Chaperone
Privacy Policy
Effective date: August 24, 2026
Chaperone is a governance gateway that lets a merchant connect AI assistants (such as Claude, ChatGPT, or developer tools) to their own Shopify store under permissions, approvals, and audit controls the merchant configures. Chaperone exists to give merchants control and accountability over what AI can do in their store. This policy explains what data the app processes and why.
Data we process
- Store identity: your shop domain, store handle, and Shopify plan, used to operate the app for your store.
- Shopify API credentials: access tokens Shopify issues to the app, stored encrypted and used only server-side. They are never shared with any AI assistant or third party.
- Configuration: your connections, permissions, connection rules, and limits (including an optional notification email address).
- Audit ledger: a permanent, tamper-evident record of every AI action — the connection that took it, the operation text, redacted inputs, the decision Chaperone made, approvals, and Shopify request identifiers. This ledger is the product: it exists so you have a receipt for everything AI does in your store.
- Approval requests: proposed changes awaiting your decision, including a before/after preview of the affected resources.
- Store data in transit: product, inventory, and other Admin API data that an AI assistant you connected requests, within the permissions you granted. Chaperone relays this data to that AI assistant and retains only the audit metadata described above.
How data reaches AI providers
Chaperone never sends your store data to any AI vendor on its own initiative. Data flows only to the AI assistants you explicitly connect, only in response to requests those clients make, and only within the permissions you granted — you can narrow or revoke that access at any time from the app, including a kill switch that blocks all AI access instantly. The AI providers you connect (e.g. Anthropic, OpenAI) process that data under their own terms as services you chose; review their policies when connecting them.
No training. We never use your store data to train AI models, and we do not sell it or share it with anyone except as directed by you.
Protected customer data
Access to order and customer data is off by default and requires both Shopify’s platform approval and your explicit opt-in. Personally identifiable customer information is redacted from data sent to AI assistants by default, and the audit ledger stores redacted inputs — not raw customer PII.
Retention and deletion
- Configuration and the audit ledger are retained while the app is installed, so your records stay complete.
- When you uninstall, Shopify’s
shop/redactprocess triggers a full purge of everything Chaperone holds for your store, typically within 48 hours of Shopify’s notice. - Customer data-request and redaction webhooks (
customers/data_request,customers/redact) are honored within the legally required timeframe, including redaction inside audit and approval records.
Sub-processors
- MongoDB Atlas — database hosting for the data described above.
- Application hosting provider — runs the Chaperone server.
- Email delivery provider — sends approval and safety notifications to the address you configure.
AI providers you connect are not our sub-processors; they are services you direct us to transmit data to.
Security
Shopify credentials are encrypted at rest and never cross the AI boundary. Every AI assistant holds only a revocable, store-bound Chaperone credential. All traffic is TLS. Data is isolated per store, and the audit ledger is append-only and hash-chained so tampering is detectable.
Contact
Questions or requests about this policy: support@xeonapp.com.