How Jarbris processes data
Last updated: August 14, 2026
This product privacy notice explains how Jarbris processes personal data in providing its service to the Shopify stores that install it. It concerns two different groups of people: the merchants who use Jarbris and the end customers of their stores.
For the data of those who merely visit jarbris.com, the website privacy notice applies instead — it is a separate document.
Two roles, and why they matter
Jarbris acts in two distinct capacities, and which one applies determines who decides:
- Processor for the data of the store's end customers. The controller is the merchant: they determine the purposes and means, and Jarbris processes that data only on their instructions. The relationship is governed by the data processing agreement (art. 28 GDPR).
- Controller for the merchant's own account data — who registers, the store details, billing. There, Jarbris decides and answers directly.
Data processed on behalf of the merchant
This is the data of the store's end customers. Jarbris receives it from Shopify, from the connected messaging channels and from the widget installed on the merchant's site.
- Conversation content — messages exchanged in the site chat, by email and in Instagram and Messenger direct messages, together with their history.
- Identity and purchase history — name, email address, orders, order count and date of the most recent purchase, received from Shopify.
- Abandoned carts — cart contents, email address and the link to resume the purchase.
- Browsing events on the merchant's site — pages and products viewed, add-to-cart actions — and the related session identifiers.
- Channel identifiers — the identifiers by which Instagram and Messenger recognise the sender.
- Consents, return requests and feedback on the answers received.
- Derived data — the customer profile, interests inferred from conversations, the memory of preferences and objections expressed, and the classifications Jarbris produces in order to decide how to reply. This is data Jarbris generates rather than receives, and it still concerns the end customer.
Data processed as controller
This is the data of those who use Jarbris: email address and name of the merchant and their operators, the Google or Microsoft account identifier where those are used to sign in, store details and credentials, billing data and tax documents, and the log of actions performed in the application.
Legal basis: performance of the service contract (art. 6.1.b GDPR), tax and accounting obligations (art. 6.1.c) and the legitimate interest in the security and proper operation of the service (art. 6.1.f).
Sub-processors
To deliver the service, Jarbris relies on the providers listed below, appointed as processors or sub-processors under art. 28 GDPR. The list is current as of the date at the top of this page.
| Provider | Where the data resides | Purpose |
|---|---|---|
| Railway | European Union | Running the application |
| Vercel | United States | Delivering the assistant on the store's site, and the dashboard |
| MongoDB Atlas | European Union (Ireland) | Primary database |
| Sentry | European Union (Germany) | Error monitoring |
| Google — Gemini API | United States | Language understanding and generation |
| Pinecone | United States | Semantic search over the catalogue |
| Resend | United States | Sending and receiving email |
| Meta Platforms | United States | Instagram and Messenger channels |
| Shopify | United States | The store platform |
| Google and Microsoft | United States | Dashboard sign-in with an existing account |
Three clarifications that change the substance
Pinecone does not receive customer text. What goes there is the merchant's catalogue data and, for each search, only the numerical representation of the question: the sentence the customer wrote never leaves the systems described above in readable form.
Google does receive message content, because it is the language model that interprets it and drafts the replies. Jarbris uses the paid tier of the API, for which Google states that it does not use submitted content to train or improve its models and does not subject it to human review, retaining it only for a limited period and solely to prevent abuse.
Emails sent to end customers load two remote resources — typefaces from Google and some icons from cdn.simpleicons.org. When the recipient opens the message, their IP address reaches those two providers. It measures nothing and follows from how the templates are built, but it is a processing operation and it has to be stated.
Transfers outside the European Union
The database, the running application and error monitoring all remain within the European Union. The other providers listed above are established in the United States: transfers to them take place on the basis of the safeguards provided by Chapter V of the GDPR, including the standard contractual clauses adopted by the European Commission.
How long it is kept
- Browsing events: 90 days from collection.
- Chat and email conversations: 365 days from the close of the session.
- Instagram and Messenger conversations: 365 days from the last message.
- A merchant account left with no connected stores: 30 days, then permanent deletion. The window is deliberate, so that a temporary uninstall or an accidental removal from a team does not destroy the account.
- Consent records: for as long as is necessary to demonstrate that consent was obtained, as the accountability principle requires.
- Billing data and tax documents: for the periods imposed by tax legislation.
When the application is uninstalled or the store closes, the associated data is deleted in accordance with the requests Shopify transmits to Jarbris (see the following section).
Security
- Communications encrypted in transit.
- Access tokens for the connected messaging channels (Instagram, Messenger) encrypted at rest with AES-256-GCM.
- Isolation between stores: every record is bound to the store it belongs to, and the queries that serve merchants are restricted to their own store. One merchant cannot reach another's data.
- Access limited to the personnel who need it, and personal data minimised in technical logs.
End customers' rights
For end-customer data the controller is the merchant: requests for access, rectification, erasure, restriction, portability and objection (arts. 15-22 GDPR) are addressed to them. Jarbris assists the merchant in acting on those requests.
Requests that Shopify forwards on behalf of a customer or a store — access to data, erasure of a customer's data, erasure of the store's data — are received and handled by Jarbris automatically, with the authenticity of each request verified.
Changes to the list of sub-processors
The list above is the current source. Before adding or replacing a sub-processor, Jarbris notifies merchants at least 30 days in advance at the email address associated with the account, so that they can assess the change and, if they do not accept it, discontinue the service.
Contact
For any question about this notice, about the data processing agreement or about exercising your rights: info@jarbris.com. The controller's full identification details are in the legal notice.
If you believe the processing infringes the law, you may lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of your own country.
Changes
This notice is updated when the tools or providers used by the service change. The date at the top of the page indicates the most recent revision.