CounterDeal
Privacy policy
Last updated:
CounterDeal is a Shopify app. It puts a chat assistant on a store’s product pages that answers shoppers’ questions and, within limits the store owner sets, offers them a deal. This policy explains what data the app handles, why, who else sees it, how long we keep it, and what you can ask us to do with it. If anything in it is unclear, email support@tangledata.com.
Who we are
CounterDeal is made and operated by TangleData. When this policy says “we” or “us”, it means TangleData. You can reach us at support@tangledata.com.
Merchants and shoppers
The app deals with two groups of people, and our role is different for each.
- Merchants — the store owners who install CounterDeal from Shopify. For the data about a merchant and their store, we decide how it is used, as described here.
- Shoppers — people who visit a merchant’s store and use the chat. For shopper data we act on behalf of the merchant, as their service provider (a “processor” in data-protection terms). The merchant runs the store and is responsible for its own privacy policy; we use shopper data only to provide the app to that merchant. If you are a shopper, the store’s privacy policy applies to you as well as this one.
What we collect from merchants
When a store installs the app, we receive and keep:
- Store details from Shopify: the store’s name, its myshopify.com address, its currency and time zone, and the permissions it granted the app. Used to run the app for that store.
- Shopify access tokens that let the app act for the store. Stored encrypted, and deleted as soon as the app is uninstalled.
- The product catalogue: product titles, descriptions, types, tags, variants, prices, stock levels and, where Shopify provides it, each item’s unit cost. The assistant answers product questions from these details, and the offer rules use the prices and costs. Costs never leave our server — they are not shown to shoppers or sent to the AI model.
- The merchant’s settings: which products can be negotiated, the lowest price and the steps the assistant may offer, the assistant’s tone and button text, and similar choices. Changes to the commercial settings are recorded in an audit log (what changed, when, and which store changed it).
- Billing records: the number of shopper messages answered each month, and the status of the store’s Shopify app subscription and usage charges. Payment itself is handled by Shopify; we never see the merchant’s payment details.
We do not collect the names, email addresses or other personal details of a merchant’s staff. Merchants sign in through Shopify, and the app receives only Shopify’s signed confirmation of which store is signed in.
What we collect from shoppers
Chatting needs no account, name, email or phone number. Here is everything the app handles when a shopper visits a product page that has the assistant on it.
A visitor ID on your device
The chat keeps a random, signed visitor ID in your browser’s local storage on the store’s website (under the name ain_visitor). When the chat talks to our server directly rather than through the store, our server may also set a cookie holding the same ID, which expires after one year. The ID identifies a browser on one store, not a person, and a different store gets a different ID. Our database stores only a one-way hash of it. We use it to:
- keep your conversation when you reload the page;
- apply the store’s own rules — for example, that the same visitor cannot start the bargaining again straight after a deal;
- measure whether the assistant helps the store. A fixed share of visitors (chosen by the store, 20% unless the store changes it) is placed at random in a group that never sees the assistant, so the store can compare the two groups. Which group you are in is worked out from the visitor ID alone — never from anything about you.
The chat also keeps a note of your current conversation in your browser’s session storage, which is cleared when you close the tab. Clearing your browser’s storage, or using a private window, gives you a new visitor ID.
What you type into the chat
Your messages and the assistant’s replies are stored, shown to the store owner in their dashboard, and sent to an AI model to understand your message and write a reply (see How the AI model is used). Before a message is stored or sent anywhere, the app removes:
- payment card numbers, card expiry dates and security codes;
- phone numbers;
- email addresses.
A street address typed into the chat is not removed — addresses have no reliable shape to detect. Please don’t type your address in the chat. When you are ready to buy, the chat offers a separate form for it (below).
Offers and the conversation’s history
We record each offer the assistant makes — the product, size or variant, quantity, price and any free delivery or gift — when it expires, and whether it was accepted and reached checkout. We also keep a short history per visitor ID (for example, the best deal it has been given and when) so the store’s rules can be applied.
The checkout form
If you accept a deal, the chat can show a form for your name, email, phone number and delivery address, so the Shopify checkout opens already filled in. Every field is optional. What you enter passes through our server once, to build the checkout link, and goes to Shopify’s checkout. We do not store it in our database, and it is never sent to the AI model.
Orders
When the store tells us an order has been paid, we read the order’s number, currency, totals, discount codes and the products and quantities in it, to check whether it came from a deal the assistant made. When it did, we also keep the buyer’s Shopify customer ID with that visitor’s record, so that a later request to see or delete that customer’s data finds everything we hold. It is never used for pricing or offers. We do not read or store the buyer’s name, email address, phone number or address from the order.
Technical data
Requests from the chat usually reach us through Shopify, on the store’s own domain. To stop abuse, the app limits how many requests one visitor, one store or one internet address can make; those counters are held in memory only and are not saved to our database. Our web server keeps standard access logs (internet address, time and the address requested), which are deleted after 14 days.
What we never collect
- Payment card details. There is no card field anywhere in the app. Payment happens in Shopify’s checkout, which we never see inside.
- Device fingerprints. We do not identify visitors by their device, browser settings or internet address. If you clear your storage, we do not try to recognise you again.
- Sensitive information such as race, religion, health, sexual orientation, gender or political views. The app never asks for it.
- Tracking across stores or websites. The app has no advertising cookies or third-party trackers, and a visitor ID on one store means nothing on another.
How the AI model is used
The assistant’s replies are written by a large language model. We reach it through OpenRouter, a service that routes requests to AI model providers; the model we use today is OpenAI’s GPT-4o mini. For each reply, the model receives the product’s details from the store’s catalogue, the recent conversation (with card numbers, phone numbers and email addresses already removed), and the offer the app has already approved, so it can put it into words.
The model does not receive the store’s lowest price, costs or margins, your visitor history, your order, or anything from the checkout form. It has no say in the price: every offer is decided by fixed rules the store owner sets, checked on our server, and nothing a shopper types can change those rules. We do not train or fine-tune any AI model on merchant or shopper data.
How offers are decided
What a shopper can be offered depends only on the store’s settings, the product and its price, the conversation so far, and that visitor ID’s own history with the store (such as a waiting period after a recent deal). Offers never depend on who you are: not on race, religion, health, gender or any other sensitive characteristic — the app does not know them — and not on your location or device. Any shopper can always ignore the chat and buy at the store’s normal price.
Who else handles the data
We use these service providers to run the app:
| Provider | What it does for us | What it receives |
|---|---|---|
| Shopify | The platform the app runs on: installation, the product catalogue, relaying the chat on the store’s domain, discount codes, checkout, order notices and billing | Chat requests pass through it; it creates the discount codes for accepted deals and receives checkout form details |
| OpenRouter | Routes requests to the AI model | Product details and the recent conversation, as described above |
| OpenAI | Provides the model OpenRouter routes to (OpenRouter may use another host of the same model) | The same, via OpenRouter |
| Hetzner Online | Hosts the server that runs the app and its database, in Helsinki, Finland | Everything the app stores |
| Cloudflare | DNS only — it tells browsers where our server is | No app traffic or personal data passes through it |
Our server is in the European Union (Finland). OpenRouter and OpenAI are based in the United States, so conversation text sent to the model is processed there. Each provider handles data under its own terms and privacy policy.
How long we keep it
- Negotiation data — chat conversations, visitor records and negotiation history, and offers — is kept for 12 months, then deleted.
- Web server access logs are deleted after 14 days.
- Shopify access tokens are deleted as soon as the store uninstalls the app.
- Everything about a store — its settings, catalogue, conversations, offers, usage and billing records — is erased 48 hours after the store uninstalls the app, when Shopify sends us its request to delete the shop’s data. If the store reinstalls within those 48 hours, its data is kept.
Until then, store data is kept while the app is installed, for as long as it is needed to run it.
Your rights, and Shopify’s privacy requests
Depending on where you live, you may have the right to see the personal data held about you, to have it corrected or deleted, or to object to how it is used.
- Shoppers: because we act for the store, the quickest route is to ask the store directly. Shopify passes a store’s customer privacy requests on to us, and we honour them: when Shopify asks for a customer’s data, we provide the store with the data we hold that is linked to that customer; when Shopify asks us to delete a customer’s data, we delete it. Because chatting needs no name or account, much of what we hold is not linked to an identified person, and we can act only on data we can match to you. You can also email us at support@tangledata.com.
- Merchants: you can switch the assistant off at any time, and uninstalling the app stops it immediately and deletes your access tokens. Your store’s data is erased 48 hours later, as above. To ask for your data or for earlier deletion, email support@tangledata.com.
Security
- All traffic to and from the app is encrypted in transit with TLS (HTTPS).
- Shopify access tokens are encrypted in our database with AES-256-GCM. Visitor IDs and offer tokens are never stored as they are — only as one-way hashes.
- Each store’s data is kept separate: every database query for a store’s data is limited to that store.
- The merchant dashboard only shows a store’s data to someone signed in to that store through Shopify, and messages from Shopify are only accepted with a valid Shopify signature.
- The database accepts connections only from the server it runs on.
No system is perfectly secure. If we learn of a breach affecting personal data, we will tell the affected merchants without undue delay.
We do not sell personal data
We do not sell merchant or shopper data, share it for advertising, or use it for anything except running the app for the store it came from.
Children
CounterDeal is a tool for businesses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has entered personal details into the chat on a store, contact that store or email support@tangledata.com and we will delete it.
This website
This website (CounterDeal’s own site) sets no cookies of its own and runs no analytics. If you book a meeting with us, the booking calendar is provided by Cal.com and your booking is handled under Cal.com’s privacy policy. If you email us, we use your email only to reply. The website is hosted by DigitalOcean.
Changes to this policy
When we change this policy we update the date at the top of this page. We will not use data already collected for a new purpose without telling merchants first.
Contact
TangleData
Email: support@tangledata.com