Privacy Policy
Last updated: July 2026
AskBrew provides an AI support assistant that businesses (“customers”) embed on their websites to answer questions from their own knowledge and, where connected, to look up account information for their end users (“visitors”). This policy explains what we collect, why, and how we protect it. It applies to the AskBrew dashboard, the chat widget, and connected integrations such as Shopify.
Information we collect
From customers (account holders)
- Account details: name, email, workspace name, and authentication data managed by our identity provider.
- Knowledge you upload or import (documents, website content, notes) so the assistant can answer from it.
- Billing information, processed by our payment provider — we do not store full card details.
- Configuration: widget settings, tools/actions you define, and connected integrations.
From visitors (your end users)
- Chat messages sent to the assistant, and the answers returned.
- A random visitor identifier stored in the visitor's browser to group a conversation.
- Identity you choose to share with us (for example name or email), and, when your server verifies it, a cryptographic confirmation of that identity.
- When an action runs, the specific data your endpoint or a connected provider (e.g. Shopify) returns for that request.
How we use information
- To generate answers grounded in a customer's knowledge base.
- To run customer-configured actions, scoped to the verified visitor.
- To provide the dashboard, analytics, conversation history, and support handoffs.
- To operate billing, prevent abuse, and maintain security.
We do not sell personal data, and we do not use customer knowledge or visitor conversations to train third-party AI models beyond what is needed to answer the immediate request.
AI processing
To answer questions and create search embeddings, message content and relevant knowledge are sent to our AI provider (OpenAI) via its API. This data is processed to return a response and is not used by that provider to train its models under its API terms. Private identity claims used only to authorize an action are never included in prompts sent to the AI.
Connected integrations (Shopify)
If a customer connects a Shopify store, AskBrew stores an encrypted access token and calls the Shopify Admin API on the customer's behalf to look up order information. A lookup returns data only for orders belonging to the verified visitor. We request the minimum scopes required (read access to orders and customers). A customer can disconnect at any time from the dashboard, which disables the integration.
Subprocessors
We rely on the following processors to run the service:
- Supabase — database, authentication, and file storage.
- OpenAI — answer generation and embeddings.
- Vercel — application hosting.
- Paddle — billing and payments.
- Resend — transactional email.
- Upstash — rate limiting.
- Shopify — only when a customer connects their store.
Data retention
We retain account and configuration data for as long as a workspace is active. Conversations and knowledge are retained to provide history and analytics, and are deleted when a customer deletes the relevant data or their account. Deleting an account removes its associated data, subject to short-lived backups and any legal retention requirements.
Security
- Data is isolated per workspace using database row-level security.
- Secrets such as integration tokens are encrypted at rest.
- Visitor identity for account actions is cryptographically verified.
- Optional two-factor authentication protects customer accounts.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete personal data. Customers can export or delete their workspace data from the dashboard. Visitors should contact the business whose website they used; that business is the controller of their data, and AskBrew acts as a processor on its behalf.
International transfers
Our processors may store or process data in regions including the United States and the European Union. Where required, transfers are covered by appropriate safeguards provided by those processors.
Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this policy or your data can be sent to support@askbrew.com.
This policy is provided as a general template and does not constitute legal advice. Please review and adapt it with qualified counsel for your jurisdiction and business.