Confidence.
Built into the details.
Helpful AI needs clear boundaries. Here’s how Convi protects shopper data, verifies sensitive actions and keeps your team in control.
Trust you can look into.
Real controls. Published commitments. Clear answers for your security review.
Protected in transit. And at rest.
Access with a purpose.
The right shopper. The right action.
Infrastructure you can inspect.
A clear data lifecycle.
Commitments in writing.
First, verify.
Then, help.
A chat message alone isn’t proof of identity. Before accessing an order or making a sensitive change, Convi asks the shopper to verify their email.
The shopper asks.
“Can I update my delivery address?”
Convi checks who’s asking.
A one-time code is sent to the order email.
The right action, safely.
The verified shopper can make an eligible change.
Straight answers.
These are the questions procurement teams ask. We prefer to answer them here.
Are you SOC 2 or ISO 27001 certified?
No. Convi does not currently hold a third-party security certification. Our technical and organizational measures are published in the DPA so your team can review the commitments directly.
Do you support SSO or SAML?
Not currently. Administrative access is authenticated per user. Premium and Enterprise include separate team logins and roles, but SAML and OIDC single sign-on are not available.
Can we choose a data region?
Not currently. Convi’s infrastructure and listed subprocessors process data in the United States. International transfers are covered by the EU Standard Contractual Clauses, with the UK and Swiss addenda, as described in our DPA.
Is shopper data used to train AI models?
Our AI subprocessor processes conversations to generate responses and does not use the data to train or improve its models. We do not use one merchant’s shopper conversations to train AI models for other merchants.
What happens when we uninstall?
API keys stop working when a store uninstalls or is suspended. Shopify’s shop-redact and customer-redact webhooks govern deletion requests. On termination, the DPA commits to deletion or return within 90 days, except where the law requires retention. You may request earlier deletion.
The details, documented.
Great conversations.
Extraordinary commerce.
Bring your store’s knowledge, care, and personality
to every customer conversation.