Introduction
Chatty is live chat, AI chatbot, help center, and customer support software for Shopify merchants. Chatty is operated by AVADA GROUP COMPANY LIMITED (CÔNG TY TNHH AVADA GROUP), a company established under the laws of Vietnam under Business Registration No. 0109524114, with its registered office at 102 Tran Phu, Ha Dong, Hanoi, Vietnam. In this policy, “Chatty”, “we”, “us” and “our” refer to that company.
This policy covers two different situations, and it matters which one applies to you.
- Visitors to chatty.net. When you browse our website, request a demo, or contact our team, we decide why and how your personal data is used. For that data we are the controller, and this policy governs.
- Customers of a merchant that uses Chatty. When you chat with a store that has installed Chatty, the merchant decides why and how your data is used. The merchant is the controller and Chatty is the processoracting on the merchant’s documented instructions. For that data, the merchant’s own privacy policy governs, not this one. This policy only explains what we do with that data on the merchant’s behalf.
This policy does not apply to websites, apps, or services operated by third parties, including Shopify. Their practices are governed by their own policies.
Information We Collect
Data we collect from website visitors
- Contact details you submit through forms, such as your name, email address, company name, store URL, and any message you write.
- Booking details — your name, email address, store URL, your phone number if you give one, any guest email addresses you add, and anything you write in the notes field — when you schedule a demo on our demo request page. That page reads available slots from Cal.com and passes those details to Cal.com to confirm the appointment.
- Messages you send us through the chat widget on this website.
- Usage and technical data, such as pages viewed, referring URL, IP address, browser type, device type, and session identifiers, collected through cookies and similar technologies.
Filling in any form on this website, and writing to us through the chat widget, is entirely voluntary. There is no statutory or contractual obligation to give us these details, and the only consequence of not giving them is that we cannot answer your enquiry or book the demo you asked for.
Data we collect from merchants
- Account data: store name and domain, staff names, email addresses, and role assignments, plus authentication identifiers issued through Shopify OAuth and Firebase Authentication.
- Subscription and billing records: plan, billing amounts, and invoice records. Billing is charged and processed entirely through Shopify.
- Support correspondence: tickets, emails, and chat conversations with our support team.
- Product usage data: which features are used, session activity, and error events in the Chatty admin, used to keep the Services running and to improve them. Legal basis: our legitimate interest under Article 6(1)(f).
Where this data comes from. We receive account data, subscription and billing records from Shopify Inc. when a merchant installs Chatty and authorises the app, rather than from the individual staff member directly. Product usage data is generated by use of the Chatty admin itself. Support correspondence comes from you when you contact us. Providing account data is a requirement of entering the contract for the Services: without it we cannot create or operate a Chatty account. Providing anything beyond that is optional and has no consequence if you decline.
We do not collect or store payment card details. Payments are handled end to end by Shopify. Card numbers never reach our systems.
Data we process on behalf of merchants
When a merchant installs Chatty, we process the following categories of end-customer data on that merchant’s instructions:
- Chat messages and attachments sent through the widget.
- Contact details a shopper chooses to provide in a conversation, such as name, email address, or phone number.
- Order information synced from the merchant’s store, used to answer order status and shipping questions.
- Page views and browsing activity on the merchant’s storefront while the widget is active.
- Technical identifiers such as IP address, browser, device type, and session ID.
Legal Bases for Processing
Where the GDPR applies and we act as controller, we rely on the following legal bases under Article 6:
- Performance of a contract (Article 6(1)(b)) — creating and administering merchant accounts, delivering the Services, providing support, and handling billing.
- Legitimate interests (Article 6(1)(f)) — securing our systems, preventing fraud and abuse, diagnosing errors, and improving product quality. We balance these interests against your rights and freedoms.
- Consent (Article 6(1)(a)) — non-essential cookies and analytics, and marketing email. You can withdraw consent at any time, and withdrawal does not affect processing carried out before you withdrew.
- Legal obligation (Article 6(1)(c)) — accounting, invoicing, and tax records required under Vietnamese law.
For personal data we process on behalf of a merchant, the merchant determines the purposes and the legal basis. We process that data only on the merchant’s documented instructions and under our Data Processing Agreement.
How We Use Information
Each purpose below names the legal basis we rely on. Where we act as a processor for a merchant, the merchant chooses the basis and we act on their instructions.
- Provide, operate, and maintain the Services. Legal basis: performance of a contract, Article 6(1)(b).
- Generate AI answers to shopper questions using the merchant’s configured knowledge sources. Legal basis: processing on the merchant’s documented instructions, Article 28(3)(a); the merchant is the controller.
- Route conversations to the right merchant staff member. Legal basis: the merchant’s instructions, Article 28(3)(a).
- Answer order status, shipping, and product questions using order and catalog data synced from the store. Legal basis: the merchant’s instructions, Article 28(3)(a).
- Authenticate users, enforce plan limits, and process subscriptions through Shopify. Legal basis: performance of a contract, Article 6(1)(b).
- Respond to support requests and communicate service notices. Legal basis: performance of a contract, Article 6(1)(b), and our legitimate interest in supporting our own users, Article 6(1)(f).
- Answer enquiries sent through this website, schedule and run the demos people book, and follow up on those conversations. Legal basis: steps taken at your request before entering a contract, Article 6(1)(b), and our legitimate interest in answering follow-up questions and handling disputes, Article 6(1)(f) — which is also why we keep this correspondence for 24 months.
- Monitor availability and performance, investigate incidents, and protect against abuse. Legal basis: our legitimate interest in keeping the Services secure and available, Article 6(1)(f).
- Produce aggregated statistics that do not identify any individual. Legal basis: our legitimate interest in understanding how the Services are used, Article 6(1)(f). Once aggregated, the result is no longer personal data.
- Send product and marketing email to merchant staff who have consented, with an unsubscribe link in every message. Legal basis: consent, Article 6(1)(a), withdrawable at any time.
- Meet legal, accounting, and tax obligations. Legal basis: compliance with a legal obligation, Article 6(1)(c).
We do not sell personal data, and we do not use merchant or end-customer conversation content to train our own models. We do share online identifiers from this website with Meta through the advertising pixel described under Cookies and Tracking — that is the only sharing of its kind that happens on this site, and in California it does not happen unless you accept.
Cookies and Tracking
We use cookies and similar technologies on chatty.net to keep the site working, remember your preferences, and measure how the site is used, and to measure our advertising. We run Google Analytics 4 through Google Tag Manager. We run the Meta Pixel, which tells Meta when you open a page here and when you go on to our Shopify App Store listing, and which sets identifiers that last three months. We run the Crisp chat widget, which sets a cookie so a conversation survives a page reload and lasts 6 months from your last visit, renewed each time you return. Cloudflare sets cookies for bot protection and security. Our demo request page does not show the support chat widget; it reads booking slots from Cal.com and hands your booking details to Cal.com when you confirm, straight from your browser.
If you are in the European Economic Area, the United Kingdom, Switzerland, Brazil, or California, we ask before setting any non-essential cookie: the banner appears on your first visit and nothing non-essential loads until you accept. Elsewhere those cookies are set when a page loads and you can switch them off at any time from the cookie settings link at the bottom of every page. To tell the two apart we read the country your connection comes from, using a check that runs against chatty.net itself rather than an outside location service; within the United States we also read the time zone your browser reports, because the country alone does not identify California. You can change or withdraw your choice at any time, in any country. Strictly necessary cookies are set without consent because the site cannot function without them. The embedded customer videos load nothing until you press play, and the button says what it loads before you press it, so pressing it is your consent for that one item. The interactive product demo works the same way if you have not accepted cookies; if you have, it loads when you scroll to it. Our Cookie Policy sets out each case.
For the full list of cookies, their purposes, and how long they last, see our Cookie Policy.
Sub-processors and Sharing
We use a limited set of vendors to run the Services. Each one is bound by a written contract with confidentiality and data protection obligations that are at least as protective as our own.
- Google LLC (Google Cloud Platform, Firebase, BigQuery) — Hosting, database, cache, logging, analytics. Location: United States.
- Google LLC (Gemini API) — AI answer generation. Location: United States.
- OpenAI, L.L.C. — Content moderation, embeddings. Location: United States.
- Anthropic PBC (Claude API) — AI answer generation for the product demo on chatty.net, and building the store knowledge memory. Location: United States.
- Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (DeepSeek API) — AI answer generation for selected stores, and building the store knowledge memory. Location: China.
- Amazon Web Services, Inc. (S3, CloudFront, SES) — File storage, CDN, transactional email. Location: United States.
- Cloudflare, Inc. — Real-time chat delivery, CDN. Location: Global edge network, data stored in the United States.
- Meili SAS (Meilisearch Cloud) — Search index. Location: United States.
- Peaberry Software, Inc. (Customer.io) — Lifecycle email to merchant staff; no end-customer data. Location: United States.
- Slack Technologies, LLC — Internal operational notifications for our support team. Location: United States.
A further set of vendors receives data from visitors to this website and from merchant staff who contact our support, but never end-customer data we process on a merchant’s behalf, so they are not sub-processors under our Data Processing Agreement. Crisp IM SAS is in France; Cal.com, Inc., Arcade Software, Inc. and Meta Platforms, Inc. are in the United States, each under its own data processing terms. Google LLC also appears here in a second, separate role: it hosts the embedded customer videos on our homepage. Google LLC is a sub-processor for the merchant services listed above, but the video embed is a website function only and carries no end-customer data. Cloudflare, Inc. appears here in the same way: it is a sub-processor for the merchant services listed above, and it separately sits in front of this website, where it sees only visitor data. Crisp IM SAS runs the support chat on chatty.net. It receives the messages you send through the widget and, if you have accepted cookies and then submit a form on this website, your name, email address and store URL, so our team recognises you if you open a chat later. Cal.com, Inc. handles demo scheduling and receives the booking details you submit on our demo request page. Arcade Software, Inc. hosts the interactive product demo on our homepage and sees your IP address once that demo loads. Google LLC receives your usage and device data through Google Analytics 4 and Google Tag Manager. Meta Platforms, Inc. receives, through the Meta Pixel, the pages you open on this website, the fact that you clicked through to our Shopify App Store listing, your IP address, and the identifiers described in our Cookie Policy. Meta acts as an independent controller for that data and may use it to show you our ads on its own services. Neither Google nor Meta receives anything from you before you accept, if you are in the European Economic Area, the United Kingdom, Switzerland, Brazil, or California; elsewhere both load with the page and stop as soon as you reject them. Google LLC also hosts the infrastructure behind the live Chatty demo on this website: if you start that demo, the messages you type and your session identifier reach Google Cloud and Firebase in the United States, the same platforms described in our sub-processor list. Impact Tech, Inc.runs the tracking link behind our “Try app free” button: pressing it sends you through impact.com to the Shopify App Store, and Impact sees your IP address and the page you came from so Shopify can attribute the install. Nothing is set until you press the button. What we use on our side is the aggregate install count Impact reports back to us; we do not use it to identify or contact individual visitors. Our legal basis is our legitimate interest under Article 6(1)(f) in knowing which installs came from this website. Cloudflare, Inc. sits in front of this website, so it sees your IP address on every visit, and runs the Turnstile anti-bot check once you interact with one of our forms. Both set the cookies listed in our Cookie Policy and are strictly necessary to keep the site available.
When you submit a form on this website — a newsletter signup, an enterprise enquiry, or a demo request — the details normally go to our own form and CRM system operated by AVADA GROUP at crm-form.avada.io. The one exception is a booking made on our demo request page, which goes to Cal.com.
Before we add or replace a sub-processor, we give merchants at least 30 days’ written notice. Merchants may object on reasonable grounds relating to data protection. The current list is maintained at chatty.net/sub-processors.
Shopify is not a sub-processor of Chatty.Shopify is the merchant’s own platform and billing provider, and the merchant’s relationship with Shopify is governed by Shopify’s terms and privacy policy.
We may also disclose personal data when we are required to do so by applicable law, court order, or a valid request from a public authority, and where we are legally permitted we will tell the affected merchant first. If Chatty is involved in a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the acquiring entity, which remains bound by this policy or a policy offering equivalent protection. We will notify merchants before their data becomes subject to a different policy.
AI Processing
Chatty generates answers using the Google Gemini API and uses OpenAI for content moderation and embeddings. Anthropic answers in the product demo on this website and helps build the store knowledge memory. DeepSeek generates answers for selected stores and also helps build the store knowledge memory. To generate an answer, the relevant conversation content and the merchant’s configured knowledge sources are sent to the provider handling that store over an encrypted connection. Google, OpenAI and Anthropic process this data in the United States; DeepSeek processes it in China.
Under the API terms of Google and OpenAI, data submitted through the API is not used to train their models. We have not verified an equivalent term for Anthropic or DeepSeek and will not claim one until we can produce it on request. Merchants who want no processing outside the United States, or off the DeepSeek route, can write to [email protected]. Chatty is a limited-risk AI system under Regulation (EU) 2024/1689 (the EU AI Act), not a high-risk system. Under Article 50(1) the duty to make clear that an AI is answering falls on us as the provider of the system, and the widget does not yet carry a built-in notice — our AI compliance page explains what a merchant has to put in place.
For details on how we meet AI transparency and governance obligations, see our AI compliance page.
International Data Transfers
Every server and store that holds your data is located in the United States. Our database, application runtime, file storage, transactional email, analytics, backups, and search index all run in United States regions, and real-time chat delivery runs on a global edge network with the data itself stored in the United States. Our personnel in Vietnam access those systems remotely to operate and support the Services. No customer data is stored in Vietnam. The one vendor in the list above that processes outside the United States is the DeepSeek API, which generates answers for selected stores in China.
For personal data transferred out of the European Economic Area to the United States, we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, using Module Two (controller to processor) and Module Three (processor to processor) as applicable, together with a transfer impact assessment and supplementary technical measures.
The transfer to China is the exception. Those clauses cover the route to the United States. They do not cover the transfer to the DeepSeek API in China, and we are not going to name a mechanism we cannot produce on request. We are settling that paperwork now and will publish it on our sub-processors page, with the date, as soon as it is signed. Merchants who do not want any processing outside the United States can write to [email protected] and we will keep their store off that routing.
For transfers from the United Kingdom, we rely on the same clauses as supplemented by the UK International Data Transfer Addendum, version B.1.0, in force since 21 March 2022. For transfers from Switzerland, we apply the Standard Contractual Clauses with the adaptations required by the Swiss Federal Act on Data Protection, with the Federal Data Protection and Information Commissioner (FDPIC) as the competent authority.
These contractual clauses are the only transfer mechanism we rely on. We are not certified under, and do not claim the benefit of, any self-certification scheme for transfers to the United States. Those schemes are open only to organisations established in the United States, and Chatty is a Vietnamese company.
Getting a copy.Anyone — visitor, merchant, or a customer of a merchant — can request a copy of the clauses we rely on by emailing [email protected]. We send the executed clauses with commercial terms redacted, along with our transfer impact assessment on request.
Data Retention
- Order data synced from a store is kept for as long as it is needed to answer order and shipping questions for that store. It is deleted when the merchant asks us to delete it, on the same timetable as any other written deletion request.
- Conversations deleted by a merchant are removed from production immediately and kept in a recovery store for three months so an accidental deletion can be undone, then deleted permanently and automatically.
- Conversations in active useare retained for as long as the merchant keeps using the Services. They are not deleted on a timer. A merchant’s plan may limit how far back they can browse their own history; that is a limit on what the plan displays, not a shorter retention period.
- Written deletion or return requests are completed within 30 days and confirmed in writing.
- Backups — data removed from production is purged from the backup change history within 30 days.
- Accounting and invoicing records are kept for the period required by Vietnamese accounting law. These records contain merchant business details and amounts only, never end-customer data.
- Website analytics data— the usage and technical data Google Analytics 4 collects — after you accept analytics cookies where we ask first, or from the first page view everywhere else — is retained for 14 months in Analytics, after which event-level records are deleted and only aggregated reports remain. The cookies themselves expire after two years, or sooner if you withdraw consent, which deletes them.
- Website enquiries and support conversations — the data you send us through a form on chatty.net, or through the chat widget on this website, is kept for 24 monthsafter our last contact with you, then deleted. The same 24-month period applies to support correspondence with merchants — tickets, emails and chat threads about the Services — measured from our last contact. This is data for which we are the controller. You can ask us to delete it sooner at any time.
- Merchant account data and product usage data — the account, store and settings records that make the Services work, and the usage and error events from the Chatty admin, are kept for as long as the account is open. They are deleted when the account is deleted, on the 30-day and three-month schedule set out above. We do not keep them on a separate timer.
Security
- Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256 at the storage layer provided by Google Cloud and AWS.
- Merchant authentication uses Shopify OAuth and Firebase Authentication. We never hold merchant passwords.
- Production access is controlled through Google Cloud IAM on a least-privilege basis.
- Every administrative action is written to Google Cloud Audit Logs, which cannot be disabled or deleted.
- Merchant data is segregated by store identifier so one store cannot read another store’s data.
- We notify affected merchants of a personal data breach within 72 hours of becoming aware of it, with the facts known at that time and our remediation steps.
To be explicit about what we do not have: Chatty does not hold SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27701, or PCI DSS certification. We describe the controls we actually operate and make no claim to any certification or third-party attestation. Because we neither collect nor store payment card data, PCI DSS is outside the scope of our systems.
No system is perfectly secure. We use appropriate technical and organisational measures, but we cannot guarantee that data will never be accessed or disclosed in breach of those measures.
Your Rights
Where the GDPR or UK GDPR applies, you have the following rights in relation to your personal data:
- Access (Article 15) — obtain confirmation of whether we process your data and get a copy of it.
- Rectification (Article 16) — have inaccurate or incomplete data corrected.
- Erasure (Article 17) — have your data deleted where the conditions are met.
- Restriction (Article 18) — have processing limited while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20) — receive data you provided in a structured, commonly used, machine-readable format.
- Objection (Article 21) — object to processing based on legitimate interests, and object to direct marketing at any time.
- Not to be subject to a decision based solely on automated processing (Article 22), including profiling, that produces legal or similarly significant effects.
- Withdraw consent (Article 7(3)) at any time, without affecting processing carried out before withdrawal.
To exercise any of these rights, email [email protected]. We respond within one month. We may need to verify your identity before acting, and we may extend the deadline where the law allows, in which case we will tell you why. To delete a Chatty account and the data held in it, follow the steps on our account deletion page.
Your right to object (Article 21). You have the right to object at any time, on grounds relating to your particular situation, to any processing we carry out on the basis of our legitimate interests. Where you object to processing for direct marketing, including any profiling connected to it, we stop that processing immediately and without needing a reason from you. Email [email protected] to object; you can also unsubscribe from any marketing email using the link in the email itself.
If you are a customer of a merchant that uses Chatty and you send your request to us, we will forward it to that merchant without undue delay and support them in responding. The merchant is the controller and decides how to answer.
We do not make decisions about you by automated means alone. The AI assistant drafts and sends answers, but it produces no decision with a legal or similarly significant effect on anyone, so Article 22 of the GDPR does not apply. A merchant’s staff can take over any conversation at any point.
You also have the right to lodge a complaint with a supervisory authority (Article 77). In the European Union this is the authority in the Member State where you live, work, or where the alleged infringement occurred; where no such authority can be identified, you may address the Data Protection Commission of Ireland. In the United Kingdom it is the Information Commissioner’s Office (ICO). In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC).
California Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the following rights:
- Right to know what personal information we collect, the sources, the purposes, and the categories of recipients.
- Right to delete personal information we hold about you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information.
- Right to limit the use and disclosure of sensitive personal information.
- Right to non-discrimination for exercising any of these rights.
- Right to use an authorized agent to submit a request on your behalf, with proof of authorisation.
The categories below use the statutory labels in section 1798.140(v) of the California Civil Code. For each one we collect it from you directly, from Shopify, or from your browser, and we disclose it to the service providers named in this policy for a business purpose. We have not sold any category in the last twelve months. We do share two categories — identifiers and internet activity — with Meta through the Meta Pixel on this website, which counts as sharing for cross-context behavioural advertising under the CPRA; the detail is set out further down this section. We do not collect sensitive personal information as that term is defined by the CCPA. We keep each category for the period set out in Data Retention above: website enquiries and support correspondence for 24 months after our last contact; account and usage data for as long as the account is open, then deleted on the schedule described there; and billing records for as long as Vietnamese accounting law requires.
- Identifiers— name, email address, store URL and domain, IP address, account and session identifiers.
- Customer records— phone number and billing records where you give them.
- Commercial information— subscription plan, billing amounts, and order data synced from a store.
- Internet or network activity— pages viewed, referring URL, browser and device type, and how features are used in the Chatty admin.
- Geolocation data— approximate location inferred from an IP address, at city level, nothing finer.
- Audio, electronic, visual, thermal, olfactory, or similar information — the content of chat messages and support correspondence you send us.
- Inferences— none. We do not build profiles about individuals.
Chatty does not sell personal information. We do share personal information for cross-context behavioural advertising, as the CCPA defines that term: the Meta Pixel on this website passes online identifiers and browsing activity to Meta Platforms, Inc., which may use them to show you our ads. That is the only such sharing we do, the categories involved are identifiers and internet activity. In California the pixel is held back until you accept, so for a California resident it does not happen unless you say yes; outside the regions where we ask first, the pixel loads with the page until you reject it. We honour the Global Privacy Control signal sent by your browser as a valid opt-out request. To exercise a California right, email [email protected]. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days where the request is complex, in which case we tell you why before the first period runs out.
Vietnam Personal Data Protection
As a company established in Vietnam, we process personal data in accordance with the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, both effective 1 January 2026. This includes obligations on notice, consent, records of processing, impact assessment for cross-border transfers, and breach notification. Requests under Vietnamese law go to the same address: [email protected].
Children
Chatty is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If we learn that we hold personal data collected from a child under 16, we delete it. If you believe a child has provided us with personal data, contact [email protected] and we will investigate.
Data Processing Agreement
Any merchant can request a countersigned Data Processing Agreement, wherever you are based, by emailing [email protected].
The DPA is built on Article 28 of the GDPR and incorporates the Standard Contractual Clauses and the UK Addendum for international transfers. It has been in effect since 1 January 2026 and covers processing instructions, confidentiality, security measures, sub-processor terms, assistance with data subject requests, breach notification, and deletion or return of data at the end of the contract.
Changes to This Policy
We update this policy when our practices, our vendors, or the law change. The date at the top of the page always shows when the current version took effect. For material changes that affect how we handle personal data, we notify merchants by email or in the app before the change takes effect. Continued use of the Services after a change takes effect means the updated policy applies.
Contact
AVADA GROUP COMPANY LIMITED (CÔNG TY TNHH AVADA GROUP)
Business Registration No. 0109524114
102 Tran Phu, Ha Dong, Hanoi, Vietnam
For any question or request about personal data, email [email protected]. This is the correct address for access, deletion, DPA, and security enquiries.
We have not yet appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR. The appointment is in progress, and we will publish the representative’s name and address on this page once it is complete. Until then, please contact us directly at the address above.
We have not appointed a Data Protection Officer under Article 37 of the GDPR. We are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring of individuals, and we do not process special categories of data on a large scale, so the appointment is not required. Privacy enquiries are handled by our privacy team at the address above.


