Privacy policy

Vestfold Hall — Privacy Policy

Last updated: August 10, 2026

Vestfold Hall ("Vestfold Hall," "we," "us," or "our") is a managed AI sales-and-service assistant application for Shopify stores, operated by Gilliam Technical Services LLC. This Privacy Policy explains what information the Vestfold Hall app and chat agent ("the Service") collect, how we use and share it, how long we keep it, and the rights available to merchants and their customers.

Note for merchants: This policy describes how we handle data in providing the Service to you. You remain the data controller for your store and your customers, and you are responsible for your own store privacy policy and for obtaining any consents required in your jurisdiction.

1. Who we are

Service / brand name: Vestfold Hall
Operator: Gilliam Technical Services LLC ("GTS")
Contact for privacy inquiries: privacy@vestfoldhall.com
Mailing address: 142 Eastview Drive #4872, Emerald Isle, NC 28594, USA

If you have questions about this policy or wish to exercise a privacy right, contact us at the email above.

2. What information we collect

We practice data minimization: we request only the data the Service needs to function.

The app requests the following Shopify access scopes: read_products, write_products, read_content, read_themes, read_legal_policies, read_orders, read_customers, read_fulfillments, read_merchant_managed_fulfillment_orders, read_inventory, read_shipping, read_returns, read_online_store_navigation, and unauthenticated_read_product_listings.

Shopify governs four customer fields individually. We request only two of them — email address and postal address. We do not request or receive customers' names, and we do not request or receive customers' phone numbers.

a. Information from the merchant / store (via Shopify APIs)

• Store domain (e.g., your-store.myshopify.com) and store name.

• Store contact email, used to route inquiries and reports to you.

• Product catalog content (read_products, unauthenticated_read_product_listings) — product title, handle, status, description, price range, variant pricing, product type and collections. This builds the knowledge base the agent answers from and lets it recognise sales.

• Product description edits (write_products) — when you review and accept a suggested content fix, we update that product's description. Nothing is written without your explicit approval on screen, and we re-read the published storefront afterwards to confirm the change is actually visible.

• Published store content (read_content) — the titles, text and URLs of your blog posts, used as supplementary knowledge the agent can summarise and link to. This scope also nominally grants access to blog-contributor account details (author email, IP, browser/OS); the app does not read, request or store any of it.

• Theme colour settings (read_themes) — the published theme's colour values only, read-only, used solely to offer brand-match swatches. The theme is never modified.

• Published store policies (read_legal_policies) — the text and public URL of your refund/return, shipping, privacy and terms pages, read-only, so the assistant can summarise and link them faithfully. These are your own published pages; no customer data is involved.

• Inventory levels (read_inventory) — available quantities and inventory policy per variant, to detect products that are live but cannot be bought. Not customer data.

• Shipping configuration (read_shipping) — your delivery zones, rates and methods, to detect gaps such as a zone with no rate or weight-priced shipping on products with no weight. Not customer data.

• Navigation and redirects (read_online_store_navigation) — menu structure and URL redirects, to find links that lead nowhere. Not customer data.

b. Order, fulfillment and returns data (via Shopify APIs)

To answer shoppers' questions about their own orders, to help merchants catch delivery problems before customers complain, and to watch returns activity for the merchant, the Service reads:

• Order records (read_orders) — order number, creation and cancellation dates, financial and fulfillment status, order total, line items, risk assessment and shipping method.

• Fulfillment and shipment records (read_fulfillments, read_merchant_managed_fulfillment_orders) — fulfillment status, shipment status, tracking events and timestamps, and ship-by deadlines.

• A customer identifier (read_customers) — Shopify's opaque internal customer ID only, used to recognise that two orders came from the same buyer. We do not read the customer record's name, email, phone or address through this scope.

• Email address on an order — read for one purpose only: to confirm that a shopper asking about an order is the person who placed it. See §3.

• Shipping address line — read for one purpose only: to flag a delivery address that looks wrong before the delivery fails. See §3.

• Returns (read_returns) — read-only. We watch the return events Shopify reports (requested, approved, declined, closed, cancelled) so the merchant's Health page can show what is waiting and for how long. The app takes no return actions: it does not create, approve, decline or process returns, and it issues no refunds and no shipping labels. Decisions happen in Shopify admin or the merchant's returns tooling, exactly as they would without us.

What we do not do with this data. We do not build shopper profiles across stores. We do not use order or customer data to train any AI model. We do not sell it, and we do not share it for advertising. We do not receive customers' payment card details, which Shopify never exposes to apps.

c. Information from the merchant's customers (shoppers, via the chat widget and support email)

When a shopper interacts with the on-storefront chat widget, we collect:

• The messages the shopper types and the agent's replies (the conversation transcript), including messages exchanged during a live chat with a member of the store's team.

• Any contact information a shopper voluntarily provides — for example an email address or phone number they choose to share so the store can follow up.

• The shopper's IP address and timestamps, used solely for rate-limiting, abuse prevention and security.

• Support email. Each store gets a dedicated support intake address operated by us. When a customer emails it (directly, or because the merchant forwards their public support address to it), we receive and store that email — the sender's address and name, the subject, and the message text — and present it to the merchant as a support ticket. This is the same hand-off record described above, arriving by email instead of chat, and it is retained on the same 60-day schedule (see §6).

When a shopper asks for a person, the transcript and any contact details they shared are passed to the merchant so the merchant can respond. We retain that hand-off record on the merchant's behalf for a limited period (see Retention), and live-chat sessions are automatically deleted within 24 hours.

We do not deploy advertising or cross-site tracking cookies. The widget stores the current conversation in the browser's sessionStorage only, and it is cleared when the session ends.

3. How we use information

• Provide the chat agent — answer shopper questions using the store's product catalog, published content and policies.

• Answer a shopper's questions about their own order. When a shopper asks about an order, the assistant asks for the order number and the email address on that order, and returns status only when both match. The email is used solely to verify that the person asking is the person who placed the order; it is never displayed back, and it is not stored. A shopper who cannot supply the matching email is not told whether the order exists, and repeated failed attempts from the same address are locked out.

• Returns monitoring. Show the merchant the return activity Shopify reports — what has been requested, approved, declined and closed, and how long open returns have been waiting — and annotate cases against the merchant's posted return window. The app makes no return decisions and takes no return actions; Shopify and the merchant handle approvals, refunds, notifications and labels exactly as they would without us.

• Store health monitoring for the merchant. Detect operational problems and report them to the merchant — stalled or failed deliveries, orders paid but not shipped, a shipping zone with no rate, a bestseller out of stock, broken links, content faults, and similar. One of these checks inspects the shipping address line on unfulfilled orders to flag an address that appears undeliverable. These reports are for the merchant's own store and are not shared.

• Support desk. Bring shopper conversations that need a person — and customer emails sent to the store's support intake address — into one queue for the merchant, draft replies for the merchant to review and send, and record the outcome. Replies to email tickets are sent on the merchant's behalf, carrying the store's name and branding.

• Lead capture and human support — deliver voluntarily shared contact details and the conversation to the merchant, and enable the merchant to respond.

• Intelligence reports — aggregated summaries for the merchant (top questions, product interest, unmet demand). Derived from conversation content and intended to be aggregated, not to profile individual shoppers.

• Security and abuse prevention — rate-limiting and blocking abusive use, including detecting and blocking attempts to guess order numbers or email addresses.

• Service operation, maintenance and support.

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

Automated decision-making. The Service makes no automated decisions about customers. Returns are monitored, never decided: approvals, declines and refunds are performed by the merchant in their own tooling. A shopper chatting with the assistant may ask for a human at any point.

4. AI processing and subprocessors

To deliver the Service we use the following subprocessors. We share only the data necessary for each to perform its function.

• Anthropic, PBC — generates the agent's responses (Claude AI models). Data shared: conversation messages and the store's product knowledge base.

• Cloudflare, Inc. — hosting, edge compute and key-value storage. Data shared: catalog knowledge base, conversation logs, captured leads.

• Render — application hosting and managed database for the merchant-facing app. Data shared: store settings and the application data described in this policy.

• Shopify, Inc. — app platform and data source. Data shared: store, product and order data via Shopify APIs.

• Resend — email delivery and receiving. Outbound: merchant reports, alerts, lead notifications, and the merchant's replies to support tickets. Inbound: customer emails sent to the store's support intake address are received on our infrastructure at Resend before becoming tickets. Data shared: merchant email addresses and report content; for support email, the customer's email address, name, subject and message text.

Conversation content sent to Anthropic is processed to generate a reply and is not used to train Anthropic's models under our API terms.

Order lookups are reduced before any model sees them. When a shopper asks about an order, our own server performs the lookup and returns only the status facts needed to answer — order number, status, dates and tracking. The customer's email address and postal address are not placed in the model prompt.

5. Where data is stored and processed

Data is stored and processed on Cloudflare's and Render's infrastructure. The Service is operated from the United States. By using the Service, merchants and shoppers understand that data may be processed in the United States and other countries where our subprocessors operate.

6. How long we keep data

• Product catalog knowledge base — kept current; refreshed from the store and replaced on update. Deleted when the app is uninstalled and the retention period elapses.

• Conversation transcripts / logs — automatically expire approximately 30 days after the interaction.

• Live-chat sessions — automatically deleted within 24 hours.

• Support hand-off records — retained up to 60 days, or until deleted on request or when the store's data is purged.

• Email support tickets — completed tickets are deleted 60 days after completion, the same schedule as support hand-off records. Open tickets are retained until the merchant completes them or the store's data is purged.

• Captured leads — retained so the merchant can act on them, until deleted on request or until the store's data is purged.

• Order and fulfillment records — we retain only the operational facts needed to run the health checks and the returns watch (order number, status, dates, totals, line items). These are refreshed from Shopify and are deleted when the store's data is purged.

• Returns records — retained while the app is installed so the merchant keeps a complete return history, exportable as CSV at any time, and purged with the rest of the store's data on uninstall.

• Protected-data access log — we keep a record of each access to protected customer data: who, when, from which screen, which record, and which field names were read — never the field values. Retained 180 days, then deleted.

• Deletion on request — when we receive Shopify's customers/redact request for a shopper, we delete that shopper's captured contact details, their support hand-off transcripts, and any email support tickets from their address.

• On uninstall — the agent is deactivated immediately. All of the store's data is purged when we receive Shopify's shop/redact request (sent 48 hours after uninstall), or sooner on request.

7. Data subject and consumer rights

Depending on where they live, individuals (including merchants' customers) may have rights to access, correct, delete, or restrict the processing of their personal information, and to not be discriminated against for exercising those rights. This includes rights under the California Consumer Privacy Act (CCPA/CPRA), the Virginia CDPA, the Colorado Privacy Act, and similar U.S. state laws, as well as the EU/UK GDPR where applicable.

How we honor requests:

• We support Shopify's mandatory privacy webhooks: Customer Data Request, Customer Redact, and Shop Redact. When a merchant or Shopify forwards one of these, we respond accordingly — compiling or deleting the relevant data.

• Shoppers and merchants may also contact privacy@vestfoldhall.com directly. We verify and respond to requests within the timeframes required by applicable law.

• If a shopper makes a privacy, access, or deletion request through a store's chat widget, the assistant does not action it directly — it records the request and forwards it to that merchant (and, where relevant, to us) to process under this policy.

• Because Vestfold Hall acts as a service provider / processor to the merchant, we will also assist the merchant in responding to requests they receive directly.

8. Security

We protect information using industry-standard measures, including:

• Encryption in transit (HTTPS/TLS) for all data exchange, and encryption at rest for our application database and key-value storage, including all backups. Our database provider encrypts primaries, replicas and backups with AES-256; our key-value storage is encrypted with AES-256-GCM.

• Secret management — API keys and shared secrets are stored as encrypted, write-only secrets and are never exposed to the storefront or to shoppers.

• Least-privilege access — the app requests only the scopes listed in §2, and only two of the four protected customer fields. It does not request customer names. It does not request phone numbers. It does not edit your theme, and it does not read the blog-contributor personal data that read_content nominally exposes.

• Access logging — every read of protected customer data is recorded, including failed and denied attempts. The log stores field names, never field values.

• Verification before disclosure — order information is released to a shopper only on a matching order number and email address, and an unmatched request is answered identically to a request for an order that does not exist.

• Abuse and rate-limit controls, including lockout after repeated failed order lookups, and per-address and per-store ceilings.

• Separation of environments — development and testing run against separate Shopify applications, separate hosting services and separate databases from production.

• Limited staff access to production data, with strong authentication and two-factor authentication required.

• Documented procedures — we maintain a written data-loss-prevention strategy and a written security incident response policy, including a 72-hour merchant notification commitment.

No method of transmission or storage is 100% secure, but we work to protect your information and to notify affected parties of incidents as required by law.

9. Children's privacy

The Service is intended for use by merchants and the general shopping public. It is not directed to children, and we do not knowingly collect personal information from children under the age of 16 (or the age defined by local law).

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying merchants. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

11. Contact

Gilliam Technical Services LLC — Vestfold Hall
Privacy inquiries: privacy@vestfoldhall.com
Mailing address: 142 Eastview Drive #4872, Emerald Isle, NC 28594, USA