Legal
Last updated: April 7, 2026
At AskZoye, we believe privacy is a feature, not a checkbox. This policy explains what data we collect, why we collect it, who we share it with, and the rights you have over your information. If anything here is unclear, email privacy@askzoye.com and a real person will reply.
AskZoye is an AI-powered customer service platform for e-commerce stores running on Shopify and WooCommerce. We provide a chat widget that merchants embed on their storefronts so end customers can ask questions about products, orders, shipping, and returns — answered automatically by an AI agent trained on the merchant's catalog and policies.
We act in two distinct roles depending on whose data we're handling:
Merchant account data (we are the controller)
End-customer chat data (we process on the merchant's behalf)
Automatically collected data
We use the data we collect to:
Under GDPR, our legal bases for processing are: performance of a contract, our legitimate interests in operating and securing the service, your consent (for marketing emails and non-essential cookies), and compliance with legal obligations.
AskZoye uses large language models (LLMs) from OpenAI and Anthropic to generate answers. When an end customer sends a message, the relevant text — together with retrieved product or order data from the merchant's store — is sent to one of these providers over a zero-retention API endpoint to produce a reply.
We do not allow our LLM providers to train any model on Customer Data. OpenAI and Anthropic contractually commit not to use API inputs or outputs to train their models, and we use endpoints that do not retain content beyond the time needed to return a response.
AI outputs are probabilistic. They may occasionally be inaccurate, incomplete, or out of date. AskZoye is designed to support — not replace — human judgment, and the merchant remains responsible for the information their store presents to customers. We do not use AskZoye to make legal or similarly significant automated decisions about individuals.
We rely on a small set of vetted vendors to run AskZoye. Each one has a Data Processing Agreement in place with us and is bound to confidentiality and security obligations.
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Application hosting and edge network | United States |
| Neon | PostgreSQL database hosting | United States / EU |
| OpenAI | LLM inference (zero retention) | United States |
| Anthropic | LLM inference (zero retention) | United States |
| Paddle | International payment processing and tax | United Kingdom |
| Safepay | Pakistan payment processing | Pakistan |
| Inngest | Background jobs and workflows | United States |
| Upstash | Rate limiting and Redis cache | Global edge |
| Google / GitHub | OAuth sign-in | United States |
| Vercel Blob | File and media storage | United States |
We will give merchants at least 30 days' notice before adding or replacing a subprocessor that handles personal data, so you have time to object.
AskZoye is operated from Pakistan, and several of our subprocessors are based in the United States, the European Union, and the United Kingdom. When we transfer personal data across borders, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum where applicable, and a Transfer Impact Assessment to ensure your data receives an equivalent level of protection.
If you are in the EU or UK and would like a copy of the SCCs we have in place with a specific subprocessor, email privacy@askzoye.com.
We protect your data with industry-standard safeguards including TLS 1.3 encryption in transit, AES-256 encryption at rest, scoped API tokens, role-based access control on our internal systems, and least-privilege access for our team. We log administrative actions and review them regularly.
No system is perfectly secure. If we learn of a security incident affecting your personal data, we will notify affected merchants without undue delay and, where required, within 72 hours of discovery.
Depending on where you live, you may have the right to:
To exercise any of these rights, email privacy@askzoye.com and we will respond within 30 days. If you are an end customer chatting on a merchant's storefront, please contact that merchant first — they are the controller of your data.
California residents have additional rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt out of any “sale” or “sharing” of personal information. AskZoye does not sell personal information.
AskZoye is built for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data through AskZoye, contact us and we will delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will notify merchants by email and update the “Last updated” date at the top of this page at least 30 days before the changes take effect. Continued use of AskZoye after that date means you accept the updated policy.
For privacy questions, data subject requests, or to report a security issue:
AskZoye is operated from Pakistan. End customers chatting on a merchant's storefront should contact that merchant first — they are the controller of their own customer data.
AI resolves 67% instantly. The rest? You handle on WhatsApp — from your phone. No dashboards. No laptops. No missed sales.
Free plan available. No credit card. Works with Shopify & WordPress.