Privacy Policy

Last updated: September 7, 2026

Anro Agents ("we", "our", "us") operates the anroagents.com website and the AI Sales Chat Agent application for Shopify. This Privacy Policy explains how we collect, use, and protect your information.

Data Controller

The controller responsible for your personal data under the GDPR is:

Anro Technologies Limited
Nafpliou 15, 3025 Limassol, Cyprus
Registration number: HE 439985
VAT: CY10439985O
Email: support@anroagents.com

Information We Collect

Merchant data: When you install our Shopify app, we access your store's product catalog (titles, descriptions, prices, images, URLs) to enable the AI chat agent to answer customer questions. We also store your Shopify store domain and access tokens required for the integration.

Customer chat data: When a visitor uses the chat widget on your store, we process the chat messages to generate AI responses. Chat messages are processed in real time and stored temporarily to maintain conversation context.

Account data: When you create an account on anroagents.com, we collect your email address and store it securely for authentication and communication purposes.

Access logs on connected domains: If you connect a domain of your own, that domain is served from our infrastructure, and requests to it are recorded in standard web server logs: the requested address, the time, the browser or crawler identification (user agent), the referring page, and the visitor's IP address. These logs cover your agent's page and its discovery manifest. We keep them to operate and secure the service, and to tell you whether AI crawlers and agent registries have actually read your manifest — the thing the domain exists to make possible. They are deleted after 90 days.

Download data: When you request one of the free materials published at anroagents.com/resources, we collect your email address so we can deliver the file — attached to an email, with a download link alongside it. We also record when you requested it, the page or campaign that referred you, and a hashed form of your IP address, which we keep as proof of consent and to stop the form being abused. Marketing email is sent only if you tick the opt-in box on that form; the file itself is delivered either way.

How We Use Your Information

Data Storage and Security

Most of your data is stored on Amazon Web Services (AWS) infrastructure in the European Union (Ireland, eu-west-1, with static site assets in Frankfurt, eu-central-1). Two sets of data sit in a managed Postgres database operated by Neon (Databricks, Inc.), also hosted in the European Union (Frankfurt, eu-central-1): the searchable index built from the material you supply as a knowledge base, and the public registry entries described below. We use industry-standard security measures including encryption in transit (TLS), encryption at rest, and access controls that key every record to the account owning it. The measures are described in the security overview and listed in Annex II of the Data Processing Agreement.

Data Sharing

We do not sell or rent your personal information. We share it only with the providers we need to run the Service, and only for that purpose:

International Transfers

The Service is hosted in the European Union, and data stays there except for two things it has to leave for: generating the agent's replies and indexing your knowledge base, which send conversation content and uploaded material to our AI model provider in the United States; and our own transactional email, which goes through a provider in the United States. Email your agent sends a visitor is not among them — it is sent from a mailbox you connect yourself. Both transfers rely on the mechanism in that provider's own data processing terms — the Standard Contractual Clauses approved by the European Commission, and the EU–U.S. Data Privacy Framework where the provider is certified under it.

Our AI model provider is contractually prohibited from using data sent through its API to train or improve its models, and we do not use your conversations or documents to train any model of our own.

The providers we rely on, what each one receives and where it processes it, are listed at anroagents.com/subprocessors.html.

Data Processing Agreement

Where your agent processes your visitors' personal data, you are the controller and we are the processor acting on your instructions. Those terms — the Article 28 GDPR agreement, the processing details, the security measures and the sub-processor commitments — are set out in our Data Processing Agreement, which applies automatically when you accept the Terms of Service. Nothing needs to be signed for it to be in force; a counter-signed copy is available on request.

How the platform is built and secured is described in the security overview.

What We Publish Publicly

If you use the agent registry, some information about your business is published deliberately, so that other software can find you. The registry entry carries your business name, a description of what the agent does, the services you have priced, the places you serve, the languages the agent answers in, your website and a link to the agent. It carries no contact details and no personal data about you or your visitors.

That entry is served to anyone over plain HTTP without authentication, appears in the public catalogue at catalog.anroagents.com, and — if you verify a domain of your own — in a discovery manifest served for that domain. Other registries and agents may read, copy and redistribute it; that is what the registry is for. Publication is optional: the listing switch in the agent's settings removes the entry from our surfaces, though copies already taken elsewhere are beyond our reach.

Data Retention

Conversations. A conversation is deleted automatically once the retention period for the account has passed, counted from its last message — the transcript, the messages and everything filed under them. The account owner sets that period in Settings, up to the maximum the plan allows: 30 days on Free, 90 on Starter, 180 on Pro, 365 on Business, and as little as 7 days on any plan. The expiry is carried by the database itself, and a nightly process keeps it in step with the chosen period, including on conversations already stored.

Everything else. Product catalog data is retained as long as your app is installed. Access logs for connected domains are retained for 90 days. Application logs are retained for 30 days. Account data is retained until you delete your account. When you uninstall the app, we delete your store data within 30 days. Download data is retained until you ask us to remove it or unsubscribe. Invoices and payment records are kept for as long as tax law requires.

Backups. Deleted data can persist in point-in-time database backups for up to 35 days, after which it is gone. Backups exist to recover the database from a failure; they are not used to bring back individual records.

Your Rights

You can request access to, correction of, or deletion of your data at any time by contacting us, and we answer within 10 working days. Under the GDPR you also have the right to restrict or object to processing, to receive your data in a portable form, and to complain to your supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection.

Most of this needs no request at all. In Settings, under Your data, you can export everything the account holds — profile, agents, conversations with their messages, knowledge base, billing, team and referrals — and you can delete the account outright. Deleting takes your agents offline and out of the public registry immediately; the data is erased seven days later, and you can cancel at any point in those seven days. Conversations are also individually deletable in the dashboard, and the retention period can be shortened for the whole account at any time. Shopify merchants can uninstall the app to stop data collection.

Two things survive an account deletion, and only these: invoices and payment records, which tax law requires us to keep, and a record holding nothing but the account's identifier and the date it was deleted, so that a retained invoice does not point at nothing.

If a visitor to your site asks us directly about data your agent collected, we will not answer them on the substance — that data is yours as controller. We tell them to contact you and forward the request to you.

Cookies and Similar Technologies

On our websites (anroagents.com and directory.anroagents.com) we use a small number of cookies and browser-storage items. Nothing beyond the essential ones is set until you consent through the cookie banner, and the banner asks about two things separately:

You can accept everything, accept analytics only, or decline, and change your choice at any time via the “Cookie settings” link in the footer. If you decline or withdraw consent, the cookies already set are removed. On anroagents.com the banner offers all three choices; directory.anroagents.com runs analytics only and asks a single question.

NameProviderPurposeTypeRetentionConsent
_ga, _ga_RPSV26LEESGoogle Analytics 4Aggregate visitor statistics (pages viewed, sessions)AnalyticsUp to 2 yearsRequired
ph_…_posthogPostHog (EU region)Product analytics (how visitors use the site)AnalyticsUp to 1 yearRequired
apolloAnonId, and two keys prefixed with our Apollo app id (…_canTrack, …_eventQueue)Apollo.io, Inc. (United States)Recognizes the company behind a visit for our own outreach, and records the pages that visit viewed (browser local storage)MarketingPersistent until you withdraw consent or clear your browserRequired (marketing)
__obref, and oaiq_cs:… in browser local storageOpenAI, L.L.C. (United States)Recognizes a visit that arrived from one of our advertisements and whether it convertedMarketingPersistent until you withdraw consent or clear your browserRequired (marketing)
anro-localeAnro AgentsRemembers your chosen interface languageFunctional1 yearNot required (set only when you pick a language)
anro-cookie-consentAnro AgentsStores your cookie choice (browser local storage)EssentialPersistent until clearedNot required

Separately, our chat widget embedded on merchant storefronts uses a session identifier stored in the browser's local storage to maintain conversation context. We do not set tracking cookies on merchant storefronts.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy, please contact us at support@anroagents.com.

← Back to Anro Agents