SUGOI Chat — Privacy Policy

Last updated: October 9, 2026

日本語版

For plan prices, usage allowances, and additional charges, see Pricing and usage terms.

This policy describes how Oops Co., Ltd. ("we") handles data in the Shopify app SUGOI Chat ("the app").

1. Who we are

CompanyOops Co., Ltd. (ウープス有限会社)
RepresentativeIsao Takahashi
AddressMAT Tokiwamatsu 203, 1-13-4 Higashi, Shibuya-ku, Tokyo 150-0011, Japan
Contactsupport@misell-theme.com
Websitehttps://oops.jpn.com

2. What the app collects

2-1. Through Shopify's APIs

The only required installation scope is read_products. Merchants can explicitly grant optional read_shipping for Shopify-grounded delivery settings and optional read_orders for recent-order support. To create FAQ drafts through the FAQ integration, merchants can also grant optional metaobject write scopes (write_metaobject_definitions, write_metaobjects). These are used only to create the FAQ definition and drafts; the app requests no write access to orders, products, or customers.

The recent-order fields are retrieved when the merchant opens the customer-service briefing and are used only as supporting information there. We do not store them in our database or send them to an external AI provider. An order total is not represented as Shopify Analytics sales.

This order-support feature uses Protected Customer Data Level 1 and read_orders. It does not retrieve or display individual customer names, addresses, phone numbers, or email addresses through the API. The app does not request read_customers, read_all_orders, read_reports, or write access to orders or products.

To answer delivery-status questions, the app uses the customer ID signed by Shopify on the App Proxy request to retrieve the logged-in shopper's own most recent order delivery information from Shopify (order number, order date, fulfillment and payment status, carrier, tracking number, and tracking URL — never the shopper's name, address, phone number, or email address). Browser-supplied order content is not trusted as an answer source. The retrieved data is used only to generate the reply and is never stored in our database (see section 4).

When a merchant sets up a post-purchase offer (a discount code the merchant already created in Shopify, shown once in the chat at a later visit to a logged-in shopper who bought a product the merchant selected) on a shop that granted read_orders, the app uses the customer ID signed by Shopify on the App Proxy request to retrieve, for the logged-in shopper's own recent orders, Shopify's internal order ID, order timestamp, cancellation status, and product IDs with current quantities, and decides in code whether the shopper bought a selected product. After the offer is shown, the app retrieves the same shopper's order IDs, order timestamps, cancellation status, and the discount codes used, to check whether an order used the offered code. No AI is used for these decisions and order data is not sent to any external AI provider. The only data stored in our database is the "post-purchase offer records" described in section 4; product titles, amounts, and line items are not stored.

When product reviews are enabled, the app uses the logged-in customer ID signed by Shopify on the App Proxy request to look up that shopper's own orders from the last 55 days and check cancellation, product IDs and titles, current quantities, and fulfillment status. It does not retrieve names or email addresses from orders. Product reviews store the rating, optional title, body, display name, and, only for the Judge.me destination, the email address the shopper enters, after the shopper reviews the content and explicitly consents. The native destination does not collect an email address. Review consent is separate from consent to save preferences.

2-2. Directly from the merchant

Text entered as service tone, public store rules, product knowledge and FAQs is stored and sent to the AI provider to generate replies. Do not enter customer personal data or confidential internal information.

We may process account information supplied by Shopify as part of the session needed to connect and authenticate the admin app.

Visual search starts off for new app installations. Only after a merchant explicitly enables it in the app admin does the app send the primary images of published products to Voyage AI to create visual-search vectors. Existing stores keep their enabled or disabled setting, and merchants can disable visual search in the app admin. Product titles, prices, and descriptions are not sent to Voyage AI.

2-3. From storefront visitors (shoppers)

Review bodies, display names, and email addresses are not included in chat history, AI reply generation, or logs. AI does not generate or rewrite review ratings or bodies, or extract preferences from reviews. Ratings, titles, bodies, and display names may be published after store approval; email addresses and customer IDs are not exposed by the review display API.

After a store enables retention, storefront questions and answers may be encrypted and normally kept for 30 days (up to 90 days for an unresolved case) after attempted removal of identifiers. The original text of order-status questions and answers, order delivery snapshots, purchased product data, shopper search images and vectors, handoff content, and reply-to email addresses are not stored in our database. Aggregated improvement observations without original text may include order-related categories and counts. Information outside the retention scope is discarded after a reply or search result is generated.

The storefront chat sets no cookies. Instead, it keeps the following in the visitor's browser storage (localStorage and sessionStorage). None of it is stored on our servers, and none of it is used for advertising or behavioral targeting.

StorageKeyContentsRetention
localStoragesugoi_sidVisitor ID (conversation ID)No expiry (until the visitor clears the site data in the browser)
localStoragesugoi_consent, sugoi_consent_declinedWhether the visitor opted in to, or declined, saving preferencesNo expiry
localStoragesugoi_profileSize and color preferences when opted in (up to 5 each). Opting out erases the sizes and colorsNo expiry
localStoragesugoi:recently-viewedHandles and view times of recently viewed products (up to 10)No expiry
sessionStoragesugoi:chatConversation history and the product cards shown (so the conversation continues across pages)Cleared when the tab closes
sessionStoragesugoi-chat-status-okA marker that service availability was checkedCleared when the tab closes
sessionStoragesugoi:chat:login-pendingAn order question to resend after the shopper logs in from the chat (resent only within 10 minutes)Cleared when the tab closes
sessionStoragesugoi:chat:offer-checkedA marker that post-purchase offers were already checked that day (to avoid checking again the same day)Cleared when the tab closes
sessionStoragesugoi:chat:offerThe post-purchase offer shown (message, code, suggested product, deadline) and the signed-in customer ID it was shown to. Removed when applied, declined, or expired, or when a different customer signs inCleared when the tab closes
sessionStoragesugoi:chat:review-checked:<customerId>A marker that product reviews were checked that day. The key includes the signed-in customer ID; no review body, display name, or email address is storedCleared when the tab closes

While the visitor has opted in, the size and color preferences are sent to our server with every message and used to generate storefront chat replies (Google Gemini, section 5). The server does not store them. Without opt-in, preferences are neither stored nor sent. The visitor ID, recently viewed products, and conversation history are stored as described above regardless of opt-in. Admin authentication uses Shopify and its authentication mechanisms.

As with any web service, our hosting infrastructure records server access logs (source IP address, timestamp, requested path). We use these for troubleshooting and abuse prevention.

3. How we use the data

We use the data solely to operate the app's features:

We do not use the data for advertising, behavioral targeting, or sale to third parties. We do not use it to train AI models (see section 5 for how our AI providers handle it).

4. Where data is stored, and for how long

Location

Data is processed by the providers below. All processing takes place outside Japan and outside the European Economic Area. The United Kingdom, where Judge.me Ltd is located, is designated by Japan's Personal Information Protection Commission under Article 28 of the Act on the Protection of Personal Information as a foreign country with a level of protection equivalent to Japan's.

ProviderPurposeRegion
Render Services, Inc. (USA)Application hostingSingapore
Neon Inc. (USA)DatabaseSingapore
Shopify Inc. (Canada)Store platformAs determined by Shopify
Google LLC and the applicable Google contracting entityGenerating storefront chat replies; commander chat replies only when OpenAI cannot be reached or does not finish within the time limitMay be processed or cached temporarily in any country where Google or its agents maintain facilities
OpenAI, L.L.C. (USA)Generating commander chat replies (the setup guide on every plan; other modes and the morning report on the Pro plan); generating visual-search repliesUnited States
Voyage AI Innovations, Inc. (USA, a MongoDB company)Generating vectors for visual searchMay be processed in the United States
Resend, Inc. (USA)Delivering staff notification emails when the store has turned on staff handoffUnited States
Judge.meReceiving and publishing reviews and sending confirmation emails when selected by the store; reading aggregates with an optional public tokenUnited Kingdom (Judge.me Ltd). Its sub-processors include providers located in the United States; Judge.me states that it transfers data under standard contractual clauses and the UK Addendum

Retention

DataRetention
Storefront questions and answersAfter activation, removal of identifiers is attempted before encrypted storage per shop. Normally expire 30 days after reply completion and are purged daily. A merchant may record a reason and deadline to hold a specific unresolved case for up to 90 days from the question. Turns involved in a data request are held for 30 days from that request. Original text from order-status and image-search turns is excluded. Authenticated merchant staff access is audited
Matching identifiers for retained turnsVisitor and signed-in customer IDs are converted to shop-scoped keyed hashes and deleted with the raw turn. A keyed customer hash and request status are kept for up to 90 days after a data access request. Original IDs are not stored
Grouped improvement observationsControlled categories, product, outcome and count, without original text. Expire 12 months after last observation; groups below three are hidden and rows are purged daily
Order delivery snapshot (order number, tracking number, etc.)Not stored (discarded after the reply is generated)
Recent-order supporting information displayed in the adminNot stored (retrieved from Shopify when the page is viewed)
Post-purchase offer recordsWhen a merchant sets up post-purchase offers: the Shopify customer ID of each shopper found eligible, Shopify's internal order ID and timestamp of the order that made them eligible and of the order found to use the code, and the times the offer was shown, applied, not applied (with the reason), declined, and matched to a purchase, and when a purchase was last looked up. No names, addresses, phone numbers, email addresses, product titles, or amounts. Deleted by a scheduled job about 90 days after the offer deadline; customers/redact deletes that shopper's records and shop/redact deletes all of the shop's records. The last lookup time kept to limit lookups (one per shopper) is also deleted on customers/redact and shop/redact
Post-purchase offer settingsDeleted on shop/redact
Product review ledgerStores the shop, Shopify customer ID, product ID and title, rating, review title, body and display name, destination at submission, consent version and time, submission, moderation and sending times, rejection reason and delivery state. Email retention is described below. Published, hidden and Judge.me-approved rows have no uniform deletion deadline; customers/redact deletes that customer's rows and shop/redact deletes all shop rows
Email addresses for Judge.meJudge.me acceptance (accepted), being marked done by the merchant (marked_done), or rejection (rejected) starts a retention period of 30 days; addresses are deleted by hourly maintenance after that deadline. Unresolved sends and rows that are only permanent are kept for manual resend; rejection or marking done sets the expiry
Rejected review titles, bodies, and display namesCleared by hourly maintenance 30 days after rejection. The ledger row with customer and product IDs remains for deduplication. customers/redact and shop/redact delete the row itself
Pending product reviewsUnapproved (pending) rows are deleted by hourly maintenance 180 days after submission
Product review settingsDeleted on shop/redact. See section 5 for Judge.me retention
Access token / sessionDeleted when the app is uninstalled
Extra-charge event delivery recordsStore identifier, billing period, count, send time, and deduplication ID only; no conversation content or shopper information. Sent records are purged by scheduled processing after 90 days. Unsent records are kept until successfully retried. Both are deleted on shop/redact
Delivery rule settingsDeleted on Shopify's shop/redact request, sent 48 hours after uninstall
Synced product catalogSame as above
Service tone, store rules, product knowledge and FAQsDeleted on shop/redact
Visual-search vectors generated from published product imagesDeleted when the merchant disables visual search, when the app is uninstalled, or on shop/redact. The vector table does not store image bytes, product titles, prices, or descriptions
Shopper search images and search-query vectorsNot stored (discarded after search results are generated)
Data kept in the shopper's browser (visitor ID, consent, preferences, recently viewed products, conversation history)Not stored in our database. Retention in the browser is shown in the table in section 2-3 (localStorage has no expiry; sessionStorage is cleared when the tab closes)
Usage counters (monthly/daily message counts)Only the shop domain and a count are stored — never chat content or shopper data. Deleted on shop/redact
Commander settings, aggregate metrics caches retained from earlier releases, this app's own usage records, and morning reportsConfiguration values, usage counts, and catalog-sync information are stored. This candidate release does not retrieve or refresh Shopify sales, order, or session aggregates and does not include conversation content or individual customer data. Existing caches are deleted on shop/redact
Data access audit recordsTime, shop, actor, operation category, and outcome; no conversation content, tracking numbers, or tokens. Records older than the 30-day retention threshold are deleted on the next audited access or maintenance run, and on shop/redact
Infrastructure logsCurrently 7 days at Render; other providers apply their own retention periods

As of October 5, 2026, Neon's history restore window is six hours for each of the Pilot and public app projects. Records deleted from the database may remain recoverable until that window expires. Any restore must reapply deletion requests and retention expiry.

“Not stored” in the table refers to our database. External AI providers' retention is described in section 5. Commander aggregate caches retained from earlier releases are not refreshed by this candidate release and remain until deleted.

5. Disclosure to third parties

We disclose data to the service providers described in this section as needed to operate the app, send product reviews on the store's instructions to the Judge.me service the store uses (the reviewer's explicit consent is also obtained; see below), and where required by law. We do not sell the data. The providers listed above (Render, Neon, Shopify) act as processors handling data only as needed to operate the app.

Providing product reviews to Judge.me

After the store approves a review, and only when Judge.me is the destination, the app provides Judge.me with the rating, optional title, review body, display name, shopper-entered email address, product ID, and store domain. This is sent on the store's instructions (the store chose Judge.me as the destination in SUGOI settings and approved the review) to the Judge.me service the store uses (Judge.me Ltd, United Kingdom), to receive and publish the review. Judge.me's own documentation describes the store as the data controller and Judge.me as a processor handling the data for the store. The reviewer's explicit consent is also obtained. Native reviews and unapproved reviews are not sent to Judge.me.

Judge.me sends a confirmation email and adds a review record to the store's customer record matching that email address. The address is entered by the shopper; SUGOI cannot verify its owner. Judge.me's own retention periods are governed by its terms and privacy policy; its processing locations are described in the table in section 4.

Deleting a review in SUGOI does not delete the review on Judge.me. SUGOI has no feature to delete or edit reviews sent to Judge.me. On Judge.me, the reviewer can edit or delete the review from their Judge.me reviewer profile, or ask the store or Judge.me (support@judge.me) to delete it. The actions available to the store in the Judge.me admin are limited, and SUGOI cannot guarantee completion of remote deletion.

Stores that choose Judge.me as the destination should tell shoppers in their own privacy policy that reviews are provided to Judge.me (Judge.me's documentation also asks the store to inform reviewers).

Product review aggregates used in storefront answers are limited to counts, average ratings, and star distributions for native published reviews and aggregates available from Judge.me, sent to the storefront AI. Morning reports send counts of new submissions, pending reviews, native published reviews, Judge.me acceptances, and unsent reviews, plus whether sending is paused, to the Commander AI. These aggregates contain no review bodies, titles, display names, email addresses, or customer IDs. Judge.me acceptance is not proof of publication or verification.

Use of an AI provider

The app uses an external AI service to generate chat replies. The shopper-facing storefront chat and the merchant-facing commander chat (the setup guide on every plan; other consultation modes and morning reports on the Pro plan) use separate paths.

The app (Singapore) → Google LLC and the applicable Google contracting entity (storefront chat)

ModelGoogle's Gemini 3.7 Flash
Endpointhttps://generativelanguage.googleapis.com (Gemini API). No third-party routing service is involved
What is sentMessages typed into the chat (including the recent conversation history), information about the product being viewed and the selected variant, catalog information (such as titles) for the products in the previous reply, recently viewed products and favorites, the size and color preferences when the visitor opted in, excerpts from the product catalog, the shop's display name, the merchant-configured delivery rule wording, public Shopify policy text and URLs and Shopify Market/destination/rate candidates and post-dispatch transit estimates when the merchant grants access, service tone, store rules, product knowledge and FAQs, and — when enabled — the latest order's delivery snapshot (order number, tracking number, tracking URL, etc., with no name, address, phone, or email fields; still treated as order-related data), and the product titles, sizes, and colors of the logged-in shopper's own recent purchases when purchase-based suggestions are enabled (only on stores that granted the optional order access)
What is not sentWe do not fetch names, addresses, phone numbers, emails, or payment details from order/customer APIs for transmission. Purchased product titles, sizes, and colors are sent only under the conditions above. Information users type into messages is transmitted
TrainingWe use a Paid Service through a project with active Cloud Billing. Google does not use submitted prompts or responses to improve its products
RetentionGoogle logs prompts and responses for a limited period to detect and prevent prohibited use and to satisfy required legal disclosures; its terms do not state a number of days. Project-isolated implicit in-memory caching can last up to 24 hours. We do not use Google Search or Maps Grounding, the File API, the Interactions API, or explicit context caching
International transfers and subprocessorsData may be stored temporarily or cached in any country where Google or its agents maintain facilities. Google's Data Processing Addendum applies; names, processing countries, and activities are published in the Google Cloud subprocessors list

The app (Singapore) → OpenAI, L.L.C. (USA) (commander chat — the setup guide on every plan, including Free and Standard; other consultation modes and the morning report on the Pro plan — and visual-search replies)

ModelOpenAI's GPT-6 Luna (gpt-6-luna)
Endpointhttps://api.openai.com (USA). Connected directly, with no routing service in between
What is sentMessages typed into the commander chat (including the recent conversation history), the consultation mode, Shopify product event timestamps and action types, product catalog updates, and this app's configuration. On stores with visual search enabled: the shopper's consented search image (the same sanitized copy sent to Voyage) and the matched candidates' titles, prices and currencies. This candidate release does not send Shopify sales, order, or session aggregates. For shops with post-purchase offers, the counts of offers shown, applied, not applied, and followed by a purchase with the same code (last 30 days, counts only — no customer IDs, order IDs, or amounts) are sent to generate the morning report
What is not sentOrder line items and customer names, addresses, phone numbers, and email addresses are not retrieved or sent. Information users type into messages is transmitted
TrainingNone — OpenAI does not use API data to train or improve its models unless we explicitly opt in, and we have not
RetentionWe send requests with response storage disabled (store: false), so no conversation state is kept at OpenAI. Under OpenAI's terms, abuse-monitoring logs are retained for up to 30 days unless longer retention is required by law

Only when OpenAI cannot be reached or does not finish within the time limit, commander replies are generated with the same Google Gemini API used for storefront chat (gemini-3.7-flash, same endpoint and terms). The content sent is the same as for OpenAI above.

When merchant staff ask Commander about shopper conversations, retained questions and answers after attempted identifier removal, or grouped observations, are sent to the Commander AI provider. Automated removal cannot detect every identifier in free text; shoppers are advised not to enter personal information.

The app (Singapore) → Voyage AI Innovations, Inc. (USA, a MongoDB company) (visual search)

Modelvoyage-multimodal-3.5
What is sentPublished product images when the merchant enables visual search, and search images that shoppers explicitly consent to send. Images are re-encoded into a supported format before transmission, removing attached metadata such as location information
What is not sentProduct titles, prices, descriptions, shop domain, conversation text, and order, customer, or payment data
Storage by usWe store only the vectors generated from published product images in our Singapore database. Shopper images and search-query vectors are not stored
Training and Voyage retentionOur organization opted out on September 10, 2026. Customer Content submitted after opt-out is not used for model training or future model improvement and is deleted immediately after processing (zero-day retention)
International transfer and subprocessorsProcessing may occur in the United States. Voyage's DPA applies. Its current subprocessors are Amazon Web Services, Inc., Google LLC, and Baseten Labs, Inc. Voyage remains responsible for its subprocessors and provides 30 days' notice before adding one. Standard Contractual Clauses or equivalent mechanisms apply where relevant

The storefront chat connects directly to Google's Gemini API with no routing service that dispatches requests across providers. Under Google's terms, processing is not restricted to one country and may occur where Google or its agents maintain facilities. Commander connects directly to OpenAI's API; only when OpenAI cannot be reached does it use the same Google Gemini API as the storefront chat. Replies to a shopper's image-search upload are also generated with OpenAI (GPT-6 Luna); the similarity search itself runs on Voyage AI.

If we change the AI provider or model, we will revise this policy in advance and name the provider and the country where processing occurs.

Delivering staff handoff emails

When the store has turned on staff handoff, the app sends a handoff only when the shopper presses "Send to staff". It is delivered to the notification address the store set, through the email delivery provider Resend, Inc. (USA). What is sent: the store's display name, the request summary the shopper reviewed, the recent conversation, the page being viewed, product handles, and the optional reply-to email address the shopper entered. We do not store the handoff content or the reply-to address in our database; they are discarded after delivery. To prevent duplicate sends and manage send counts, we store only identifiers and counts that contain no content. The reply draft in the handoff is fixed template text and is not sent to any AI provider.

Weather lookups

When a shopper asks about the weather, the app fetches a forecast from the Japan Meteorological Agency's public API (www.jma.go.jp). Only the forecast zone derived from the connection's region (prefecture) is used to look up the forecast; no personal data is sent.

Notice to shoppers

The chat is intended for questions about products and delivery timing. Please do not enter personal information such as your name, address, phone number, or credit card number. Anything you type is sent to Google and may be processed in a country where Google or its agents maintain facilities.

6. Responding to data deletion requests

The app implements Shopify's mandatory compliance webhooks:

For access to product review data, the merchant uses the product reviews admin page with the customer ID filter to inspect the reviews still retained and respond. Reviews are not included in the conversation access-request list. customers/redact deletes all local product reviews for that customer, including published, hidden, rejected, and sent to Judge.me. shop/redact deletes the shop's product review ledger and settings. On Judge.me, the reviewer can edit or delete the review from their Judge.me reviewer profile, or ask the store or Judge.me (support@judge.me) to delete it. SUGOI cannot guarantee completion of deletion on Judge.me.

You may also contact support@misell-theme.com to request access, correction, or deletion of data.

7. Security

8. Changes that come with new features

If we add features that change what data the app collects or which providers it uses, we will revise this policy in advance. If additional access scopes become necessary, we will ask merchants to approve them.

9. Changes to this policy

We will post any changes to this policy on this page. For significant changes, we will notify merchants in the app's admin page or by email.

10. Contact

Oops Co., Ltd.
MAT Tokiwamatsu 203, 1-13-4 Higashi, Shibuya-ku, Tokyo 150-0011, Japan
support@misell-theme.com