OneSite Assistant

Privacy

OneSite Assistant answers shoppers’ questions about a shop’s catalogue. This policy says what data we receive, why, who else processes it, how long we keep it and how to exercise your rights.

Last updated 17 September 2026

Who we are and what this covers

OneSite Assistant is a service of OneSite Agency (“we”). This policy covers the Shopify app, the assistant installed on shops outside Shopify (WooCommerce and others), the merchant dashboard and our website assistant.onesite.agency.

OneSite Agency is a trading name of ARTIQUS LTD, a company registered in England and Wales under number 12357522. Registered office: 32 Regent Street, Wycliffe College, Stonehouse, Gloucestershire, GL10 2AD, United Kingdom.

For data about a shop’s visitors (“shoppers”), the merchant whose shop they visit is the controller and we are its processor: we handle that data to run the service for that merchant, on the instructions set out in this policy and our Terms of Service, and — only for shops that subscribe with us directly — for the de-identified learning described below. For merchants’ own accounts, for that learning and for our website, we are the controller.

What we receive from Shopify

Through the permissions the merchant approves at install:

  • read_products — the catalogue: titles, descriptions, prices, availability, images, product links and publication dates; new arrivals are taken from the publication dates.
  • read_locales — the shop’s published languages, so the assistant can answer in the storefront’s language.
  • read_orders — used in two ways. First, through the order-created and order-cancelled notifications, which Shopify trims to the fields we name: order ID and number, time, currency, totals, cart reference, note attributes, discount codes with the amount each took off, and line items (product, title, quantity, price, line properties and each line’s discount). From these we show the merchant which orders followed a conversation with the assistant, the orders and revenue the assistant helped produce, and which orders used each discount code. Second, we read the store’s orders from the last 60 days, taking only which products were sold and in what quantity after refunds, to rank that store’s own bestsellers in that store; this is never used for any other merchant. No customer name, email, phone or address is requested or stored.

Two further permissions are optional. The merchant grants them from inside the app only to use the feature they serve, and can withdraw them:

  • write_discounts — lets the merchant create, switch on and off and delete discount codes in their Shopify store from our app, and see how often each code was used and on which orders, including orders the assistant helped with. Discount codes are not shopper data; their use is read from the order notifications above.
  • write_customers — lets us write contacts that shoppers leave in the assistant into the merchant’s own Shopify customers, as described under “Contacts shoppers leave” below.

Shopify also tells us the shop’s domain and the state of its app subscription, and gives us access keys, which we keep to call its API. Apart from writing contacts when the merchant allows it, we do not access customer records, and we do not request access to checkouts, payments or staff accounts.

What we hold about merchants

  • Account, for merchants who sign in on our site: email address, a password stored only as an Argon2id hash, and language. The Shopify app has no separate account; it opens inside your Shopify admin.
  • Sign-ins: the time, IP address and browser of each session, so you can spot a sign-in that was not yours.
  • Shop: domain, catalogue, the settings you choose and the subscription’s state. For shops outside Shopify, the catalogue is read from the storefront, a product feed or our plugin.
  • Billing: merchants who subscribe with us directly pay through Stripe. Card details are entered at Stripe and never reach us; we receive Stripe’s customer and subscription identifiers and the subscription’s state.
  • Applications sent from our website: the shop’s address, platform, catalogue size and the contact you leave (email, phone, WhatsApp or Telegram).
  • Our website and dashboard: usage analytics through PostHog (EU cloud) — pages viewed, actions taken, browser and device. PostHog keeps no identifier in your browser unless you allow it. Two first-party cookies tie a visit to a later sign-up and remember which sign-up path you were shown. Neither is set inside the assistant’s panel on a shop’s storefront.
  • Referrals: if a partner in our referral programme (a blogger or agency) brought your shop to us, that partner sees your shop’s domain, whether it is paying and the commission accrued for it.
  • Emails you send us.

What we hold about shoppers

Per shop, and only for that shop:

  • The conversation: what the shopper types or dictates to the assistant, and the products shown and chosen. Dictated speech is turned into text on our own servers (GigaAM); the audio is not stored — only its length is written to our logs.
  • A random session identifier, not linked to a name or an account.
  • Approximate location — country and city — looked up from the IP address in a table on our own server. The IP address itself is not stored.
  • How the visit started and on what: referrer, UTM tags, landing page, device type, browser, operating system and the time zone the browser reports. The time zone shows when shoppers ask, by their own clock; it is not a location.
  • Events: the assistant opened, products shown and clicked, added to cart, and orders tied to the session.
  • A contact — email address, phone or WhatsApp number, or Telegram username — only if the shopper chooses to leave one after a request the shop could not answer; it is stored with that request, as described below. Where the shop runs a consent banner, the offer appears only if the shopper allowed marketing.

Answers are written by an AI model from the shop’s own catalogue and are labelled as picked by AI. They can be wrong: the product page and the merchant’s own terms are what count.

Contacts shoppers leave

Asking for a person: if a shopper presses “Talk to a person” and leaves an email address and a few words, we send them straight to the shop’s owner by email and do not store them. We keep only the fact that the request was made (the shop and a session name, to stop repeats). The shop answers the shopper itself and is responsible for what it does with the contact.

With the contact we store when it was left, which version of the notice was shown and in which language, and whether the shopper ticked a separate box for the shop’s news and offers. That box is unticked by default.

Leaving a contact means agreeing to one message about that request. The shop may send news and offers only if the separate box was ticked.

Contacts are stored encrypted (AES-GCM), with the key kept outside the database. To find a shopper’s contacts when a deletion or data request arrives, we also keep a keyed hash (HMAC-SHA256) of each contact, from which the contact cannot be recovered.

On Shopify stores, and only if the merchant allows it in the app (the optional write_customers permission), we write the contact into the merchant’s own Shopify customers: the email address, or the phone number in international format. The customer is tagged “onesite-assistant” and grouped in a segment named “OneSite Assistant”.

  • A marketing subscription is set only if the shopper ticked the box — to email for an email address, to SMS for a phone number — as single opt-in, with the time the box was ticked. A WhatsApp number is written without a subscription.
  • Telegram usernames and numbers without a country code are not written, and nothing else is sent: no name, no request text, no location.
  • We keep the Shopify customer number and whether the write succeeded, with Shopify’s reason if it did not. They are deleted with the contact — 395 days (13 months) after the request was recorded, or when Shopify forwards the customer’s deletion request — and are included when a customer asks for their data.

From the moment a contact is written, the merchant holds that customer record in Shopify as its own controller.

In the shopper’s browser

The assistant keeps two random values in the shop’s own browser storage (localStorage): a conversation identifier that expires after a period without messages, so the assistant can follow what was said, and a visitor marker that tells the merchant whether this browser has visited before. Neither contains a name, an email or anything the shopper typed.

Only when the shopper allows analytics, the assistant also marks the way to the purchase, so the merchant can see which orders followed a conversation: a line-item property (_ai_shop_q) with the answer’s identifier on products added to the cart from the assistant; on Shopify stores with our app, a cart attribute (__ai_shop) with the conversation identifier; on shops with our WordPress module, a first-party cookie (ai_shop_thread) with the conversation identifier, kept for 14 days. These markers end up in the merchant’s own order records.

On Shopify stores the assistant reads Shopify’s Customer Privacy API. On other sites it reads the site’s cookie banner — the WP Consent API, Cookiebot, OneTrust, CookieYes, Borlabs Cookie or any banner using the IAB TCF — and does not count a shopper who declined or has not answered yet. If the shopper refuses analytics, no usage events are sent; if they refuse marketing, no contact form is offered. The assistant still answers — that is the shopper’s own request. We use no advertising cookies and build no profiles across shops.

While the shop’s cookie banner is on screen, the assistant stays hidden, so the banner can be read and answered; we recognise the banners of common consent tools. Until the shopper opens the assistant or allows analytics, nothing about them is recorded. On stores with our Shopify app, only the merchant’s settings decide which of the assistant’s features run on the storefront: they cannot be switched on by adding anything to the page address.

Public ratings and reviews from other sites

For book shops, our servers read public book pages on livelib.ru and chitai-gorod.ru: each book’s rating and up to 12 reviews with the reviewer’s display name, date and text. We store them, refresh them about every 14 days and show them on product pages with the source named and linked, so shoppers can see readers’ opinions next to the book — our and the merchant’s legitimate interests. To summarise what readers praise and criticise, the review texts, without reviewer names, are sent to DeepSeek. If you wrote one of these reviews and want it removed from our copy, write to us. A shop can switch this off: its product pages and the assistant then show none of it, and we no longer look up ratings for its catalogue. We keep each review, with its author’s name, for at most 30 days after the source last showed it; the book’s overall rating names no one and is kept.

None of this applies to stores that use our Shopify app: we do not use their catalogue to look up ratings or reviews on other sites, and we show none of them on their product pages or in the assistant’s answers.

Why we use it and on what legal basis

  • To answer shoppers and show the merchant what was asked, found and bought — on the merchant’s instructions. For shopper data the merchant chooses the legal basis; a contact the shopper leaves rests on their consent.
  • To provide the service you signed up for and bill for it — performance of our contract with you (GDPR Art. 6(1)(b)).
  • To keep the service secure and working — sign-in records, rate limits, error logs and product analytics on our own website — our legitimate interests (Art. 6(1)(f)).
  • To improve product ordering, spelling and product lists for all shops from the aggregated activity of shops that subscribe with us directly, as described below — our legitimate interests (Art. 6(1)(f)).
  • To keep payment records where the law requires it — legal obligation (Art. 6(1)(c)).

We do not sell data or share it for advertising, and we do not train or fine-tune language models on any merchant or shopper data. Data from shops that installed through Shopify is not used for any kind of learning. From the activity of shops that subscribe with us directly we build three things used for all shops: the weights our product-ordering formula gives to 13 signals, fitted to which of the shown products shoppers clicked; a spelling and wording dictionary for each niche, built from shoppers’ questions; and a “what shoppers choose” list, made of clicks summed across shops. Each is built only from what at least two shops contribute, contains no shopper identity and names no shop. Apart from these, one merchant’s catalogue, shopper records and reports are never used for another merchant.

Who processes it for us

  • Hetzner Online GmbH, Germany — hosting. Our servers are in Nuremberg; everything we store lives there.
  • DeepSeek, Hangzhou, China — the language model. To compose an answer it receives the text of the conversation and product data from the shop’s catalogue; to describe products it receives catalogue data and, for books, the texts of public reviews. It receives no shopper name, contact, IP address or order data.
  • Shopify — the platform the app runs on, and billing for app installs.
  • Stripe — billing for merchants who subscribe with us directly.
  • PostHog, EU cloud — usage analytics on our website and dashboard.
  • Telegram — when enabled, internal notifications to our team about new merchant applications, with the shop’s address and the contact left.

Search, text embeddings and speech recognition run on our own servers; no third party takes part. We add any new processor to this list, and change the date above, before it starts.

For agencies and lawyers, what we store, for how long, who sees it and where it is processed is set out on one page: Data processing.

Transfers outside the European Economic Area

What we store stays in Germany. Each request to the language model is a transfer to China, which has no EU adequacy decision. We limit it to the conversation text, catalogue data and public review texts — no names, contact details, IP addresses or order data — and send it over an encrypted connection. As controller, the merchant decides whether this transfer is acceptable for their shoppers.

Shopify, Stripe and PostHog may process data in other countries under their own published data protection terms.

How long we keep it

  • Shopper records — conversations, sessions, visits, events and contacts, with the Shopify customer number stored for a contact — are deleted 13 months after they were recorded.
  • After an uninstall the shop’s data stays, so a reinstall brings it back, until Shopify sends its erasure notice (shop/redact) 48 hours later. Then everything about the shop is deleted: catalogue, conversations, contacts, orders and settings. In any case it is deleted within 30 days of an uninstall or of the end of a direct subscription.
  • A merchant account and its sign-in records are kept while the account exists, and deleted within 30 days of a request.
  • Applications are kept until you ask us to delete them.
  • Nightly database backups are kept for 14 days on the same server, so deleted data is gone from backups within 14 days.

Requests Shopify forwards for customers

  • Data request (customers/data_request): within 30 days we send the store owner the data we hold about that customer, as a machine-readable file.
  • Erasure request (customers/redact): we delete the contact that customer left, the conversations linked to it and the orders listed in the request.
  • Shop erasure (shop/redact): we delete everything we hold about the shop.

Your rights

Under the GDPR and similar laws you can ask for access to your data, its correction or erasure, restriction of processing and a copy in a machine-readable format (portability), and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time. You can also complain to a data protection authority.

Shoppers: the merchant decides about your data, so write to the shop first; if you write to us, we pass the request on and help the merchant answer it. Merchants: write to the address below, and we answer within 30 days.

Security

Traffic to and from our servers is encrypted with TLS. Access to production systems is limited to our operator. Passwords are stored only as Argon2id hashes and sign-in tokens only as SHA-256 fingerprints. Shoppers’ contacts are stored encrypted (AES-GCM), with the key kept outside the database. Notifications from Shopify and Stripe are accepted only with a valid signature. Every shop’s records are kept apart and read only on behalf of that shop. Nightly database backups are encrypted (AES-256), readable only by the server’s administrator account, and kept for 14 days.

Our operator can open a merchant’s dashboard to help with a support question; every such opening is recorded in our logs with who opened which shop.

If something goes wrong

If a breach affects personal data we hold, we tell the affected merchants without undue delay and no later than 72 hours after we become aware of it — what happened, which data and what we are doing about it — so they can meet their own obligations. Where the law requires it we also notify the data protection authority, and we notify Shopify when data from its platform is involved.

Children

The service is for businesses. The assistant does not ask anyone for their age or identity, and we do not knowingly collect personal data from children under 16. If you believe a child left contact details, write to us and we will delete them.

Changes to this policy

When this policy changes, the date at the top changes with it. Changes to how merchants’ or shoppers’ data is used are announced to merchants before they take effect.

Who to write to

OneSite Agency. Questions about this policy, requests about your data and notices go to the address below; we usually answer within one business day.

hello@onesite.agency

This page is published in several languages. Where they differ, the English text is the one that binds.