Privacy Policy
Effective July 31, 2026
1. Who we are
Pickup is an AI voice abandoned-cart recovery app for Shopify, operated by Exil AI (“Pickup”, “we”, “us”). This policy explains what personal data we process when a merchant installs Pickup, how we use it, who we share it with, and the rights available to merchants and their customers. We act as a data processor on behalf of the merchant (the data controller) for their customers’ personal data.
2. Information we process
When a merchant installs Pickup and as it operates, we process:
- Merchant account data — store domain, name, email, plan, and settings, from Shopify.
- Customer personal data — a shopper’s name, email address, and phone number, plus the contents of their abandoned cart and the recovery checkout link. This is “Protected Customer Data” under Shopify’s rules and is used only to contact that shopper on the merchant’s behalf — to recover an abandoned checkout, and, where the merchant has switched those agents on, to win back a lapsed customer or ask about a delivered order.
- Order & fulfilment data — for the agents that work a merchant’s existing customers, we keep a record of their orders: the order’s identifier and number, what was in it and what it came to, the currency it was charged in, when it was placed, whether it was cancelled, and the shipment status, tracking number and the date a carrier reported it delivered. It is used to decide who to call and when — how long a customer has been quiet, and whether an order has arrived yet — and to let an agent speak accurately about the order it is calling about.
- Call data — call outcome, duration, transcript, a short AI summary, sentiment, and the call recording. Recordings are captured for every call regardless of plan; which plans can play them back is a billing matter, not a collection one.
- Satisfaction responses — where the post-purchase agent is switched on, the score a customer gives out of ten and the reason they give for it. The score and comment are written back to that order in the merchant’s own Shopify admin, so the merchant holds them as their own data too.
- Inbound caller data — where a merchant has added the optional inbound phone number, we process the number a person is calling from, together with the same call data above, for anyone who dials it. That includes people who never abandoned a checkout and people who reached the number by mistake. The calling number is matched against the merchant’s own orders so the assistant can answer questions about the caller’s own order, and about nobody else’s.
- Consent & suppression records — any opt-out or “do not call” request, and the suppression records we keep in order to honor it.
3. How we use it
- To place a recovery phone call, on the merchant’s behalf, to shoppers who abandoned checkout.
- Where the merchant has switched them on: to call a customer who has not ordered recently with a welcome-back offer, and to call after an order has been delivered to ask how it went. The satisfaction score and the customer’s comment are stored against that order, including as a metafield in the merchant’s own Shopify admin. Order history is used to decide who to call and when, and for nothing else.
- To answer calls to a merchant’s inbound number, where they have added one — looking up the caller’s own order by the number they are calling from, and answering questions about that order and about the merchant’s published policies. The assistant never discusses an order it cannot match to the caller.
- To generate the agent’s spoken responses and to email the shopper their checkout link and any discount.
- To produce the merchant’s dashboard analytics, transcripts, and call outcomes.
- To provide support and to keep the service secure and reliable.
4. Consent and choices
Recovery calls are placed on behalf of the merchant, who is responsible for having a lawful basis and any consent required to contact their customers. Pickup honors opt-outs immediately: a customer can opt out at any time — by saying so on a call or using the unsubscribe link in any recovery email — and we suppress all future contact. A merchant can also add a number to their Do Not Contact list on the shopper’s behalf. Merchants also control calling hours, the recovery discount, and which agents run.
5. How data is shared
We do not sell personal data and do not use it for advertising. We share personal data only with vetted service providers that process it on our behalf, under contract and solely to operate Pickup. These providers fall into the following categories:
- Cloud hosting & database infrastructure (United States) — runs the application and stores app data.
- Telephony & voice processing — connects the phone calls and generates the agent’s speech and responses.
- Email delivery — sends the recovery emails.
We also exchange data with Shopify, the platform Pickup runs on. A current list of our named sub-processors is available to merchants on request at privacy@exil.ai.
6. Retention and deletion
We keep personal data only as long as needed to provide the service, then remove it on a scheduled basis. When a merchant uninstalls Pickup, their store data is deleted in response to Shopify’s shop-redaction request. We honor Shopify’s mandatory customers/redact and customers/data_request webhooks: a customer’s data is erased (transcripts, recordings, summaries, phone, and the contact record) on a redaction request, and exported to the merchant on a data request.
7. Your rights
Depending on where you live (e.g. the EU/UK under GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, delete, or restrict the use of your personal data, and to withdraw consent. Because the merchant is the controller of their customers’ data, shoppers should contact the store; the store can fulfill access and deletion through Shopify’s data-request and redaction flows, which we support. You may also contact us at the address below and we will assist the merchant.
8. Security
Data is encrypted in transit (TLS) and at rest. Database access is least-privilege with row-level security so each store’s data is isolated, application credentials are stored in a managed secret store, and secrets are never written to logs. We restrict access to personal data to what the service requires.
9. International transfers
Pickup is hosted in the United States, so personal data is processed there. Where required, transfers rely on appropriate safeguards.
10. Children
Pickup is a business tool and is not directed to children, and we do not knowingly process children’s personal data.
11. Changes
We may update this policy; material changes will be reflected by the effective date above and, where appropriate, communicated to merchants.
12. Contact
Questions about this policy or your data? Email privacy@exil.ai.