Effective date: February 26, 2026 · Last updated: February 26, 2026
Remora (“we,” “us,” or “our”) operates the customer service platform available at app.remora.cx (the “Service”). This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our Service, whether you are a Shopify merchant (“Merchant”), a member of a Merchant’s support team (“Agent”), or a customer of a Merchant (“End Customer”).
We provide the same privacy rights to all individuals, regardless of geographic location. If you are located in the European Economic Area (EEA), United Kingdom, or California, additional details relevant to your rights are noted throughout.
When a Merchant installs the Remora Shopify app and authorizes access, we retrieve the following from the Shopify Admin API:
We request read_customers, read_orders, read_all_orders, read_products, and related scopes. We only access data necessary for customer service operations.
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Ticket resolution & customer service | Customer records, order data, messages | Legitimate interest / contract performance |
| AI ticket classification & draft generation | Ticket content, customer context, order history, knowledge base | Legitimate interest with disclosure |
| Order lookup (WISMO automation) | Order data, fulfillment & tracking info | Contract performance |
| Analytics & reporting | Aggregate ticket volume, response times, CSAT scores | Legitimate interest |
| Account management & authentication | Agent account info, session data | Contract performance |
| Service improvement | Aggregate usage patterns (no PII) | Legitimate interest |
We do not sell personal data. We do not use personal data for advertising, profiling, or automated decision-making that produces legal effects.
Remora uses artificial intelligence (powered by Anthropic’s Claude models) to:
Human oversight: By default, AI operates in “sandbox” mode — all AI-generated responses are drafted for human review. An Agent must explicitly approve and send every reply. Merchants may optionally enable graduated autonomy for low-risk ticket categories, with configurable confidence thresholds and automatic rollback.
AI audit logging: Every AI action (classification, draft generation, auto-resolution) is recorded in an append-only audit log with the model used, input/output tokens, confidence score, and whether the output was sent, edited, or discarded.
Opt-out: Merchants can disable AI processing entirely in Settings. End Customers whose records are marked with a processing restriction are automatically excluded from AI processing.
Anthropic’s Claude API does not use customer data for model training. See Anthropic’s Privacy Policy for details.
We share personal data only with the service providers (“sub-processors”) necessary to operate the Service:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Neon (Neon Inc.) | Primary database hosting | United States |
| Vercel (Vercel Inc.) | Application hosting & edge network | United States (global edge) |
| Anthropic (Anthropic PBC) | AI classification & draft generation | United States |
| Postmark (ActiveCampaign LLC) | Inbound & outbound email delivery | United States |
| Cloudflare (Cloudflare Inc.) | File storage (R2) for email attachments | United States |
We do not share personal data with any other third parties, data brokers, or advertising networks. We may disclose data if required by law, regulation, or valid legal process.
| Data Type | Retention Period | After Retention |
|---|---|---|
| Tickets & messages | Duration of subscription + 30 days | Pseudonymized at 2 years; hard deleted at 5 years |
| Customer records | Duration of subscription + 30 days | Deleted upon account closure or DSAR request |
| AI audit logs | 3 years (PII redacted); metadata retained indefinitely | PII fields redacted; aggregate metadata preserved |
| Email attachments | Same as associated message | Deleted from object storage |
| Webhook event logs | 90 days | Deleted |
| DSAR records | Indefinite (compliance proof) | Never deleted |
| Agent account data | Duration of subscription + 30 days | Deleted upon account closure |
When a Merchant uninstalls the Shopify app, we receive a shop/redact webhook from Shopify and delete all associated shop data within 30 days.
Our Service and all sub-processors are located in the United States. If you are located outside the United States (including in the EEA or UK), your personal data will be transferred to and processed in the United States.
For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Module 2: Controller to Processor, and Module 3: Processor to Sub-Processor where applicable). Our sub-processors maintain their own data transfer mechanisms:
Merchants located in the EEA may request a copy of our Data Processing Agreement (DPA) including SCCs by contacting us at the address below.
Regardless of where you are located, you have the following rights with respect to your personal data:
Contact us at the address below. We will respond within 30 days.
Your personal data is processed by Remora on behalf of the Merchant. To exercise your rights, contact the Merchant directly. If the Merchant is unable to assist, or if you wish to contact us directly, email us at the address below.
Shopify may also forward data subject requests to us via mandatory compliance webhooks (customers/data_request, customers/redact). We process these within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.
We use only essential cookies necessary for the Service to function:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Authentication & session management | 24 hours |
| CSRF state cookie | Shopify OAuth security | 10 minutes |
We do not use analytics cookies, advertising cookies, tracking pixels, or any third-party tracking technologies. We do not participate in cross-site tracking or retargeting.
When a Merchant uninstalls the Remora Shopify app:
shop/redact webhook (delivered 48 hours after uninstall)Merchants may request immediate deletion at any time by contacting us.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify Merchants via email or an in-app notice at least 30 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.
For privacy-related questions, data subject requests, or to request a copy of our Data Processing Agreement:
Remora
Email: privacy@remora.cx
We aim to respond to all requests within 30 days.