Legal

Privacy Policy

Last updated: June 22, 2026

This Privacy Policy explains how Support Agent (“Support Agent,” “we,” “us,” or “our”), a product of Automations For eCom, collects, uses, stores, shares, and protects information when you use our AI email-support service for Shopify brands (the “Service”). By connecting a mailbox or store to the Service, you agree to this policy.

Who this policy covers

The Service is used by merchants and their team members (“you” or the “customer”) to read, categorize, and draft replies to support emails. In doing so, the Service also processes information about your customers - the people who email your support inbox. We act as a data processor on your behalf for that end-customer information; you are the data controller and are responsible for having a lawful basis to process it.

Information we collect

Account information

  • Your name and email address, used to create and authenticate your account.
  • Team membership and role data, used to control access within your workspace.

Mailbox data (Gmail / IMAP)

When you connect a support mailbox, we access the email content needed to provide the Service: message subjects, bodies, sender and recipient addresses, headers (such as thread identifiers), timestamps, and attachments where relevant. We use this strictly to categorize inbound messages, draft grounded replies, and send approved replies from your mailbox on the original thread. For Gmail connections we store an encrypted OAuth refresh token; we never see or store your Google password. For IMAP/SMTP connections, credentials you provide are stored encrypted at rest.

Shopify store data

If you connect Shopify, we access order, fulfillment, tracking, and customer-history data for the limited purpose of grounding support replies in accurate, real order information (for example, answering “where is my order” questions). We request the minimum scopes needed for this.

Workspace content

  • Knowledge-base entries, reply drafts, approvals/edits, and category trust statistics you generate.
  • Optional Slack workspace connection details (an incoming-webhook URL) used only to post notifications.

Usage and technical data

We collect basic logs and operational metadata (timestamps, error events, processing status) needed to run, secure, and debug the Service.

How we use information

  • To read, categorize, and draft replies to inbound support emails.
  • To enrich drafts with live Shopify order data for accuracy.
  • To operate the “earned autonomy” feature, which only enables automatic sending for a topic after you have approved enough drafts.
  • To authenticate users, provide team access, and secure the Service.
  • To send you essential service and account email.
  • To maintain, debug, and improve the reliability of the Service.

Google API Services - Limited Use disclosure

Support Agent’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide and improve the user-facing features of the Service.
  • We do not transfer or sell Google user data for advertising, marketing, or other unrelated purposes.
  • We do not allow humans to read your Google user data except (a) with your explicit consent for specific messages, (b) where necessary for security or to comply with applicable law, or (c) where the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or ML models.

AI processing

The Service uses Google’s Gemini API to categorize messages, generate reply drafts, and create vector embeddings for retrieval. Content is sent to this provider only to perform these tasks for you. We use the paid Gemini API, under terms where submitted content is not used to train Google’s models. Drafts are generated to assist your team; you remain responsible for reviewing replies until a topic has earned automatic sending.

How we share information

We do not sell your data or your customers’ data. We share information only with service providers (“subprocessors”) that help us run the Service, under contractual confidentiality and data-protection obligations:

  • Google - Gmail access (when connected) and the Gemini AI API.
  • Shopify - order and customer data (when connected).
  • Supabase - authentication and encrypted database/storage.
  • Vercel - application hosting and serverless compute.
  • Resend - sending our internal/account email only (never your customer replies).
  • Slack - optional notification delivery (when connected).

We may also disclose information where required by law, to protect our rights or users’ safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).

Data retention and deletion

We retain data for as long as your account is active or as needed to provide the Service. You can disconnect a mailbox or store at any time, which revokes our access. On request, or when you delete your account, we delete or anonymize your data within a commercially reasonable period, except where retention is required by law. To request deletion, contact us at the address below.

Security

We use industry-standard safeguards, including encryption in transit (TLS) and encryption at rest for sensitive credentials and tokens. Database access is gated by row-level security so each workspace can only reach its own data. No method of transmission or storage is perfectly secure, but we work to protect your information.

International transfers

Our providers may process data in regions including the United States. Where personal data is transferred internationally, we rely on the providers’ lawful transfer mechanisms.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us. Because we process your customers’ data on your behalf, end-customer requests should be directed to you as the controller; we will assist you in responding.

Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate.

Contact us

Questions about this policy or your data? Email us at zeyad@automationsforecom.com.

Get your inbox answering for you.

Connect your mailbox in minutes. The agent starts in draft-only and earns the right to send as you approve, so you can try it without handing over the keys.

Drafts first, always · No credit card required