Legal
Privacy Policy
Effective date: 26 June 2026
1. Who we are
Niak AI (“Niak”, “we”, “us”) operates the niak.ai platform — an AI-powered customer support widget for Shopify and e-commerce merchants. This policy describes how we collect, use, and protect information when you use our service, either as a merchant (dashboard user) or as a visitor chatting through a merchant’s embedded widget.
Contact: iniyanvanand@gmail.com
2. Data we collect
Merchant accounts
- Name and email address (via Clerk authentication)
- Shopify store URL (if connected)
- Billing information (processed by Stripe — we never see raw card numbers). Pricing and the billing model may change over time, including the introduction of usage-based (metered) billing — see our Terms for notice periods.
- Knowledge base content you upload or provide (URLs, FAQ text)
- Dashboard activity and usage metrics
Widget visitors (your customers)
- Chat messages sent through your widget
- Anonymous session identifier (no name, email, or IP stored by default)
- Email address — only if a visitor voluntarily provides it during an escalation when you are offline
- Timestamp and conversation metadata
Automatically collected
- Server logs (request method, path, response code, timestamp) — no message bodies logged
- Basic analytics (page views on niak.ai — not on your store)
3. How we use data
- To operate the AI chat service and generate responses from your knowledge base
- To display conversation history in your merchant dashboard
- To enforce rate limits and protect against abuse
- To send transactional emails (escalation alerts, billing receipts) — no marketing without consent
- To detect and prevent security threats and prompt-injection attacks
- To improve the platform (aggregated, anonymised signals only)
We do not sell, rent, or share visitor conversation data with third parties for advertising. We do not use visitor messages to train AI models.
4. Data isolation
Every query to our database is scoped to your company. No merchant can access another merchant’s conversations, knowledge base, or visitor data. This is enforced at the database level on every request — not just by application logic.
5. Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI response generation | Visitor messages + knowledge chunks |
| OpenAI | Embedding knowledge content | Knowledge text only (no visitor data) |
| Supabase | Database & storage | All structured data (hosted EU/US) |
| Clerk | Merchant authentication | Merchant email & name |
| Stripe | Billing & payments | Billing details (PCI-compliant) |
| Resend | Transactional email | Merchant email + alert content |
| Vercel | Hosting & CDN | Request logs (no message bodies) |
6. Data retention
- Conversation messages: retained for 12 months while your plan is active, then automatically deleted
- Ended or unpaid plans: conversations, messages, and knowledge base content are permanently deleted 14 days after a trial ends or a subscription lapses. Resuming a paid plan within those 14 days cancels the deletion.
- Merchant account data: retained while your account is active, deleted within 30 days of account closure on request
- Visitor session IDs: anonymised after 90 days
- Server logs: purged after 30 days
7. Your rights
Depending on your location, you may have rights under GDPR, UK GDPR, or similar laws, including the right to access, correct, or delete your data. To exercise any of these rights, email us at iniyanvanand@gmail.com. We will respond within 30 days.
Merchants:you are the data controller for your customers’ conversation data. We process it on your behalf as a data processor. You are responsible for informing your visitors that AI chat is in use and that conversations are stored.
8. Cookies
niak.ai uses only essential cookies required for authentication (session token) and security (CSRF protection). We do not use advertising, tracking, or analytics cookies. The widget embedded on your store sets no cookies on your visitors’ browsers.
9. Security
All data is encrypted in transit (TLS 1.2+) and at rest. API keys are never exposed to the browser. We apply rate limiting, prompt-injection filtering, and row-level security on every database query. Security incidents are disclosed to affected merchants within 72 hours.
10. Children
Niak AI is not intended for use by or directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data through a merchant’s widget, contact us and we will delete it promptly.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be notified by email to merchants at least 14 days before they take effect. The effective date at the top of this page will always reflect the current version.
12. Contact
Questions, concerns, or data requests:
iniyanvanand@gmail.com