Skip to content

CounterDeal

Privacy policy

Last updated:

CounterDeal is a Shopify app. It puts a chat assistant on a store’s product pages that answers shoppers’ questions and, within limits the store owner sets, offers them a deal. This policy explains what data the app handles, why, who else sees it, how long we keep it, and what you can ask us to do with it. If anything in it is unclear, email support@tangledata.com.

Who we are

CounterDeal is made and operated by TangleData. When this policy says “we” or “us”, it means TangleData. You can reach us at support@tangledata.com.

Merchants and shoppers

The app deals with two groups of people, and our role is different for each.

What we collect from merchants

When a store installs the app, we receive and keep:

We do not collect the names, email addresses or other personal details of a merchant’s staff. Merchants sign in through Shopify, and the app receives only Shopify’s signed confirmation of which store is signed in.

What we collect from shoppers

Chatting needs no account, name, email or phone number. Here is everything the app handles when a shopper visits a product page that has the assistant on it.

A visitor ID on your device

The chat keeps a random, signed visitor ID in your browser’s local storage on the store’s website (under the name ain_visitor). When the chat talks to our server directly rather than through the store, our server may also set a cookie holding the same ID, which expires after one year. The ID identifies a browser on one store, not a person, and a different store gets a different ID. Our database stores only a one-way hash of it. We use it to:

The chat also keeps a note of your current conversation in your browser’s session storage, which is cleared when you close the tab. Clearing your browser’s storage, or using a private window, gives you a new visitor ID.

What you type into the chat

Your messages and the assistant’s replies are stored, shown to the store owner in their dashboard, and sent to an AI model to understand your message and write a reply (see How the AI model is used). Before a message is stored or sent anywhere, the app removes:

A street address typed into the chat is not removed — addresses have no reliable shape to detect. Please don’t type your address in the chat. When you are ready to buy, the chat offers a separate form for it (below).

Offers and the conversation’s history

We record each offer the assistant makes — the product, size or variant, quantity, price and any free delivery or gift — when it expires, and whether it was accepted and reached checkout. We also keep a short history per visitor ID (for example, the best deal it has been given and when) so the store’s rules can be applied.

The checkout form

If you accept a deal, the chat can show a form for your name, email, phone number and delivery address, so the Shopify checkout opens already filled in. Every field is optional. What you enter passes through our server once, to build the checkout link, and goes to Shopify’s checkout. We do not store it in our database, and it is never sent to the AI model.

Orders

When the store tells us an order has been paid, we read the order’s number, currency, totals, discount codes and the products and quantities in it, to check whether it came from a deal the assistant made. When it did, we also keep the buyer’s Shopify customer ID with that visitor’s record, so that a later request to see or delete that customer’s data finds everything we hold. It is never used for pricing or offers. We do not read or store the buyer’s name, email address, phone number or address from the order.

Technical data

Requests from the chat usually reach us through Shopify, on the store’s own domain. To stop abuse, the app limits how many requests one visitor, one store or one internet address can make; those counters are held in memory only and are not saved to our database. Our web server keeps standard access logs (internet address, time and the address requested), which are deleted after 14 days.

What we never collect

How the AI model is used

The assistant’s replies are written by a large language model. We reach it through OpenRouter, a service that routes requests to AI model providers; the model we use today is OpenAI’s GPT-4o mini. For each reply, the model receives the product’s details from the store’s catalogue, the recent conversation (with card numbers, phone numbers and email addresses already removed), and the offer the app has already approved, so it can put it into words.

The model does not receive the store’s lowest price, costs or margins, your visitor history, your order, or anything from the checkout form. It has no say in the price: every offer is decided by fixed rules the store owner sets, checked on our server, and nothing a shopper types can change those rules. We do not train or fine-tune any AI model on merchant or shopper data.

How offers are decided

What a shopper can be offered depends only on the store’s settings, the product and its price, the conversation so far, and that visitor ID’s own history with the store (such as a waiting period after a recent deal). Offers never depend on who you are: not on race, religion, health, gender or any other sensitive characteristic — the app does not know them — and not on your location or device. Any shopper can always ignore the chat and buy at the store’s normal price.

Who else handles the data

We use these service providers to run the app:

ProviderWhat it does for usWhat it receives
ShopifyThe platform the app runs on: installation, the product catalogue, relaying the chat on the store’s domain, discount codes, checkout, order notices and billingChat requests pass through it; it creates the discount codes for accepted deals and receives checkout form details
OpenRouterRoutes requests to the AI modelProduct details and the recent conversation, as described above
OpenAIProvides the model OpenRouter routes to (OpenRouter may use another host of the same model)The same, via OpenRouter
Hetzner OnlineHosts the server that runs the app and its database, in Helsinki, FinlandEverything the app stores
CloudflareDNS only — it tells browsers where our server isNo app traffic or personal data passes through it

Our server is in the European Union (Finland). OpenRouter and OpenAI are based in the United States, so conversation text sent to the model is processed there. Each provider handles data under its own terms and privacy policy.

How long we keep it

Until then, store data is kept while the app is installed, for as long as it is needed to run it.

Your rights, and Shopify’s privacy requests

Depending on where you live, you may have the right to see the personal data held about you, to have it corrected or deleted, or to object to how it is used.

Security

No system is perfectly secure. If we learn of a breach affecting personal data, we will tell the affected merchants without undue delay.

We do not sell personal data

We do not sell merchant or shopper data, share it for advertising, or use it for anything except running the app for the store it came from.

Children

CounterDeal is a tool for businesses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has entered personal details into the chat on a store, contact that store or email support@tangledata.com and we will delete it.

This website

This website (CounterDeal’s own site) sets no cookies of its own and runs no analytics. If you book a meeting with us, the booking calendar is provided by Cal.com and your booking is handled under Cal.com’s privacy policy. If you email us, we use your email only to reply. The website is hosted by DigitalOcean.

Changes to this policy

When we change this policy we update the date at the top of this page. We will not use data already collected for a new purpose without telling merchants first.

Contact

TangleData
Email: support@tangledata.com