Privacy notice

How Getail's website and Shopify app handle store, shopper, and integration information.

Effective September 29, 2026. This notice describes Getail's website and Shopify app. Optional integrations and scheduled operations apply only when configured and functioning; the retention windows below are not guaranteed deletion deadlines.

Operator and contact

Letail, LLC
2969 Riverside Blvd
Sacramento, CA 95818
United States

Contact: support@getail.com.

Scope and responsibility

Getail provides this public website and a Shopify app that merchants may add to their stores. This notice covers information handled by those Getail services. A merchant chooses whether to enable the storefront chat, pickup, loyalty, and optional Google features. Shoppers should also read the notice of the store where they shop. Getail does not replace the merchant's order, payment, or customer-service systems.

Website visits and enquiries

The current static marketing website has no contact-form backend, analytics tracker, advertising pixel, or chat widget in its source. Its contact links open your email application. If you email Getail, your address, message, and any details you include can be handled by the mail-routing provider and the people responding. Avoid sending passwords, API keys, payment details, or customer transcripts by email. The website host and network providers may receive technical request information, such as IP address, requested URL, time, browser details, and error information. Actual production logging and retention settings have not been verified.

Messages to support@getail.com are forwarded to the person responding at pete@letail.com; a reply may come from that address. This website does not currently set analytics or advertising cookies. Hosting and network providers may handle technical request logs according to their own practices.

Information handled by the Shopify app

  • Store and administrator information. The app stores the Shopify store domain, store name and contact details, locale, currency, time zone, installation status, Shopify access sessions, and administrator account fields supplied through those sessions. Merchants set agent instructions, widget appearance, enabled tools, support destinations, and feature settings.
  • Product knowledge. Merchants can select catalog data, pages, public URLs, text-file content, or question-and-answer material for training. Getail stores source metadata, extracted text chunks, and embeddings for retrieval. Merchant-provided source text may itself contain personal information and should be reviewed before it is added.
  • Conversations and contact. Starting a storefront widget session creates a conversation and a short-lived access token. The app stores shopper messages, assistant replies, timestamps, status, usage counts, and events such as answers, escalations, product clicks, and tool calls. A signed-in shopper's Shopify customer ID may be linked to the chat. A shopper requesting email follow-up supplies an address, receives a verification code, and, after verification, has verification/consent times and a handoff ticket recorded. Verification shows access to the mailbox, not ownership of an order.
  • Order questions and pickup. For order status, the app queries Shopify with an order number and compares the supplied email with the order email; the query can return fulfillment, financial status, delivery, and tracking details. For availability and pickup it uses product, inventory, and location data. A proposed reservation can record product, quantity, store, referral source, and any name, email, or phone the shopper supplies. Shopper confirmation can reserve stock and create a Shopify draft order. These records are separate from records held by Shopify and the merchant.
  • Loyalty, if enabled. Shopify paid-order events can create points accounts and transaction entries linked to a Shopify customer ID or store-scoped email hash. The app stores balances, earn/redeem history, order references, and issued discount codes. Signed-in shoppers may check points and request redemption through the widget.
  • Privacy and operational records. The app records Shopify customer-data and redaction webhook receipt, hashed payload identifiers, status, and merchant export/fulfillment attestations. It also keeps job state, billing/usage records, and structured logs used to operate and troubleshoot the service.

The fields present depend on merchant settings, shopper actions, and connected integrations. These features do not require a shopper's payment-card number; do not type one into chat.

AI, Shopify, Google, and other recipients

When a merchant configures its own Google Gemini API key, Getail sends shopper questions and recent chat context, selected knowledge excerpts, instructions, and relevant tool results to Gemini to generate answers. It sends selected source text and shopper search text for embeddings, and can send a Google Business Profile review plus merchant brand instructions to draft a reply. The merchant's API key is stored in encrypted form. AI output can be inaccurate; merchants should supervise knowledge, enabled tools, and public replies.

Shopify supplies store, customer, order, location, product, inventory, billing, and app-authentication data for enabled features. The app can write a Shopify draft order and inventory hold after pickup confirmation, and a discount code when an eligible shopper requests loyalty redemption.

If a merchant connects Google, the app requests permissions to identify the connected account, list Google Chat spaces, manage Business Profile features, and access Merchant Center features. It stores the Google account email, granted scopes, encrypted OAuth tokens, and selected space, location, or Merchant Center account. An enabled Chat handoff can post the shopper's latest question, escalation reason, and an inbox link to the chosen space. Business Profile review sync stores the public reviewer name, rating, comment, timestamps, and draft or posted reply; posting sends a reply to Google. Merchant Center publishing sends mapped product and per-store inventory data, not a shopper contact record by design.

When configured, an SMTP provider sends follow-up verification codes to shoppers and escalation notices to a merchant support address. The notice links to the merchant inbox rather than copying the transcript. Server-side error reports can go to Sentry if enabled; the code removes request bodies and some authentication fields, but this does not guarantee that reports contain no personal data. Structured logs can include store and record identifiers.

These providers receive information only in connection with the applicable configured feature or website operation. Their locations and retention practices may differ from Getail's; contact us for information about the providers currently used for your store.

Security, retention, and deletion

The app encrypts structured shopper contact fields on conversation, pickup, and loyalty records, and merchant AI keys and Google OAuth tokens, using per-store application keys. A store-scoped email hash helps locate customer records. Chat message text is not application-level field encrypted. Authenticated store administrators can use the store-scoped inbox and privacy-request tools. These measures do not mean that all copies at Shopify, Google, email recipients, logs, or backups are encrypted or deleted together.

The code defaults to a 30-day shopper-contact/conversation window and a 90-day activity-event window; merchants can set 7–90 and 30–365 days respectively. A scheduled sweep is written to delete eligible chat transcripts and contact details after inactivity or closure, remove contact details from older pickup records, detach contact details from idle loyalty accounts, and trim old activity events. It does not delete every business record. Pickup/order references, loyalty balances and ledgers, billing/usage records, tickets, and privacy-request audit records may remain. Actual production scheduling and successful sweep runs have not been verified, so these code values are not a guaranteed deletion deadline.

On a Shopify customer-redaction webhook, the code looks for records by Shopify customer ID and/or store-scoped email hash, removes matched chat transcripts and contact details, and detaches contact details from matching pickup and loyalty records. Matching depends on available identifiers. On uninstall, the code removes Shopify sessions, revokes widget access, and tries to revoke/delete the Google connection; it does not immediately remove every store record. On Shopify's later shop-redaction webhook, it deletes the store row and related app tables, while a separate compliance audit record remains. None of this proves deletion from external services, downloaded exports, logs, or backups.

Records retained for billing, usage, loyalty, support, and privacy-request handling may outlast the configurable conversation and activity windows. Copies held by Shopify, Google, email recipients, or backup providers follow separate processes. Contact us about a particular record or request.

Questions and privacy requests

For a purchase, pickup, or loyalty question, contact the store where you shopped. Getail receives Shopify customer-data requests in a store-specific queue. An authenticated merchant can download a scoped export of matched Getail conversations, pickup records, and loyalty data, then verify the requester and record that a response was delivered. The export does not include Shopify's own order export, anonymous chats that cannot be linked to the request, or already-purged records. Downloading does not automatically send the export or close the request. Shopify redaction webhooks trigger the app actions above, subject to delivery and successful processing.

You may write to support@getail.com about Getail's website or app-data handling, including access, correction, or deletion questions. Do not include more shopper information than needed. Store-scoped requests may require identity verification and coordination with the relevant merchant. Replies may come from pete@letail.com.