Draft. No lawyer has reviewed it yet. What it says describes how the software actually works; the legal wording has not been checked.
Privacy policy — Krealo Chat
Version 3 · effective 6 October 2026 · Krealo Media · ken@krealomedia.com
Draft: no lawyer has reviewed it yet.
Krealo Chat is a live chat that a merchant installs on their site. This page describes what the service stores, why, where, and for how long. It describes how the software actually works, not an intention.
Who does what
The merchant decides what is collected in their conversations and is the data controller. Krealo Media runs the service on their behalf and is the processor. There is one exception, and only one: the merchant's own billing data, where Krealo Media is the controller (see "Billing", below).
Person in charge of the protection of personal information (Québec Law 25, s. 3.1): Keneth Walters, Krealo Media — ken@krealomedia.com. The data processing agreement is here (in French).
What is stored
| Data | Why |
|---|---|
| Conversation messages and attachments (images and PDF, 8 MB max) | That is the conversation. Without it there is no service. |
| A visitor identifier kept in the browser | To recognise the same person's thread when they come back. |
| Pages visited, landing page, referrer, language | So the agent knows which product is being discussed. |
| Device, browser, IP address and the approximate city derived from it | Language, time zone and abuse limits. |
| Cart contents, on Shopify | Read from the store itself, to answer about what the person is about to buy. |
| Email or phone, only if the person types them | To pick the conversation back up and find their orders. |
Krealo Chat never asks for a password or a card number, and has no way to receive one.
Billing
The service has been paid for since 23 September 2026, and an invoice needs data the chat never asked for: the company name, the billing address, an email, the tax number (GST/QST) if the business has one, and the invoice history. Those come from the merchant, not from their visitors.
The card number never reaches us: the payment is handled by our payment provider and the number does not pass through Krealo Chat's servers. What the chat already said — it never asks for a card — remains true word for word.
For that billing data Krealo Media is the controller, not the processor: they are our invoices and our accounting obligation. They are kept for six years, as Canadian tax law requires, so they outlive the closing of the account — it is the only thing we keep for a reason that is not yours.
Shopify store data
With the merchant's authorisation the service reads the store catalogue and, using the email the visitor themselves provided, their last five orders. With no email, no order is requested: the store's customer list is never browsed.
Artificial intelligence
When an agent asks for it, the text of a conversation may be sent to Google's Gemini API to draft a reply, summarise the thread or transcribe a voice message. Nothing is sent automatically; a person has to ask.
A member of the store's team may also connect their own AI assistant (Anthropic's Claude, OpenAI's ChatGPT or Meta's Muse, in the United States) to their Krealo Chat account. That assistant can then read what the member already sees in the console: conversations, notes and visitors. Emails and phone numbers are masked by default, every access is written to the store's audit log, and the member can revoke the connection at any time.
Where
On Google Cloud and Firebase, in the United States (region
us-central1).
For how long
- Visitor record — journey, cart, city, device: anonymised automatically after 30 days.
- Conversations — kept as the business's history. On a deletion request the identity is erased, not the thread: with no name, email, phone, IP or city, what remains identifies nobody. A business cannot make a complaint disappear.
- Invoices — six years, because Canadian tax law requires it.
Your rights
Access, correction, deletion and withdrawal of consent: write to the
merchant, or to
ken@krealomedia.com. Requests sent by Shopify
(customers/data_request, customers/redact,
shop/redact) are handled automatically.
Uninstalling
On uninstall the store access token is deleted immediately and the chat stops appearing. Forty-eight hours later Shopify requests erasure of the shop and visitor records are anonymised.
If you close your account
The chat switches off on your sites. Nothing is deleted: conversations, messages, visitor records and sites stay exactly as they are, with no time limit, and reopening the workspace gives you everything back intact.
One exception, and it is the only one: visitor records keep being anonymised after 30 days of inactivity, the same as for an open account. That deadline protects your store's customers, not your account, so closing yours does not suspend it.
It works this way so that closing an account can be simple: a button that erases eight months of conversations with no way back is a button you have to hide behind three confirmations, and then closing stops being simple.
If you want everything erased, write to us at ken@krealomedia.com and we will do it. That is your right and we have to answer it.