CreaScale AIAI sales agent for commerce
Legal

Privacy Policy

How the CreaScale AI application processes personal data when it is installed on your store and when it talks to your customers.

Last updated:

1.Who we are

CreaScale AI is an AI sales-assistant application ("the App", "we", "us") operated by Matrix Tower LLC. The App connects to a merchant's online store and answers that merchant's customers on WhatsApp, Instagram and an embeddable web chat widget, and can create orders — including cash-on-delivery (COD) orders.

For personal data processed through the App, the merchant who installs the App is the data controller, and Matrix Tower LLC acts as a processor acting on the merchant's instructions. For account, billing and operational data of the merchant themselves, we act as controller.

Data-protection contact: support@creascale.ai.

2.Scope of this policy

This policy covers personal data processed by the CreaScale AI application when it is installed on a Shopify store (or connected via our supported channels) and when it converses with end-customers. It does not cover the merchant's own website, the Shopify platform itself, or third-party services the merchant uses independently of the App.

3.Data we process

a. Merchant & account data

b. Store data accessed via the Shopify Admin API

With your authorization (see the scopes in §6), the App reads store data to answer customers accurately and place orders:

c. End-customer data captured in conversations

d. Conversation history & memory

We store conversations, a rolling conversation summary, and structured "memory" facts (for example a customer's stated preferences or last order) so the assistant can hold context across messages. Catalog text, knowledge-base text and those memory facts are indexed as numerical embeddings to enable semantic search, which is why the memory facts appear in the Google row of §5.

4.Why we process it & legal bases

PurposeGDPR legal basis (Art. 6)
Provide the AI assistant, answer customers and create orders on the merchant's behalfPerformance of a contract (6(1)(b)); for end-customers, the merchant's legitimate interest / performance of the customer's order (6(1)(f)/(b))
Read catalog, inventory and customer records to give accurate answersLegitimate interest of the merchant in serving its customers (6(1)(f))
Metering, billing and abuse/cost protectionContract (6(1)(b)) & legitimate interest (6(1)(f))
Legal & compliance obligations (incl. Shopify GDPR webhooks)Legal obligation (6(1)(c))

Where required, the merchant is responsible for obtaining any consent from its own customers for messaging on WhatsApp/Instagram.

5.Sub-processors

We use the following sub-processors to run the App. Each receives only the data needed for its function.

Sub-processorFunctionData involved
Anthropic (Claude API)Generates the assistant's replies, and reads a customer file the merchant supplies in order to map its columnsConversation content, relevant catalog context, and the raw cells of the customer file the merchant supplies (for example the columns of a Google Sheet, which can contain phone numbers and names)
Google (Gemini Embeddings API)Semantic indexing/search over the catalog, the knowledge base and the memory factsCatalog and knowledge-base text, and the memory facts recorded about an end-customer, which can include their delivery address — all turned into embeddings
Supabase (PostgreSQL & Vault)Database hosting and encrypted secret storageAll stored application data (see §3)
Meta Platforms (WhatsApp Business API & Instagram Graph API)Message delivery on those channelsMessages and channel contact identifiers
ShopifyThe commerce platform the App connects toStore & customer data per granted scopes
RenderHosting of the application and of its logsAll application data processed at runtime, and the technical logs the application writes
Upstash (Redis)Short-term conversation buffer, kept for at most 72 hoursThe body of the messages exchanged in a conversation
ResendSending the emails of the AppThe merchant's email address and the content of the emails we send them — including the export produced for a customers/data_request, which contains that customer's stored data

International transfers. Some sub-processors are located outside the EEA/UK (e.g. in the United States). Where personal data is transferred internationally, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and equivalent mechanisms.

This is the current list. It is also available on request at support@creascale.ai, and §13 below explains how we inform you before we add or replace a sub-processor.

6.Shopify Protected Customer Data

The App requests the following Shopify access scopes:

read_products · read_orders · write_orders · read_customers · read_inventory · read_locations

Reading customer name, address and phone is Protected Customer Data under Shopify's requirements. We access it only to answer the customer, recognise a returning customer, and create the order they request; we do not sell it or use it for advertising; and we apply the security controls in §8.

We do not ask for the customer's email address. No query the App sends to Shopify selects that field, so the App never reads it and never stores it. This is a deliberate minimisation: the assistant answers on WhatsApp, Instagram and the web widget, and it does not need an email address to do that. The App also only reads customer records — it never writes to them.

Mandatory Shopify compliance webhooks

We implement Shopify's three privacy webhooks (endpoint /api/compliance/shopify/gdpr, requests are HMAC-verified):

Uninstalling the App immediately revokes and purges the stored Shopify access token.

7.Data retention

An automated purge runs on a schedule. Personal data that has passed the window below is either deleted or irreversibly anonymised. The windows are:

Revoked opt-ins are never purged. When a customer opts out — for example by replying "STOP" — that revocation is kept indefinitely and is deliberately excluded from the purge: erasing it would let messaging resume towards someone who has objected.

Some records are anonymised rather than deleted. A row that carries a usage quota, an idempotency key (which is what stops the same message or the same order from being sent twice) or a revenue figure is kept for that purpose, but the recipient is erased from it, so the row no longer identifies anyone.

Personal data is also erased, on the same basis, when we receive a customers/redact or shop/redact request (see §6), or on a documented request to support@creascale.ai. Stored credentials are purged immediately when a store uninstalls. Short-lived operational caches of store data are held only transiently to serve a conversation.

8.Security

9.Your rights

Under the GDPR, individuals in the EEA/UK have the right to access, rectify, erase, restrict or object to processing, and to data portability. Because we act as a processor for end-customer data, requests from a store's customers are normally directed to that store (the controller); we assist the merchant in fulfilling them, including through the Shopify webhooks above.

Under the CCPA/CPRA, California residents have the right to know what personal information is collected, to request deletion, to correct it, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information.

To exercise any right, contact support@creascale.ai. You also have the right to lodge a complaint with your local supervisory authority.

10.Cookies

The App is an assistant that runs inside Shopify and messaging channels; it does not use advertising or tracking cookies to process the personal data described here. The embeddable web widget uses only the storage strictly necessary to maintain a conversation session.

11.Children

The App is intended for use by merchants and their adult customers. It is not directed at children, and we do not knowingly collect personal data from children under the age required by applicable law.

12.Changes to this policy

We may update this policy to reflect changes in the App or in legal requirements. Material changes will be posted on this page with a revised "Last updated" date above.

13.Data Processing Agreement

This section is the data processing agreement between the merchant and Matrix Tower LLC for the personal data of the merchant's customers that is processed through the App. It applies from the moment the App is installed, and it prevails over any conflicting statement elsewhere in this policy.

a. Roles

For the personal data of end-customers, the merchant is the controller and Matrix Tower LLC is the processor. The subject matter of the processing is the operation of the AI sales assistant; its duration is the term of the merchant's use of the App; its nature and purpose are described in §3 and §4; the categories of personal data and of data subjects are those listed in §3.

b. Processing on documented instructions

We process end-customer personal data only on the merchant's documented instructions — this policy, the settings the merchant configures in the App, and the actions the merchant takes in it — unless we are required to process it by a law to which we are subject, in which case we inform the merchant before processing unless that law forbids it. We do not sell end-customer personal data and we do not use it for our own advertising.

c. Confidentiality of personnel

The persons authorised to process end-customer personal data are bound by an obligation of confidentiality, and their access is limited to what each of them needs in order to run and support the service.

d. Security measures

We implement the technical and organisational measures set out in §8 (Security), and we keep the access journal described in §7.

e. Sub-processors

The merchant gives a general authorisation for us to engage the sub-processors listed in §5. We inform the merchant before we add or replace a sub-processor, and the merchant may object to that change; if the objection cannot be resolved, the merchant may stop using the App and request the deletion or return of the data under (h) below. Each sub-processor is bound by data-protection obligations no less protective than those of this section, and we remain responsible to the merchant for their performance.

f. Assistance with data-subject rights

We assist the merchant in answering requests from its customers to access, rectify, erase, restrict, object to or port their personal data — in particular through the Shopify compliance webhooks described in §6 (customers/data_request, customers/redact, shop/redact) and through the retention windows in §7. Where such a request reaches us directly, we pass it to the merchant rather than answer it ourselves.

g. Personal data breach

We notify the merchant of a personal data breach affecting its customers' personal data without undue delay and at the latest within 72 hours after becoming aware of it, together with the information we hold on the nature of the breach, its likely consequences, and the measures taken or proposed to address it.

h. Deletion or return at the end of the service

When the merchant stops using the App, we delete or return the end-customer personal data, at the merchant's choice, and delete the existing copies — except where storage is required by law, or where a record is kept in the anonymised form described in §7. Stored credentials are purged immediately on uninstall.

i. International transfers

Where end-customer personal data is transferred outside the EEA or the UK, that transfer is covered by the EU Standard Contractual Clauses — the controller-to-processor module between the merchant and us, and the processor-to-processor module for onward transfers to our sub-processors — together with the UK International Data Transfer Addendum. Both are incorporated into this section by reference.

j. Demonstrating compliance

We make available to the merchant the information necessary to demonstrate compliance with the obligations of this section, and we allow for and contribute to audits, including inspections, carried out by the merchant or by another auditor it mandates, on reasonable prior notice and during normal business hours. Requests are sent to support@creascale.ai.

14.Contact

Matrix Tower LLC
CreaScale AI — data protection
Email: support@creascale.ai