Marvyn AI • Shopify App & Web Platform

Privacy Policy

This policy explains how Marvyn AI handles information when you use either our Shopify embedded app or the standalone web version available at marvyn.co. Both experiences follow the same privacy principles.

Last updated: September 28, 2025

1. Who We Are

Marvyn AI ("Marvyn", "we", "our", or "us") provides an AI-powered customer support and product recommendation platform. Merchants can run Marvyn as a Shopify embedded app or via the web dashboard at marvyn.co. Unless a section states otherwise, the statements below apply to both deployment options.

2. Information We Collect

2.1 Merchant Account Data

When you create a Marvyn account or install the Shopify app, we collect:

  • Contact details (name, email, company name, Shopify store URL)
  • Authentication and billing identifiers provided by Shopify (shop ID, access tokens, plan information)
  • Subscription selections, usage metrics, and customer support communications

2.2 Store & Customer Data We Process on Your Behalf

Whether you use the Shopify app or connect via API/CSV through the web dashboard, we synchronise certain store data you authorise. This can include:

  • Product catalogue data (titles, descriptions, pricing, inventory status)
  • Store policies, FAQs, marketing content, and custom knowledge base materials that you provide
  • End-customer chat transcripts, feedback, and intents submitted through the widget
  • Order and customer metadata only when you explicitly enable those features inside the app

We act as the data processor for this information under Shopify's Partner Program and only use it to supply the service according to your instructions.

2.3 Automatically Collected Information

  • Device, browser, and network identifiers when you access our dashboard
  • Usage analytics (feature interactions, response latency, error reports)
  • Cookies or similar technologies for session management and to remember preferences

3. How We Use Information

  • Provide, configure, and maintain the chatbot experience within your Shopify store
  • Generate AI responses, product recommendations, and analytics you request
  • Train and fine tune AI models on de-identified interaction patterns to improve accuracy
  • Monitor performance, debug issues, and secure the infrastructure
  • Bill for paid plans, process refunds where applicable, and comply with Shopify billing requirements
  • Communicate product updates, security advisories, or policy changes

We do not sell personal information and we do not use customer content for advertising. Model training is performed on aggregated or anonymised data unless you opt out via support.

4. Sharing & International Transfers

We share information only with service providers that help us deliver the app:

  • Cloud hosting, databases, and logging platforms (primarily located in the United States)
  • OpenAI or other large language model providers that generate chatbot responses
  • Analytics, error monitoring, and payment processors such as Stripe and Shopify

Each vendor is bound by contractual obligations to protect your data and only process it for the services we request. Where information is transferred outside of the country where it was collected, we rely on Standard Contractual Clauses or equivalent safeguards.

5. Data Retention & Deletion

  • Merchant account data is stored for the duration of your subscription and a reasonable back-up period (typically 90 days) after cancellation, unless local law requires longer retention.
  • Chat transcripts and training materials remain until you delete them within the dashboard or request removal. You may also toggle automatic transcript retention.
  • Upon uninstalling the Shopify app, we automatically revoke API tokens and queue associated store data for deletion within 30 days, except where retention is required to settle invoices or resolve disputes.

To request deletion sooner, email privacy@marvyn.co.

6. Legal Bases & Rights

Depending on your jurisdiction (e.g., GDPR, UK GDPR, CCPA/CPRA):

  • We process personal data to perform our contract with you, comply with legal obligations, or pursue legitimate interests such as product improvement.
  • You can request access, correction, deletion, restriction, portability, or object to certain processing. Californian users may opt out of "sharing" for cross-context behavioural advertising (which we do not perform).
  • Submit requests via privacy@marvyn.co. We may verify your identity before fulfilling the request.

7. Security Measures

We use encryption in transit, access controls, network segmentation, logging, and regular vulnerability reviews. You remain responsible for safeguarding the credentials you generate for your team and for configuring Shopify permissions appropriately.

8. Children & Sensitive Data

Marvyn AI is designed for business users and is not intended for children under 16. You should not input sensitive personal data (e.g., payment card details, health information) into the chatbot unless required for your business and lawful under applicable regulations.

9. Uninstalling the Shopify App & Disconnecting the Web Account

When a merchant uninstalls the Marvyn AI Shopify app, Shopify notifies us immediately. We revoke the store's API credentials, disable new data ingestion, and begin data deletion as described above. If you disconnect the web dashboard or close your account from marvyn.co, we follow the same process and queue associated data for deletion. You may contact us to confirm deletion or request exported transcripts before removal completes.

10. Updates to This Policy

We will post updates on this page and, when material changes occur, notify account owners via email or in-app banners. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

11. Contact

Marvyn AI
Email: privacy@marvyn.co
Support portal: marvyn.co/contact