Skip to main content

Privacy Policy

Last updated: August 6, 2026 · Version 1.0

1. Introduction and scope

This Privacy Policy explains how Caro, a Shopify app built and operated by Vosaire (“we”, “us”), collects, uses, and protects data when a merchant installs Caro on their Shopify store.

This policy covers two groups: (A) Merchants — the Shopify store owners and staff who install and configure Caro; and (B) Shoppers— visitors to a merchant's storefront who interact with the Caro chat widget. For Shopper data, the Merchant is the data controller and Caro processes that data as a processor on the Merchant's behalf.

Caro is a distinct product from Vosaire's general web platform — installing Caro does not create or affect any account on any other Vosaire product.

2. Who we are

Caro is built by Vosaire. For privacy matters, contact privacy@vosaire.com.

3. Information we collect

When a merchant installs Caro, we collect and process the following, solely to deliver the app's features:

  • Store information: shop name, shop owner email, store URL, and shop ID
  • Products, collections, pages, blog posts, and store policies — used to train Caro's AI knowledge base
  • Live inventory and stock levels, for real-time availability answers (on qualifying plans)
  • Order data — order number, line items, and fulfillment status — for order-status lookup
  • Customer email addresses associated with orders, for order lookup and coupon attribution
  • Customer notes, tags, and email/SMS marketing consent, written back to Shopify only when a merchant enables that feature (on qualifying plans)
  • Discount codes and draft orders created on the merchant's behalf, only when a merchant enables the Sales agent (on qualifying plans)
  • Theme structure metadata, read-only, used to guide merchants through activating the storefront widget — Caro never writes to a theme
  • Conversation transcripts between Caro and shoppers
  • Revenue attribution linking conversations to completed orders

All data above may be transmitted to OpenAI to generate AI responses — see Section 4.

4. AI and LLM processing

Caro uses OpenAIas its LLM provider. When Caro answers a shopper, relevant store data and conversation context is sent to OpenAI's API over an encrypted connection.

We do not use your store data or conversation content to train, fine-tune, or improve any AI model— including Caro's own systems or OpenAI's foundation models. OpenAI's API data usage terms prohibit training on API inputs by default.

AI-generated responses may occasionally be inaccurate or incomplete. Merchants and shoppers should verify important information independently.

5. Data retention

Data categoryRetentionBasis
Store & conversation dataDuration of install + 30 days after uninstallContract
Knowledge base contentUntil re-synced or 30 days after uninstallContract
Security / audit logs12 monthsLegitimate interest
Support communications3 yearsLegitimate interest

Caro never handles payment card or billing data directly — subscription billing runs entirely through Shopify. See our Refund Policy.

6. Data storage and security

Data is stored primarily on servers in the European Union (Hetzner, Germany), with file storage in the United States (Cloudflare R2). We use TLS 1.3 in transit, AES-256 encryption at rest, and role-based access controls.

In the event of a data breach affecting personal data, we will notify affected merchants and, where required, supervisory authorities within 72 hours of becoming aware.

7. Sub-processors

We use the following sub-processors, each bound by a data processing agreement:

Sub-processorPurposeCountry
OpenAIAI response generationUS
Amazon Web Services (SES)Transactional email deliveryUS
Cloudflare R2File and knowledge-base storageUS
HetznerServer infrastructureGermany

8. GDPR compliance webhooks

Caro implements all three Shopify-required GDPR compliance webhooks:

  • customers/data_request — acknowledged within 30 days; we notify the merchant of all data held for that customer.
  • customers/redact — customer PII is anonymized and related coupon records removed within 30 days of the request.
  • shop/redact — all data tied to the merchant's store (conversations, knowledge sources, revenue records, organization record) is permanently deleted within 30 days of uninstallation.

9. Shopify API scopes

Caro requests only the scopes needed to deliver its features:

  • read_products — catalog sync for AI training and product cards
  • read_orders / write_orders — order lookup and adding notes/tags
  • read_all_orders — order lookup beyond Shopify's 60-day default window
  • read_customers / write_customers — resolving a shopper's identity; saving notes, tags, or consent when enabled
  • read_content — pages and blog posts for AI training
  • read_legal_policies — store policies for AI training
  • read_themes — read-only, to guide widget activation
  • read_inventory — live stock levels (qualifying plans)
  • read_discounts / write_discounts — Sales agent discount codes (qualifying plans)
  • read_draft_orders / write_draft_orders — Sales agent checkout links (qualifying plans)

10. Your rights

10.1 GDPR (EEA, UK, Switzerland)

You may access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time. Deletion requests are fulfilled within 30 days except where retention is legally required. Contact privacy@vosaire.com.

10.2 CCPA / CPRA (California)

California residents may know, access, correct, and delete their personal information, and opt out of sale or sharing. We do not sell or share personal information. Email privacy@vosaire.com with subject “CCPA Request”.

11. Children's privacy

Caro is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@vosaire.com and we will delete it promptly.

12. Business transfers

In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity. We will give reasonable notice before your data becomes subject to a different privacy policy.

13. Changes to this policy

For material changes, we will notify merchants by email at least 14 days before they take effect. The “Last updated” date above reflects the most recent revision.

14. Contact us

Questions, data requests, or complaints: privacy@vosaire.com. We aim to respond within 5 business days.