Privacy Policy
Last updated: July 2026
At Mojeeb, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you use our AI-powered customer support platform.
1. Information We Collect
We collect information that you provide directly to us and information that is automatically collected when you use our services:
- Account Information: Name, email address, company name, and contact details when you create an account
- Conversation Data: Customer support conversations, chat messages, and interactions processed through our platform
- Usage Data: Information about how you use our services, including features accessed and time spent
- Technical Data: IP address, browser type, device information, and operating system
- Payment Information: Billing details and payment card information (processed securely through our payment providers)
- Connected Platform Data: Data we access from platforms you choose to connect, strictly as described in Section 4
2. How We Use Your Information
We use the collected information for the following purposes:
- Providing and improving our AI customer support services
- Processing and responding to customer inquiries
- Analyzing sentiment and optimizing response quality
- Sending service updates, security alerts, and support messages
- Processing payments and managing subscriptions
- Complying with legal obligations and protecting our rights
- Improving our AI models and service performance
3. Our Role: Controller and Processor
Mojeeb plays two different roles depending on whose data is involved, and this determines who is responsible for what.
- As a controller. For the account information of our own business customers — the people who sign up for and administer a Mojeeb account — we decide how and why that data is processed, and this Policy governs it.
- As a processor. For the personal data of your customers and end users contained in conversations handled through the platform, you are the data controller and we act as your processor. We process that data only to provide the Services, on your instructions.
Where we act as your processor, you are responsible for establishing a lawful basis for the processing, for providing the required privacy notices to your end users, and for obtaining and evidencing any consents required by applicable law. If an end user contacts us directly to exercise their rights, we will refer them to you and assist you in responding.
4. Connected Platforms & Integrations
Mojeeb only connects to a third-party platform when you explicitly authorize it, and each integration is limited to the narrowest access needed to deliver the feature you enabled. You can disconnect any integration at any time from your dashboard, which immediately revokes our access.
4.1 Shopify
We access your product catalog only. We do not access your customers, orders, or payment data — this is enforced structurally by the permission scope we request, not merely by policy.
- What we access: your product catalog — product titles, descriptions, prices, and availability — under Shopify's
read_productspermission scope, together with your store domain to identify the connection. - What we never access: customer records, order data, checkout or payment information, or any other personal data held in your Shopify store. Our requested scope does not grant access to them, so this is a structural limitation of the integration rather than an internal policy choice.
- Why we access it: so your Mojeeb AI agent can accurately answer shopper questions about your products — availability, pricing, specifications, and similar catalog details.
- How it is handled: catalog data is fetched live from Shopify at the time a question is asked. We do not copy, replicate, or maintain your product catalog in our systems.
Deletion and uninstall
- Uninstalling the Mojeeb app from your Shopify store immediately severs our access to your store.
- On receipt of Shopify's app-uninstall and
shop/redactwebhooks, we delete the stored connection record and the associated access token. - Because we hold no Shopify customer personal data at any point, Shopify's
customers/data_requestandcustomers/redactobligations are satisfied by construction — there is no such data for us to return or erase.
4.2 WhatsApp Business & Meta (Facebook Messenger)
- What we access: messages exchanged between your business and its customers on the channels you connect, together with the sender's platform identifier and profile name, and the business account or page identifiers needed to route replies.
- Why: to receive incoming customer messages, generate replies with your AI agent, and send those replies on your behalf through the channel.
- How it is handled: message content is processed to produce a response and is retained under the limits in Section 7. You remain the controller of your customers' data on these channels, and your use of them is additionally governed by Meta's own terms and policies.
4.3 Instagram
- What we access: direct messages and, where you enable it, comments on your business account, along with the associated account identifiers and public profile name of the person contacting you.
- Why: to let your AI agent reply to direct messages and respond publicly or privately to comments on your behalf.
4.4 Google Sheets & Google Calendar
- What we access: only the specific spreadsheets or calendars you select when authorizing the integration.
- Why: to write captured lead information to your chosen sheet, and to check availability and create bookings in your chosen calendar, when you enable those features.
- What we never access: we do not browse, index, or access other files in your Google Drive account.
4.5 Security of Integration Tokens
Authorization (OAuth) access tokens issued to us by connected platforms are encrypted at rest in our systems and are used solely to query or send messages through the platform that issued them. They are never shared with other customers or third parties, and they are deleted when you disconnect the integration, uninstall the app, or close your account.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption of data in transit (TLS) and at rest
- Encryption of third-party integration tokens at rest
- Secure data storage with regular backups
- Access controls and authentication measures
- Regular security audits and vulnerability assessments
- Practices aligned with GDPR and other applicable data protection regulations
However, no method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and any transmission of data is at your own risk. You are responsible for maintaining the confidentiality of your account credentials and for restricting access to authorized personnel within your organization.
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and provide the information reasonably necessary for you to meet your own notification obligations.
6. Data Sharing and Subprocessors
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- With your explicit consent
- To comply with legal obligations or court orders
- To protect our rights, privacy, safety, or property
- With the service providers (subprocessors) listed below, who assist in operating our platform under contractual confidentiality and security obligations
- In connection with a merger, acquisition, or sale of assets
We use the following subprocessors to deliver the Services:
- Google — AI and large language model processing used to generate agent responses
- Supabase — database and data storage
- Microsoft Azure — application hosting and infrastructure
- Stripe — payment processing
In addition, the messaging and business platforms you choose to connect — such as WhatsApp Business, Meta, Instagram, Google, and Shopify — necessarily receive and transmit data as part of delivering the integration you enabled, as described in Section 4. Each subprocessor may process data only to provide services to us and may not use it for their own purposes. We may update this list as the Services evolve and will reflect changes in this Policy.
7. Data Retention
We retain conversation and message data for a maximum of twelve (12) months. After that period it is permanently deleted or irreversibly anonymized.
Specific retention periods are as follows:
- Conversation and message data: retained for no longer than 12 months from the date the message is processed, then deleted or irreversibly anonymized
- Account and profile information: retained for the life of your account and for up to 12 months after termination, to allow for reactivation and to resolve any outstanding matters
- Billing, invoicing, and transaction records: retained for the period required by applicable tax, accounting, and commercial law, which may exceed 12 months
- Connected platform tokens and connection records: retained only while the integration is connected, and deleted on disconnection, app uninstall, or account closure
- Aggregated and anonymized data: once data is irreversibly anonymized it is no longer personal data and may be retained indefinitely to improve and analyze the Services
- Backups: data deleted from active systems may persist in encrypted backups for up to 90 days until those backups are cycled out in the ordinary course
We may retain information for longer than the periods above where we are required to do so by law, or where retention is necessary to establish, exercise, or defend legal claims, to investigate suspected abuse or security incidents, or to comply with a lawful request from a competent authority. You may request earlier deletion at any time — see our data deletion instructions.
8. AI and Automated Processing
The Services use artificial intelligence and large language models to generate automated replies and to analyze conversations for sentiment, intent, and routing. You should be aware that:
- Conversation content is processed by AI systems, including third-party model providers acting as our subprocessors, in order to generate responses
- AI-generated output is automated and may be inaccurate or incomplete; it should not be relied upon as professional advice
- We do not sell conversation data, and we do not use identifiable customer conversation content to train publicly available third-party foundation models
- We may use aggregated and irreversibly anonymized data to evaluate, tune, and improve the quality and performance of the Services
If your use of the Services involves automated decision-making that produces legal or similarly significant effects for an individual, you are responsible for ensuring an appropriate lawful basis and for providing any human review that applicable law requires.
9. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request a copy of the information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (View detailed instructions)
- Portability: Request your data in a portable format
- Opt-out: Unsubscribe from marketing communications
- Restriction: Request limitation on how we use your information
We will respond to verified requests within the timeframe required by applicable law. We may need to verify your identity before acting, and we may decline requests that are manifestly unfounded, excessive, or that would adversely affect the rights of others. If you are an end user of one of our business customers, please direct your request to that business, which controls the data.
10. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, analyze usage patterns, and improve our services. You can manage cookie preferences through your browser settings, though some features may not function properly if cookies are disabled.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including countries that may not provide the same level of data protection as your jurisdiction. This may occur because our infrastructure, AI model providers, or messaging platform partners operate internationally. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws, such as contractual protections with the recipients. By using the Services, you acknowledge that such transfers are necessary to provide them.
12. Children's Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes through our platform or via email. Your continued use of our services after such notifications constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related inquiries or to exercise your rights, please contact us:
Email: privacy@mojeeb.app
Website: www.mojeeb.app
Data Protection Officer: dpo@mojeeb.app