VendlyVendly
Book a demo

Privacy Policy

Last updated: August 21, 2026

Vendly ("Vendly", "we", "us") provides merchants with a unified inbox and AI-powered customer service agent that connects to WhatsApp, Messenger, Instagram, and email. This policy explains what information we collect, how we use it, and the choices available to merchants and their customers.

This policy applies to getvendly.com and the Vendly dashboard, and to messages exchanged through the channels a merchant connects to their Vendly account. It does not cover the practices of Shopify, Meta, Google, or other third-party platforms merchants and customers use independently of Vendly — please review their own privacy policies as well.

Who this policy covers

Merchants: the store owners and team members who sign in to the Vendly dashboard to manage conversations, connect channels, and review analytics.

Customers: the shoppers who message a merchant's store on a connected channel. Customers interact with Vendly indirectly, through the merchant's WhatsApp number, Messenger page, Instagram account, or support email address.

Information we collect

We collect the following categories of information:

  • Account information — a merchant's name, email address, and password hash used to sign in to the dashboard.
  • Shopify store data — order, customer, product, and policy information accessed through the Shopify Admin API, limited to the OAuth scopes a merchant grants when connecting their store.
  • Conversation data — message content, timestamps, and delivery status for conversations across WhatsApp, Messenger, Instagram, and email.
  • Customer contact identifiers — a customer's phone number, social handle, or email address, and any name they provide, as needed to route and reply to their messages.
  • Voice notes — audio files a customer sends and their text transcript, used to let the AI agent respond to spoken messages.
  • Payment link data — order value and payment status for payment links created through our payments provider; we do not receive or store full card numbers.
  • Usage data — anonymized or aggregated analytics about how merchants and visitors use the Vendly dashboard and marketing site.

How we use information

We use the information above to:

  • Generate and send AI agent replies to customer messages, grounded in a merchant's store data and conversation history.
  • Look up order status and carry out returns, refunds, and cancellations a customer requests, through the Shopify Admin API.
  • Transcribe voice notes so the AI agent can understand and respond to them.
  • Hand a conversation to a human teammate when the AI agent cannot resolve it, and let that teammate see the relevant message history.
  • Score conversations for speed, resolution, and sentiment as part of the quality audit merchants can enable.
  • Send pre-fulfillment cash-on-delivery confirmations, restock notices, and payment-recovery outreach that a merchant has turned on.
  • Show merchants analytics about conversation volume, channel mix, and response performance.
  • Maintain the security of the Vendly dashboard and investigate misuse.

AI processing

Message content is sent to Anthropic's Claude models to generate the AI agent's replies. Voice-note audio is sent to OpenAI's transcription model to produce a text transcript before the agent responds to it.

These providers process this data under their commercial API terms, which state that data submitted through API access is not used to train their general-purpose models. We do not send data to these providers for any purpose other than generating a reply or a transcript for the merchant's conversation.

Other service providers

We share information with the following service providers, only as needed to operate Vendly:

  • Shopify — order, customer, and product data, and store connection.
  • Meta — WhatsApp, Messenger, and Instagram message delivery.
  • Google — Gmail API access for the email channel, where a merchant connects it.
  • Anthropic and OpenAI — AI reply generation and voice-note transcription.
  • Paymob — payment link creation and status.
  • Neon — our Postgres database provider, which stores account, conversation, and order-action records.
  • Vercel — application hosting and file storage for media like images and voice notes.
  • Pusher — real-time delivery of new messages to the dashboard.
  • PostHog — product analytics on the dashboard and marketing site.
  • Meta Pixel — ad measurement on the marketing site (getvendly.com) only, not inside the dashboard or in customer conversations.

We do not sell merchant or customer information to third parties.

Data storage and security

Data is encrypted in transit using HTTPS. Dashboard sessions are authenticated with an HttpOnly session cookie, and access to a store's data is scoped to that store's merchant account.

We retain data for as long as a merchant's store remains connected to Vendly, so conversation history stays available to the merchant's team and the AI agent.

Data deletion and Shopify compliance webhooks

We support Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. When a merchant uninstalls Vendly or a customer requests their data be deleted, we act on these webhooks to remove the corresponding records.

Merchants or customers who want to request access to or deletion of their data outside of these webhooks can contact us at the email below.

Cookies

The Vendly dashboard sets a single functional session cookie needed to keep a merchant signed in. It is not used for tracking.

getvendly.com, our marketing site, uses PostHog and Meta Pixel cookies to measure site usage and ad performance. These do not run inside the merchant dashboard or in customer conversations.

Children's privacy

Vendly is a business tool for merchants and is not directed at children. We do not knowingly collect information from children under 13 through the Vendly dashboard.

International data transfers

Vendly's infrastructure providers may process and store data outside of the country where a merchant or customer is located. We rely on our providers' own safeguards for cross-border transfers.

Changes to this policy

We may update this policy as Vendly's features change. We will update the date at the top of this page when we do, and material changes will be communicated to merchants directly.

Contact us

Questions about this policy, or requests about your data, can be sent to privacy@getvendly.com.