Winback AI logo — a price tag inside a countdown timer
Winback AI
Privacy

Privacy Policy, Winback AI

How we collect, use, and protect merchant and customer data for AI-powered abandoned-cart recovery on Shopify.

Last updated: September 29, 2026 · Winback AI is operated by NeoImbus Tech Pvt. Ltd. ("we", "us")

1. What this policy covers

This policy describes how the Winback AI app for Shopify ("the App") collects, uses, and protects data when a merchant installs it on their Shopify store. It covers both merchant data and the store's customer data processed on the merchant's behalf.

2. Data we collect

  • Merchant/store data: store name and domain, contact details, product catalog data, plan and billing status (billing is processed by Shopify, we never see your payment card).
  • Customer data (processed for the merchant): names, email addresses, phone numbers, and shipping regions from abandoned checkouts; order history related to recovery attribution; cart contents; storefront interaction events (pages, products, and searches, keyed to an anonymous client ID).
  • Call data: call recordings, transcripts, and AI-generated summaries of recovery calls, made available to the merchant in their dashboard.

Phone numbers and emails come exclusively from the merchant's Shopify checkout. The App does not inject forms, popups, or any data-collection UI into the storefront.

3. How we use it

  • Placing and managing AI recovery calls and enabled SMS on the merchant's behalf; sending recovery email only when a sender is configured
  • Minting and delivering one-time discount codes (FuseCodes)
  • Recovery attribution, analytics, and reporting to the merchant
  • Service operation, support, and abuse prevention

We do not sell personal data, use it for advertising, or use it to train third-party AI models.

4. Calling practices

  • The AI assistant discloses on every call that it is an AI.
  • Calls respect configurable calling windows and retry caps.
  • A customer's request not to be contacted again is honored permanently via a do-not-call list.
  • Call recordings are made available to the merchant; see §6 for how app-held records are deleted.

5. Subprocessors

We use the following service providers to operate the App:

  • Shopify, platform, webhooks, and billing
  • Vapi, AI voice call infrastructure
  • Twilio, SMS delivery
  • Google Cloud Platform, application hosting and backups; PostgreSQL and Redis run on our Google Cloud virtual machine
  • Resend, recovery email delivery when that feature is enabled

6. Retention & deletion

  • In our app database, abandoned-checkout records and expired FuseCodes are routinely removed once they are more than 90 days old.
  • Uninstalling removes app access and store settings. On a Shopify shop-redaction request, our handler deletes that shop's checkout, call, FuseCode, and do-not-call records from the app database. Customer redaction removes matching checkout, call, and FuseCode records; when a phone number is known, a do-not-call marker is kept to prevent further outreach.
  • We process Shopify's customer data requests and redaction requests. Contact us directly about other app-held data or deletion requests.

7. Your rights (customers)

If you are a shopper whose data was processed by a store using Winback AI, contact that store first, we act as their processor. You may also reach us directly at contact@kolz.ai for access, correction, or deletion requests, or to be added to the do-not-call list.

8. Security

Data in transit is encrypted (HTTPS/TLS). Webhooks are verified with HMAC signatures. Access to production data is restricted to authorized personnel.

9. Changes & contact

We will post updates to this policy on this page. Questions: contact@kolz.ai · NeoImbus Tech Pvt. Ltd.