Last updated: 2026-07-31
This policy explains what data Selbi (operated by Selbi Technology Pvt Ltd) accesses when a merchant connects their store to us, why we access it, who we share it with, and how to request its deletion. It applies to merchants who connect a Shopify store to Selbi, and to their end customers whose data passes through the Service.
When a merchant connects Selbi to their Shopify store and support inbox, we access:
When a merchant connects a Gmail or Google Workspace mailbox, Selbi accesses the following through the Gmail API:
We request two Gmail scopes and no others:
gmail.readonly, to read incoming messages, and gmail.send, to send
the merchant's reply from their own address. We do not modify, label, archive
or delete any message, and we do not read mail that predates the connection — synchronisation
begins from the moment the mailbox is connected. A merchant can disconnect at any time from
Settings → Integrations, which revokes our access at Google and deletes the stored
credential.
We only access what is needed to operate the Service for the merchant who connected their account. We do not access data from stores that have not connected to Selbi.
We use the data above to: read and classify incoming support messages, draft replies, propose store actions for merchant approval, and show the merchant a unified view of a customer's orders and conversation history inside their Selbi dashboard. Drafting replies and classifying messages involves sending relevant message and order content to our AI sub-processor (see below) for processing.
We share data with the following third parties strictly to operate the Service:
| Sub-processor | Purpose |
|---|---|
| Anthropic | AI language processing of support messages and drafted replies |
| Groq | AI classification of incoming support messages (fast inference tier) |
| Fireworks AI | AI classification of incoming support messages (fast inference tier) |
| Supabase | database hosting and storage of your account and customer data |
| Razorpay / Paddle | payment processing for subscription billing |
| Clerk | identity and sign-in for your team’s dashboard access |
| Inngest | background workflow processing of support conversations — carries customer addresses and order references as they are handled |
| Google Cloud | application hosting, secret storage, and operational logs |
| Upstash | session and one-time verification code storage for chat identity verification |
| Vercel | hosting for the merchant dashboard |
We do not sell merchant or customer data to anyone, for any purpose. We do not share data with third parties for their own marketing or advertising use.
Drafting replies and classifying messages involves sending message content to the AI providers named above — Anthropic, Groq and Fireworks AI. Each of them operates under terms that prohibit using data submitted through their APIs to train or improve their models.
Selbi does not use your data, or your customers' data, to develop, improve or train any model of our own. Message content is processed to answer the message in front of us and is not accumulated into a training set.
Selbi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We retain order, customer, and conversation data for as long as a merchant's account is active, so the Service can continue to answer questions using historical context. If a merchant cancels their subscription, we retain their data for a limited period to allow reactivation or export, after which it is deleted from our active systems, except where we are required to retain records for legal, tax, or accounting purposes.
Merchants can request deletion of their account and connected data at any time by emailing support@selbi.app. End customers of a merchant who wish their data removed from Selbi should contact the merchant directly, or email us and we will forward the request to the relevant merchant and assist with deletion from our systems.
Each merchant's data is isolated at the database layer — one merchant's data is never visible to another merchant or to another merchant's customers. Access to production data is limited to what is required to operate and support the Service.
Data is encrypted in transit and at rest. Credentials for connected accounts — such as the token authorising access to a merchant's mailbox — are additionally encrypted at the application layer with a per-merchant authenticated key, so a stored credential cannot be read outside the merchant it belongs to, even from within our own database.
Depending on your location, you may have rights to access, correct, or delete your personal data, or to object to certain processing. To exercise these rights, contact us at support@selbi.app.
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new "Last updated" date.
Questions about this policy? Email support@selbi.app, or see our Contact page for our registered business details.