If the Customer asks about an order and provides them, an order number and email address, used solely to look up that order's status.
We do not collect: Shopify passwords, payment card numbers, or any special-category personal data. We do not use tracking cookies for advertising.
3. How we use data
- To generate relevant AI responses to Customer questions using the Merchant's configured information.
- To look up order status when a Customer requests it (order number + email are matched against the Merchant's Shopify orders; a response is only returned when both match).
- To operate, maintain, and improve the App's core functionality.
- To provide support to Merchants who contact us.
We do not sell data, share it with advertisers, use it for profiling, or use Customer conversations to train third-party AI models beyond what is necessary to generate a single response.
4. AI processing
Customer messages are sent to our AI provider (Anthropic) to generate responses. This processing happens in real time to answer the immediate question. Messages are transmitted securely and are not used by us to build advertising profiles.
5. Where data is stored
Conversation data and Merchant configuration are stored in our database hosted on Supabase, with data residency in the European Union. Data is transmitted over encrypted connections (HTTPS/TLS).
6. How long we keep data
- Conversation data: retained to provide the service and deleted on request or when a Merchant uninstalls the App (see Section 8).
- Merchant configuration: retained while the App is installed.
- Order lookups: the order number and email a Customer provides are used only for the immediate lookup and are stored only as part of the conversation record, subject to the same deletion rules.
7. Data sharing and sub-processors
We share data only with the service providers necessary to run the App:
- Shopify — platform, billing, and store/order data access.
- Anthropic — AI response generation.
- Supabase — database hosting (EU).
- Vercel — application hosting.
- Brevo — transactional email (e.g. login codes) where applicable.
Each processes data only as needed to provide their service. We do not share data with any other third party.
8. Your rights and data deletion (GDPR)
Customers and Merchants in the EU have the right to access, correct, or delete their personal data, and to restrict or object to processing.
Automatic deletion: The App implements Shopify's mandatory privacy webhooks:
- customers/data_request — responds to a Customer's data access request relayed by the Merchant.
- customers/redact — deletes the relevant Customer's conversation data.
- shop/redact — deletes all of a Merchant's stored data after the App is uninstalled (triggered by Shopify 48 hours after uninstall).
Manual requests: You can also contact hello@kulova.com at any time to request access to or deletion of your data. We respond within the timeframes required by GDPR.
9. Data security
We protect data with encrypted connections, row-level access controls on our database so that each store's data is isolated, server-side authorization checks, and restricted access to production credentials. No method of transmission or storage is 100% secure, but we take reasonable and industry-standard measures to protect your data.
10. Children
The App is not directed at children and is not intended to collect data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact
For any question, request, or concern about privacy or your data:
Email: hello@kulova.com
Kulova, Finland