Conversell
  • Products
    • Bot Builder
    • Knowledge Base AI
    • Analytics
  • Features
    • Product search
    • Product recommendations
    • Ordering
    • Order tracking & delivery notifications
    • Customer support and FAQs
  • Channels
  • Pricing
  • Resources
  • Contact
  • Log in
  • Start for free
Log in Start for free
Legal

Privacy Policy

9 rue des Colonnes, 75002 Paris, France privacy@conversell.ai

Contents

  • 1. Who We Are & Scope
  • 2. Definitions
  • 3. Channels & Information We Collect
  • 4. Third-Party Platforms
  • 5. How We Use the Information
  • 6. Artificial Intelligence Processing
  • 7. Our Role as Processor
  • 8. Sharing & Sub-Processors
  • 9. Data Retention
  • 10. Data Security
  • 11. Your Rights
  • 12. International Data Transfers
  • 13. Cookies
  • 14. Children's Data
  • 15. Changes to this Policy
  • 16. Contact Us

Privacy & data requests

privacy@conversell.ai →

1. Who We Are and Scope of this Policy

This Privacy Policy explains how Conversell ("Conversell", "we", "us", "our") collects, uses, discloses and protects personal data when you use our website, our applications, and our conversational AI services across web chat, Facebook Messenger, Instagram, WhatsApp and voice channels (together, the "Service").

Conversell is operated by Conversell, la Société par actions simplifiée unipersonnelle (SASU) incorporated under French law with a share capital of €15,000, with its registered office at 9 rue des Colonnes, 75002 Paris, France, registered under number 983 844 143 RCS Paris.

The Service is used by two categories of data subjects:

  • Merchants / Users: our business customers and their staff who configure and operate bots.
  • End-Users: the end-customers of those Merchants who interact with the bots through messaging and voice channels.

This Policy covers both, and indicates where our role differs (Controller vs. Processor). By using the Service you agree to the practices described in this Policy. If you do not agree, please do not use the Service.

2. Definitions

  • "Personal Data": any information relating to an identified or identifiable natural person.
  • "Merchant Data" / "Customer Data": data a Merchant stores in or transmits through the Service, including data about their own End-Users.
  • "End-User": an individual who interacts with a bot operated by a Merchant.
  • "Controller" / "Processor": as defined by the EU General Data Protection Regulation 2016/679 ("GDPR").
  • "Platforms": third-party platforms integrated with the Service, including Meta (Facebook, Messenger, Instagram, WhatsApp), Shopify, and Google.

3. Channels and Information We Collect

3.1 Social Messaging Channels (Meta: Messenger & Instagram)

When an End-User chats with a bot on these platforms, the system collects:

  • Unique Channel IDs: Page-Scoped ID (PSID) for Messenger, Instagram-Scoped ID (IGSID), and app-scoped identifiers.
  • Public Profile Data: display name, profile picture, and language/locale settings.
  • Conversation Data: the actual text messages exchanged, along with timestamps and session tracking.

3.2 WhatsApp Channel

Because WhatsApp is structurally tied to a phone number, the data collected shifts slightly:

  • Unique Channel IDs: WhatsApp ID (wa_id) and the user's actual phone number.
  • Public Profile Data: WhatsApp display name, profile picture, and language settings.
  • Conversation Data: text messages exchanged with the bot and chat metadata (timestamps).

3.3 Voice Channels / Callbots

When a customer interacts with the service over a phone call (processed via our telephony sub-processor Jambonz):

  • Voice audio: live voice audio is processed in real time only to generate the transcript. The audio is not recorded or retained.
  • Transcripts: the text transcripts generated from the call, processed as Conversation Data to operate the bot.
  • Call Metadata: call timestamps, session lengths, and telephony identifiers.

3.4 Account & Administrative Channel (Merchants Only)

This covers the information collected from the business owners or staff who set up and pay for the platform:

  • Identity & Contact Info: full name, email address, phone number, and company name.
  • Billing & Location Data: billing details and country of residence. Payment information (e.g. card numbers) is processed and stored by our payment providers (Shopify Billing / Stripe) and is not stored by Conversell.
  • Support & Feedback Data: the content of emails, support tickets, survey responses, or direct feedback sent to Conversell.

3.5 Automated Technical Channel (Web Chat & Web Platform)

Subject to your cookie choices (see Section 13), background cookies and similar technologies may collect:

  • Network & Device Info: IP address, device type, browser type, operating system, and browser language.
  • Interaction Data: pages viewed, referring URLs, precise access times, and email/link interactions.

3.6 Optional Contact Data

Certain bot flows may include quick reply options that allow End-Users to voluntarily share contact information. If a bot flow includes quick reply buttons requesting an email address or phone number, such information will only be collected when the End-User actively chooses to provide it by selecting the relevant quick reply option. This data is collected solely for the purpose communicated at the time of collection and processed in accordance with this Privacy Policy.

3.7 Commerce / Store Data (Shopify and e-commerce integrations)

To answer End-User questions about their orders and products, the Service retrieves data from the connected store on the Merchant's behalf. This data is retrieved on demand to produce the response and is not retained beyond what is necessary to provide it:

  • Customer identifiers: store Customer ID.
  • Order data: order number, status, line items, fulfilment and tracking information.
  • Address data: shipping / billing address, including postal (ZIP) code, used to verify an order (e.g. order number + postal code).
  • Customer contact data: name, email, phone (from the store customer record).
  • Product catalogue data: products, prices and availability, used for recommendations and to ground answers (may be cached for performance and refreshed periodically).
  • Cart / checkout data: where the cart re-engagement feature is enabled by the Merchant.

Where the integration is Shopify, this data is handled in accordance with Shopify's API Terms and Protected Customer Data requirements (data minimisation, limited retention and security).

3.8 Workspace Data

This covers the technical configuration details, settings, and metadata provided by Merchants when creating and managing their operational environment within the platform:

  • Workspace Profile: Workspace name, unique URL, and workspace description.
  • Brand Identity: Brand name, brand description, and core business activity.
  • Operational Settings: Target integrated platform, default system language, and the designated email address for human assistance.

3.9 Merchant-Authorized Business Knowledge Base

To ensure the conversational AI provides accurate answers regarding the Merchant's business, offerings, and customer service policies, the Service processes public information from the Merchant's designated online assets.

  • Data Processed: Public text, documentation, FAQs, and institutional information made available by the Merchant.
  • Purpose: This information is processed contextually to ground the conversational AI's answers and align response generation with the Merchant's business profile.

The Merchant is responsible for designating these assets and warrants that it has the right to authorise Conversell to process the relevant content for this purpose.

3.10 Sensitive (Special-Category) Data

The Service is not designed or intended to collect special-category data (such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, or political opinions) within the meaning of Article 9 GDPR. End-Users are asked not to share such information through the bots. Where an End-User nonetheless volunteers such data in free-text conversation, it is processed only as Conversation Data to operate the bot and is subject to the same retention and deletion rules set out in this Policy.

4. Data Compliance for Integrated Third-Party Platforms

Meta Platforms

We receive and process data through Meta's APIs strictly to operate the bot as outlined in Section 3. We use this data solely to deliver and improve the conversational service requested by the Merchant. We do not sell it and comply with Meta's Platform Terms. End-Users may request deletion at any time via Meta's Data Deletion Callback or our Data Deletion page.

E-Commerce Platforms (Shopify)

When a Merchant installs the Conversell app on Shopify, we handle Shopify customer data in accordance with Shopify's API Terms and Protected Customer Data requirements. We retrieve order, customer and product data on demand to answer End-Users (order status, product recommendations and, where enabled, cart re-engagement) and do not retain it beyond what is necessary. We implement Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact and shop/redact), allowing data access and deletion requests to be honoured seamlessly.

5. How We Use the Information (Purposes and Legal Bases)

We process Personal Data for the following purposes, relying on the corresponding GDPR legal bases:

Purpose GDPR Legal Basis
Provide, operate and maintain the Service Performance of a contract
Process payments and manage the Merchant relationship Performance of a contract / Legal obligation
Answer End-User queries using store data (orders, products) Performance of a contract (on the Merchant's behalf)
Improve, secure and develop the Service Legitimate interests
Communicate service updates and marketing Legitimate interests / Consent
Comply with legal obligations Legal obligation

6. Artificial Intelligence Processing

The Service uses large language models and related AI components to generate responses. Conversation content may be processed by our AI sub-processors solely to produce the bot's answers.

We do not use Merchant or End-User conversation content to train foundation models for unrelated purposes, and we contractually require our AI providers to process data only on our documented instructions.

The AI is used to generate conversational answers and assist with support; it does not make decisions that produce legal effects concerning End-Users, or similarly significantly affect them, without human involvement, within the meaning of Article 22 GDPR. Where a request exceeds what the bot can handle, it is routed to the Merchant's designated human assistance contact.

7. Our Role as Processor (Data Processing Terms)

Where Conversell processes End-User Personal Data on behalf of a Merchant, the Merchant acts as Controller and Conversell acts as Processor. These data processing terms apply in that situation and satisfy Article 28 GDPR; no separate Data Processing Agreement is required.

  • Subject-matter and duration: processing of End-User Personal Data for the duration of the Merchant's subscription, for the purpose of operating the Service.
  • Instructions: we process Personal Data only on the Merchant's documented instructions, including as configured in the Service.
  • Confidentiality: persons authorised to process the data are bound by confidentiality.
  • Security: we implement the technical and organisational measures described in Section 10.
  • Sub-processors: the Merchant authorises the sub-processors listed in Section 8; we inform Merchants of changes and remain responsible for their compliance.
  • Assistance: we assist the Merchant with data-subject requests, security, breach notification and impact assessments, taking into account the nature of the processing.
  • Deletion / return: on termination, we delete or return End-User Personal Data in accordance with Section 9 and applicable law.

8. Sharing and Sub-Processors

We do not sell Personal Data. We share data only with trusted sub-processors that support the Service under data processing agreements, including:

  • Google Cloud / Firestore: infrastructure.
  • Google Gemini: AI models.
  • Weaviate: self-hosted vector database for RAG.
  • Jambonz: voice / telephony channel.
  • Stripe / Shopify Billing: payment processing and billing (card data is handled directly by these providers and is not stored by Conversell).

We keep this list of sub-processors up to date. Before adding or replacing a sub-processor that processes End-User Personal Data, we inform affected Merchants in advance and give them a reasonable opportunity to object on legitimate data-protection grounds.

9. Data Retention

We minimise the data we retain and keep it only as long as necessary for the purposes set out in this Policy, or as required by law. The following periods apply:

Data category Retention
End-User channel IDs, profile and conversation data (chat & voice transcripts), plus any optional contact details (email/phone) voluntarily provided by End-Users While the Merchant account is active; deleted or anonymised after 12 months of inactivity
Voice audio Not retained (processed in real time only)
Commerce / store data (orders, customer, addresses) Retrieved on demand; not retained beyond the response
Product catalogue (cached for RAG) Cached short-term and refreshed periodically
Merchant account & contact data Duration of the contract + 3 years after closure
Billing & accounting records 10 years (French Commercial Code)
Support & feedback data Duration of the relationship + 3 years
Technical logs 6 to 12 months
Cookies & similar technologies Up to 13 months (consent record kept as proof)
Workspace data Duration of the contract; deleted or anonymized within 30 days of account termination
Merchant Website Data (Scraped for RAG) Cached and stored for the duration of the Merchant's contract; periodically refreshed or deleted upon Merchant request or account termination

End-Users and Merchants may also request deletion at any time (see Section 11); verified requests are actioned within 30 days.

10. Data Security

We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure or destruction. Internal access to data is strictly controlled and limited to what is necessary.

These measures include, in particular:

  • encryption of Personal Data in transit (TLS) and at rest on our infrastructure;
  • role-based access controls, authentication and the principle of least privilege;
  • security controls, logging and monitoring on our cloud infrastructure;
  • contractual security and confidentiality commitments from all sub-processors.

In the event of a personal data breach, we act without undue delay to investigate and contain it and, where legally required, notify the competent supervisory authority and affected Merchants in accordance with Articles 33 and 34 GDPR.

11. Your Rights and How to Exercise Them

Subject to applicable law, you have the following rights: access, rectification, erasure, restriction of processing, objection, data portability, and the right to withdraw consent. You also have the right to lodge a complaint with a supervisory authority (in France, the CNIL).

End-Users and Merchants can request deletion of their data by emailing privacy@conversell.ai or using our Data Deletion page. We action verified requests within 30 days.

Before actioning a request we may need to verify your identity. End-Users whose data is processed on a Merchant's behalf may also contact the relevant Merchant directly; in that case we assist the Merchant in responding.

12. International Data Transfers

Personal Data may be processed in countries outside the European Economic Area (EEA). Where this occurs, we put in place appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to ensure an adequate level of protection.

13. Cookies

We use cookies and similar technologies to operate, secure, personalize and improve the Service. Strictly necessary cookies are used to provide the Service. Non-essential cookies (such as analytics) are set only with your prior consent, collected through our cookie consent banner, and you can change your choices at any time via Cookie settings. Disabling some cookies may affect functionality. Cookies are retained for a maximum of 13 months, unless a longer period is required for security, legal or operational purposes.

14. Children's Data

The Service is not directed to children under 15 (or the higher age required by applicable local law), and we do not knowingly collect their Personal Data.

15. Changes to this Policy

We may update this Policy from time to time. Changes will be posted on this page with a new "Last updated" date. Where a change materially affects how we process Personal Data or your rights, we will provide reasonable prior notice through the Service or by email before it takes effect.

16. Contact Us

Email (General): contact@conversell.ai
Email (Privacy / Data Requests): privacy@conversell.ai
Postal Address: 9 rue des Colonnes, 75002 Paris, France

Conversell

Conversell is a leading SaaS solution enabling businesses to deliver personalized conversational AI for e-commerce. Build, deploy, and manage smart chatbots effortlessly - no coding required.

Product

  • Bot Builder
  • Knowledge Base AI
  • Analytics
  • Pricing

Company

  • Home
  • Features
  • Channels
  • Contact

Contact & legal

  • support@conversell.ai
  • contact@conversell.ai
  • Privacy Policy
  • Terms of Service
  • Data Deletion
  • Legal Notice
Copyright © 2026, All Rights Reserved · Conversell SASU · 9 rue des Colonnes, 75002 Paris, France Privacy Terms Legal Notice

We use cookies or similar technologies to improve your browsing experience. By continuing, you agree to our Privacy Policy.