Saytu is a product of Bot and Life Co., Ltd. (company registration 0105547132674), 100 J.Press Tower A, Floor 12, Nanglinchee Rd., Chong Nonsee, Yannawa, Bangkok 10120, Thailand. It is the data controller for the processing described below. Privacy requests and questions go to info@botnlife.co.
What we process
Operating the assistant involves three kinds of data: the product catalog and store policies you connect, the text of visitor conversations with the character, and — only when order lookup is enabled — order-lookup inputs such as an order number or email needed to check order status.
Redaction before storage
Order-lookup inputs are passed through a redaction step before a conversation is ever written to the database. Messages produced this way are tagged as redacted at the point of storage, not redacted after the fact.
Contact identifiers
We don't store shopper email or phone numbers in plaintext. We store a one-way hash of the identifier (plus a short masked preview for support screens), which cannot be reversed back into the original email or phone number.
Retention
Contact identifiers expire automatically about 90 days after last activity, after which a scheduled job anonymizes them. Live chat session records have a 24-hour lifetime and are removed automatically after that. Conversation transcripts otherwise remain until deleted through a merchant request or app uninstall.
Uninstalling the Shopify app
When a merchant uninstalls Saytu on Shopify, Shopify sends a shop/redact webhook roughly 48 hours later. On receiving it, we hard-delete everything tied to that shop: conversations, messages, contacts, knowledge sources, and the shop record itself.
Shopify customer GDPR webhooks
We honor Shopify's mandatory customer privacy webhooks: customers/redact (erase a specific customer's data on request) and customers/data_request (report what we hold about a customer).
Subprocessors
We use the following service providers to operate Saytu. Conversation content is sent to the AI, speech-to-text, and text-to-speech providers below solely to produce a reply — it is not used to train their public models.
AWS S3 — asset and uploaded character model storage
MongoDB Atlas — database
Shopify — billing for Shopify installs
Stripe — billing for web installs
Clerk — authentication for web installs
International transfer
Most of the subprocessors above are US-hosted. Using Saytu means conversation and account data may be transferred to, and processed in, the United States and other countries outside Thailand.
Your choices
Merchants can request anonymization or deletion of their shop's data from Settings or by contacting info@botnlife.co. Shoppers who want their data deleted or reported on should ask the merchant's store to submit that request — see the Shopify customer GDPR webhooks above for how that's handled.
Changes to this policy
We may update this policy as the product changes. The date at the top of this page reflects the last update.
Contact
Privacy questions can be sent to info@botnlife.co.