Skip to content

Privacy Policy

Last updated: 8 June 2026

Who we are

Reply Desks is a customer-support helpdesk for Shopify merchants. This policy explains what data Reply Desks processes when a merchant connects their store and uses the app to manage customer conversations.

Data we process

  • Support messages: emails and messages between the merchant and their customers, including sender name, email address and message content.
  • Shopify store data: when a merchant connects their store, we access order, customer and product information through the Shopify Admin API to display order details and process refunds and store credit the merchant initiates.
  • Account data: the merchant's name, email and workspace settings.
We do not sell personal data, and we do not use customer data for advertising.

How we use it

Data is used solely to provide the helpdesk: showing conversations and order context, sending replies, issuing refunds/credit at the merchant's request, and optional AI features (summaries, suggested replies, translation). AI processing is performed by Anthropic and is not used to train models.

Sharing

We share data only with sub-processors needed to run the service: Shopify (store data), Resend (outbound email), Anthropic (AI features), and our hosting provider. Each processes data only to provide their function.

Retention & deletion

Closed tickets are deleted once they pass the workspace's retention window — 24 months by default, changeable in Settings → Preferences. Open tickets are never deleted by retention. Merchants can export or delete their data at any time. We honour Shopify's mandatory data requests: oncustomers/redactwe delete the customer's conversations, and onshop/redactwe delete all data for the store. When the app is uninstalled, the store's access token is revoked.

Data Processing Agreement

Merchants act as the controller of their customers' data and Reply Desks as the processor. Our Data Processing Agreement sets out that relationship, our sub-processors and our breach notification commitment.

Security

Data is transmitted over HTTPS and stored on encrypted volumes. Credentials — Shopify access and refresh tokens, mailbox passwords — carry a second layer of AES-256-GCM encryption, so a database dump alone yields no working credential. Access to a customer's personal data is logged. Staff access is role-based and enforced server-side.

Contact

Questions or data requests: [email protected] or WhatsApp +1 (332) 231-0016.