OrderSpike
Privacy policy
Last updated 9 September 2026
OrderSpike is a shopping assistant a merchant installs on their Shopify store. It answers shoppers from that store’s catalogue and reports which conversations led to sales. This page says exactly what it reads, what it keeps, and how to have that deleted.
Who we are
Eloquent Technologies FZCO is the data controller for the information described here. Reach us at privacy@orderspike.ai.
What the app reads from a store
Only what the assistant needs to answer and to attribute a sale. The app requests these Shopify permissions and no others:
| Products, inventory, listings | The catalogue the assistant recommends from, and live prices and stock so it never quotes a figure it has not just checked. |
|---|---|
| Orders | To tell a merchant which orders followed a conversation. See below for the narrow set of fields this keeps. |
| Metaobjects | Where the merchant’s widget settings are stored — in their own store, not ours. |
| Files | So a merchant can upload a logo for the assistant into their own Shopify Files. |
What we store about shoppers
No names, email addresses, phone numbers or postal addresses.The app holds Shopify’s protected customer data access at level 1 with no optional customer fields selected, and does not read or retain those fields.
- Conversations.What a shopper typed and what the assistant answered, with an identifier the widget generates in the shopper’s own browser. This is not linked to a Shopify customer account.
- Cart and order attribution.A cart token, an order id, an order number, the order total and currency, Shopify’s numeric customer id, and the product lines. This exists to answer “did that conversation lead to a sale?” and nothing else.
- Interaction events. Which products were viewed, added to a cart, and ordered, and when.
The assistant’s answers are generated by a large-language-model provider under a contract that forbids training on the content sent to it. Message content is sent to that provider to produce a reply and for no other purpose.
What we store about merchants
The store domain, the widget settings the merchant chooses, and the access credential Shopify issues at install. The credential is encrypted at rest and is used only to read that store’s own catalogue and orders.
How long we keep it
| Webhook delivery records | 30 days |
|---|---|
| Cart attribution sessions | 37 days |
| Conversations and analytics | 24 months, then deleted |
| Catalogue copy and credential | Deleted when the app is uninstalled |
Uninstalling, and deletion
Uninstalling the app revokes our access immediately. Shopify then sends us a shop redaction request, and we delete the store’s credential and its catalogue copy.
We answer Shopify’s customers/data_request, customers/redact and shop/redact webhooks. A merchant or a shopper can also write to privacy@orderspike.ai and we will confirm within 30 days.
Who else sees it
Our hosting provider, our database and analytics infrastructure, and the language-model provider that generates replies. We do not sell data, and we do not share it for advertising.
Where it is held
On servers in the European Union. Where data is transferred outside it, that transfer is covered by standard contractual clauses.
Your rights
Access, correction, deletion, export and objection, under the GDPR and equivalent laws. Write to privacy@orderspike.ai.
Changes
If this policy changes materially, the date above changes with it and merchants using the app are told before the change takes effect.