Privacy policy
How Zobi collects, uses, and protects personal data.
Who we are and what this covers
Zobi is a conversational-commerce sales tool for Shopify stores. It is operated by Zobi OÜ, a private limited company (osaühing) incorporated under the laws of Estonia ('Zobi', 'we', 'us', 'our'), with its registered office at Maakri 23a, Tallinn, Estonia. You can contact us at legal@heyzobi.com.
Zobi connects to a merchant's Shopify store through the Recoup Shopify app and sends AI-written conversational messages to that merchant's customers over iMessage, with SMS and RCS as fallback channels. Those messages help recover abandoned checkouts and drive repeat purchases. The conversations are two-way and may include discount codes and checkout links. The service is early-stage and pre-launch.
This policy explains how we handle personal data that we control. That means data about visitors to our marketing website, data about the people who hold a Zobi merchant account, and our own business and marketing communications. For this data, Zobi OÜ is the controller.
For a merchant's own customers, the roles are different. When we process a merchant's customers' personal data (such as names, phone numbers, emails, and order, checkout, or cart data) to send messages, the merchant is the controller and Zobi OÜ is the processor. We act only on that merchant's documented instructions. Those terms are set out in our data processing addendum. The merchant, not Zobi, decides why and how that data is used and is responsible for responding to its customers' data-subject requests. See the next section if you received a message, and the section on your rights below for more.
If you received a message from a store
If you received a message from a store that uses Zobi and you want to access, correct, or delete your data, the store (the merchant) is the data controller, not Zobi. Please contact that store directly, since they decide how your personal data is used and are responsible for responding to your request. Zobi processes that data only as the merchant's processor, on the merchant's documented instructions, under our data processing addendum. If you send such a request to us anyway, we will, where the DPA requires, forward it to the relevant merchant or assist that merchant in responding, but we cannot decide the outcome of your request ourselves. For details on the messages we send and how to stop them, see our messaging policy.
Personal data we collect
Website visitors
When you visit our marketing website, we collect usage and analytics data, such as pages viewed, approximate location derived from your IP address, device and browser type, and referring links. Some of this is collected through cookies and similar technologies. For details on what we set and how to control it, see our cookie policy.
Merchant account holders
When you sign up for and use a Zobi merchant account, we collect:
- your name and email address;
- your Shopify store domain;
- billing details, processed through Stripe (we fund sending through an ad-spend wallet that you top up; Stripe handles the payment data);
- a Shopify access token that lets us connect to your store through the Recoup app and make the API calls the service needs;
- account and support records, such as settings you configure and messages you send us.
Merchant customers (where we act as processor)
To run the messaging service for a merchant, we process that merchant's customers' personal data, including names, phone numbers, email addresses, and order, checkout, and cart data. We process this data only on the merchant's instructions and only to provide the service. We are the processor for this data; the merchant is the controller. The terms of that arrangement, including our security obligations, are in the data processing addendum.
How we use data and our legal bases
Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on the following legal bases for the data we control:
- Performance of a contract. To create and manage your merchant account, provide the service, process billing through Stripe, and give you support.
- Legitimate interests. To operate, secure, and improve our website and service, understand how the service is used, prevent fraud and abuse, and communicate with you about your account. We balance these interests against your rights.
- Consent. For non-essential cookies and analytics where consent is required, and for any optional marketing communications. You can withdraw consent at any time.
- Legal obligation. To meet our accounting, tax, and other legal requirements, and to respond to lawful requests.
Our legitimate interests include keeping the website and service running and secure, preventing fraud and abuse, understanding and improving how the service is used, and protecting and enforcing our legal rights. Where we rely on legitimate interests, you can object as described under your rights below.
For merchant-customer data that we process as a processor, the merchant is responsible for having a valid legal basis as controller. We do not decide the purposes of that processing.
AI processing of message content
The conversational messages Zobi sends are generated with the help of one or more third-party AI model providers, which act as our subprocessors. To generate a reply, message content and the limited context needed to write it (such as a customer's name and the relevant order, checkout, or cart details) may be processed by these providers.
We process message content only to provide the service and, for merchant-customer data, only on the merchant's instructions under the data processing addendum. We do not sell personal data. We do not use message-recipient personal data, or the content of those messages, to train third-party public AI models. Our subprocessors are bound by contract to use the data only to provide their services to us and not to train their own models on it except as permitted by those contracts. The current AI providers we use are listed on our subprocessors page.
Sharing and subprocessors
We do not sell personal data. We share it with service providers that help us run the business, under contracts that require them to protect it and use it only for the services they provide to us. These include:
- messaging delivery providers, such as Blooio, SendBlue, AgentPhone, and Twilio;
- hosting and storage providers, such as DigitalOcean (EU, Amsterdam) and DigitalOcean Spaces, and Railway, which hosts the Recoup connector and its database;
- Stripe, for billing and payments;
- a third-party AI model provider, which generates the conversational messages.
A current list of the subprocessors we use to provide the service is on our subprocessors page. We may also disclose data where required by law, to enforce our terms, or in connection with a merger, acquisition, or sale of assets, subject to appropriate safeguards.
International transfers
We host the service in the EU (Amsterdam). Some of our subprocessors, including providers based in the United States, may process personal data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA to a country without a European Commission adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and, where applicable, on an adequacy decision or an approved certification framework. The current subprocessors and their locations are listed on our subprocessors page. You can ask us for more information about these safeguards using the contact details below.
How long we keep data
We keep personal data only as long as we need it for the purposes described in this policy, then delete or anonymise it. We decide how long to keep data based on why we hold it, how sensitive it is, whether we still need it to provide the service or to defend or establish legal claims, and what applicable law requires.
In general: account data is kept while your account is active and for a reasonable period afterwards; billing and transaction records are kept as long as tax and accounting law requires (in Estonia, typically up to seven years); and website analytics data is kept for a limited retention window. As a backstop, except where law requires or permits a longer period (for example, to keep accounting records or to defend legal claims), we will not retain personal data we control for longer than ten years after our relationship with you ends. For merchant-customer data that we process as a processor, retention follows the merchant's instructions and the terms of the data processing addendum.
Security
We use reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, loss, and misuse. These include access controls, encryption in transit, and limiting who can access data on a need-to-know basis. The specific measures that apply when we process merchant-customer data as a processor are described in the data processing addendum.
However, no method of transmission over the internet and no method of electronic storage is 100% secure. While we strive to protect personal data, we cannot guarantee its absolute security, and any transmission is at your own risk. To the fullest extent permitted by applicable law, we are not liable for unauthorised access to, or loss, alteration, or disclosure of, personal data that occurs despite our reasonable measures or that is beyond our reasonable control. Nothing in this paragraph limits our obligations or your rights that cannot be limited or excluded under the GDPR or Estonian law.
Your rights
Where the GDPR applies, you have the following rights over personal data we control about you:
- access to your data;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- portability of data you provided to us;
- restriction of processing in certain circumstances;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, where we rely on consent.
To exercise any of these rights, contact us using the details below. To protect your data, we will take reasonable steps to verify your identity before we act on a request, and we may ask for information that lets us confirm who you are. We will respond within the time the law allows (generally one month, which we may extend where the law permits for complex or numerous requests). These rights are not absolute and may be subject to exemptions under the GDPR and Estonian law.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), which is our lead authority, or the supervisory authority in your country of residence or work.
If your request concerns data we process on a merchant's behalf as a processor (for example, messages you received from a store that uses Zobi), please direct it to that merchant, who is the controller of that data. If you send such a request to us, we will pass it on to the relevant merchant or ask you to contact them directly.
California privacy notice
This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
In the past 12 months we have collected the following categories of personal information about the people whose data we control: identifiers (such as name, email, and store domain), commercial information (such as billing and transaction records), internet and network activity (such as website usage and analytics), and inferences drawn from that information.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
Where we handle the personal information of a merchant's California customers in order to provide the messaging service, we act as that merchant's service provider under the CCPA/CPRA. We process that information only to perform the service for the merchant under our contract, and we do not sell or share it or use it for our own purposes. Requests about that information should be directed to the merchant.
Subject to limits in the law, California residents have the right to know what personal information we collect and how we use it, to request access to or deletion of their personal information, to correct inaccurate personal information, and not to be discriminated against for exercising these rights. To make a request, contact us using the details below. We will verify your request before responding, and you may use an authorised agent where the law allows.
Children
Our service is directed to businesses, not to children. We do not knowingly collect personal data from children under the age of 16, the digital-consent age under the GDPR. If you believe a child under 16 has provided us with personal data, contact us and we will take appropriate steps to delete it.
Liability and the role of this policy
This policy is provided for information. It describes our practices but does not, by itself, create rights or obligations beyond those required by law. Our liability for matters relating to personal data and privacy is governed by, and limited and capped in accordance with, our terms and, for merchant-customer data, our data processing addendum, in each case to the fullest extent permitted by applicable law.
Nothing in this policy, our terms, or our data processing addendum excludes or limits any liability, right, or remedy that cannot lawfully be excluded or limited, including any non-waivable rights you have under the GDPR or Estonian law.
Changes to this policy
We may update this policy from time to time. When we do, we will change the 'Last updated' date at the top of the page, and the updated policy takes effect when posted. We will give you additional notice if the changes are significant. Please review this page periodically.
How to contact us
For privacy questions or to exercise your rights, contact us at privacy@heyzobi.com or legal@heyzobi.com.
- Controller: Zobi OÜ (osaühing), registered in Estonia
- Registered office: Maakri 23a, Tallinn, Estonia
- Data protection contact: privacy@heyzobi.com
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), our lead supervisory authority, or with the supervisory authority in your country of residence or work. This policy is governed by the laws of Estonia.
For more on the messages we send and the channels we use, see our messaging policy. For the terms that govern use of the service, see our terms, our data processing addendum, our cookie policy, and our subprocessors page.
This document is provided for general information and does not constitute legal advice. If you have questions about it, contact us at legal@heyzobi.com.

