Privacy Policy

    Last updated: 10 September 2026

    1. Introduction

    Auto Recover AI ("Auto Recover", "we", "us", or "our") respects your privacy and is committed to protecting personal data.

    This Privacy Policy explains how we collect, use, store and protect personal data when you use the Auto Recover service, visit our website, install or use our Shopify application, or otherwise interact with us.

    Auto Recover provides automated abandoned-cart recovery services to e-commerce merchants, including AI-powered SMS conversations with customers who have abandoned a checkout or cart.

    For the purposes of applicable data protection law, Auto Recover may act as:

    • a data controller in relation to merchant account information, billing information, website visitors and other information we determine the purposes of processing;
    • a data processor when processing customer personal data on behalf of a merchant in connection with the Auto Recover service.

    Where Auto Recover acts as a processor, the merchant remains responsible for determining the purposes and lawful basis for processing its customers' personal data and for ensuring that it has the necessary rights and permissions to provide that data to Auto Recover.

    We comply with applicable UK data protection laws, including the UK GDPR and the Data Protection Act 2018, as applicable.

    2. Information We Collect

    2.1 Merchant and Account Information

    When you create or use an Auto Recover account, we may collect:

    • Name and contact details
    • Email address
    • Shopify store name and URL
    • Shopify store and account identifiers
    • Account login and authentication information
    • Service configuration and preferences
    • Subscription and billing information
    • Information relating to your use of the Service
    • Communications between you and Auto Recover support

    Payment and subscription transactions may be processed through Shopify and/or other payment providers used by Auto Recover.

    2.2 Customer Information Processed on Behalf of Merchants

    When a merchant uses Auto Recover, we may process personal data relating to the merchant's customers, including:

    • Customer name
    • Phone number
    • Email address where provided
    • Cart and checkout information
    • Products and quantities in an abandoned cart
    • Cart value
    • Discount codes and offers
    • Checkout and recovery links
    • SMS messages sent and received
    • Conversation history
    • Message delivery information
    • Link clicks and other interaction information
    • Order and purchase information relevant to determining recovery attribution
    • Information required to calculate and report recovered revenue

    The precise information processed depends on the merchant's Shopify configuration and the features enabled within Auto Recover.

    2.3 Technical and Usage Information

    We may also collect technical information such as:

    • IP address
    • Browser and device information
    • Log information
    • Authentication and security information
    • Service usage information
    • Error and diagnostic information

    We use this information to operate, secure, troubleshoot and improve the Service.

    3. How We Use Personal Data

    We may use personal data to:

    • Provide and operate Auto Recover
    • Integrate with Shopify stores
    • Identify abandoned carts and checkouts
    • Send abandoned-cart recovery messages on behalf of merchants
    • Facilitate AI-powered conversations
    • Respond to customer messages
    • Provide recovery links and permitted incentives or discount codes
    • Track customer interactions with recovery messages
    • Attribute purchases and calculate recovered revenue
    • Provide merchants with analytics and reporting
    • Calculate applicable recovery fees
    • Process subscriptions and payments
    • Provide customer support
    • Maintain and improve the Service
    • Detect fraud, misuse and security incidents
    • Comply with legal and regulatory obligations
    • Enforce our Terms of Service

    We do not sell personal data.

    4. Controller and Processor Roles

    4.1 Merchant Customer Data

    For customer data processed through Auto Recover on behalf of a merchant, the merchant generally acts as the data controller and Auto Recover acts as the data processor.

    The merchant is responsible for:

    • determining the purposes for which customer data is processed;
    • determining the appropriate lawful basis for processing;
    • providing appropriate privacy information to its customers;
    • ensuring that its collection and use of telephone numbers complies with applicable law;
    • ensuring that customers have provided any required consent or otherwise satisfy the applicable requirements for SMS communications;
    • configuring Auto Recover appropriately;
    • responding to customer requests where required; and
    • ensuring that its use of Auto Recover complies with applicable laws and regulations.

    Auto Recover processes customer data in accordance with the merchant's instructions and the purposes described in these terms.

    Where Auto Recover processes personal data as a processor, the applicable processing relationship is also governed by the data-processing provisions contained in our Terms of Service and any applicable Data Processing Addendum.

    4.2 Auto Recover Account Data

    Auto Recover acts as a controller for information relating to its own business relationship with merchants, including account administration, billing, security, support and service management.

    5. Legal Bases for Processing

    Where we act as a controller, we may rely on one or more of the following legal bases:

    • Contract: where processing is necessary to provide the Service or manage our relationship with you;
    • Legal obligation: where processing is necessary to comply with applicable law;
    • Legitimate interests: where processing is necessary for legitimate business interests, such as security, fraud prevention, service improvement and business administration, provided those interests are not overridden by applicable rights;
    • Consent: where consent is required and has been obtained.

    Where we act as a processor on behalf of a merchant, the merchant is generally responsible for identifying and documenting the appropriate lawful basis for processing its customers' data.

    6. SMS Messaging and Customer Communications

    Auto Recover facilitates SMS communications between merchants and their customers for abandoned-cart recovery.

    The merchant is responsible for ensuring that it has the legal right to send those messages.

    This includes complying with applicable requirements relating to:

    • consent;
    • direct marketing;
    • electronic communications;
    • privacy;
    • opt-outs;
    • suppression lists;
    • applicable telecommunications requirements; and
    • any requirements imposed by SMS providers or telecommunications carriers.

    Auto Recover may provide features such as opt-out handling, quiet hours and messaging controls, but these features do not transfer the merchant's legal responsibilities to Auto Recover.

    Applicable UK rules concerning electronic marketing can impose specific requirements on SMS and other electronic marketing communications.

    7. AI Processing

    Auto Recover uses artificial intelligence and automated processing to generate and manage customer conversations.

    Depending on the Service configuration, information provided to an AI service may include relevant conversation history, cart information, customer information and instructions necessary to generate an appropriate response.

    We use appropriate contractual and technical measures with our AI and technology providers and seek to limit information shared with them to information reasonably necessary to provide the Service.

    AI-generated responses are generated automatically and may not always be accurate, complete or appropriate. Merchants remain responsible for configuring the Service and reviewing or controlling its use where appropriate.

    8. Third-Party Service Providers

    We use selected third-party service providers to operate Auto Recover. These may include providers for:

    • Shopify integration and commerce data;
    • SMS delivery and telecommunications;
    • AI and machine-learning services;
    • cloud hosting and infrastructure;
    • authentication and security;
    • analytics and monitoring;
    • payment and billing services; and
    • customer support.

    Examples may include Shopify, Twilio and AI infrastructure providers.

    Third-party providers may process personal data only as necessary to provide their services to Auto Recover and/or as otherwise permitted by applicable law.

    We may update our service providers from time to time.

    Where required by applicable data protection law, appropriate contractual protections and authorisations will be maintained for sub-processors. UK GDPR processor contracts generally require provisions covering security, confidentiality, sub-processors, assistance with rights requests and end-of-contract handling.

    9. Data Sharing

    We may disclose personal data:

    • to service providers and sub-processors required to operate the Service;
    • to Shopify where necessary for the Shopify integration;
    • to SMS providers such as Twilio where necessary to send and receive messages;
    • to AI providers where necessary to generate automated responses;
    • to professional advisers where necessary;
    • where required by law, regulation or legal process;
    • to protect the rights, property or security of Auto Recover, our users or others; or
    • in connection with a merger, acquisition, sale or transfer of all or part of our business.

    We do not sell personal data to third parties.

    10. International Data Transfers

    Some of our service providers may process personal data outside the United Kingdom.

    Where personal data is transferred outside the UK and applicable data protection law requires safeguards, we will use an appropriate lawful transfer mechanism, which may include:

    • UK adequacy regulations or adequacy decisions;
    • the UK International Data Transfer Agreement;
    • the UK Addendum to the EU Standard Contractual Clauses; or
    • another lawful transfer mechanism recognised under applicable law.

    11. Data Retention

    We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Service, maintaining records, resolving disputes, complying with legal obligations and enforcing our agreements.

    Unless a different period is required by law or agreed with a merchant:

    • merchant account information may be retained for the duration of the account and for a reasonable period afterwards;
    • customer and abandoned-cart information may be retained for up to 12 months following its creation or the relevant customer interaction;
    • billing and transaction records may be retained for the period required for accounting, tax and legal purposes.

    We may retain limited information for longer where necessary to establish, exercise or defend legal claims, prevent fraud or comply with legal obligations.

    When personal data is no longer required, we will delete it or anonymise it where reasonably practicable.

    12. Data Security

    We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

    These measures may include:

    • encryption in transit;
    • encryption at rest where supported;
    • access controls;
    • authentication and authorisation controls;
    • tenant/data isolation;
    • webhook authentication and signature verification;
    • logging and monitoring;
    • secure development practices;
    • vulnerability and security monitoring; and
    • restricted access to production systems.

    No internet-based service can guarantee absolute security.

    13. Data Breaches

    If we become aware of a personal data breach affecting data processed on behalf of a merchant, we will take appropriate steps to investigate, contain and remediate the incident and notify the relevant merchant where required by applicable law.

    The merchant remains responsible for determining whether it is required to notify affected individuals or a supervisory authority in relation to its role as controller.

    14. Your Rights

    Depending on the circumstances and applicable law, individuals may have rights including:

    • Access to personal data
    • Rectification of inaccurate data
    • Erasure
    • Restriction of processing
    • Data portability
    • Objection to certain processing
    • Withdrawal of consent where processing relies on consent

    Where Auto Recover processes your personal data on behalf of one of our merchant customers, requests relating to that processing may need to be directed to the relevant merchant.

    Where appropriate, we will assist the merchant with responding to such requests.

    For privacy enquiries relating directly to Auto Recover, contact us at:

    elevaytedigital@gmail.com

    We will respond within the timeframe required by applicable law.

    15. Cookies

    Our website and Service may use essential cookies and similar technologies required for authentication, security, session management and operation of the Service.

    Where we use non-essential cookies or similar technologies that require consent, we will obtain consent where required by applicable law.

    16. Children's Privacy

    Auto Recover is a business service and is not directed at children.

    Merchants must not knowingly use Auto Recover to process children's personal data where doing so would breach applicable law.

    17. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time.

    Where we make material changes, we may notify you through the Service, by email or by other appropriate means.

    The "Last updated" date at the top of this Privacy Policy indicates when it was most recently revised.

    18. Contact Us

    If you have questions about this Privacy Policy or our privacy practices, contact:

    Auto Recover AI
    Email: elevaytedigital@gmail.com

    You may also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).

    Information Commissioner's Office