Privacy Policy Background

Privacy Policy & Terms of Service

01. SCOPE & ACCEPTANCE OF TERMS

Welcome to Copiwin Support ("Copiwin", "we", "us", or "our"). This Privacy Policy and Terms of Service governs your access to and use of the Copiwin Shopify Application, platform dashboard, websites, and associated AI customer support automation services (collectively, the "Service"). By installing, registering for, or using our Service, you ("Merchant", "User", or "you") acknowledge that you have read, understood, and agree to be bound by this Policy.

Copiwin operates primarily as a Data Processor on behalf of Shopify merchants when processing end-customer personal data, and as a Data Controller with respect to merchant account and login credentials. If you do not agree with the terms outlined in this agreement, you must uninstall the application and discontinue use of our services immediately.

02. MERCHANT ACCOUNT & VERIFICATION

To utilize Copiwin's AI customer support tools, merchants must register using a valid email address, create secure authentication credentials, and authorize Copiwin to connect to their Shopify store domain via official OAuth protocols.

Merchants are solely responsible for maintaining the accuracy and confidentiality of their account credentials, sender names, and connected store details. Copiwin utilizes automated rate limiting, single-use One-Time Passwords (OTP), and encrypted JWT sessions to protect against unauthorized account access.

03. AI PROCESSING & SUPPORT SERVICES

Copiwin provides AI-driven customer support automation, email thread management, and Retrieval-Augmented Generation (RAG) knowledge retrieval for Shopify e-commerce merchants. The automated processing capabilities function as follows:

  • AI Ticket Classification: Inbound support emails are categorized by intent (Order Inquiry, Delivery, Returns, Refunds, Exchanges, Product Questions, Complaints) and assigned a confidence score.
  • Vector Knowledge Retrieval (RAG): Store catalog metadata, products, and order status summaries are indexed in isolated vector namespaces to supply accurate context for support responses.
  • Drafting & Auto-Reply Rules: Based on your confidence threshold settings (Green, Yellow, Red routing), Copiwin either auto-sends support replies or queues drafts for human agent review.

Copiwin does not use your store's proprietary customer support data or personal customer emails to train global foundation models for third parties. All AI analysis is performed strictly within isolated tenant namespaces to service your store's support inquiries.

04. BILLING & SUBSCRIPTION TERMS

1

All subscription billing for Copiwin is managed through the official Shopify Billing API. Billing charges will appear directly on your recurring Shopify invoice.

2

Merchants agree to maintain accurate store payment information with Shopify. Plan upgrades, downgrades, and recurring billing cycles take effect immediately upon confirmation through Shopify's checkout interface.

3

Copiwin does not directly collect, store, or process credit card numbers or banking credentials. All financial transactions are processed securely by Shopify Payments.

05. CANCELLATION & SUBSCRIPTION POLICY

Shopify Billing Cancellation Notice
You may cancel your Copiwin subscription at any time by uninstalling the application from your Shopify Admin center or downgrading to the Starter plan.

For billing discrepancies, prorated refund inquiries, or subscription assistance, please contact our privacy and support team at support@allspaces.com.

06. INTELLECTUAL PROPERTY & DATA OWNERSHIP

You retain full ownership of all store data — including product catalogs, store policies, customer communications, and brand assets. Copiwin retains all proprietary rights, trademarks, and intellectual property in the underlying Copiwin software, AI classification engines, vector search pipelines, and user interfaces.

07. DATA COLLECTION & SUB-PROCESSORS MATRIX

We collect and process only the personal information necessary to deliver, secure, and improve our AI support services. Below is a comprehensive overview of data categories, processing purposes, and authorized third-party sub-processors:

PERSONAL DATA CATEGORIES COLLECTED
  • Merchant Name & Email Address
  • Shopify Store URL & Access Tokens
  • Avatar Images (Metadata Sanitized)
PURPOSE & AUTHORIZED SUB-PROCESSOR
  • Account setup, tenant isolation, and administrative communications.
  • Sub-Processors: Shopify Inc. (App Platform), Resend (OTP Email Delivery).
PERSONAL DATA CATEGORIES COLLECTED
  • End-Customer Email & Full Name
  • Order History, Financial/Fulfillment Status
  • Shipping Address & Tracking Numbers
PURPOSE & AUTHORIZED SUB-PROCESSOR
  • Retrieval-Augmented Generation (RAG) for automated order lookup and customer support resolution.
  • Sub-Processor: Shopify Inc. (Admin GraphQL/REST APIs).
PERSONAL DATA CATEGORIES COLLECTED
  • Email Thread Contents & Snippets
  • OAuth Tokens (Google Workspace, Office365)
  • IMAP / Encrypted SMTP Credentials
PURPOSE & AUTHORIZED SUB-PROCESSOR
  • Email inbox synchronization, ticket classification, and automated reply dispatching.
  • Sub-Processors: Nylas Inc. (Inbox Sync), OpenAI LLC (AI Response Drafting).
PERSONAL DATA CATEGORIES COLLECTED
  • Store Product Catalog & Policy Text
  • Text Embeddings & RAG Vector Namespaces
  • AI Intent Classifications & Agent Feedback
PURPOSE & AUTHORIZED SUB-PROCESSOR
  • Vector search indexing for store Q&A resolution and continuous AI prompt refinement.
  • Sub-Processors: Pinecone Systems, Inc. (Vector DB), OpenAI LLC (Embeddings & Completion).
PERSONAL DATA CATEGORIES COLLECTED
  • IP Address & User-Agent Headers
  • Authentication & Security Audit Logs
  • Rate Limit Counters & Session Tokens
PURPOSE & AUTHORIZED SUB-PROCESSOR
  • Multi-tenant security enforcement, threat mitigation, and system audit logging.
  • Internal Security: Encrypted JWT middleware, PostgreSQL database logging.

All third-party sub-processors have executed Data Processing Agreements (DPAs) and maintain strict compliance with EU-US Data Privacy Frameworks and Standard Contractual Clauses (SCCs).

08. GLOBAL PRIVACY COMPLIANCE (GDPR & CCPA)

Copiwin is fully compliant with global data protection regulations including the EU General Data Protection Regulation (EU GDPR 2016/679), UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and Shopify App Developer Standards:

  • EU & UK GDPR Compliance: We operate on explicit Lawful Bases for Processing (Contract Performance & Legitimate Interest under Art. 6) and respect all Data Subject Rights (Art. 15-22).
  • CCPA / CPRA Rights: We explicitly confirm that Copiwin DOES NOT SELL or SHARE your personal information or store customer data for monetary or targeted advertising considerations.
  • Shopify Developer Compliance: We adhere strictly to Shopify API License & Terms of Use, implementing mandatory compliance webhooks for real-time customer and store data erasure.
Merchants may manage communication preferences or opt out of automated AI replies at any time by updating their inbox settings in the dashboard or contacting PRIVACY SUPPORT via email at support@copiwin-support.com.

09. SECURITY SAFEGUARDS & MULTI-TENANT ISOLATION

Multi-Tenant Architecture & Data Isolation
Copiwin enforces production-grade tenant isolation at every layer of the application architecture. Every database query, vector search request, and API route handler strictly validates tenant boundaries using JWT context middleware.
  1. Encryption in Transit & at Rest: All web traffic is encrypted using TLS 1.3/HTTPS. Sensitive credentials and tokens are encrypted at rest using AES-256-GCM.
  2. Image Payload Sanitization: Profile avatar uploads undergo magic-bytes verification and Sharp image processing to strip EXIF metadata and prevent code execution.
  3. HMAC Webhook Signatures: All incoming Shopify webhooks undergo timing-safe HMAC SHA-256 verification using SHOPIFY_CLIENT_SECRET to prevent request spoofing.
  4. Access Controls & Audit Logging: Administrative endpoints enforce bearer token authentication (CRON_SECRET) and log security events to an append-only AuditLog database.

While we enforce robust enterprise-grade security controls, no internet transmission is 100% secure. Merchants are responsible for maintaining strong password security and controlling team access.

10. DATA SUBJECT & MERCHANT PRIVACY RIGHTS

Under applicable privacy laws, merchants and store customers possess specific rights regarding their personal data. You have the right to request access to your personal data (Right to Access), request correction of inaccurate profile information (Right to Rectification), request complete deletion of your data (Right to be Forgotten), export your data in a structured machine-readable format (Right to Data Portability), and object to or restrict automated AI processing. To exercise any of these rights, please contact our Data Protection team.

11. AUTOMATED REDACTION & SHOPIFY WEBHOOKS

Copiwin automatically processes mandatory Shopify Compliance Webhooks in real-time. Customer data export requests (customers/data_request) generate structured HTML/JSON reports emailed directly to store owners. Customer deletion requests (customers/redact) trigger immediate PII sanitization in database tables and vector indexes. Store uninstallations (shop/redact) trigger complete hard deletion of all store catalogs, support threads, vector namespaces, and orphaned user accounts within 48 hours.

12. CONTACT INFORMATION & DATA PROTECTION OFFICER

For questions, data access requests, or privacy concerns regarding this Privacy Policy and Terms of Service, please contact our Data Protection Officer at: support@allspaces.com

13. COMMUNICATION & NOTIFICATION POLICY

By registering for Copiwin, you consent to receive essential service and security communications, including:

  • One-Time Passwords (OTP) and login verification codes
  • System maintenance and AI performance status alerts
  • Shopify billing and subscription updates
  • Customer support ticket escalation notifications

You can customize or disable non-essential notification alerts in your Dashboard Settings.

To opt out of promotional communications, select Unsubscribe in any received transactional email or adjust your profile preferences.

14. DISPUTE RESOLUTION & LIMITATION OF LIABILITY

To the maximum extent permitted by applicable law, Copiwin and its officers, directors, employees, and suppliers shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, customer goodwill, data, or operational disruptions arising from your use of or inability to use the Service.

Any disputes, claims, or controversies arising out of or relating to this agreement or the breach, termination, enforcement, interpretation, or validity thereof shall be settled by binding arbitration in accordance with standard commercial arbitration rules.

Both parties agree that any dispute resolution proceedings will be conducted solely on an individual basis and not as part of a class action, consolidated, or representative lawsuit.

15. ACKNOWLEDGEMENT & POLICY UPDATES

We reserve the right to update this Privacy Policy and Terms of Service periodically to reflect changes in legal requirements, AI capabilities, or system features. Continued use of Copiwin following published updates constitutes full acceptance of the revised terms.