01The short version#
Backpilot processes two kinds of data: data about merchants who connect their stores (we decide how — we are the controller), and data belonging to those stores’ shoppers who talk to the assistant (the store decides — the store is the controller and we process on its behalf). We don’t run ads, don’t sell data, don’t track anyone across the web, and never see payment card details — checkout happens on the store itself. The “Backpilot for WooCommerce” sections describe that product’s data flows; the general sections cover the website and everything we do.
Backpilot for WooCommerce
02Merchants (we are the controller)#
When you connect a store we process:
- your store’s URL;
- the administrator email you connect with;
- your WordPress, WooCommerce and Backpilot plugin versions;
- your store’s product catalog (products, categories, prices, images — the data the assistant answers from);
- your plan, and how many conversations your store used each month;
- any correspondence with us.
Legal basis: performing our agreement with you, and our legitimate interest in operating and improving the service.
03Shoppers (the store is the controller; we are its processor)#
When a shopper talks to the assistant we process on the store’s behalf:
- the conversation messages;
- a session identifier;
- the shopper’s cart contents on that store;
- the page they opened the assistant from;
- their language;
- their browser’s user-agent string.
We do not ask shoppers for their identity, and the assistant does not need it. We never receive payment details. Shoppers who want to exercise data rights should contact the store they were shopping at; we assist the store in answering.
04AI processing#
Conversations are answered by large language models reached through our inference gateway (OpenRouter, Inc.), which routes to model providers such as Google. Conversation content is used to generate the answer. We do not use it to train models, and our providers’ API terms do not permit them to use it to train theirs; providers may retain content for a limited period for abuse and reliability monitoring under those terms.
05Retention#
Chat sessions expire automatically. Catalog and conversation data are retained while your store is connected so the assistant can work and so we can bill honestly (monthly conversation counts are our billing records). When you disconnect, we stop processing, and we delete your store’s catalog and conversation data within 90 days. Want it gone sooner? Write to [email protected] and we will confirm when it’s done. Monthly usage totals may be kept longer as billing records.
06Payments#
Paid plans are purchased through a merchant of record — a third-party reseller that is the seller on your invoice. When you buy or manage a plan, the merchant of record processes your checkout and billing data — including the payment details we never see — as an independent controller under its own privacy policy, linked at checkout, not as our subprocessor. Checkout and invoice pages are served by the merchant of record and use its own cookies for checkout and fraud prevention.
From the merchant of record we receive what we need to run your subscription: its status, your plan, your billing country, and the email used at checkout.
General
08Where data lives#
Our systems run in the European Union (hosting: DigitalOcean, Amsterdam; edge/CDN: Cloudflare; operational telemetry: SigNoz Cloud, EU; website analytics: Umami Cloud, EU). Some providers are outside the EU: conversation content is sent to our AI gateway and model providers in the United States to generate each answer (see AI processing for what they may retain), and we access our systems from outside the EU for operations and maintenance. Where personal data leaves the EEA we rely on the EU Standard Contractual Clauses or the provider’s EU–US Data Privacy Framework certification, as applicable.
09Your rights#
If you’re in the EU/EEA or a similar jurisdiction you can ask us for access, correction, deletion, restriction, or a copy of your data, and you can complain to your supervisory authority.
Merchants: write to [email protected]. Shoppers: start with the store you visited (it is the controller); we help it respond.
10Subprocessors#
| Subprocessor | What it does |
|---|---|
| DigitalOcean | Hosting (EU) |
| Cloudflare | Edge / CDN |
| OpenRouter, Inc. | AI inference gateway |
| AI model providers (routed via OpenRouter) | AI inference — e.g. Google |
| SigNoz | Operational telemetry (EU) |
| Umami Software, Inc. | Website analytics (EU; cookieless, aggregate only) |
| Google Workspace |
We’ll update this list here as it changes.
11Who we are#
Backpilot is operated by Nikulin O.S., an individual entrepreneur registered in Ukraine. Contact for anything in this policy: [email protected].
12Changes#
Updates appear on this page with a new date; material changes to connected stores are announced by email.