Privacy Policy

Effective date: August 19, 2026

Last updated: September 1, 2026

This Privacy Policy describes how Egissystems, Inc. (“Tracklepop,” “we,” “us”) collects, uses, stores, and discloses information in connection with the Tracklepop app (“App”), a Shopify-integrated AI customer support tool.

If you do not agree with this Privacy Policy, please do not install or use the App. This Privacy Policy is incorporated into and should be read together with our Terms of Service. We may periodically update it; material changes will be reflected by an updated “Last updated” date, and where the change requires your renewed consent to keep processing your data, we will request that consent directly (see §11).

1. Scope and roles

Tracklepop is installed by Shopify merchants (“Merchant,” “you,” if you’re the store owner) to provide AI-assisted customer support. In the course of providing that service, Tracklepop processes:

  • Merchant account data — information about your store and staff who use the Tracklepop dashboard.
  • End-customer data — information about your shop’s customers (the people who email or message your store for support), which Shopify and you provide to Tracklepop so the App can answer their questions.

For end-customer data, the Merchant is the data controller and Tracklepop is the data processor / service provider, acting only on the Merchant’s instructions and for the purpose of providing the App. This policy explains our processing of both categories.

For Merchant account data, Egissystems, Inc. acts as the Personal Information Controller under the Philippine Data Privacy Act of 2012, processing the data to establish and administer your account and deliver the App under our Terms of Service with you.

2. Information we collect

From Shopify, when you install the App:

Data Purpose
Shop domain, OAuth access token Authenticate API calls to your store. Access/refresh tokens are encrypted at rest using industry-standard encryption, with key-rotation support.
Order data (order ID, line items, status) Ground AI replies about order status. Retained on a rolling 60-day window only — older snapshots are not kept.
Fulfillment/tracking data (tracking number, carrier, status) Answer shipment-status questions.
Customer records (name, email, order history) Identify the person contacting support and personalize the reply.
Store policies (refund/shipping/privacy policy text, Online Store pages/FAQ as fallback) So AI answers quote your actual store policies instead of guessing.

We only process the data categories the App’s functionality actually requires. Where Shopify’s API grants us potential access to a broader scope than the App needs to function, we do not process, store, or use the unused portion.

From your customers, when they contact support:
  • The content of their messages/emails to your support channel.
  • Any information they volunteer in those messages.
Automatically:
  • Application error and performance data via Sentry, when configured.
  • Log and usage data (IP address, browser type, device information, request timestamps, feature usage, error reports) to operate and troubleshoot the App.

3. Cookies and similar technologies

We do not use browser cookies for tracking. Dashboard authentication uses bearer tokens (JWT), not session cookies. We use only the minimum functional storage necessary for the App to work, and no marketing, advertising, or third-party analytics cookies.

4. How we use information

  • To generate AI-drafted responses to customer support inquiries, grounded in your real order data, product/policy content, and conversation history.
  • To detect and flag potential fraud, abuse, or prompt-injection attempts against the AI system.
  • To maintain, secure, and improve the App.
  • To comply with legal obligations (e.g., GDPR/CCPA requests, described in §8).

We do not sell personal information, and we do not use customer support content for advertising or to train foundation models operated by third parties.

Legal basis for processing (Philippine Data Privacy Act)

For ordinary personal information, we process on the same contract-necessity basis under Section 12(b) of the Data Privacy Act of 2012 — processing necessary to perform our contract with the Merchant, or steps taken at a Merchant’s request prior to entering that contract.

Under Philippine Data Privacy law, where a customer volunteers sensitive personal information, we process that information only where the data subject has given specific consent and do not rely on contract necessity or legitimate interest as basis for processing sensitive personal information. We minimize our need to rely on consent by redacting or masking sensitive identifiers at the point we receive them, as described in Section 5 below.

5. AI processing and subprocessors

Tracklepop uses third-party AI providers to draft support responses:

  • OpenAI — primary provider, used for response drafting, content moderation, intent classification, and semantic search over your knowledge base.
  • Anthropic (Claude) — fallback provider only, used solely when OpenAI is unavailable, times out, or errors.

Before any customer text is sent to either provider, it is anonymized. We use an automated PII-scrubbing step that detects and redacts the following categories from customer messages, conversation history, and the assembled AI prompt at the point we receive them, and again prior to every external call: **names, email addresses, phone numbers, physical addresses, credit card numbers, IP addresses, and government ID numbers (e.g., SSNs)**. The redacted, anonymized text — not the original — is what OpenAI/Anthropic receive, and is also what we retain in our own systems; unredacted values are not stored. Real values are restored only afterward, locally, when producing the final draft shown to your support team; they are never sent back out to a third party.

A small number of purely local safety checks (prompt-injection detection, escalation-keyword matching, and security event logging) analyze the raw, un-redacted message at the moment it is received, but this analysis never leaves our servers, the raw message is not persisted beyond this check, and is never transmitted to OpenAI, Anthropic, or anyone else.

Other recipients of data:
Recipient Role Data they access
Shopify Platform / Billing API Shop, order, customer data as necessary for the App to operate
OpenAI AI response drafting (primary) Anonymized customer message text only (see above)
Anthropic AI response drafting (fallback) Anonymized customer message text only (see above)
Sentry Error tracking, when configured Application error/performance data
Railway Production hosting and infrastructure All stored data (encrypted at rest/in transit)

We may also disclose data to legal or regulatory authorities where required by law, subpoena, or court order, or to a successor entity in the event of a merger, acquisition, or sale of business assets, subject to standard confidentiality protections. We do not share Customer personal information with third parties for their own independent marketing purposes.

Our subcontracting of processing to the providers named above is authorized by, and subject to the data-processing terms of, our Terms of Service with each Merchant.

6. How we store and protect information

  • Encryption in transit: all connections to the App (webhooks, OAuth, API) use HTTPS/TLS.
  • Encryption at rest: Shopify OAuth tokens are encrypted before storage.
  • Tenant isolation: customer, conversation, and message data is stored in a multi-tenant database with strict access controls enforced at the database layer, so one store’s data cannot be accessed through another store’s request context, even in the event of an application-level bug.
  • Access control: production data access is limited to authorized personnel for support and engineering purposes.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Data retention and security incident notification

  • Order snapshots: capped at a rolling 60-day window; older order data is not retained.
  • Customer and conversation/message records: retained for the duration of the Merchant’s active use of the App, and, for any given conversation thread, for no longer than twenty-four (24) months from the last activity on that thread, and in all cases deleted or anonymized earlier (a) on receipt of a verified deletion request (see §8), or (b) if the Merchant uninstalls the App and a corresponding redaction request is processed. We periodically delete conversation/message records that exceed this retention period.
  • Billing records: retained as long as required for tax/accounting compliance, even after other data is deleted.

Security incident notification. If we become aware of a personal data breach involving sensitive personal information, or other information that could enable identity fraud, and we believe unauthorized acquisition has occurred that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and affected data subjects within seventy-two (72) hours of that determination, consistent with NPC Circular No. 16-03, and will notify the affected Merchant promptly so that the Merchant can meet its own notification obligations as data controller.

8. Your rights (GDPR / CCPA / Philippine DPA / similar laws)

If you are an end-customer of a Merchant using Tracklepop, requests about your personal data should generally go to the Merchant (the data controller), who can relay them to us, or directly to Shopify’s standard data-subject request flow, which we support via mandatory compliance webhooks:

  • Right to access: on request, we can provide the personal data we hold about a customer (name, email, account creation date, and a list/count of their support conversations — not full message contents).
  • Right to deletion/erasure: on request, we anonymize the customer’s name and email and redact the text of their messages. This is processed asynchronously and is idempotent (safe to request more than once).
  • Shop-level deletion: if a Merchant uninstalls the App and requests deletion, all data associated with that store — including its customers’ data — is deleted.

We will respond to requests without undue delay, and in any event within one month of receipt, unless the request’s complexity requires up to three months in total.

9. International data transfers

Our AI subprocessors (OpenAI, Anthropic) and our production hosting provider (Railway) may process data in the United States or other countries outside your country of residence. Our production environment is hosted in the **US West (California, USA)** region.

Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and equivalent safeguards for UK and Swiss transfers, as the legal mechanism for that transfer. Where a subprocessor’s data practices are not otherwise publicly documented, we agree with that subprocessor on the scope of data accessed and ensure it is processed only for the purpose for which it was engaged.

Egissystems, Inc. is a Philippine corporation, and personal data we process originates in significant part in the Philippines. For those transfers, we rely on contractual and organizational safeguards consistent with the Data Privacy Act of 2012 and its Implementing Rules, including the data sharing and processing agreements with OpenAI, Anthropic, and Railway addressing security measures, purpose limitation, and breach notification.

10. Children’s privacy

The App is a business tool used by Shopify merchants and is not directed at children. We do not knowingly collect or solicit data from, or direct personalized advertising to, anyone under the age of 13 (or under 16 in the European Economic Area), nor knowingly allow such individuals to use the App.

If you believe we may have inadvertently collected data from a child under the applicable age, please contact us so we can delete it promptly.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and, where required by law, we will provide additional notice or request renewed consent. Continued use of the App after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

12. Contact us

Questions about this policy or your data can be directed to:

Egissystems, Inc.
9F Uptown Bonifacio Tower 3, 36th St. cor. 11th Ave., Bonifacio Global City, Taguig City, Philippines 1634
legal@tracklepop.com