Salesreach

Privacy Policy

Effective August 28, 2026

This Privacy Policy explains how Revotech OÜ (registry code 17332344, Estonia), doing business as "Salesreach" ("we", "us"), collects, uses, and protects data when a Shopify merchant ("Merchant", "you") installs the Salesreach app, and when Salesreach's AI sales agent communicates with a Merchant's customers ("Customers") on the Merchant's behalf.

For data about Customers, the Merchant is the data controller and Salesreach acts as the Merchant's data processor / service provider, under the instructions given through the app's settings. For data about the Merchant's own account, Salesreach is the data controller.

1. Data we collect

From your Shopify store

When you install Salesreach, Shopify grants us access to the following Admin API scopes, which we use only to power the features below:

ScopeWhat it's used for
read_customersCustomer name, email, phone, order count, lifetime spend, tags, address — to personalize outreach, route the right persona, and match a paid order to the agent conversation that produced it.
read_ordersOrder totals, line items, discount codes used, order notes, and the order's contact and shipping phone — to recognise orders placed through the agent's checkout links, codes or carts and attribute that revenue. Abandoned checkouts (items, checkout link, the customer's phone and SMS consent) — to send one recovery message and confirm the checkout is still unfinished before sending. Phone numbers are compared when the order arrives and are not stored with the attribution record.
read_products, read_inventoryProduct titles and availability — to generate accurate cross-sell suggestions.
read_fulfillmentsShipment delivery status — to time optional post-delivery check-in and refill reminders from when an order actually arrives.
write_discountsTo create and track the single-use discount codes the agent offers Customers.

Conversation data

Message transcripts between the Salesreach AI agent and a Customer (SMS and WhatsApp), the Customer's phone number, and metadata about the conversation (channel, journey stage, persona used).

Merchant account data

Your Shopify store domain, the settings you configure in the app (discount limits, persona selection, flow plans), and your Shopify Admin API access token, which we store to make authorized calls to your store on your behalf.

Technical data

IP addresses and request logs for our internal admin tools, used only for access control and abuse prevention.

2. How we use data

We do not sell personal data, and we do not use Customer data for advertising.

3. Who we share data with

We share data with the following sub-processors, solely to provide the service described above:

ProviderPurpose
ShopifyThe commerce platform this app is built on top of.
MongoDB AtlasDatabase hosting for conversations, store settings, and discount records.
TwilioDelivers outbound SMS and WhatsApp messages and receives Customer replies; processes the Customer's phone number and message content.
OpenRouterRoutes conversation text to the AI model that drafts the agent's reply (models from providers including xAI, Google, OpenAI, and Alibaba/Qwen, depending on configuration).
ElevenLabsGenerates synthesized voice-note audio for stores using that feature, from message script text.
Our infrastructure/hosting providersApplication hosting and caching.

We may also disclose data if required by law, or to protect the rights, property, or safety of Salesreach, our Merchants, or others.

4. Data retention

5. Your rights

Depending on where you or your Customers are located, applicable law (including the EU/UK GDPR) may give individuals the right to access, correct, delete, restrict, or receive a copy of their personal data, and to object to certain processing.

For Customers, these requests should go through Shopify's standard privacy tooling for your store; we fulfill the corresponding customers/data_request and customers/redact webhooks Shopify sends us within the required window. Merchants or Customers can also reach us directly at support@salesreach.net.

6. International data transfers

Revotech OÜ is based in Estonia (EU). Some of our sub-processors listed above operate in the United States or other countries outside the EEA. Where that's the case, we rely on those providers' own data-protection commitments (such as Standard Contractual Clauses) to safeguard the transfer.

7. Security

Webhooks from Shopify are verified with HMAC signatures, all traffic is encrypted in transit (HTTPS/TLS), our internal admin tools are access-restricted and access-logged, and Shopify access tokens are never exposed to a Merchant's or Customer's browser. See our Security & Incident Response page for full detail, including our data breach notification process.

8. Children's privacy

Salesreach is a business tool for Shopify Merchants and is not directed at, or knowingly used to collect data from, children.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by a new effective date at the top of this page.

10. Contact us

Revotech OÜ, registry code 17332344, Estonia.
Email: support@salesreach.net