WallaB.AI logo

Privacy Policy

WallaB.ai

Effective Date: July 26, 2026

WallaB.ai ("WallaB.AI," "we," "us") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect information through the WallaB.AI subscription-retention platform — the merchant dashboard, the shopper portal, and the WallaB.AI app for Shopify (together, the "Service").

1Scope & Roles

For merchants (stores that install WallaB.AI), we act as a data controller for merchant account information. For shoppers (a merchant's subscription customers), we process personal data on the merchant's behalf, as a processor/service provider, to deliver subscription-management and retention features.

2Information We Collect

Merchant Account Information

  • Email address and hashed password (we never store plaintext passwords)
  • Role and shop association
  • Retention-policy settings you configure (discount limits, allowed offers, tone)

Shop Data (via Shopify APIs)

  • Shop domain, products, variants, and selling plans
  • Subscription contracts, billing cycles, and billing outcomes

Shopper Data (processed for the merchant)

  • Name and email address
  • Subscription details, delivery preferences, and subscription history
  • One-time login codes (stored only as hashes, short-lived)

AI Conversation Records

  • Transcripts of conversations with WallaB (our retention assistant)
  • Offers proposed and accepted, outcomes, and AI audit metadata (model used, reasoning summaries)

Operational Records

  • Application event logs with request identifiers (for security, support, and reliability)

We Do Not Collect

  • Payment card information — payments are processed entirely by Shopify and the merchant's payment gateway; card data never touches our systems
  • Location or device tracking data
  • Advertising or marketing profile data

3How We Use Information

  • Operate subscription management: skips, pauses, swaps, resumes, and cancellations
  • Run retention features: WallaB cancel-save conversations, failed-payment recovery, win-back
  • Enforce merchant-configured limits (e.g. maximum discount) on every AI-proposed offer
  • Provide merchants full transparency: analytics, event logs, and every AI conversation transcript
  • Send operational notifications (login codes, billing and subscription updates)
  • Secure, debug, and improve the Service

We do not sell personal information and we do not use it for third-party advertising.

4AI Processing (WallaB)

WallaB is an AI assistant. Conversations may be processed by Anthropic's Claude models via API to generate responses. Our AI provider does not use data submitted through its API to train its models, per its published policies.

  • Every AI decision is logged and auditable by the merchant, including the offer proposed and why
  • The AI cannot exceed merchant-configured limits — offers are validated server-side before they are ever applied
  • Conversations are automatically monitored and filtered for abusive or inappropriate language to keep interactions professional; flagged content is logged for the merchant's review
  • Shoppers always have a plain, one-click cancellation path that does not require talking to the AI

5Shopify Integration & Privacy Webhooks

The Service integrates with Shopify under Shopify's protected customer data requirements. We honor Shopify's mandatory privacy webhooks: customer data requests (customers/data_request), customer erasure (customers/redact), and shop erasure 48 hours after uninstall (shop/redact) — each fulfilled within 30 days. Shopify is governed by its own privacy policy and terms.

6Data Hosting & Security

The Service is hosted on Google Cloud infrastructure in the United States. We implement commercially reasonable safeguards, including:

  • Encrypted connections (TLS) and encryption at rest
  • Hashed passwords and hashed one-time login codes
  • Encrypted storage of Shopify access tokens
  • Role-based access controls and audit logging

No system can be guaranteed 100% secure.

7Data Retention

  • Merchant and subscription records are retained while the merchant account is active
  • After app uninstallation, shop data is deleted in accordance with Shopify's shop/redact requirements
  • AI conversation transcripts are retained for the merchant's audit and transparency while the shop is active
  • Operational logs are retained for a limited period for security and reliability

Live demo follow-up. If you try our live demo, we ask for your email address to sign you in. If you also check the box requesting a follow-up, we will send you a single email about WallaB.AI within about a week. We do not add you to a mailing list, and we never send a second message from that sign-in. Demo sign-in data, including your email address, is automatically deleted within 7 days. After deletion we retain only a one-way cryptographic hash of the address, used solely to ensure we never email you again — including if you try the demo more than once or have unsubscribed. You can decline at sign-in, or unsubscribe from the email itself.

8Data Sharing

We share information only with the sub-processors needed to run the Service:

  • Shopify (commerce platform and billing)
  • Google Cloud (hosting and database infrastructure)
  • Anthropic (AI processing for WallaB conversations)
  • Email delivery providers (operational notifications)
  • If required by law, or to protect legal rights and prevent fraud

9Your Rights

Merchants may request access, correction, export, or deletion of their account data at support@wallab.ai.

Shoppers should direct privacy requests to the merchant they subscribe with; we support merchants in fulfilling those requests through Shopify's privacy webhook process described in Section 5.

10Children's Privacy

The Service is not intended for minors under 18. We do not knowingly collect information from children.

11GDPR & Data Transfers

If you are in the European Economic Area or United Kingdom, you have rights of access, rectification, erasure, restriction, objection, and portability with respect to your personal data. We process data on the basis of performing our contract with merchants and our legitimate interest in operating the Service.

Data is stored in the United States (Google Cloud). Where data is transferred out of the EEA/UK, we rely on Standard Contractual Clauses. You may also lodge a complaint with your local supervisory authority.

12Security Breach Notification

In the event of a data breach affecting Virginia residents, we will notify affected individuals and, where required, the Virginia Attorney General as required by Va. Code § 18.2-186.6, without unreasonable delay. If EU/UK residents are affected, we will notify the relevant supervisory authority within 72 hours as required by GDPR.

To report a security concern, email support@wallab.ai with the subject line [SECURITY].

13Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised effective date; continued use of the Service indicates acceptance.

14Contact Information

WallaB.ai

25 Catoctin Cir SE Unit 1006

Leesburg, VA 20177-8766

Email: support@wallab.ai

Website: wallab.ai

15Cookies & Browser Storage

We use cookies and browser storage only to make the Service work: to keep you signed in, to protect sign-in and app installation, and to remember small display preferences. We do not use them to build a profile of you, and we do not use them for advertising. Every item we set is listed below.

Public Website (Marketing Pages)

The public pages — the home page, pricing, FAQ, documentation, and this policy — set no cookies at all for a visitor who does not sign in. If you use the light/dark toggle in the site header, that one choice is kept in your browser's session storage for the current browsing session and is discarded when you close the tab. Nothing else is written to your device, and nothing written there identifies you.

Because an anonymous visitor to the public website receives no non-essential cookies, we do not present a cookie-consent banner. Until July 2026 the site set one 90-day affiliate-attribution cookie (wlb_ref); it has been removed, nothing reads it, and any copy still on your device is expired the next time you visit a page that used to set it.

Merchant Dashboard (After You Sign In)

  • auth_token — keeps you signed in. About 15 minutes. Required.
  • auth_token_refresh — renews that session so you are not asked for your password every 15 minutes. 7 days. Required.
  • theme — your chosen colour theme, so the first paint of a page is already correct. 1 year. Preference.
  • wallab_plan_cap_banner — remembers that you dismissed the plan-usage notice. 7 days. Preference.
  • wallab_gs_autoredirect — sends a new merchant to the setup guide at most once per browser session. Expires when you close the browser. Functional.
  • wallab_claim_banner_dismissed — remembers that you dismissed the "claim your account" notice. Expires when you close the browser. Preference.

The dashboard also uses your browser's local and session storage for display state only: your colour-theme choice, whether you dismissed this month's email-usage notice, your progress through a guided tour and the setup guide, and a short-lived copy of your plan name so the header can render without an extra request. None of it is sent to third parties.

Shopper Portal

  • wallab_portal — keeps you signed in to the subscription portal after you enter your one-time code. 30 days. Required.
  • theme — your light/dark choice. 1 year. Preference.

Installing the Shopify App

  • shopify_oauth_state — protects the app-installation handshake against cross-site request forgery. It also carries which store started the install and, when the install link included one, a partner referral code. It is signed, so it cannot be altered in the browser, and it is deleted as soon as the installation finishes. 10 minutes. Required.

WallaB.AI Staff Console

These are only ever set for WallaB.AI staff accounts signing in to our internal console — never for merchants or shoppers.

  • wlb_platform_access — staff sign-in session. 2 hours. Required.
  • wlb_platform_preauth — short-lived credential held between the password step and the two-factor step. 5 minutes. Required.
  • wlb_imp_banner — shows the visible banner displayed while a staff member is viewing a merchant account for support. 30 minutes. Functional.

No Third-Party Tracking

We run no third-party analytics, advertising, or tracking tags anywhere on the Service: no Google Analytics, no Google Tag Manager, no Segment, no PostHog, no Plausible, no Hotjar, and no advertising pixels. Our Content-Security-Policy permits scripts only from our own domain, so a third-party tracker cannot run on these pages.

Two related facts, for completeness. Web fonts are served by Google Fonts (fonts.googleapis.com and fonts.gstatic.com), so that request reaches Google's servers; it sets no cookie and stores nothing on your device. Separately, a merchant may choose to connect their own analytics destination (such as PostHog or Klaviyo) to receive their own retention events — that runs server-to-server from our systems and never places anything in a shopper's browser.

How We Count Referrals From AI Assistants

When a visitor reaches one of our public marketing pages from an AI assistant, we record a single row on our own servers containing two things: which assistant it came from (for example, "claude") and the page path. We do not store the IP address, the user-agent, the query string, the full referring URL, or any identifier — and nothing at all is written to the visitor's device. It is a counter, not a profile, and it cannot be linked back to a person.

Controlling Cookies

Every browser lets you view, block, and delete cookies and site storage, usually under Settings → Privacy. Blocking or deleting the preference items above costs you nothing but the preference. Blocking the required ones will break the Service: you will not be able to sign in to the dashboard or the shopper portal, and app installation will fail, because those cookies are how a signed-in session and an installation handshake are recognised at all.