WallaB.AI logo

Privacy Policy

WallaB.ai

Effective Date: July 1, 2026

WallaB.ai ("WallaB.AI," "we," "us") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect information through the WallaB.AI subscription-retention platform — the merchant dashboard, the shopper portal, and the WallaB.AI app for Shopify (together, the "Service").

1Scope & Roles

For merchants (stores that install WallaB.AI), we act as a data controller for merchant account information. For shoppers (a merchant's subscription customers), we process personal data on the merchant's behalf, as a processor/service provider, to deliver subscription-management and retention features.

2Information We Collect

Merchant Account Information

  • Email address and hashed password (we never store plaintext passwords)
  • Role and shop association
  • Retention-policy settings you configure (discount limits, allowed offers, tone)

Shop Data (via Shopify APIs)

  • Shop domain, products, variants, and selling plans
  • Subscription contracts, billing cycles, and billing outcomes

Shopper Data (processed for the merchant)

  • Name and email address
  • Subscription details, delivery preferences, and subscription history
  • One-time login codes (stored only as hashes, short-lived)

AI Conversation Records

  • Transcripts of conversations with WallaB (our retention assistant)
  • Offers proposed and accepted, outcomes, and AI audit metadata (model used, reasoning summaries)

Operational Records

  • Application event logs with request identifiers (for security, support, and reliability)

We Do Not Collect

  • Payment card information — payments are processed entirely by Shopify and the merchant's payment gateway; card data never touches our systems
  • Location or device tracking data
  • Advertising or marketing profile data

3How We Use Information

  • Operate subscription management: skips, pauses, swaps, resumes, and cancellations
  • Run retention features: WallaB cancel-save conversations, failed-payment recovery, win-back
  • Enforce merchant-configured limits (e.g. maximum discount) on every AI-proposed offer
  • Provide merchants full transparency: analytics, event logs, and every AI conversation transcript
  • Send operational notifications (login codes, billing and subscription updates)
  • Secure, debug, and improve the Service

We do not sell personal information and we do not use it for third-party advertising.

4AI Processing (WallaB)

WallaB is an AI assistant. Conversations may be processed by Anthropic's Claude models via API to generate responses. Our AI provider does not use data submitted through its API to train its models, per its published policies.

  • Every AI decision is logged and auditable by the merchant, including the offer proposed and why
  • The AI cannot exceed merchant-configured limits — offers are validated server-side before they are ever applied
  • Conversations are automatically monitored and filtered for abusive or inappropriate language to keep interactions professional; flagged content is logged for the merchant's review
  • Shoppers always have a plain, one-click cancellation path that does not require talking to the AI

5Shopify Integration & Privacy Webhooks

The Service integrates with Shopify under Shopify's protected customer data requirements. We honor Shopify's mandatory privacy webhooks: customer data requests (customers/data_request), customer erasure (customers/redact), and shop erasure 48 hours after uninstall (shop/redact) — each fulfilled within 30 days. Shopify is governed by its own privacy policy and terms.

6Data Hosting & Security

The Service is hosted on Google Cloud infrastructure in the United States. We implement commercially reasonable safeguards, including:

  • Encrypted connections (TLS) and encryption at rest
  • Hashed passwords and hashed one-time login codes
  • Encrypted storage of Shopify access tokens
  • Role-based access controls and audit logging

No system can be guaranteed 100% secure.

7Data Retention

  • Merchant and subscription records are retained while the merchant account is active
  • After app uninstallation, shop data is deleted in accordance with Shopify's shop/redact requirements
  • AI conversation transcripts are retained for the merchant's audit and transparency while the shop is active
  • Operational logs are retained for a limited period for security and reliability

8Data Sharing

We share information only with the sub-processors needed to run the Service:

  • Shopify (commerce platform and billing)
  • Google Cloud (hosting and database infrastructure)
  • Anthropic (AI processing for WallaB conversations)
  • Email delivery providers (operational notifications)
  • If required by law, or to protect legal rights and prevent fraud

9Your Rights

Merchants may request access, correction, export, or deletion of their account data at support@wallab.ai.

Shoppers should direct privacy requests to the merchant they subscribe with; we support merchants in fulfilling those requests through Shopify's privacy webhook process described in Section 5.

10Children's Privacy

The Service is not intended for minors under 18. We do not knowingly collect information from children.

11GDPR & Data Transfers

If you are in the European Economic Area or United Kingdom, you have rights of access, rectification, erasure, restriction, objection, and portability with respect to your personal data. We process data on the basis of performing our contract with merchants and our legitimate interest in operating the Service.

Data is stored in the United States (Google Cloud). Where data is transferred out of the EEA/UK, we rely on Standard Contractual Clauses. You may also lodge a complaint with your local supervisory authority.

12Security Breach Notification

In the event of a data breach affecting Virginia residents, we will notify affected individuals and, where required, the Virginia Attorney General as required by Va. Code § 18.2-186.6, without unreasonable delay. If EU/UK residents are affected, we will notify the relevant supervisory authority within 72 hours as required by GDPR.

To report a security concern, email support@wallab.ai with the subject line [SECURITY].

13Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised effective date; continued use of the Service indicates acceptance.

14Contact Information

WallaB.ai

25 Catoctin Cir SE Unit 1006

Leesburg, VA 20177-8766

Email: support@wallab.ai

Website: wallab.ai