upfall

voidX AI — Privacy Policy

Last Updated: July 22, 2026

upfall Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy and rights of the merchants who install our application and of the shoppers who interact with it. This Privacy Policy describes how we process personal information in connection with voidX AI (the "App"), an AI-powered chat assistant that merchants operating stores on the Shopify platform can embed in their storefronts.

This Policy is established in accordance with the Personal Information Protection Act of the Republic of Korea ("PIPA") and is designed to comply with international data protection laws, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the Act on the Protection of Personal Information of Japan ("APPI") (collectively, "International Data Protection Laws").

This Policy applies only to the App. Our general service and website (voidx.ai) are governed by a separate privacy policy.


Article 1. Purpose of Processing and Legal Basis

  1. The Company processes personal information for the following purposes:

    • Merchant (store owner) information: installing and authenticating the App, connecting to the merchant's Shopify store, provisioning and operating the App, customer support, and service announcements. The App is currently offered free of charge; if paid features are introduced in the future, billing will be processed exclusively through Shopify's billing system.
    • Shopper (store visitor / end-user) information: operating the in-store chat assistant, generating AI responses to shopper messages, maintaining conversation context during a session, and detecting abusive or abnormal usage.
  2. For data subjects subject to the GDPR (EU/EEA/UK residents), the legal basis for processing is as follows:

    • Contract Performance (GDPR Art. 6(1)(b)): establishing and performing the service agreement with the merchant.
    • Compliance with Legal Obligations (GDPR Art. 6(1)(c)): meeting statutory retention obligations under tax, commercial, and other applicable law.
    • Legitimate Interests (GDPR Art. 6(1)(f)): service security, fraud prevention, and service improvement, balanced against data subjects' rights and freedoms.
    • Consent (GDPR Art. 6(1)(a)): where required, for optional communications.
  3. Controller / Processor roles. With respect to shopper data processed through the chat assistant on a merchant's store, the merchant acts as the Controller and is responsible for establishing a lawful basis and for its own privacy disclosures to shoppers; the Company acts as the Processor and processes such data on the merchant's documented instructions. With respect to the merchant's own account and installation data, the Company acts as a Controller.


Article 2. Personal Information Collected and Collection Methods

  1. The Company collects only the minimum information necessary to operate the App. The Company does not intentionally collect sensitive personal information or the personal information of children.

  2. Information collected from or about the merchant (via Shopify's secure installation and authentication flow):

    • Shopify store domain (e.g., example.myshopify.com)
    • Shopify API access token (an encrypted credential used to connect to the store; not shared with third parties)
    • Basic store profile and configuration information necessary to operate the App (store name, primary domain, currency, time zone, country, and Shopify plan type)
    • The Company does not collect the merchant's contact email or other direct contact details through the App.
  3. Product information retrieved from the store (via the Shopify API):

    • Product catalog data such as product titles, descriptions, prices, availability, and images, retrieved on demand to enable the assistant to answer product questions. This is store/business data and generally does not contain personal information; the App does not maintain its own stored copy of the product catalog.
  4. Information collected from shoppers through the chat assistant:

    • Chat conversation content — the messages a shopper types into the chat widget and the AI responses returned. The App does not require shoppers to log in or provide their identity, and does not collect or store any identifier linking a conversation to a specific shopper. Shoppers may voluntarily include personal information in their messages; we ask merchants to advise shoppers not to submit unnecessary personal or sensitive information.
    • Technical information — the App does not store IP addresses, browser details, or operating system information in its application database, and does not link such information to chat content. Standard server access logs containing IP addresses and browser user-agent strings are generated at the infrastructure level for security and operational purposes, are retained for a limited period, and are not linked to chat conversations. The chat widget uses a session identifier to maintain conversation continuity; this identifier is not linked to a shopper's identity.
  5. The App does not access or collect Shopify order data or shopper account personal information (such as names, addresses, or payment details) from the Shopify store.


Article 3. Processing and Retention Period

  1. The Company retains personal information only for as long as necessary for the purposes described above or as required by law.

  2. Retention periods:

    • Merchant account and installation data (including the access token): retained for the duration of the App installation. The access token is destroyed immediately upon uninstallation, and remaining store data is deleted in accordance with Article 9 (Shopify shop/redact webhook), and in any event no later than the periods required by law.
    • Shopper chat conversation content: retained while the App remains installed on the merchant's store, in order to provide conversation history and improve service quality. All chat content associated with a store is deleted upon Shopify's store redaction request following uninstallation (shop/redact, see Article 9), or earlier upon a valid deletion request.
    • Statutory records (where the Company acts as Controller for merchant data): retained for the minimum periods required by applicable law (e.g., records related to contracts and complaints).

Article 4. Disclosure of Personal Information to Third Parties

  1. The Company does not sell personal information. The Company discloses personal information to third parties only with the data subject's consent, on the merchant's documented instructions (where the Company is a Processor), or where required or permitted by law.

  2. The Company does not "sell" or "share" personal information as defined under the CCPA/CPRA and does not process personal information for cross-context behavioral advertising. The Company does not knowingly sell or share the personal information of consumers under 16 years of age.

  3. In accordance with Article 27 of Japan's APPI, the Company does not disclose the personal information of residents of Japan to third parties without a lawful basis.


Article 5. Sub-processors (Entrustment of Processing)

  1. To operate the App, the Company entrusts personal information processing to the following sub-processors:

    Sub-processorPurposeLocationRetention / Usage Period
    Amazon Web Services, Inc. (AWS)Cloud hosting and data storage (region: US, us-east-1)United StatesUntil termination of the processing agreement or fulfillment of purpose
    Anthropic, PBCGeneration of AI chat responses (chat message content is transmitted to Anthropic's API to produce responses)United StatesUnder Anthropic's Commercial Terms and Data Processing Addendum, inputs and outputs are not used to train Anthropic's models, and API logs are retained only for a limited period (Anthropic's default is short-term retention)
  2. Each sub-processor is engaged under a written agreement that restricts processing to the entrusted purpose, prohibits unauthorized re-entrustment, and imposes appropriate technical and organizational safeguards, consistent with PIPA Article 26 and, where applicable, GDPR Article 28 (Data Processing Agreement).

  3. Shopify. Shopify is not a sub-processor of the Company. Shopify operates the platform through which the App is distributed and through which merchant and store data are made available to the Company. Shopify processes personal information as an independent business under its own privacy policy (https://www.shopify.com/legal/privacy).

  4. If the Company adds or changes a sub-processor, it will update this Policy accordingly.


Article 6. Data Storage Location and International Transfer

  1. Storage location. Merchant data and shopper chat content processed by the App are stored and processed on cloud infrastructure located in the United States (AWS, us-east-1).

  2. International transfer for AI response generation. To generate AI responses, shopper chat message content is transmitted to Anthropic, PBC in the United States. Because the Company is established in the Republic of Korea and shoppers may be located in various jurisdictions, this involves the cross-border transfer of personal information.

  3. Transfer safeguards.

    • For transfers subject to the GDPR/UK GDPR, the Company relies on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) with its sub-processors, together with supplementary technical measures such as encryption in transit and at rest.
    • For transfers subject to PIPA, the Company provides notice of overseas transfer in this Policy, including the recipients (AWS, Anthropic), the country of transfer (United States), the items transferred, and the purpose and retention period, and applies appropriate protective measures.
    • All data in transit is protected with SSL/TLS encryption.

Article 7. Rights of Data Subjects and How to Exercise Them

  1. Data subjects may exercise the following core rights: access, rectification, erasure, and restriction of processing.

  2. EU/EEA/UK residents may additionally exercise the rights to data portability, objection, rights relating to automated decision-making, withdrawal of consent, and to lodge a complaint with a supervisory authority.

  3. California residents may exercise the rights to know, to delete, to correct, to opt out of sale/sharing (the Company does not sell or share), to non-discrimination, and may use an authorized agent.

  4. Residents of Japan may exercise the rights to disclosure, correction, and cessation of use under the APPI.

  5. How shoppers exercise rights. Because the merchant is the Controller of shopper chat data, shoppers should generally direct requests to the merchant (the store they interacted with). The merchant can submit the request to us, and we will assist as Processor — including via Shopify's data request and redaction webhooks (see Article 9). Note that because the App stores no identifier linking conversations to individual shoppers, in most cases the Company will hold no personal data attributable to a specific shopper, and will confirm this in response to such requests. Shoppers may also contact us directly using the details in Article 12, and we will route the request appropriately.

  6. How merchants exercise rights. Merchants may contact the Company using the details in Article 12. Uninstalling the App triggers deletion of store data as described in Article 9.


Article 8. Destruction of Personal Information

  1. The Company destroys personal information without undue delay once the retention period expires or the purpose of processing is achieved.

  2. Method. Electronic files are deleted using technical methods that render recovery impossible; any paper records are shredded or incinerated.


Article 9. Shopify Data Protection Requirements (Mandatory Webhooks)

As required for Shopify apps, the Company implements Shopify's mandatory compliance webhooks and responds to them as follows:

  1. customers/data_request — The App does not collect or store any identifier linking chat conversations to individual shoppers. Upon receiving this webhook, the Company records the request and confirms that the App holds no personal data attributable to the requesting shopper — chat conversations cannot be associated with a specific shopper by design.

  2. customers/redact — Upon receiving this webhook, the Company records the request. Because the App stores no shopper identifiers, there is no shopper-attributable personal data to erase. If a merchant separately identifies specific chat content containing personal information and requests its deletion, the Company will delete it.

  3. shop/redact — Approximately 48 hours after a merchant uninstalls the App, Shopify sends a request to erase the store's data. Upon receipt, the Company deletes all data associated with that store, including cached store analysis results, assigned assistant configuration, and all chat conversation content (the encrypted access token is destroyed earlier, at the time of uninstallation). Records of webhook receipt are retained for audit purposes with the store reference removed.

The Company processes these webhooks within the timeframes required by Shopify and applicable law.


Article 10. Cookies and Local Storage

  1. The chat widget may use strictly necessary cookies or local/session storage to maintain the state of an active chat session (for example, to keep a conversation open as the shopper navigates the store). These are essential to the functioning of the chat assistant.

  2. For EU/EEA and UK residents, any non-essential cookies are set only with prior consent, consistent with the ePrivacy Directive and applicable national law. Consent for cookies on the storefront is managed by the merchant.


Article 11. Security Measures

The Company implements technical, administrative, and physical safeguards, including:

  1. Administrative: internal management plans, access governance, and regular staff training.
  2. Technical: access control to processing systems, encryption of credentials (including the Shopify access token) and personal information, security monitoring, and intrusion detection.
  3. Transmission: SSL/TLS encryption for data in transit.
  4. Breach response: in the event of a personal data breach, the Company takes necessary remedial action and notifies affected data subjects, merchants, and relevant supervisory authorities as required by applicable law.

Article 12. Chief Privacy Officer and Contact

  • Name: So Young Lee
  • Position: Chief Privacy Officer (CPO)
  • Email: contact@upfall.co.kr
  • Phone: +82-2-6191-8254
  • Address: 5th Floor, Room 512, JS Tower, 144-19 Samsung-dong, Gangnam-gu, Seoul, Republic of Korea

Data subjects may contact the Chief Privacy Officer regarding any matter related to personal information protection. The Company will respond without undue delay.


Article 13. Remedies for Rights Infringement

  1. Residents of Korea may seek remedies through: the Personal Information Dispute Resolution Committee (1833-6972, www.kopico.go.kr), the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Supreme Prosecutors' Office (1301, www.spo.go.kr), and the National Police Agency (182, ecrm.police.go.kr).

  2. Residents of the EU/EEA, the UK, California, and Japan may lodge complaints with their respective supervisory authorities. Details are available from the Chief Privacy Officer.


Article 14. Changes to This Policy

  1. This Policy is effective as of the date above. If the Company makes changes, it will provide notice at least 7 days before the changes take effect (at least 30 days for material changes affecting data subject rights).

Addendum. This Privacy Policy is effective on July 22, 2026.