Legal Document

Privacy Policy

How we collect, use, and protect your information

Last updated: September 22, 2025

Introduction

Kandid ("we," "our," or "us") provides AI-powered customer support and engagement solutions ("the Service") to merchants who use Shopify to power their stores. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with your Shopify-supported store.

Personal Information the App Collects

Information from Shopify Account

When you install the App, we are automatically able to access certain types of information from your Shopify account: read access to products, customers, orders, script tags, shipping, discounts, collections, blogs, themes, pages, pixels, and customer events.

Merchant Information

Information about you and others who may access the App on behalf of your store, such as your name, address, email address, phone number, and billing information.

Customer Information

Information about individuals who visit your store, such as their IP address, web browser details, time zone, and information about the cookies installed on the particular device.

Technical Information

We collect personal information directly from the relevant individual, through your Shopify account, or using technologies such as cookies, log files, web beacons, tags, and pixels to track actions and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.

How Do We Use Your Personal Information?

Service Provision

We use the personal information we collect from you and your customers in order to provide the Service and to operate the App.

Communication

To communicate with you about the App, send you important service updates, security alerts, and respond to your inquiries via email.

Optimization

To optimize or improve the App and enhance user experience.

Marketing

To provide you with information or advertising relating to our products or services.

Sharing Your Personal Information

Service Providers

We share information with trusted third-party service providers who help us operate our service, including payment processors, email services, and analytics providers.

Legal Compliance

We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

Behavioral Advertising

Targeted Advertising

We use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative's ("NAI") educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

Opt-Out Options

You can opt out of targeted advertising by visiting the Digital Advertising Alliance's opt-out portal at: http://optout.aboutads.info/.

Data Security

Encryption

We use industry-standard encryption to protect your data both in transit and at rest.

Access Controls

We implement strict access controls and authentication mechanisms to protect your account and data.

Regular Security Reviews

We regularly review and update our security practices to protect against unauthorized access and data breaches.

Incident Response

We have procedures in place to detect, respond to, and notify users of any security incidents that may affect their data.

Your Rights

European Residents

If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.

Data Processing

If you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above.

International Transfers

Please note that your information will be transferred outside of Europe, including to Canada and the United States.

Data Retention

Order Information

When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.

Account Data

We retain your information for as long as your account is active or as needed to provide our services and comply with legal obligations.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Changes

We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.