Privacy Policy - IaOrana AI Assistant
Last Updated: July 8, 2025
Overview
IaOrana LLC ("we," "our," or "us") is committed to protecting the privacy of merchants and their customers who use the IaOrana AI Assistant application ("the App"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our App.
Information We Collect
From Merchants
- Store Information: Shop domain, store name, and Shopify store ID
- Product Data: Product titles, descriptions, prices, and images via Shopify's API
- Analytics Data: Conversation metrics, revenue attribution, and performance statistics
- Contact Information: Email addresses for support and notifications
From Customers (End Users)
- Conversation Metrics: Aggregate data about conversation length, product recommendations shown, and conversion events (not actual message content)
- Interaction Data: Product views, cart additions, and purchase attributions
- Session Information: Temporary session identifiers for conversation continuity
- Device Information: Browser type and device type for optimization
Automatically Collected
- Usage Analytics: Feature usage, performance metrics, and error logs
- Technical Data: IP addresses (for rate limiting), API request logs
How We Use Information
To Provide Services
- Power AI-driven product recommendations
- Process customer inquiries and provide responses
- Track conversation-to-purchase attribution
- Generate analytics and insights for merchants
To Improve Our Service
- Enhance AI response accuracy
- Optimize product recommendation algorithms
- Improve user experience and interface
- Debug technical issues
For Business Operations
- Calculate revenue-based fees (2.5% of attributed sales)
- Provide customer support
- Send important service updates
- Ensure platform security and prevent abuse
Data Storage and Security
Storage
- Data is stored on secure servers in the United States
- We use industry-standard encryption for data in transit and at rest
- Conversation metrics are retained for analytics purposes
- Actual conversation messages are not stored - only aggregate metrics
- Merchants can request data deletion at any time
Security Measures
- SSL/TLS encryption for all data transmissions
- Secure API authentication tokens
- Regular security audits and updates
- Access controls and employee training
Data Sharing and Disclosure
We DO NOT:
- Sell personal information to third parties
- Share customer conversation content with other merchants
- Use customer data for advertising purposes
- Transfer data outside our service providers
We MAY Share Data:
- With Service Providers: OpenAI (for AI processing) and infrastructure providers
- For Legal Compliance: When required by law or to protect rights
- With Merchant Consent: Export features for merchant's own use
- In Aggregate: Anonymous, aggregated insights that don't identify individuals
Third-Party Services
OpenAI
We use OpenAI's GPT models to power conversational AI. Conversations are processed by OpenAI under their privacy policy. We do not send personally identifiable information to OpenAI beyond conversation content.
Shopify
We access store data through Shopify's API under their platform agreements. We only request necessary permissions for app functionality.
Data Rights
Merchant Rights
- Access all data collected about your store
- Export analytics and conversation data
- Request data deletion
- Opt-out of specific features
Customer Rights
- Conversations are ephemeral - we don't store message content
- Only aggregate metrics are retained (e.g., "3 products shown, 1 added to cart")
- No persistent customer profiles are created
- Merchants control their customer data
Cookies and Tracking
- We use essential cookies for session management
- No third-party tracking cookies
- No cross-site tracking
- Local storage used only for conversation state
Children's Privacy
Our service is not directed to individuals under 13. We do not knowingly collect information from children.
International Data Transfers
Data may be processed in countries other than where you reside. We ensure appropriate safeguards are in place for international transfers.
Changes to Privacy Policy
We may update this policy and will notify merchants of significant changes via email or in-app notifications.
Contact Information
For privacy-related questions or requests:
Email: privacy@iaorana.ai
Address: IaOrana LLC, Orange County, California, United States
Data Protection Officer
For GDPR-related inquiries: dpo@iaorana.ai
Compliance
This privacy policy is designed to comply with:
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- Shopify Partner Program Agreement
- Applicable data protection laws
Dispute Resolution and Arbitration
Binding Arbitration: Any dispute or claim relating to this Privacy Policy or the use of the IaOrana AI Assistant shall be resolved through binding arbitration in accordance with the commercial arbitration rules of the American Arbitration Association. The arbitration shall be conducted in Orange County, California.
Class Action Waiver: You agree that any arbitration or proceeding shall be limited to the dispute between us and you individually. You waive the right to participate in a class action, class-wide arbitration, or any other proceeding where someone acts in a representative capacity.
Exceptions: Notwithstanding the above, either party may seek injunctive or other equitable relief in any court of competent jurisdiction.
Governing Law and Jurisdiction
This Privacy Policy and any disputes arising out of or related to it shall be governed by the laws of the State of California, without regard to its conflict of law provisions. For any disputes not subject to arbitration, you consent to the exclusive jurisdiction of the state and federal courts located in Orange County, California.
By using IaOrana AI Assistant, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms.