Contents

Data processing agreement — Shopify stores

Version 2026-09-v1 — effective September 28, 2026

1. Purpose and parties

This data processing agreement (the "Agreement") applies when an Echo Support customer (the "Merchant") connects its Shopify store to its Echo organization. It supplements the Terms of Service (the "Terms"), in particular their section 11, for the information that comes from the store. For that information, the Agreement prevails over the Terms in case of inconsistency.

  • The Merchant operates the store. It is the person responsible, under Quebec's Act respecting the protection of personal information in the private sector, for its customers' personal information.
  • Groupe Echo Inc., a business corporation incorporated in Quebec, NEQ 1182473588, with its head office at 2390, rue du Cardinal, Terrebonne, Quebec J7M 0B6 ("Groupe Echo", "we", "us"), processes that information on the Merchant's behalf, as its mandatary within the meaning of section 18.3 of that Act.

The Merchant accepts the Agreement by ticking the box on the "Connect a Shopify store" screen; the person who ticks it represents that they are authorized to bind the Merchant. We record the accepted version, its date and the Echo account that accepted it. Shopify Inc. is not a party to the Agreement.

2. What we do with the store information

We use access to the store only so that the Echo Support assistant can answer the Merchant's customers who write through the chat widget:

  • giving the status of an order, when a customer asks for it, if the number and email address they provide point to the same order;
  • forwarding to the Merchant's team a request to cancel an order, change its address or return it, checked the same way, through an internal note and by handing the conversation over to a human;
  • searching the products published on the online store;
  • answering from the store's published policies and pages.

Nothing is changed in Shopify: no cancellation, no address change, no refund, no return. We do not sell this information, we use it for no other purpose, and Groupe Echo does not train any artificial intelligence model with it.

3. Access requested from Shopify

The Echo app asks Shopify for four access scopes, all read-only: orders (read_orders), products (read_products), online store pages (read_online_store_pages) and policies (read_legal_policies). It asks for no write access. Through these scopes, Shopify only makes orders from the last 60 days available.

4. Information read, and information never read

When the store is connected

  • The store's identifier, name, currency, primary domain and email address. The email address is used only to send the store a notice of the connection. It is not kept in the store record; it remains only in the email sending queue and in the mail server's logs, until they are automatically cleaned up, and in backups, until they are overwritten.
  • The access token that Shopify gives Echo.

Orders, when a customer asks

We do not copy the store's orders. An order is read from Shopify at the moment a customer asks about it, using the number and email address they give in the conversation. If both point to the same order, the assistant receives: the order number, its date, whether it is cancelled, its payment status and fulfillment status; for each shipment, its status, the carrier, the tracking number and link, and the estimated and actual delivery dates; the title and quantity of the items.

Never read: the customer's postal address, phone number and name, the payment method, the amounts, the order's notes and tags, or the order status page. The email address recorded on the order is used only for the check: it is not part of what the assistant receives.

Products

For each customer search, the active products published on the online store that match it: title, link, price range in the store's currency, availability, variants and an excerpt of the description. The catalogue is not copied to Echo; only the result of a search stays in the conversation where it took place.

Policies and pages

The store's policies (refund, shipping, terms, etc.) and its ten most recently updated published pages are copied into the organization's knowledge base: when the store is connected, every day, and when the owner or an administrator of the organization clicks "Sync now". This copy only happens if the organization's plan includes the AI assistant.

The lookup log

Every order lookup is recorded in a log attached to the conversation: the order looked up, the outcome of the check and a fingerprint of the email address given, never the address itself. This log is used to find, in order to erase it, the information of a store or of a customer.

5. Retention

  • Lookup results and internal notes. The result of an order or product lookup stays in the conversation where it took place, and the order appears in the internal note of a forwarded request. That result is not sent back to the language model with later messages; the answer the assistant wrote from it is a message of the conversation like any other. All of them follow the conversation that contains them and go with it, under the conditions of section 11 of the Terms.
  • Copied policies and pages: as long as the store is connected.
  • Access token: as long as the store is connected; it is erased as soon as the store is disconnected or the app is uninstalled.
  • Lookup log: it goes with its conversation, and at the latest 400 days after the lookup.
  • Store record (domain, installation and connection dates, accepted version of the Agreement, date and author of the acceptance): as long as the app is installed; it is deleted on the store erasure request that Shopify sends after uninstallation, and at the latest 30 days after uninstallation.
  • Backups: overwritten on their normal cycle; erased information may remain in them until then.

6. Disconnection and uninstallation

The Merchant may end the connection at any time: with the "Disconnect" button on the Shopify card of Echo's Connectors screen, or by uninstalling the Echo app from its Shopify admin. In both cases, we erase the access token immediately, then, within 30 days:

  • the copied policies and pages, and their entries in the knowledge base;
  • in every conversation where the store's tools were available to the assistant: the results of order and product lookups; all of the assistant's internal notes, if an order was looked up in it; and the conversation's entry in the search index of resolved conversations;
  • the lookup log;
  • the store's name, currency and primary domain.

What this purge does not erase: the answers the assistant wrote in conversations, which may restate an order's status, tracking or items. They are part of the Merchant's support history and follow the conversation (section 5). Escalation emails already sent to the Merchant's team stay in its inboxes. If the store is connected again to the same organization before the purge ends, the copied policies and pages remain with the new connection.

Disconnecting does not remove access on the Shopify side: to do so, the Merchant uninstalls the app from its Shopify admin (Settings → Apps).

7. Privacy requests forwarded by Shopify

Shopify forwards to Echo the privacy requests that concern the store. We handle them within 30 days of receipt:

  • A customer's access to their information (customers/data_request): handled manually. We give the Merchant the information we hold about that customer for its store, so that it can answer the customer.
  • Erasure of a customer (customers/redact): in every organization connected to the store that knows this person, we erase them as for an erasure request under Law 25 (contact record, conversations and attachments), and we delete every conversation that the lookup log links to their email address or to their orders. Once the request is handled, the erasure register keeps only a fingerprint of the address. If no organization knows the person, nothing is kept about them.
  • Erasure of the store (shop/redact), which Shopify sends after uninstallation: the purge described in section 6, then deletion of the store record, unless the app has been reinstalled in the meantime.

These requests can also be sent to us at vie-privee@echo-group.ca.

8. Subprocessors

The store information is processed by the providers named in our Privacy Policy, which keeps the list up to date:

  • OVH Hosting Inc. (Beauharnois, Quebec, Canada): hosting of the application, database, files and email.
  • OpenRouter, Inc. (United States): receives the messages of conversations handled by the assistant, with the results of order and product lookups and excerpts of the policies and pages, and routes them to the provider that runs the DeepSeek V4 Flash language model. That provider is chosen by OpenRouter; depending on the one selected, processing may take place in the United States or in another country. Groupe Echo does not yet restrict that choice and is not notified when it changes.
  • Cohere Inc. (Canada): computes the search vectors ("embeddings") of the copied policies and pages, of the assistant's search queries and of a short excerpt of resolved conversations. This computation may take place outside Canada.
  • GitHub, Inc. (United States): storage of a daily backup copy of the database, encrypted before it is sent; the decryption key stays with Groupe Echo Inc.
  • Functional Software, Inc. (Sentry) (European Union): error reports from the dashboard, in which text and input fields are masked.

Information handled by the assistant therefore leaves Canada. Stripe and Google, also named in the Privacy Policy, receive no store information. Each provider applies its own retention rules.

9. Security

  • Read-only access, limited to the four scopes of section 3. Requests to Shopify only go to the store's myshopify.com address.
  • Access token encrypted at rest (AES-256-GCM), decrypted only at the moment of a lookup, never displayed or returned by the dashboard.
  • Traffic encrypted in transit (TLS).
  • Messages from Shopify (installation, uninstallation, privacy requests) authenticated by their HMAC signature.
  • Isolation by organization. The connection is never automatic: it requires confirmation by a signed-in member, and only the organization's owner and administrators can connect, sync or disconnect the store.
  • Failed order checks are capped per conversation, per visitor, per order and per email address; when the cap for an order or an email address is reached, the organization's owner is notified by email, at most once an hour.

A matching order number and email address does not prove who the person is: both appear on the parcel label and in the confirmation email. That is why the assistant never gives the address, the phone number or the payment method, and why the note of a request reminds the Merchant's team to confirm the request with the order's email address, in Shopify, before cancelling an order or changing its address.

10. Breaches, incidents and verifications

We notify the Merchant's person in charge of the protection of personal information without delay of any breach or attempted breach, by any person, of the obligations relating to the confidentiality of its store information, and of any confidentiality incident affecting that information, as soon as it comes to our attention. The notice goes to the owner of the Echo organization connected to the store, or to the address the Merchant designates for that person at vie-privee@echo-group.ca. We record every confidentiality incident in our register and cooperate with the measures and reports the law requires of the Merchant, in particular to Quebec's Commission d'accès à l'information and to the persons concerned.

Verifications. The Merchant's person in charge of the protection of personal information may carry out any verification relating to the confidentiality of the store information. Upon request at vie-privee@echo-group.ca, we answer their questions and questionnaires, provide the description of our security measures and our privacy impact assessment of the Shopify integration, and agree with them on any other verification they require.

11. The Merchant's responsibilities

  • Inform its customers, in particular in its privacy policy, that an AI assistant provided by Groupe Echo answers in the chat, that it can look up their orders at their request and that their messages are processed outside Quebec; and obtain the consents the law requires.
  • Carry out, where applicable, the privacy impact assessment the law requires before communicating information outside Quebec. Upon request at vie-privee@echo-group.ca, we provide the information about our processing that this assessment needs.
  • Handle, in Shopify, the cancellations, address changes and returns forwarded by the assistant, after confirming the request with the order's email address.
  • Keep its published policies and pages up to date: the assistant answers from what they say.
  • Avoid adding sensitive information to Echo (health, social insurance numbers, banking details): it is not masked before being sent to the language model.
  • Forward to us, at vie-privee@echo-group.ca, its customers' requests that require our involvement.

12. Term, end and changes

The Agreement takes effect when the store is connected and ends when it is disconnected or the app is uninstalled. The erasure commitments (sections 6 and 7) and the confidentiality commitments survive until they are fully carried out. Every new connection requires a new acceptance.

We may change the Agreement under the rules of section 14 of the Terms: for any significant change, including the addition of a subprocessor that would receive store information, we notify the Merchant by email at least 30 days before it takes effect, and the Merchant may disconnect its store before that date. This notice covers the subprocessors named in section 8, with which Groupe Echo deals directly; it does not cover OpenRouter's choice of the provider that runs the language model: OpenRouter may change that provider, and therefore the country of processing, at any time and without notifying us (section 8). Each version has a number, shown at the top of this page; the one the Merchant accepted is recorded.

13. Governing law and language

The Agreement is governed by the laws of Quebec and the federal laws of Canada that apply there. It is written in French; the English version is provided for convenience, and the French version prevails in case of inconsistency.

14. Contact us

Groupe Echo Inc.
2390, rue du Cardinal, Terrebonne, Quebec J7M 0B6, Canada
Person in charge of the protection of personal information: Isaac Poirier Bernard, president — vie-privee@echo-group.ca
General questions and the pilot program: contact@echo-group.ca