Jarbris

How Jarbris processes data

Last updated: August 14, 2026

This product privacy notice explains how Jarbris processes personal data in providing its service to the Shopify stores that install it. It concerns two different groups of people: the merchants who use Jarbris and the end customers of their stores.

For the data of those who merely visit jarbris.com, the website privacy notice applies instead — it is a separate document.

Two roles, and why they matter

Jarbris acts in two distinct capacities, and which one applies determines who decides:

Data processed on behalf of the merchant

This is the data of the store's end customers. Jarbris receives it from Shopify, from the connected messaging channels and from the widget installed on the merchant's site.

Data processed as controller

This is the data of those who use Jarbris: email address and name of the merchant and their operators, the Google or Microsoft account identifier where those are used to sign in, store details and credentials, billing data and tax documents, and the log of actions performed in the application.

Legal basis: performance of the service contract (art. 6.1.b GDPR), tax and accounting obligations (art. 6.1.c) and the legitimate interest in the security and proper operation of the service (art. 6.1.f).

Sub-processors

To deliver the service, Jarbris relies on the providers listed below, appointed as processors or sub-processors under art. 28 GDPR. The list is current as of the date at the top of this page.

Provider Where the data resides Purpose
Railway European Union Running the application
Vercel United States Delivering the assistant on the store's site, and the dashboard
MongoDB Atlas European Union (Ireland) Primary database
Sentry European Union (Germany) Error monitoring
Google — Gemini API United States Language understanding and generation
Pinecone United States Semantic search over the catalogue
Resend United States Sending and receiving email
Meta Platforms United States Instagram and Messenger channels
Shopify United States The store platform
Google and Microsoft United States Dashboard sign-in with an existing account

Three clarifications that change the substance

Pinecone does not receive customer text. What goes there is the merchant's catalogue data and, for each search, only the numerical representation of the question: the sentence the customer wrote never leaves the systems described above in readable form.

Google does receive message content, because it is the language model that interprets it and drafts the replies. Jarbris uses the paid tier of the API, for which Google states that it does not use submitted content to train or improve its models and does not subject it to human review, retaining it only for a limited period and solely to prevent abuse.

Emails sent to end customers load two remote resources — typefaces from Google and some icons from cdn.simpleicons.org. When the recipient opens the message, their IP address reaches those two providers. It measures nothing and follows from how the templates are built, but it is a processing operation and it has to be stated.

Transfers outside the European Union

The database, the running application and error monitoring all remain within the European Union. The other providers listed above are established in the United States: transfers to them take place on the basis of the safeguards provided by Chapter V of the GDPR, including the standard contractual clauses adopted by the European Commission.

How long it is kept

When the application is uninstalled or the store closes, the associated data is deleted in accordance with the requests Shopify transmits to Jarbris (see the following section).

Security

End customers' rights

For end-customer data the controller is the merchant: requests for access, rectification, erasure, restriction, portability and objection (arts. 15-22 GDPR) are addressed to them. Jarbris assists the merchant in acting on those requests.

Requests that Shopify forwards on behalf of a customer or a store — access to data, erasure of a customer's data, erasure of the store's data — are received and handled by Jarbris automatically, with the authenticity of each request verified.

Changes to the list of sub-processors

The list above is the current source. Before adding or replacing a sub-processor, Jarbris notifies merchants at least 30 days in advance at the email address associated with the account, so that they can assess the change and, if they do not accept it, discontinue the service.

Contact

For any question about this notice, about the data processing agreement or about exercising your rights: info@jarbris.com. The controller's full identification details are in the legal notice.

If you believe the processing infringes the law, you may lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of your own country.

Changes

This notice is updated when the tools or providers used by the service change. The date at the top of the page indicates the most recent revision.