Legal

Privacy Policy

Last updated: August 15, 2026

Providara AI Concierge Service (“Providara,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices available to you.

It applies to merchants who purchase Providara services or use the platform for:

  • Custom Web setup and widget embed on their ecommerce website
  • Shopify deployment or installation
  • WooCommerce connection or subscription

Where relevant, it also applies to end customers (shoppers) who interact with the AI concierge on a merchant's storefront—whether Custom Web, Shopify, or WooCommerce.

1. Who we are

Providara is an AI concierge service for ecommerce storefronts. It recommends products, answers shopper questions, and guides customers on the merchant's website. Merchants may deploy Providara as:

  • Custom Web — an embeddable widget on the merchant's existing ecommerce website (primary offering)
  • Shopify — a managed or private-app style deployment
  • WooCommerce — a store connection with widget or plugin embed and a subscription where applicable

Our marketing website is providara.com. The merchant platform is at app.providara.com. For privacy inquiries, please contact us.

2. Data we collect

We collect personal data in the categories below. We collect only what is needed to operate Providara AI Concierge Service. We do not take broader store, site, or customer access than needed for concierge operation.

Merchant data (all platforms). When you create an account, purchase a setup package or subscription, or connect a store, we may collect:

  • Your name, email address, and business name
  • Account credentials and support communications with our team
  • Site or store identifiers, which vary by deployment:
    • Custom Web: website domain(s), widget token, and embed configuration
    • Shopify: shop domain and store identifier
    • WooCommerce: store URL and site identifier
  • Billing information for setup packages and subscriptions, processed by Paddle (our merchant of record). We do not store full payment card numbers
  • AI provider API keys and related configuration you choose to connect (for example, Grok, Groq, or Together AI). Usage and charges from your AI provider are between you and that provider

Catalog and store data. We process product and related catalog information so the concierge can recommend and explain what you sell. How that data arrives depends on the platform:

  • Custom Web: product and catalog data you upload, sync, or provide through a configured feed, API, or CSV as supported by the platform; and custom RAG documents you upload for brand knowledge
  • Shopify: store data accessed only through the OAuth scopes you approve at installation: read_products, write_products, and write_app_proxy. This may include product catalog data (titles, descriptions, variants, prices, images, and inventory quantities as they appear on product and variant records returned by the Products API) and shop metafields we write using write_products for widget configuration such as welcome message, widget token, and related theme preferences. We do not modify your product listings, prices, or catalog content through this scope. We do not access order history or Shopify Admin customer records. We do not request read_orders, read_customers, read_content, or read_inventory scopes. Storefront add-to-cart actions use the Shopify Ajax Cart API in the shopper's browser session; we do not access carts through Admin API scopes.
  • WooCommerce: product data retrieved through WooCommerce REST API credentials you connect. Those keys are stored encrypted. We use them to sync catalog information needed for product guidance; we do not use them to take broader store access than needed to operate the concierge.

Storefront shopper data (all platforms). When shoppers use the AI concierge on a Custom Web, Shopify, or WooCommerce storefront, we process:

  • Chat messages and session identifiers
  • Conversation context needed to respond (for example, products discussed or viewed during the session)
  • Optional email address or profile fields if the shopper voluntarily provides them

For storefront shopper data, the merchant is the data controller. Providara acts as a data processor, handling this data on the merchant's behalf to operate the AI concierge.

Technical data. We collect logs, IP addresses, browser and device information, and security and abuse-prevention signals to operate, secure, and improve the service. This includes technical logs generated by the widget across Custom Web, Shopify, and WooCommerce storefronts.

Website visitors. If you visit providara.com without creating an account or connecting a store, we may collect contact form submissions and standard website analytics as described in the Cookies and analytics section below.

3. How we use data

We use personal data to:

  • Operate the AI concierge on the merchant's storefront (Custom Web embed, Shopify embed or app proxy, or WooCommerce embed)
  • Sync product catalog data, retrieve catalog or RAG context, and apply widget configuration
  • Process setup and subscription payments through Paddle
  • Provide customer support and respond to inquiries
  • Maintain security, prevent abuse, and improve reliability and product features
  • Send service-related communications (for example, setup instructions, billing receipts, and product updates)
  • Comply with legal obligations and, where a Shopify deployment is used, Shopify partner requirements, and enforce our terms

We do not sell your personal data. We do not use merchant store or catalog data to train public-facing AI models in a way that identifies your business without your consent, except as needed to deliver the service you purchased.

4. Platform integrations

Providara is offered across three deployment options. Data practices below apply only to the platform you actually use.

4.1 Custom Web

The merchant embeds a Providara loader or widget script on their ecommerce website. Storefront requests are authenticated with the merchant's site or shop identifier and widget token. Allowed domains and similar origin controls (including CORS-style restrictions where applicable) limit where the widget may run.

Catalog data and custom RAG documents are stored under the merchant's workspace and kept isolated from other merchants. Disabling or removing the embed stops new collection from that storefront. Retention rules in Section 8 still apply to data already collected until a deletion request or account closure is processed.

4.2 Shopify

For Shopify deployments, Providara is installed through OAuth. We access Shopify data only with the scopes you approve during installation, as described in Section 2.

Storefront chat and related requests from the theme app embed (“Providara AI Service”) are routed to our API through the Shopify app proxy (/apps/providara/*). App proxy requests are verified using Shopify-signed requests.

We subscribe to Shopify mandatory privacy webhooks, including customers/data_request, customers/redact, and shop/redact. We also handle app/uninstalled to begin removal of associated shop data when you uninstall the app.

When you uninstall Providara, we delete or anonymize associated shop and customer interaction data within a reasonable timeframe. A shop/redact webhook completes erasure in accordance with Shopify's required timeline for partner apps.

Merchants may export or delete customer chat data through privacy tools in the merchant platform at app.providara.com, where those features are available.

4.3 WooCommerce

For WooCommerce deployments, the merchant connects their store using API keys and, where offered, a plugin, then embeds the Providara widget on the WooCommerce storefront. We sync product catalog data needed for recommendations.

If you disconnect the store or uninstall the integration, we stop catalog sync. We delete or anonymize associated shop and customer interaction data within a reasonable timeframe, subject to backup cycles and legal retention requirements.

5. Legal bases (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process personal data under the following legal bases:

  • Contract: to provide Providara and fulfill our agreement with you
  • Legitimate interests: to secure our service, prevent abuse, and improve functionality, balanced against your rights
  • Consent: where required, such as for optional marketing emails (you may withdraw consent at any time)
  • Legal obligation: where we must comply with applicable law, including Shopify partner data-protection requirements where you use a Shopify deployment

6. How we share data

We share data only as needed to operate Providara. Using Custom Web does not mean we share data with Shopify or WooCommerce unless you also use that platform.

  • Shopify — only for Shopify deployments: app installation, OAuth, product sync, app proxy requests, and storefront integration
  • WooCommerce store API — only for WooCommerce deployments, using credentials the merchant connects, to sync catalog data needed for the concierge
  • Paddle — payment processing for setup packages and subscriptions across all products (merchant of record)
  • Cloud and AI providers — hosting, infrastructure, and AI inference. AI providers receive chat content and catalog context only as needed to generate responses for a given session, under contractual safeguards. This includes third-party AI providers whose API keys you supply
  • Professional advisors — legal, accounting, or security services when necessary
  • Authorities — when required by law or to protect rights and safety

We require subprocessors to handle data only on our instructions and with appropriate security measures. A list of key subprocessors is available on request.

7. International transfers

Providara may process data in the United States and other countries where we or our providers operate. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an adequacy decision applies.

8. Data retention

We retain merchant account, site or store configuration, and related service data while you use the service and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements.

Chat logs and related usage data are retained for a limited period for support and analytics, then deleted or anonymized unless a longer retention period is required by law.

We delete or anonymize applicable data within a reasonable timeframe when:

  • You close your account or cancel the service
  • We receive a valid deletion request
  • For Shopify merchants: you uninstall the app, or we process Shopify privacy webhooks such as shop/redact or customers/redact
  • For WooCommerce merchants: you disconnect the store
  • For Custom Web merchants: the service ends, the domain is removed, or you request deletion

Deletion is subject to backup cycles and legal retention requirements.

9. Your rights

Depending on your location, you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with your local supervisory authority

Merchants can exercise many rights through tools at app.providara.com where those features are available, or by contacting us.

Storefront shoppers who interact with a merchant's AI concierge should contact the merchant first, because the merchant is the data controller for that data. We will assist merchants in fulfilling valid requests where applicable, including requests routed through Shopify compliance webhooks for Shopify deployments.

10. Cookies and analytics

Our marketing website may use cookies and similar technologies for essential functionality, preferences, and analytics. You can control cookies through your browser settings.

The Providara widget may use session storage, local technical storage, or similar technologies required for the concierge to function on Custom Web, Shopify, and WooCommerce storefronts.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. Widget requests are validated using the merchant's widget token. Third-party API secrets—such as Shopify access tokens, WooCommerce API keys, and merchant-supplied AI keys—are stored encrypted where we hold them.

For Shopify deployments, app proxy requests to our API are verified using Shopify-signed requests.

No method of transmission or storage is completely secure; we encourage you to use strong passwords, protect your AI provider API keys, and limit account access to trusted team members.

12. Children

Providara is a business service not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us so we can delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post changes on this page and update the “Last updated” date. Material changes will be communicated by email or in-app notice where required by law.

Questions?

If you have questions about this policy, please contact us. Related policies: Terms of Service, Privacy Policy, Refund Policy, Service Agreement.