SpeakingOf

Privacy Policy

This policy describes what the SpeakingOf Shopify app collects, how it is used, where it is stored, and how long it is kept.

Last updated: 31 August 2026

About this app

SpeakingOf is an independent Shopify app operated by its sole developer. It adds storefront conversations to a merchant's store. For the conversation data described below the merchant is the data controller and SpeakingOf acts as a processor on the merchant's instructions.

Information collected through Shopify's APIs

  • Customers - customer ID, display name, first and last name, email address, account state, tags, number of orders, and amount spent, to identify a participant and apply the access rules a merchant sets for a space.
  • Orders - order number and date, financial and fulfilment status, total, line item titles and quantities, and fulfilment tracking details, shown to the merchant's team in the Inbox.
  • Store and languages - shop identifier, currency, contact email, time zone, Shopify plan, and the store's enabled language names and locale codes. The app uses the language data to show and manage localised chat content.
  • Catalogue - products, collections, pages, and articles, to attach a conversation to the page a customer is viewing.
  • Commerce events - via Shopify's Web Pixel, cart and checkout events with product and variant identifiers, quantities, amounts, and currency. These contain no names, emails, or addresses.

Information collected from the merchant

App configuration (spaces, access rules, appearance, copy, languages), team working data (internal notes, saved replies, statuses, moderation decisions), a notification email address when email reports are enabled, support requests, and automated logs of configuration and moderation changes.

Information collected from customers

Messages, replies, reactions, poll votes, and image attachments a customer sends; the display name shown in a conversation and an email address if a guest supplies one; and usage events such as opening the chat or interacting with a recommended product.

The storefront chat stores four items on the customer's device so a conversation keeps working across page views and the app can attribute a chat interaction to a cart. None is used for advertising or cross-site tracking.

  • speakingof_guest_session in local storage - lets a guest return to their own conversation; expires after 180 days.
  • speakingof:session-id in session storage - cleared when the browser tab closes.
  • speakingof:tab-instance-id in session storage - distinguishes one browser tab from another; cleared when the browser tab closes.
  • speakingof:cart-journey:<cart id> in session storage - links a chat session to the cart it influenced for order attribution; cleared when the browser tab closes.

For the same attribution purpose, SpeakingOf writes __speakingof_journey, an opaque journey identifier, to the Shopify cart. Shopify may carry that cart attribute to the resulting order, where it follows the merchant's Shopify data lifecycle.

How the information is used

Only to provide the features the merchant has configured: showing and delivering storefront conversations, supporting the merchant's team in the Inbox, moderating content, sending notifications the merchant enables, and producing that merchant's analytics and attribution reporting.

The information is not sold, not used for advertising, not used to train machine learning models, and not combined across merchants into a shared profile. Each store's data stays with that store, unless the merchant connects their own stores into one workspace.

How long it is kept

  • Messages, reactions, and poll votes - up to 24 months, then deleted.
  • Private support history - the conversation view shows the most recent 90 days on Core, 365 days on Growth, and 730 days on Pro. This limits what is displayed to the participants; it is not a deletion schedule.
  • Image attachments - deleted automatically once the retention window the merchant selects has passed (7, 30, 90, or 180 days; 180 days by default), measured from the moment the image is attached to a message.
  • Guest session tokens - 180 days from last use.
  • Configuration, analytics, and attribution records - for the life of the merchant's account.

The app implements Shopify's data request, customer redaction, and shop redaction webhooks. Uninstalling marks the store inactive and stops all further processing; when Shopify then sends the shop redaction request, the store's conversations, configuration, attachments, and billing records are permanently deleted. When Shopify sends a customer redaction request, that customer's conversation data and attachments are deleted.

Where it is stored and processed

SpeakingOf runs on Amazon Web Services in the us-east-1 (United States) region, and data is stored and processed there wherever the merchant and their customers are located. The service providers used are Amazon Web Services (hosting, database, attachment storage) and Resend (notification email), alongside Shopify itself for authentication, billing, and the APIs above.

SpeakingOf keeps no separate infrastructure of its own: the app runs entirely on the services above, and it is not established in the European Economic Area. Merchants in the EEA, the United Kingdom, or Switzerland who need a data processing agreement for their own compliance can rely on the Data Processing Agreement, which applies from installation.

Contact

Write to hello@speakingof.app with any question about this policy, to exercise a data right, or to request a countersigned copy of the Data Processing Agreement. The operator's full legal name, country of establishment, and registered address are provided to any merchant who asks.

If you are a customer of a store using SpeakingOf, contact that store first - the merchant controls the conversations on their storefront and can remove your data or pass the request on.