Privacy Policy
Effective September 2, 2026
1. Overview
This Privacy Policy describes how Contactly (“Contactly,” “we,” “us”) handles information when a merchant installs the Contactly app on their Shopify store, and when a shopper submits a form on a merchant’s storefront through Contactly.
2. Information we collect
- Form submission data: whatever a shopper enters into a merchant’s Contactly form — typically name, email, message, and any custom fields the merchant has added, which may include order numbers or file uploads.
- Merchant and store data: store domain, plan/subscription details, form configurations, and staff account information for merchants using the shared inbox.
- Uploaded files: attachments a shopper submits through a file-upload field, stored via presigned direct-to-storage uploads and scanned for malware before being made available to the merchant.
3. How AI processing works
Contactly uses a third-party AI provider (Anthropic’s Claude) to power summaries, intent/sentiment tagging, spam scoring, and draft-reply suggestions. Submission content may be sent to this provider to generate these outputs. AI-generated drafts are never sent to a shopper automatically — a human on the merchant’s team must review and send any reply.
4. Your rights (GDPR and similar laws)
Contactly has built-in support for data subject rights via Shopify’s mandatory compliance webhooks:
- Customer data request — a shopper can request the data a merchant holds about them.
- Customer redaction — a shopper can request their data be deleted.
- Shop redaction — when a merchant closes their store, their data is deleted from Contactly’s systems.
Contact us at the address below to exercise these rights directly.
5. Sub-processors
Contactly relies on infrastructure and service providers to operate, including cloud hosting, email delivery, file storage, and AI processing. We only share the data necessary for each provider to perform its function.
6. Data retention
Submission and account data is retained for as long as a merchant’s store remains active on Contactly, and for a limited grace period after cancellation to allow for data export, after which it is deleted.
7. Security
We isolate each merchant’s data at the data-access layer so that one store’s information is never visible to another. File uploads go through presigned, direct-to-storage transfer with antivirus scanning before merchant access.
8. Contact
Questions about this policy or requests regarding your data can be sent to [email protected].
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date above.