Privacy Policy

Last updated:

Evolvoom, Inc. ("we," "us," "our," or "Company") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered conversational retention platform for e-commerce brands ("Service").

1. Introduction

By installing our Shopify app, creating an account on our website, or otherwise using the Service, you agree to the terms of this Privacy Policy.

Company Information: Evolvoom, Inc. 1111b South Governors Avenue, Ste 34868 Dover, Delaware 19904 Email: hello@evolvoom.io

2. How You Access Our Service

Our Service is available through two channels, each with distinct billing arrangements.

2.1 Shopify App Store Installation

If you install Evolvoom directly from the Shopify App Store:

  • Your subscription and billing are managed entirely through Shopify's billing system, in accordance with Shopify's Terms of Service.

  • A 30-day free trial is available upon installation. Your Shopify account will not be charged until the free trial period ends.

  • After the trial, your subscription renews monthly and charges are applied to your Shopify billing account.

  • Evolvoom does not collect, process, or store your payment information — Shopify handles all payment data on our behalf.

  • Cancellations are managed through your Shopify admin or by uninstalling the app.

2.2 Direct Website Signup (evolvoom.io)

If you create an account directly through our website:

  • Billing and payment processing are handled by Stripe, our third-party payment processor.

  • A 30-day free trial may be offered at signup, after which your subscription renews monthly.

  • You authorize us to charge your Stripe payment method on file for: (a) the monthly subscription fee, and (b) any credit top-ups or usage overages accrued during the billing period.

  • Evolvoom does not store your full credit card number, CVV, or banking details. Stripe stores and processes all payment data under PCI-DSS compliance.

  • Cancellations can be managed through your account dashboard or by contacting hello@evolvoom.io.

3. Free Trial

We offer a 30-day free trial for new accounts regardless of signup channel.

  • No charges are applied during the free trial period.

  • Shopify installs: Shopify requires a valid payment method as part of the app installation process; it will not be charged until day 31.

  • Website signups: A payment method may be required at signup to activate your trial; it will not be charged until the trial period ends.

  • You may cancel at any time during the trial at no cost.

  • If you do not cancel before the trial ends, your subscription will automatically convert to a paid plan and your payment method will be charged.

  • Trial abuse (e.g., creating multiple accounts to extend free access) may result in account suspension.

4. Information We Collect

4.1 Personal Information You Provide

  • Account Information: Name and email address when you register

  • Contact Information: Information you provide when contacting customer support

4.2 Shopify Store Data (via Shopify API)

When you connect your Shopify store, we access and process the following data through Shopify's API:

  • Customer Data: Customer information from your store (read/write access)

  • Order Data: Order history, transaction details, and purchase information (read/write access)

  • Product Data: Product catalog and inventory information (read/write access)

  • Abandoned Checkouts: Incomplete purchase data for recovery campaigns

  • Inventory Data: Stock levels and inventory management (read/write access)

  • Discount & Pricing: Discount codes and price rules (read/write access)

  • Gift Cards: Gift card information

  • Store Settings: General store configuration

  • Fulfillment Data: Order fulfillment information

We access only the Shopify data scopes necessary to operate the Service. We do not access your Shopify billing or payment account data.

4.3 Usage and Analytics Data

  • Customer behavior patterns within your store

  • Campaign performance metrics

  • System usage data for service improvement

4.4 Payment Information

Shopify installs: We do NOT collect, store, or access your payment information. All billing is processed by Shopify.

Website signups: We do NOT store your full credit card number, CVV, or banking details. All payment data is handled by Stripe under PCI-DSS standards.

4.5 Legal Basis for Processing (GDPR)

We process personal data under the following lawful bases:

  • Consent (Article 6(1)(a)) — for marketing communications, analytics, and optional features

  • Contractual necessity (Article 6(1)(b)) — to perform obligations under your subscription or free trial

  • Legitimate interests (Article 6(1)(f)) — for fraud prevention, security, product improvement, and support

  • Legal obligations (Article 6(1)(c)) — to comply with tax, accounting, or regulatory requirements

Where processing relies on consent, we maintain records of consent (timestamp, method, and source) and provide clear mechanisms to withdraw consent at any time.

5. How We Use Your Information

  • Provide and operate our AI-powered conversational retention services

  • Initiate personalized, human-like SMS conversations with existing customers about their recent orders and experiences

  • Offer product recommendations or loyalty incentives based on prior interactions or purchases

  • Analyze customer behavior for retention and satisfaction insights

  • Provide customer support and technical assistance

  • Improve and optimize our platform and AI models

  • Process billing and manage your subscription (via Shopify or Stripe as applicable)

  • Send transactional and service-related communications

  • Comply with legal and contractual obligations

We do not use customer data for cold outreach, third-party promotions, or unrelated marketing. All communication originates from existing customer relationships or verified opt-ins.

6. Data Storage and Security

6.1 Data Isolation

Each merchant's data is logically isolated within our platform. We use industry-standard encryption in transit (TLS 1.2+) and at rest.

6.2 Opt-Out and Preferences

Our AI handles opt-outs conversationally. If an end customer indicates they no longer want messages, the AI immediately stops outreach and records the opt-out event within the merchant's account. Keywords including STOP, UNSUBSCRIBE, CANCEL, QUIT, and END are recognized automatically.

6.3 Messaging Frequency and Relevance

Messages are occasional, contextual, and limited to relevant post-purchase or loyalty follow-ups. Customers will not receive mass or generic SMS campaigns through our platform.

7. Usage-Based Billing and Credits

7.1 Subscription Plans

  • Starter — $24.99/month: 2,500 credits included per billing cycle

  • Growth — $124.99/month: 12,500 credits included per billing cycle

  • Enterprise — Contact sales for custom pricing and credit limits

Subscriptions renew monthly until canceled. Your first billing date begins after the 30-day free trial ends.

7.2 Credits and Metering

  • 1 credit = $0.01

  • Credits are consumed by platform actions (e.g., SMS segments, emails sent, AI messages) per the metering rules shown in your dashboard

  • Unused credits do not carry over unless expressly stated in your account settings

7.3 Top-Ups and Overages

  • Additional credits can be purchased in packs of 1,000 / 2,500 / 5,000 at any time

  • Top-ups are applied immediately; charges are aggregated and billed at the end of your 30-day cycle

  • Auto top-up can be enabled to maintain continuity when your credit balance falls below a set threshold

7.4 Billing by Access Channel

Shopify installs: All subscription charges, top-ups, and overages are billed through Shopify's billing system and appear on your Shopify invoice.

Website signups: All charges are processed by Stripe and billed to the payment method on file. You may update your payment method at any time through your account dashboard.

8. Third-Party Service Providers

8.1 Billing Processors

  • Shopify Billing API — for merchants who install via the Shopify App Store

  • Stripe — for merchants who sign up directly via evolvoom.io

8.2 Communication Services

  • Twilio — SMS/text message delivery

  • Resend — Email delivery and automation

8.3 AI and Infrastructure

  • OpenAI — AI-powered conversational features

  • Supabase — Database and backend infrastructure

  • Vercel — Application hosting and delivery

8.4 Support

  • Intercom — Customer support chat

All vendors are bound by strict Data Processing Agreements (DPAs) compliant with GDPR, CCPA, and TCPA. We do not sell or share customer data for third-party advertising or marketing.

9. Data Retention

9.1 Active Subscribers

We retain your information as long as you maintain an active subscription.

9.2 After Cancellation or App Uninstall

Upon cancellation or uninstalling the Shopify app:

  • All customer and store data (including backups) is permanently deleted within 30 days unless retention is required by law

  • We retain only minimal billing and contact information for legal and tax compliance

  • You may request complete data deletion by contacting hello@evolvoom.io

  • Data in third-party systems (Stripe, Shopify, Twilio, OpenAI, Supabase) is deleted or anonymized per their respective DPAs

For Shopify uninstalls specifically: we honor Shopify's mandatory GDPR data deletion webhook and initiate deletion of all associated store data within 30 days of receiving the uninstall signal.

10. Your Rights and Choices

10.1 Access and Control

You have the right to:

  • Access your personal information

  • Update or correct your account information

  • Request data deletion

  • Opt out of marketing communications

  • Request a machine-readable copy (CSV/JSON) of your stored personal data

10.2 How to Exercise Your Rights

  • Account Settings: Update information directly through your dashboard

  • Email: Contact hello@evolvoom.io with subject line "Privacy Request"

  • All verified requests are handled within 30 days

10.3 GDPR Rights (EU/UK Users)

  • Right to data portability

  • Right to object to processing

  • Right to restrict processing

  • Right to erasure ("right to be forgotten")

  • Right to lodge a complaint with a supervisory authority

10.4 CCPA Rights (California Users)

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt out of sale of personal information (Note: We do not sell personal information)

  • Right to non-discrimination for exercising privacy rights

10.5 SMS/Chat Opt-Out

Evolvoom provides the technology infrastructure that allows merchants to communicate with their customers via conversational SMS. If an end customer indicates they no longer wish to receive messages, the AI immediately stops outreach and logs the opt-out. Keywords including STOP, UNSUBSCRIBE, CANCEL, QUIT, and END are recognized automatically.

Each merchant is responsible for maintaining proper consent and honoring customer opt-out preferences in accordance with applicable law and carrier regulations.

11. Data Sharing and Disclosure

11.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

11.2 Limited Sharing

We may share information only in these circumstances:

  • Service Providers: With third-party providers as described in Section 8

  • Shopify Platform: We share necessary data with Shopify to operate within their ecosystem, in compliance with Shopify's API terms and Partner Program Agreement

  • Legal Requirements: When required by law, court order, or legal process

  • Business Protection: To protect our rights, property, or safety

  • Business Transfers: In connection with a merger, acquisition, or sale of assets

12. International Data Transfers

Evolvoom processes data in the United States and other countries outside the EEA and UK. Safeguards include:

  • European Commission Standard Contractual Clauses (SCCs) for EEA transfers

  • UK International Data Transfer Addendum for UK data subjects

  • Encryption in transit and at rest, with restricted access to personal data

Transfer Impact Assessments (TIAs) are maintained for each vendor handling EU/UK user data.

13. Cookies and Tracking

Our website uses cookies and similar technologies to remember your preferences, analyze usage, and improve user experience. You can control cookies through your browser settings.

For users in the EEA and UK, we display a cookie consent banner before setting any non-essential cookies. You may modify or withdraw cookie preferences at any time through our Cookie Settings interface. Essential cookies are used solely for authentication, billing, and security.

14. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.

15. Shopify App Store Compliance

As a Shopify Partner app, Evolvoom complies with Shopify's Partner Program Agreement, API Terms of Service, and App Store requirements:

  • We request only the minimum Shopify API scopes necessary to operate the Service

  • We do not use Shopify customer or store data for any purposes outside of operating the Service

  • Merchants retain ownership of their store data; Evolvoom acts as a data processor on the merchant's behalf

  • Upon app uninstall, we honor Shopify's mandatory GDPR data deletion webhook within 30 days

  • We comply with Shopify's requirements for handling GDPR data subject requests forwarded through the platform

  • Billing disputes for Shopify-processed charges should be directed to Shopify Support at help.shopify.com

16. Compliance

Evolvoom adheres to the following frameworks:

  • General Data Protection Regulation (GDPR — EU/UK)

  • California Consumer Privacy Act (CCPA)

  • Telephone Consumer Protection Act (TCPA)

  • CAN-SPAM Act (USA)

  • The Campaign Registry (TCR) and carrier guidelines for mixed-use messaging

  • Shopify Partner Program Agreement and API Terms of Service

Our compliance program includes consent logging, opt-out automation, data portability, and signed DPAs with all processors.

17. Data Controller and DPAs

Data Controller: Evolvoom, Inc. Email: hello@evolvoom.io Address: 1111b South Governors Avenue, Ste 34868, Dover, Delaware 19904

We maintain signed Data Processing Agreements (DPAs) with all third-party processors, including: Stripe, Shopify, Twilio, OpenAI, Intercom, Resend, Supabase, and Vercel. Each processor is contractually bound to GDPR-equivalent obligations regarding data protection, sub-processor management, and incident notification.

18. Changes to This Privacy Policy

We may update this Privacy Policy periodically. When we make changes, we will post the updated policy on this page and update the "Last Updated" date. For material changes, we may provide additional notice via email or in-app notification.

19. Contact Us

Email: hello@evolvoom.io

Address: 1111b South Governors Avenue, Ste 34868, Dover, Delaware 19904 Website: evolvoom.io

For data protection inquiries, please include "Privacy Request" in your subject line. For Shopify billing questions, contact Shopify Support directly at help.shopify.com.