The short version
- HelpEcho reads your store’s customers, orders and products so support agents can see who they are helping. It never writes to them, and never touches payment details.
- Support conversations, contact records and attachments are stored so your helpdesk has a history.
- If you switch on an AI feature, conversation text and a summary of the shopper’s recent orders are sent to Anthropic and OpenAI. Leave the AI features off and nothing is sent.
- We count how much email each store sends, so one store cannot spoil delivery for everyone else. We count volume, not content.
- We do not sell data and we do not share it for advertising.
Contents
1. Who we are
HelpEcho is a customer support helpdesk for Shopify stores. It gives merchants a shared inbox, a knowledge base, and an AI chat assistant for their shoppers.
This policy covers two things: the website at helpecho.com, and the HelpEcho app that a merchant installs on their Shopify store. They handle different data, so they are described separately.
When a merchant installs HelpEcho, that merchant is the data controller for their own shoppers’ information. We act as a processor on their behalf, under Shopify’s Partner terms.
2. This website
If you visit helpecho.com, we collect what a normal website collects.
Cookies
If you leave a comment or log in, we set cookies so you do not have to re-enter your details. Login cookies last two days, or two weeks if you choose “Remember me”. Screen preference cookies last a year.
Comments
When you leave a comment we store the comment, your IP address and your browser’s user agent string. The IP and user agent go to an automated spam detection service.
Embedded content
Articles may embed content from other sites — a video, an image. Embedded content behaves exactly as if you had visited that other site, and those sites may collect data about you and set their own cookies.
3. The HelpEcho app
Everything from here on describes the app installed on a merchant’s Shopify store, not this website.
Two groups of people appear in this data, and it is worth being clear about which is which:
- Merchants and their agents — the people who run the store and answer support tickets.
- Shoppers — the store’s customers, who write in for help.
If you are a shopper, you did not sign up with us. Your data is here because you contacted a store that uses HelpEcho, and that store decides how it is handled. Section 9 explains what you can ask for.
4. What the app reads from Shopify
At install, the merchant authorises read-only access to the following. Shopify shows these permissions before the merchant agrees to them.
| Permission | What it is used for |
|---|---|
read_customers | Name, email address and customer ID, so a ticket can be matched to the shopper who sent it |
read_orders | Order status, totals and items, so an agent can see what the shopper is asking about |
read_products | Product details, used by the chat assistant to answer product questions |
read_content | Pages and blogs, used to render the knowledge base on the storefront |
read_themes | Theme structure, used to install the support portal and chat widget |
All five are read-only. HelpEcho cannot change your customers, orders or products, and it has no access to payment card details at any point.
5. What we store
| What | Why it exists |
|---|---|
| Support conversations | Ticket subjects, message bodies and replies — whether they arrived from the storefront form, by email, or through the chat widget |
| Contact records | The shopper’s name and email address, so their conversations stay together |
| Attachments | Files a shopper or agent adds to a conversation |
| Chat transcripts | Conversations held with the AI assistant, so an agent can pick up where it left off |
| Agent accounts | Name and email of the merchant’s staff who use the helpdesk |
| Operational records | Activity logs, usage counters and email delivery diagnostics |
Inbound email is turned into tickets automatically, so anything a shopper writes to a connected support address is stored the same way.
6. AI processing
When a merchant uses an AI feature — the chat assistant, the reply writer, or the article writer — the relevant content leaves our systems and is sent to a third-party AI provider so a response can be generated.
These features are optional. With them switched off, nothing is sent to any AI provider and the helpdesk works normally.
What is sent
It depends on the feature, and may include:
- The text of the support conversation, including what the shopper wrote
- The shopper’s name and email address
- A summary of the shopper’s recent orders — currently their three most recent, with status and totals
- Product information from the store, for recommendations
Who receives it
Anthropic (Claude) and OpenAI. Content is sent so a reply can be produced and returned to the merchant’s helpdesk. Under the terms on which we use these providers, it is not used to train their models.
Turning it off
AI features are controlled per store in Settings. A merchant who would rather no shopper data reach an AI provider can leave them disabled, and every other part of HelpEcho continues to work.
7. Who else sees it
We use the following services to run HelpEcho. Each one sees only what it needs.
| Service | Purpose | What it sees |
|---|---|---|
| DigitalOcean | Database hosting | All stored data |
| Amazon S3 | Attachment storage | Files added to conversations |
| Amazon SES | Sending email | Recipient address, subject, message body |
| Postmark | Sending email (alternate) | Recipient address, subject, message body |
| Anthropic | AI features | See section 6 |
| OpenAI | AI features | See section 6 |
| Shopify | The platform HelpEcho runs on | Store and session data |
We do not sell data, and we do not share it for advertising. We disclose data to law enforcement only where we are legally required to.
8. How long we keep it
| Data | Kept for |
|---|---|
| Support conversations and contacts | As long as the app is installed, so the merchant keeps their history |
| Activity logs | 7 days |
| Deleted tickets | Held in the merchant’s trash, then removed automatically on the schedule they set |
| After uninstall | Retained briefly so a reinstall can restore the helpdesk, then deleted |
| On a deletion request | Deleted on receipt, through Shopify’s data deletion channel |
9. Your rights
If you are a shopper
The store you contacted is responsible for your data, so that is usually the fastest place to start. You can ask for a copy of what we hold about you, ask for it to be corrected, or ask for it to be deleted.
Requests raised through Shopify reach us automatically and we act on them. You can also write to us directly at [email protected].
If you are a merchant
You can export your helpdesk data at any time from the app, and uninstalling begins deletion as described in section 8.
10. Monitoring the service
Every message sent through HelpEcho leaves shared sending infrastructure. If one store sends bulk email, the bounces and spam complaints that follow damage delivery for every other store — including support email from merchants who have done nothing wrong.
So we record how much email each store sends: counts and timestamps, not message content. Where that volume looks like bulk sending rather than support, we may review the content of the messages concerned in order to investigate, and we may pause a store’s outbound email while we do.
What is and is not permitted is set out in our Acceptable Use Policy. In short: HelpEcho is for replying to people who contacted you, not for marketing or bulk sending.
11. Security
Data is encrypted in transit. Access to production systems is limited to staff who need it for their work.
Merchants authenticate through Shopify — we never see or store a Shopify password. Sessions are held server-side and expire.
If you believe you have found a security problem, please write to [email protected] before disclosing it publicly, and we will respond.
12. Changes and contact
When what we do with data changes, we update this page and change the date at the top. Material changes are announced in the app.
Questions about this policy, or a request about your data:
HelpEcho · Bolorampur, Paikpara, Alamdanga, Chuadanga 7210, Bangladesh
