mailipy.

Privacy Policy

Last updated: 3 September 2026

This is a translation of the Spanish original. In the event of any discrepancy, the Spanish version prevails.

1. Who we are

mailipy («the Service») is an AI-assisted email support tool for e-commerce stores. The controller of your account data is ORGANIC ECOM LLC (EIN 30-1338491), with registered address at 1342 NM 333, Ste C 5130, Tijeras, NM 87059 (United States). Contact: legal@mailipy.com.

2. Two distinct data relationships

It is important to distinguish two levels:

3. What data we process

CategoryDataPurpose
Account Email and password (the password is stored encrypted/hashed and mailipy never sees it in clear text). Create and give access to your account.
Connections Support mailbox credentials (IMAP/SMTP) and Shopify access token, both encrypted at rest. Read incoming email, send approved replies and look up orders.
Support content Support emails (sender, subject, body, thread) and order data retrieved from Shopify (order number, status, tracking, customer name and email). Generate draft replies for your review.
Cart recovery Abandoned checkout data from your store: buyer email, cart items, amount, currency and recovery link. Send the cart recovery emails you have configured.
Service usage Technical logs of service activity. Operate, debug and secure the Service.

4. Legal basis

We process your account data to perform the contract (providing you the Service) and, where applicable, on the basis of legitimate interest (security and product improvement). Your customers' data is processed on your behalf and on your instructions (see DPA).

5. What is sent, and when

Support replies are never sent without your approval. mailipy generates drafts that a person on your team reviews, edits and approves before sending; you stay in control of every reply.

Cart recovery emails are sent automatically, following the sequence you configure and using templates you have approved beforehand. You can turn this feature off at any time, and every recovery email includes an unsubscribe link.

6. Sub-processors (providers)

To provide the Service we rely on providers that process data on our behalf:

ProviderFunctionLocation
Anthropic (Claude API) Generates the draft text from the email content and the order. Anthropic does not use data submitted through the API to train its models. USA (with contractual safeguards — standard contractual clauses).
Google Cloud / Firebase Storage (Firestore), attachments, hosting and backend execution, sign-in authentication, secret management and technical logs. European Union (europe-west1) for the database, attachments and backend. Authentication (Firebase Authentication), technical logs and secret management rely on Google's global infrastructure, which may include the USA, under standard contractual clauses.
Resend Delivery of outgoing email (approved replies and cart recovery emails) for accounts that do not send through their own mailbox. USA (with contractual safeguards — standard contractual clauses).
Your email provider The IMAP/SMTP mailbox you connect (e.g. Gmail or your hosting provider's email). It is your own provider; mailipy only connects using the credentials you supply. Depends on your provider.

7. International transfers

Support content, order data and attachments are stored in the European Union (Google Cloud, europe-west1). The following do leave the EEA: sign-in identity data (Firebase Authentication), technical logs and Google's secret management, draft processing by Anthropic and email delivery by Resend. In addition, ORGANIC ECOM LLC is established in the United States, so operating the Service involves access to data from the USA. Where the GDPR applies, these transfers rely on the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) and on the appropriate safeguards required by law.

8. Retention

These are the periods we apply:

DataPeriod
Support emails, threads, drafts and cart recovery records For as long as the store is active in your account. Deleted when you delete the store.
Store deleted by you from the portal 30 days in the bin (in case the deletion was a mistake) and then irreversible purge of all its data.
App uninstalled in Shopify Shopify sends us the erasure request (shop/redact) 48 h after uninstalling; on receipt we delete that store's data and its credentials.
Erasure request from an end customer (customers/redact) We delete their emails, threads, drafts and recovery records on receipt of the request.
Cart recovery unsubscribes Kept for as long as the store exists, even after the rest is deleted: it is precisely the record that stops us emailing someone who asked not to be contacted again.
Technical logs 30 days (Google Cloud Logging default retention).
Your account and billing data For as long as the account is active and thereafter for the period required by applicable legal and accounting obligations.

You may request erasure at any time by writing to legal@mailipy.com.

9. Security

We apply technical and organisational measures: encryption in transit (TLS), encryption at rest of sensitive credentials, secret management, and logical isolation of data per account so that no customer can access another's data.

10. Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your data, as well as the right to data portability. To exercise them, write to legal@mailipy.com. You may also lodge a complaint with the competent data protection supervisory authority in your country of residence or establishment.

11. Changes

We may update this policy. We will publish the current version on this page along with its update date.