Legal
Privacy Policy
Effective date: 19 May 2026 ·
Last updated: 19 May 2026 ·
Version: 3.0
Our data pledge
We never use your data — or your customers' data — for any personal purpose. No reselling. No targeted ads. No sneaky training of public models on your private content. Your shop's data is yours. We are simply the trusted pilot helping you fly it.
1. Overview
AI Shop Pilot ("we", "us", "our") is a multi-tenant SaaS platform owned and operated by GoodDeed Software Solutions, registered in India. This Privacy Policy explains, in plain language, what data we collect, why we collect it, how we protect it, and the choices you have.
This policy covers everything you do through the AI Shop Pilot platform — the dashboard, the Autopilot for comments and direct messages, the chat-commerce bot, our mobile applications, our public APIs, and any related services (together, the "Service").
By using AI Shop Pilot, you agree to the practices described here. If you don't agree with any part of this policy, please don't use the Service.
2. Data We Collect
We collect only what we need to run your store and the automations you switch on. Specifically:
| Category | Examples | Why we collect it |
| Account information | Name, email, password hash, phone number | Sign-in, billing, service notices |
| Shop data | Shop name, logo, products, prices, orders, inventory | Running your storefront |
| Customer data | End-customer names, contact details, addresses, order history | Order fulfilment, on your behalf |
| Payment metadata | Transaction IDs, payment status, refund records | Reconciliation — we never store card numbers |
| Social tokens | OAuth tokens for the social channels you connect | Posting and reading on your behalf, when you ask |
| Autopilot data | Public comments on your posts, captured leads, replies sent | So Autopilot can do its job |
| Chat data | Messages between your store's bot and your customers | Bot operation and order tracking |
| Usage data | Log files, page views, feature usage, browser type, IP | Reliability, security, debugging |
We do not store card numbers, CVVs, or banking credentials. All payment processing happens through certified payment gateways under their own privacy terms.
3. How We Use Your Data
We use the data we collect strictly to provide the Service you signed up for:
- To operate the AI Shop Pilot platform and the features you have switched on
- To process orders, payments, returns and shipping on your behalf
- To publish, schedule, and analyse posts on the social channels you have connected
- To run Autopilot — analyse comments, capture leads, post replies, and direct-message order links on your behalf
- To operate the chat-commerce bot for your customers
- To generate AI content suggestions only within your account and never train shared/public models on your private data
- To send you service messages: invoices, downtime alerts, security notices, and product updates you have opted into
- To investigate abuse, fraud, and security incidents
- To meet our legal obligations under Indian law
4. What We Will Never Do
This is the part most policies skip. Here's the short version:
We will never sell your dataNot to advertisers, brokers, or anyone else — at any price.
We will never use it for personal gainNo team member or affiliate ever uses your store or customer data for personal projects, side businesses, or curiosity.
We will never train shared AI on your private contentYour products, customer messages, and leads are not used to train any public or cross-customer model.
We will never read your DMs for funEngineers can only touch private content for a written support request from you, or for a documented incident response.
No targeted advertisingWe will not profile your customers to serve ads or share signals with ad networks.
No dark patternsAccount deletion, data export, and opt-outs are one click — never buried.
If you ever suspect we have broken any of the above promises, email privacy@aishoppilot.com. We treat every report as a P0 incident.
5. Data Sharing
We only share your data in these tightly scoped cases — each one is bound by a written data-processing agreement:
- Infrastructure providers: our cloud host (India region) and email/SMS delivery providers — strictly to operate the Service.
- Payment gateways & shipping partners: only the minimum data needed to take a payment, ship an order, or process a refund that you initiated.
- Social platforms: the business pages you connect — we post and read only what you authorise via OAuth.
- Chat platforms: messaging APIs are used to operate your bot and Autopilot DMs.
- Legal compliance: only when compelled by a lawful court order or regulatory authority — we will notify you unless legally prohibited.
- Business transfer: if GoodDeed Software Solutions is ever acquired or merged, we will give you notice and the option to export and delete your data before any transfer.
6. Autopilot & AI Processing
Autopilot is the heart of AI Shop Pilot. Here is exactly what it does with data:
- Comment analysis — public comments on your posts are read to detect intent (question, buying signal, complaint, spam) and the product being asked about. Results are saved only to your account.
- Lead capture — when a comment looks like a buying signal, we save the commenter's public handle, the comment, the source post, and the matched product as a lead in your CRM.
- Auto-reply — a public reply is composed in your brand voice and posted from your connected account. You can require manual approval at any time.
- DM order link — a direct message with a personalised order link is sent from your connected account to the customer who commented.
AI processing happens in isolated, per-tenant contexts. Your private data is never used to improve a model that another customer can benefit from. You can turn Autopilot off at any time — leads, replies, and DMs already produced remain in your account for your records.
7. Storage & Security
All data is stored on encrypted servers in India. Our baseline controls include:
- AES-256 encryption at rest for sensitive data
- TLS 1.3 for everything in transit
- Industry-standard password hashing — we never see your password
- Short-lived tokens for API authentication
- Role-based access — staff can only reach the shops they are assigned to, and access is logged
- Regular security reviews and third-party penetration testing
- Daily encrypted backups with versioned retention
If we ever detect a breach affecting your personal data, we will notify you within 72 hours, share what we know, and walk you through what to do next.
8. Cookies & Tracking
We use a small set of cookies:
- Essential cookies — session management and authentication. Required for the platform to work.
- Analytics cookies — anonymised, aggregated usage stats to find broken pages and improve features. No third-party ad networks.
- Preference cookies — to remember your settings.
You can control non-essential cookies through your browser. Turning them off will not break the platform.
9. Your Rights
Under India's Digital Personal Data Protection Act, 2023 and other applicable law, you have the right to:
- Access — request a copy of all personal data we hold about you
- Correction — fix anything that is wrong or incomplete
- Erasure — delete your account and associated data (subject to lawful retention periods)
- Portability — export your data in a machine-readable format
- Objection — object to specific types of processing
- Withdraw consent — disconnect any social account or revoke OAuth at any time, instantly
To exercise any of these rights, write to privacy@aishoppilot.com. We respond within 30 days — usually much faster.
10. Third-party Services
AI Shop Pilot integrates with social and commerce platforms you choose to connect. Each of those platforms has its own privacy policy that governs what they do with your data on their side. We only pass them what is needed for the integration you have authorised.
11. Children's Privacy
AI Shop Pilot is built for businesses and is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, email privacy@aishoppilot.com and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy as the product evolves. We will email you and post a prominent dashboard notice at least 14 days before any material change takes effect. Your continued use of the Service after that date constitutes acceptance of the updated policy.