Security at Ustam

Learn how we protect your store and your customers’ data — and what we do with conversations sent to AI.

  • AES-256 at rest

    Database & storage

  • Company isolation

    Per-company encryption

  • No chat tracking

    Storefront widget

  • TLS 1.2+

    In transit

  • 48-hour deletion

    After uninstall

Security measures

Layered controls across encryption, access, AI processing, and the storefront chat widget.

Data protection

  • Encryption in transit (TLS 1.2+)
  • HTTPS enforced everywhere
  • AES-256 encryption at rest (database & storage)
  • Separate encryption key for each company
  • Cryptographic isolation between merchants
  • Managed encryption key rotation

Application security

  • Secure API endpoints
  • Input validation & sanitization
  • SQL injection prevention
  • XSS protection
  • CSRF protection

AI & customer data

  • Conversation content is sent to our AI provider only for product features you use — customer replies when AI is enabled, and admin tools like translation and summaries when your team runs them
  • We do not sell personal information or use it for advertising

Storefront privacy

  • No advertising trackers in the chat widget
  • No storefront analytics trackers in the widget
  • No device fingerprinting
  • No chat cookies

Shopify access

  • Default scopes are read-only
  • Extra permissions only when you enable a feature
  • No payment-card numbers stored by Ustam
  • Shopify compliance webhooks for data requests and deletion

Access & operations

  • Company-scoped tenancy
  • Role-based team access in the admin
  • Session management
  • Audit and security event logging
  • Production access limited to essential personnel
  • Documented incident response procedures
  • 24/7 system monitoring
  • Automated alerting

Hosting

  • Primary hosting and storage in the EU on Google Cloud
  • High-availability database configuration
  • Automated encrypted backups
  • DDoS protection
  • Web application firewall (WAF)
  • Network isolation
  • AI inference may be processed outside the EU

How we handle your data

Short answers to the questions merchants ask most.

Data retention
We retain personal data only as long as needed to provide the service. After you uninstall, related live shop data is deleted within 48 hours. Backup copies are purged within 14 days.
AI processing
Conversation content and related store context are shared with our AI provider only to run features you use: automated replies when AI is enabled on a channel, and admin tools such as translation and summaries when your team runs them.
Shopify permissions
The app installs with read-only access. Order and other optional scopes are requested only when you turn on features that need them. Billing runs through Shopify; we never store card numbers.
Employee access
Access to production systems is limited to essential personnel. You control who on your team can access your company in the admin.
Incident response
We maintain documented procedures for detecting, containing, recovering from, and communicating about security incidents that may affect personal data.
Report a vulnerability
If you find a security issue, email info@ustam.ai with enough detail to reproduce it. Please do not access other customers’ data, and give us a reasonable chance to investigate before public disclosure.

Privacy & compliance

Rights and Shopify privacy requirements we support.

GDPR and KVKK

Data subjects may request access, correction, deletion, portability, and objection, subject to limits required by law. For end-user chat data, the merchant is typically the controller and Ustam acts as a processor. Contact the merchant or info@ustam.ai; we aim to respond within 30 days.

Shopify privacy requirements

We support Shopify’s mandatory customers/data_request, customers/redact, and shop/redact webhooks for export and deletion of customer and shop data stored by the app.

Cross-border processing

Primary production systems are hosted in the European Union. Some providers that help us run the product — including AI inference — may process data in other countries. Where international transfers occur, we use appropriate safeguards as required by applicable law.

Security questions?

Our team can answer questions about our security practices and data-protection posture.

info@ustam.ai