upfall

voidX AI — Privacy Policy

Last Updated: August 28, 2026

upfall Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy and rights of the merchants who install our application and of the shoppers who interact with it. This Privacy Policy describes how we process personal information in connection with voidX AI (the "App"), an AI-powered chat assistant that merchants operating stores on the Shopify platform can embed in their storefronts.

This Policy is established in accordance with the Personal Information Protection Act of the Republic of Korea ("PIPA") and is designed to comply with international data protection laws, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the Act on the Protection of Personal Information of Japan ("APPI") (collectively, "International Data Protection Laws").

This Policy applies only to the App. Our general service and website (voidx.ai) are governed by a separate privacy policy.


Article 1. Purpose of Processing and Legal Basis

  1. The Company processes personal information for the following purposes:

    • Merchant (store owner) information: installing and authenticating the App, connecting to the merchant's Shopify store, provisioning and operating the App, customer support, and service announcements. The App is currently offered free of charge; if paid features are introduced in the future, billing will be processed exclusively through Shopify's billing system.
    • Shopper (store visitor / end-user) information: operating the in-store chat assistant, generating AI responses to shopper messages, maintaining conversation context during a session, and detecting abusive or abnormal usage.
  2. For data subjects subject to the GDPR (EU/EEA/UK residents), the legal basis for processing is as follows:

    • Contract Performance (GDPR Art. 6(1)(b)): establishing and performing the service agreement with the merchant.
    • Compliance with Legal Obligations (GDPR Art. 6(1)(c)): meeting statutory retention obligations under tax, commercial, and other applicable law.
    • Legitimate Interests (GDPR Art. 6(1)(f)): service security, fraud prevention, and service improvement, balanced against data subjects' rights and freedoms.
    • Consent (GDPR Art. 6(1)(a)): where required, for optional communications.
  3. Controller / Processor roles. With respect to shopper data processed through the chat assistant on a merchant's store, the merchant acts as the Controller and is responsible for establishing a lawful basis and for its own privacy disclosures to shoppers; the Company acts as the Processor and processes such data on the merchant's documented instructions. With respect to the merchant's own account and installation data, the Company acts as a Controller.


Article 2. Personal Information Collected and Collection Methods

  1. The Company collects only the minimum information necessary to operate the App. The Company does not intentionally collect sensitive personal information or the personal information of children.

  2. Information collected from or about the merchant (via Shopify's secure installation and authentication flow):

    • Shopify store domain (e.g., example.myshopify.com)
    • Shopify API access token (an encrypted credential used to connect to the store; not shared with third parties)
    • Basic store profile and configuration information necessary to operate the App (store name, primary domain, currency, time zone, country, and Shopify plan type)
    • The Company does not collect the merchant's contact email or other direct contact details through the App.
  3. Store information retrieved from the merchant's store (via the Shopify API):

    • Product catalog data such as product titles, descriptions, prices, availability, and images, retrieved on demand to enable the assistant to answer product questions. This is store/business data and generally does not contain personal information.
    • Store legal policy documents published by the merchant — such as refund, shipping, terms of service, privacy, and contact policies — retrieved to enable the assistant to answer questions about the store's policies. These documents are published by the merchant on its public storefront and may contain personal information that the merchant has chosen to publish or is required by law to publish (for example, the name, business address, or contact details of a business representative). As Controller, the merchant determines the content of these documents.
    • Theme and storefront configuration information, accessed in order to embed the chat widget in the merchant's storefront and display it correctly. This is configuration data and is not used to generate AI responses.
    • To allow the assistant to search the product and policy material above, that text is converted into numerical vector representations ("embeddings") and held as a search index on the Company's infrastructure (see Articles 5 and 6). Apart from this search index, the App does not maintain a separate stored copy of the merchant's product catalog or policy documents.
  4. Information collected from shoppers through the chat assistant:

    • Chat conversation content — the messages a shopper types into the chat widget and the AI responses returned. The App does not require shoppers to log in or provide their identity, and does not collect or store any identifier linking a conversation to a specific shopper. Shoppers may voluntarily include personal information in their messages; we ask merchants to advise shoppers not to submit unnecessary personal or sensitive information.
    • Technical information — the App does not store IP addresses, browser details, or operating system information in its application database, and does not link such information to chat content. Standard server access logs containing IP addresses and browser user-agent strings are generated at the infrastructure level for security and operational purposes, are retained for a limited period, and are not linked to chat conversations. The chat widget uses a session identifier to maintain conversation continuity; this identifier is not linked to a shopper's identity.
  5. The App does not access or collect Shopify order data or shopper account personal information (such as names, addresses, or payment details) from the Shopify store.


Article 3. Processing and Retention Period

  1. The Company retains personal information only for as long as necessary for the purposes described above or as required by law.

  2. Retention periods:

    • Merchant account and installation data (including the access token): retained for the duration of the App installation. The access token is destroyed immediately upon uninstallation, and remaining store data is deleted in accordance with Article 9 (Shopify shop/redact webhook), and in any event no later than the periods required by law.
    • Shopper chat conversation content: retained while the App remains installed on the merchant's store, in order to provide conversation history and improve service quality. All chat content associated with a store is deleted upon Shopify's store redaction request following uninstallation (shop/redact, see Article 9), or earlier upon a valid deletion request.
    • Product and policy search index: the embeddings derived from the merchant's product catalog and store policy documents are retained while the App remains installed, and are deleted together with the store's other data upon store redaction following uninstallation (shop/redact, see Article 9).
    • Statutory records (where the Company acts as Controller for merchant data): retained for the minimum periods required by applicable law (e.g., records related to contracts and complaints).

Article 4. Disclosure of Personal Information to Third Parties

  1. The Company does not sell personal information. The Company discloses personal information to third parties only with the data subject's consent, on the merchant's documented instructions (where the Company is a Processor), or where required or permitted by law.

  2. The Company does not "sell" or "share" personal information as defined under the CCPA/CPRA and does not process personal information for cross-context behavioral advertising. The Company does not knowingly sell or share the personal information of consumers under 16 years of age.

  3. In accordance with Article 27 of Japan's APPI, the Company does not disclose the personal information of residents of Japan to third parties without a lawful basis.


Article 5. Sub-processors (Entrustment of Processing)

  1. To operate the App, the Company entrusts personal information processing to the following parties. Direct sub-processors are engaged by the Company; re-entrusted sub-processors are engaged by a direct sub-processor with the Company's authorization.

    Sub-processorRelationshipPurposeLocationRetention / Usage Period
    Amazon Web Services, Inc. (AWS)Direct sub-processorCloud hosting and data storage (region: US, us-east-1)United StatesUntil termination of the processing agreement or fulfillment of purpose
    OpenRouter, Inc.Direct sub-processorAI gateway — shopper chat message content is routed through OpenRouter's API to the model providers listed below to generate AI chat responses. The Company uses a dedicated API key that is not shared with any other service.United StatesPrompt and completion content is not retained — input/output logging is disabled for the Company's account and all optional data-sharing features are turned off. Only request metadata (such as token counts, latency, and cost), which contains no message content, is retained. Routing to providers that use data for model training is blocked.
    OpenAI, Inc.Direct sub-processorSearch indexing — merchant product catalog text, published store legal policy text, and the short product-search terms generated by the model provider from a shopper's question, are sent to OpenAI's API to generate vector embeddings. A shopper's original chat message is not sent to OpenAI.United StatesUnder the applicable API terms, inputs are not used to train OpenAI's models. Inputs are retained for up to 30 days for abuse monitoring and are then deleted.
    Google LLCRe-entrusted by OpenRouterGeneration of AI chat responses (primary model provider) — chat message content is routed via OpenRouter to Google's Gemini APIUnited StatesInputs and outputs are not used to train Google's models. Under the applicable provider data policy, inputs and outputs are retained for up to 55 days for abuse monitoring (detection of prohibited-use violations).
    Anthropic, PBCRe-entrusted by OpenRouterGeneration of AI chat responses as a fallback provider — chat message content is transmitted to Anthropic (routed via OpenRouter) only when the primary model is unavailableUnited StatesUnder Anthropic's Commercial Terms and Data Processing Addendum, inputs and outputs are not used to train Anthropic's models, and API inputs and outputs are deleted within 30 days by default.
  2. Contractual safeguards.

    • Direct sub-processors. The Company engages each direct sub-processor under a written agreement that restricts processing to the entrusted purpose, requires the Company's authorization for any re-entrustment, and imposes appropriate technical and organizational safeguards, consistent with PIPA Article 26 and, where applicable, GDPR Article 28 (Data Processing Agreement).
    • Re-entrusted sub-processors. Google and Anthropic are engaged by OpenRouter, with the Company's authorization, solely to generate AI chat responses. The Company has no direct contractual relationship with these providers; the governing data-handling terms are those between OpenRouter and each provider. The Company has verified the training and retention conditions stated in the table above against those providers' published data policies and against its own gateway account configuration.
  3. Shopify. Shopify is not a sub-processor of the Company. Shopify operates the platform through which the App is distributed and through which merchant and store data are made available to the Company. Shopify processes personal information as an independent business under its own privacy policy (https://www.shopify.com/legal/privacy).

  4. Scope of the data sent for search indexing. The embeddings described above are generated from (i) merchant product catalog text and published store legal policy text, and (ii) short product-search terms that the model provider derives from a shopper's question in order to query the search index. A shopper's original chat message is not transmitted to OpenAI.

  5. If the Company adds or changes a sub-processor, it will update this Policy accordingly.


Article 6. Data Storage Location and International Transfer

  1. Storage location. Merchant data and shopper chat content processed by the App are stored and processed on cloud infrastructure located in the United States (AWS, us-east-1).

  2. International transfer for AI response generation. To generate AI responses, shopper chat message content is transmitted to OpenRouter, Inc. in the United States, which routes it to Google LLC (United States) as the primary model provider, or to Anthropic, PBC (United States) as a fallback provider when the primary model is unavailable. Because the Company is established in the Republic of Korea and shoppers may be located in various jurisdictions, this involves the cross-border transfer of personal information.

  3. International transfer for search indexing. To operate product and policy search, merchant product catalog text and published store legal policy text, together with the short product-search terms derived from a shopper's question, are transmitted to OpenAI, Inc. in the United States to generate vector embeddings.

  4. Transfer safeguards.

    • For transfers subject to the GDPR/UK GDPR, the Company relies on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) incorporated into its data processing agreement with Amazon Web Services, and on the data processing terms applicable to its use of OpenRouter and OpenAI. For processing re-entrusted by OpenRouter to the model providers, the Company relies on the transfer safeguards in place between OpenRouter and those providers. All transfers are additionally protected by supplementary technical measures, including encryption in transit and at rest.
    • For transfers subject to PIPA, the Company provides notice of overseas transfer in this Policy, including the recipients (AWS, OpenRouter, OpenAI, Google, Anthropic), the country of transfer (United States), the items transferred, and the purpose and retention period, and applies appropriate protective measures.
    • All data in transit is protected with SSL/TLS encryption.

Article 7. Rights of Data Subjects and How to Exercise Them

  1. Data subjects may exercise the following core rights: access, rectification, erasure, and restriction of processing.

  2. EU/EEA/UK residents may additionally exercise the rights to data portability, objection, rights relating to automated decision-making, withdrawal of consent, and to lodge a complaint with a supervisory authority.

  3. California residents may exercise the rights to know, to delete, to correct, to opt out of sale/sharing (the Company does not sell or share), to non-discrimination, and may use an authorized agent.

  4. Residents of Japan may exercise the rights to disclosure, correction, and cessation of use under the APPI.

  5. How shoppers exercise rights. Because the merchant is the Controller of shopper chat data, shoppers should generally direct requests to the merchant (the store they interacted with). The merchant can submit the request to us, and we will assist as Processor — including via Shopify's data request and redaction webhooks (see Article 9). Note that because the App stores no identifier linking conversations to individual shoppers, in most cases the Company will hold no personal data attributable to a specific shopper, and will confirm this in response to such requests. Shoppers may also contact us directly using the details in Article 12, and we will route the request appropriately.

  6. How merchants exercise rights. Merchants may contact the Company using the details in Article 12. Uninstalling the App triggers deletion of store data as described in Article 9.


Article 8. Destruction of Personal Information

  1. The Company destroys personal information without undue delay once the retention period expires or the purpose of processing is achieved.

  2. Method. Electronic files are deleted using technical methods that render recovery impossible; any paper records are shredded or incinerated.


Article 9. Shopify Data Protection Requirements (Mandatory Webhooks)

As required for Shopify apps, the Company implements Shopify's mandatory compliance webhooks and responds to them as follows:

  1. customers/data_request — The App does not collect or store any identifier linking chat conversations to individual shoppers. Upon receiving this webhook, the Company records the request and confirms that the App holds no personal data attributable to the requesting shopper — chat conversations cannot be associated with a specific shopper by design.

  2. customers/redact — Upon receiving this webhook, the Company records the request. Because the App stores no shopper identifiers, there is no shopper-attributable personal data to erase. If a merchant separately identifies specific chat content containing personal information and requests its deletion, the Company will delete it.

  3. shop/redact — Approximately 48 hours after a merchant uninstalls the App, Shopify sends a request to erase the store's data. Upon receipt, the Company deletes all data associated with that store, including cached store analysis results, assigned assistant configuration, the product and policy search index (including the embeddings derived from that content), and all chat conversation content (the encrypted access token is destroyed earlier, at the time of uninstallation). Records of webhook receipt are retained for audit purposes with the store reference removed.

The Company processes these webhooks within the timeframes required by Shopify and applicable law.


Article 10. Cookies and Local Storage

  1. The chat widget may use strictly necessary cookies or local/session storage to maintain the state of an active chat session (for example, to keep a conversation open as the shopper navigates the store). These are essential to the functioning of the chat assistant.

  2. For EU/EEA and UK residents, any non-essential cookies are set only with prior consent, consistent with the ePrivacy Directive and applicable national law. Consent for cookies on the storefront is managed by the merchant.


Article 11. Security Measures

The Company implements technical, administrative, and physical safeguards, including:

  1. Administrative: internal management plans, access governance, and regular staff training.
  2. Technical: access control to processing systems, encryption of credentials (including the Shopify access token) and personal information, security monitoring, and intrusion detection.
  3. Transmission: SSL/TLS encryption for data in transit.
  4. Breach response: in the event of a personal data breach, the Company takes necessary remedial action and notifies affected data subjects, merchants, and relevant supervisory authorities as required by applicable law.

Article 12. Chief Privacy Officer and Contact

  • Name: So Young Lee
  • Position: Chief Privacy Officer (CPO)
  • Email: contact@upfall.co.kr
  • Phone: +82-2-6191-8254
  • Address: 5th Floor, Room 512, JS Tower, 144-19 Samsung-dong, Gangnam-gu, Seoul, Republic of Korea

Data subjects may contact the Chief Privacy Officer regarding any matter related to personal information protection. The Company will respond without undue delay.


Article 13. Remedies for Rights Infringement

  1. Residents of Korea may seek remedies through: the Personal Information Dispute Resolution Committee (1833-6972, www.kopico.go.kr), the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Supreme Prosecutors' Office (1301, www.spo.go.kr), and the National Police Agency (182, ecrm.police.go.kr).

  2. Residents of the EU/EEA, the UK, California, and Japan may lodge complaints with their respective supervisory authorities. Details are available from the Chief Privacy Officer.


Article 14. Changes to This Policy

  1. This Policy is effective as of the date above. If the Company makes changes, it will provide notice at least 7 days before the changes take effect (at least 30 days for material changes affecting data subject rights).

Article 15. Revision History

DateVersionSummary of Changes
July 22, 20261.0Initial publication.
August 28, 20261.1Added OpenRouter, Inc. as a direct sub-processor (AI gateway) and Google LLC as the primary model provider re-entrusted by OpenRouter; reclassified Anthropic, PBC as a fallback model provider reached via OpenRouter; added OpenAI, Inc. as a direct sub-processor for search indexing; clarified the categories of store information retrieved via the Shopify API, including store legal policy documents and theme configuration (Article 2); updated the international transfer routes and the list of overseas recipients in Article 6; stated the applicable retention periods for each provider; clarified the direct versus re-entrusted sub-processor relationships in Article 5. The model-routing change took effect in the production service on August 27, 2026; this Policy update was published on August 28, 2026.

Addendum. This Privacy Policy is effective on August 28, 2026.