Last updated: 10 September 2026
Auto Recover AI ("Auto Recover", "we", "us", or "our") respects your privacy and is committed to protecting personal data.
This Privacy Policy explains how we collect, use, store and protect personal data when you use the Auto Recover service, visit our website, install or use our Shopify application, or otherwise interact with us.
Auto Recover provides automated abandoned-cart recovery services to e-commerce merchants, including AI-powered SMS conversations with customers who have abandoned a checkout or cart.
For the purposes of applicable data protection law, Auto Recover may act as:
Where Auto Recover acts as a processor, the merchant remains responsible for determining the purposes and lawful basis for processing its customers' personal data and for ensuring that it has the necessary rights and permissions to provide that data to Auto Recover.
We comply with applicable UK data protection laws, including the UK GDPR and the Data Protection Act 2018, as applicable.
When you create or use an Auto Recover account, we may collect:
Payment and subscription transactions may be processed through Shopify and/or other payment providers used by Auto Recover.
When a merchant uses Auto Recover, we may process personal data relating to the merchant's customers, including:
The precise information processed depends on the merchant's Shopify configuration and the features enabled within Auto Recover.
We may also collect technical information such as:
We use this information to operate, secure, troubleshoot and improve the Service.
We may use personal data to:
We do not sell personal data.
For customer data processed through Auto Recover on behalf of a merchant, the merchant generally acts as the data controller and Auto Recover acts as the data processor.
The merchant is responsible for:
Auto Recover processes customer data in accordance with the merchant's instructions and the purposes described in these terms.
Where Auto Recover processes personal data as a processor, the applicable processing relationship is also governed by the data-processing provisions contained in our Terms of Service and any applicable Data Processing Addendum.
Auto Recover acts as a controller for information relating to its own business relationship with merchants, including account administration, billing, security, support and service management.
Where we act as a controller, we may rely on one or more of the following legal bases:
Where we act as a processor on behalf of a merchant, the merchant is generally responsible for identifying and documenting the appropriate lawful basis for processing its customers' data.
Auto Recover facilitates SMS communications between merchants and their customers for abandoned-cart recovery.
The merchant is responsible for ensuring that it has the legal right to send those messages.
This includes complying with applicable requirements relating to:
Auto Recover may provide features such as opt-out handling, quiet hours and messaging controls, but these features do not transfer the merchant's legal responsibilities to Auto Recover.
Applicable UK rules concerning electronic marketing can impose specific requirements on SMS and other electronic marketing communications.
Auto Recover uses artificial intelligence and automated processing to generate and manage customer conversations.
Depending on the Service configuration, information provided to an AI service may include relevant conversation history, cart information, customer information and instructions necessary to generate an appropriate response.
We use appropriate contractual and technical measures with our AI and technology providers and seek to limit information shared with them to information reasonably necessary to provide the Service.
AI-generated responses are generated automatically and may not always be accurate, complete or appropriate. Merchants remain responsible for configuring the Service and reviewing or controlling its use where appropriate.
We use selected third-party service providers to operate Auto Recover. These may include providers for:
Examples may include Shopify, Twilio and AI infrastructure providers.
Third-party providers may process personal data only as necessary to provide their services to Auto Recover and/or as otherwise permitted by applicable law.
We may update our service providers from time to time.
Where required by applicable data protection law, appropriate contractual protections and authorisations will be maintained for sub-processors. UK GDPR processor contracts generally require provisions covering security, confidentiality, sub-processors, assistance with rights requests and end-of-contract handling.
We may disclose personal data:
We do not sell personal data to third parties.
Some of our service providers may process personal data outside the United Kingdom.
Where personal data is transferred outside the UK and applicable data protection law requires safeguards, we will use an appropriate lawful transfer mechanism, which may include:
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Service, maintaining records, resolving disputes, complying with legal obligations and enforcing our agreements.
Unless a different period is required by law or agreed with a merchant:
We may retain limited information for longer where necessary to establish, exercise or defend legal claims, prevent fraud or comply with legal obligations.
When personal data is no longer required, we will delete it or anonymise it where reasonably practicable.
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
No internet-based service can guarantee absolute security.
If we become aware of a personal data breach affecting data processed on behalf of a merchant, we will take appropriate steps to investigate, contain and remediate the incident and notify the relevant merchant where required by applicable law.
The merchant remains responsible for determining whether it is required to notify affected individuals or a supervisory authority in relation to its role as controller.
Depending on the circumstances and applicable law, individuals may have rights including:
Where Auto Recover processes your personal data on behalf of one of our merchant customers, requests relating to that processing may need to be directed to the relevant merchant.
Where appropriate, we will assist the merchant with responding to such requests.
For privacy enquiries relating directly to Auto Recover, contact us at:
We will respond within the timeframe required by applicable law.
Our website and Service may use essential cookies and similar technologies required for authentication, security, session management and operation of the Service.
Where we use non-essential cookies or similar technologies that require consent, we will obtain consent where required by applicable law.
Auto Recover is a business service and is not directed at children.
Merchants must not knowingly use Auto Recover to process children's personal data where doing so would breach applicable law.
We may update this Privacy Policy from time to time.
Where we make material changes, we may notify you through the Service, by email or by other appropriate means.
The "Last updated" date at the top of this Privacy Policy indicates when it was most recently revised.
If you have questions about this Privacy Policy or our privacy practices, contact:
Auto Recover AI
Email: elevaytedigital@gmail.com
You may also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).