Privacy Policy
1. Who controls the data
For store visitors' data, the merchant is the controller and NOLA AI acts as a processor, handling data solely to provide the contracted service. For merchant account data (account, billing, support), the controller is the company identified in the footer of this page.
2. Data we process
Store catalog: products, variants, prices, images, descriptions and inventory quantity, obtained from the e-commerce platform with read-only permissions, so the assistant can find and recommend products accurately.
Conversations: messages exchanged between the visitor and the assistant, products shown and items added to the cart during the conversation.
Voluntary contact: name, email or phone, when the visitor provides them in the conversation, so the merchant can follow up.
Technical data: store domain, conversation identifier, timestamps and error logs, for security, abuse prevention and troubleshooting.
Account and billing: store name, merchant email and subscription status.
What we do not collect: we never ask for or store credit card data. On Shopify, billing is processed entirely by the platform. The app also does not request read access to orders or to store customer data.
3. Artificial intelligence
Assistant replies are generated by third-party language models. Conversation content and catalog excerpts are sent to the model provider at reply time. This data is not used to train the provider's models.
AI-generated answers can contain errors. The merchant is responsible for reviewing what is shown publicly, especially price, availability and delivery times.
4. Who we share with
We do not sell data. We share only with providers required to operate the service: OpenAI (reply generation and catalog search vectors), Shopify or the connected e-commerce platform (catalog source, installation and billing channel) and Hostinger (application and database hosting).
Some providers process data outside Brazil, which means international data transfer, carried out with the contractual safeguards required by applicable law.
5. Retention
The catalog is kept while the app is installed; it is replaced on each sync and deleted on uninstall. Conversations and contacts are kept while the account is active, unless deletion is requested earlier. After uninstall, store data is deleted within 30 days. Technical logs are kept for up to 12 months.
6. Your rights
Brazilian data protection law (LGPD) grants the data subject the right to confirm processing, access data, correct incomplete or outdated data, request anonymization or deletion, request portability and withdraw consent.
Store visitors should contact the merchant first, as they are the controller of that data. To exercise your rights with us, write to contact@gusta.click.
7. Security
Store credentials are encrypted at rest with AES-256-GCM. Database access is restricted to the application and all traffic uses encrypted connections. No system is immune to incidents: in case of a relevant incident, we will notify those affected and the competent authority as required by law.
8. Changes
We may update this policy. Relevant changes will be announced in the app dashboard or by email, with reasonable notice. The date at the top shows the last revision.
9. Contact
Privacy: contact@gusta.click
Product support: gustavo.pontes@gusta.click
GUSTAVO FELIPE DA SILVA PONTES TECNOLOGIA DA INFORMACAO — CNPJ 49.817.096/0001-74 — Barueri/SP
Versão em português