How we handle your account data, your customers' email and chat data, and the data flows involved in AI processing
2026/08/04
Last updated: 4 August 2026
KefuAgents (kefuagents.com) is an AI customer-service product for cross-border ecommerce merchants. The service is operated by an individual developer (in this policy, "we", "us", "KefuAgents"). You can reach us at support@kefuagents.com.
We process two distinct categories of data: your account data (the merchant's own registration, billing and usage information) and your customers' email and chat data (the content of the support mailbox and storefront live chat you authorize us to take over). This policy covers both.
Roles. For your account data we act as the data controller. For your customers' email and chat data we act as your processor: you decide what mailbox to connect, what the AI is allowed to do and what gets sent. By using the service you confirm that you are authorized to let us process the mail in your support mailbox and the conversations in your storefront chat widget, and that you have fulfilled your own privacy-notice obligations toward your end customers under the laws of your region and target markets (for example the GDPR, UK GDPR, and US state privacy laws).
We collect:
Once you connect a support mailbox or install the storefront chat widget, we process the following data belonging to your customers:
How processing works, and its boundaries:
If you install our chat widget on your own store, it collects data about your visitors, and you — not us — are responsible for telling them so in your own privacy notice and obtaining any consent your jurisdiction requires.
The widget:
localStorage (not a cookie), so a returning visitor can resume their most
recent open conversation, by default within 24 hours. The ID is per-browser and
per-store; it is not shared across devices and is not used for advertising.Data is stored in a PostgreSQL database hosted by Supabase; the application runs on Vercel (Singapore region); image attachments and certain webhook payloads are stored in Cloudflare R2 object storage. All transport is TLS-encrypted. Because our providers and our AI subprocessors operate internationally, your data and your customers' data may be transferred and processed outside your own country.
We read the client IP address of requests to our public chat endpoints and use it to enforce rate limits, which is how we stop a single visitor or bot from draining a merchant's AI credits. For the more expensive endpoints the IP is written into a short-lived counter row in our database and is automatically removed once that rate-limit window has expired. We do not use IP addresses for profiling or advertising.
We do not sell your data or your customers' data. We share it only with the providers below, only for the stated purpose, and only to the extent the purpose requires.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting, scheduled jobs | All request traffic, server logs |
| Supabase | PostgreSQL database, realtime updates | All stored application data |
| Cloudflare | Object storage (R2) for attachments; bot protection (Turnstile) on sign-up; DNS; outbound mail delivery when configured as our mail provider | Attachments, webhook payloads, sign-up challenge tokens and IP, outbound notification emails |
| Google (Gemini API, paid tier) | AI classification, drafting, image understanding, real-time chat replies | Email and chat text, order context, image attachments |
| DeepSeek | AI classification, summarization and knowledge extraction; fallback provider | Email and chat text |
| Cloudflare Email Service | Transactional email to you (verification, password reset, notifications) | Your name and email address |
| Waffo | Subscription and top-up payment processing | Your billing contact details and payment instrument, handled by Waffo directly |
| Shopify | Order lookup, when you connect your store | Order and fulfilment data for the orders a support conversation is about |
| Apify | Amazon storefront and product ingestion, when that feature is enabled for your workspace | Public product listing URLs and content of your own listings; no consumer data |
| Jina | Rendering public web pages during website and knowledge ingestion, when enabled | Public URLs of your own website; no consumer data |
| Feishu / DingTalk / WeCom | Approval and review cards, only if you connect one | The review card content you choose to route there |
We may also disclose data when required by law, or where necessary to establish, exercise or defend legal claims.
We do not use any advertising network, retargeting pixel or cross-site tracker, and we run no third-party web analytics.
Cross-workspace learning is off by default. Your workspace contributes to our shared standard library — the reusable question patterns, reply structures and policy templates that benefit every merchant on the platform — only after someone with owner or manager rights turns it on under Settings → Privacy & data in the dashboard. Until that switch is on, nothing in your workspace is read for this purpose.
When it is on, what is contributed is confirmed knowledge archive entries and the reply patterns you adopted, generalized and de-identified: brand and personal names, email addresses, order and tracking numbers, amounts and addresses are stripped, and brand-specific values become placeholders. This is internal product improvement, not model training and not disclosure to other merchants.
You can withdraw at any time with the same switch — your workspace leaves the pool immediately and no later run reads its data. Material already generalized into the shared library contains nothing that identifies you or your customers and is retained.
Design partners who have signed a separate written data agreement with us are covered by that agreement, which is recorded against their workspace; to end it, write to support@kefuagents.com.
Depending on where you are, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing is based on consent. To exercise any of these, email support@kefuagents.com; we respond within 30 days.
If one of your end customers exercises data rights against you — for example asking you to delete their support history — contact us and we will carry out the erasure or export on your behalf, as your processor.
If you believe we have handled your data improperly, you may also complain to your local data protection authority.
Credentials and secrets (mailbox passwords, commerce access tokens, messaging app secrets) are encrypted at rest with AES-256-GCM. Passwords are hashed. All traffic is served over TLS. Access to production data is limited to what operating the service requires. No system is perfectly secure; if a breach affects your data we will notify you without undue delay and, where required, the relevant authority.
The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 as an account holder.
We use only strictly necessary and preference cookies. We set no analytics, advertising or tracking cookies. See the Cookie Policy for the full list.
Material changes will be announced in-app or by email at least 14 days before they take effect. The "last updated" date above always reflects the current version. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
For questions about this policy, to exercise your data rights, or to request erasure of a workspace, email support@kefuagents.com or use our contact form.