Privacy Policy
Last updated: August 6, 2026 · Version 1.0
1. Introduction and scope
This Privacy Policy explains how Caro, a Shopify app built and operated by Vosaire (“we”, “us”), collects, uses, and protects data when a merchant installs Caro on their Shopify store.
This policy covers two groups: (A) Merchants — the Shopify store owners and staff who install and configure Caro; and (B) Shoppers— visitors to a merchant's storefront who interact with the Caro chat widget. For Shopper data, the Merchant is the data controller and Caro processes that data as a processor on the Merchant's behalf.
Caro is a distinct product from Vosaire's general web platform — installing Caro does not create or affect any account on any other Vosaire product.
2. Who we are
Caro is built by Vosaire. For privacy matters, contact privacy@vosaire.com.
3. Information we collect
When a merchant installs Caro, we collect and process the following, solely to deliver the app's features:
- Store information: shop name, shop owner email, store URL, and shop ID
- Products, collections, pages, blog posts, and store policies — used to train Caro's AI knowledge base
- Live inventory and stock levels, for real-time availability answers (on qualifying plans)
- Order data — order number, line items, and fulfillment status — for order-status lookup
- Customer email addresses associated with orders, for order lookup and coupon attribution
- Customer notes, tags, and email/SMS marketing consent, written back to Shopify only when a merchant enables that feature (on qualifying plans)
- Discount codes and draft orders created on the merchant's behalf, only when a merchant enables the Sales agent (on qualifying plans)
- Theme structure metadata, read-only, used to guide merchants through activating the storefront widget — Caro never writes to a theme
- Conversation transcripts between Caro and shoppers
- Revenue attribution linking conversations to completed orders
All data above may be transmitted to OpenAI to generate AI responses — see Section 4.
4. AI and LLM processing
Caro uses OpenAIas its LLM provider. When Caro answers a shopper, relevant store data and conversation context is sent to OpenAI's API over an encrypted connection.
We do not use your store data or conversation content to train, fine-tune, or improve any AI model— including Caro's own systems or OpenAI's foundation models. OpenAI's API data usage terms prohibit training on API inputs by default.
AI-generated responses may occasionally be inaccurate or incomplete. Merchants and shoppers should verify important information independently.
5. Data retention
| Data category | Retention | Basis |
|---|---|---|
| Store & conversation data | Duration of install + 30 days after uninstall | Contract |
| Knowledge base content | Until re-synced or 30 days after uninstall | Contract |
| Security / audit logs | 12 months | Legitimate interest |
| Support communications | 3 years | Legitimate interest |
Caro never handles payment card or billing data directly — subscription billing runs entirely through Shopify. See our Refund Policy.
6. Data storage and security
Data is stored primarily on servers in the European Union (Hetzner, Germany), with file storage in the United States (Cloudflare R2). We use TLS 1.3 in transit, AES-256 encryption at rest, and role-based access controls.
In the event of a data breach affecting personal data, we will notify affected merchants and, where required, supervisory authorities within 72 hours of becoming aware.
7. Sub-processors
We use the following sub-processors, each bound by a data processing agreement:
| Sub-processor | Purpose | Country |
|---|---|---|
| OpenAI | AI response generation | US |
| Amazon Web Services (SES) | Transactional email delivery | US |
| Cloudflare R2 | File and knowledge-base storage | US |
| Hetzner | Server infrastructure | Germany |
8. GDPR compliance webhooks
Caro implements all three Shopify-required GDPR compliance webhooks:
- customers/data_request — acknowledged within 30 days; we notify the merchant of all data held for that customer.
- customers/redact — customer PII is anonymized and related coupon records removed within 30 days of the request.
- shop/redact — all data tied to the merchant's store (conversations, knowledge sources, revenue records, organization record) is permanently deleted within 30 days of uninstallation.
9. Shopify API scopes
Caro requests only the scopes needed to deliver its features:
read_products— catalog sync for AI training and product cardsread_orders/write_orders— order lookup and adding notes/tagsread_all_orders— order lookup beyond Shopify's 60-day default windowread_customers/write_customers— resolving a shopper's identity; saving notes, tags, or consent when enabledread_content— pages and blog posts for AI trainingread_legal_policies— store policies for AI trainingread_themes— read-only, to guide widget activationread_inventory— live stock levels (qualifying plans)read_discounts/write_discounts— Sales agent discount codes (qualifying plans)read_draft_orders/write_draft_orders— Sales agent checkout links (qualifying plans)
10. Your rights
10.1 GDPR (EEA, UK, Switzerland)
You may access, rectify, erase, restrict, port, or object to processing of your data, and withdraw consent at any time. Deletion requests are fulfilled within 30 days except where retention is legally required. Contact privacy@vosaire.com.
10.2 CCPA / CPRA (California)
California residents may know, access, correct, and delete their personal information, and opt out of sale or sharing. We do not sell or share personal information. Email privacy@vosaire.com with subject “CCPA Request”.
11. Children's privacy
Caro is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@vosaire.com and we will delete it promptly.
12. Business transfers
In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity. We will give reasonable notice before your data becomes subject to a different privacy policy.
13. Changes to this policy
For material changes, we will notify merchants by email at least 14 days before they take effect. The “Last updated” date above reflects the most recent revision.
14. Contact us
Questions, data requests, or complaints: privacy@vosaire.com. We aim to respond within 5 business days.