SECURITY & TRUST

Confidence.
Built into the details.

Helpful AI needs clear boundaries. Here’s how Convi protects shopper data, verifies sensitive actions and keeps your team in control.

Encrypted data Verified actions Human controlEvery interaction deserves care.
THE PRACTICAL DETAILS

Trust you can look into.

Real controls. Published commitments. Clear answers for your security review.

Protected in transit. And at rest.

TLS 1.3 protects data in transit. AES-256 encryption through Google Cloud protects data at rest. Integration credentials use a separate encryption key.

Access with a purpose.

Administrative access requires authentication. Roles follow least privilege. API keys are hashed, shown once and revocable.

The right shopper. The right action.

Order tracking, cancellations and shipping-address changes require an emailed one-time code before the assistant acts.

Infrastructure you can inspect.

Convi runs on Google Cloud with logging, monitoring and scoped rate limits. Our public status page records component uptime and incidents.

A clear data lifecycle.

Shopify customer-data and deletion webhooks are implemented. You can request earlier deletion; our DPA sets out return and deletion commitments.

Commitments in writing.

Our DPA defines the processor relationship, security measures and international transfer safeguards. Every subprocessor is listed publicly.
SENSITIVE ACTIONS

First, verify.
Then, help.

A chat message alone isn’t proof of identity. Before accessing an order or making a sensitive change, Convi asks the shopper to verify their email.

Explore order support
Order verificationExample
01

The shopper asks.

“Can I update my delivery address?”

02

Convi checks who’s asking.

A one-time code is sent to the order email.

03

The right action, safely.

The verified shopper can make an eligible change.

YOUR REVIEW, MADE EASIER

Straight answers.

These are the questions procurement teams ask. We prefer to answer them here.

Contact our privacy team
Are you SOC 2 or ISO 27001 certified?

No. Convi does not currently hold a third-party security certification. Our technical and organizational measures are published in the DPA so your team can review the commitments directly.

Do you support SSO or SAML?

Not currently. Administrative access is authenticated per user. Premium and Enterprise include separate team logins and roles, but SAML and OIDC single sign-on are not available.

Can we choose a data region?

Not currently. Convi’s infrastructure and listed subprocessors process data in the United States. International transfers are covered by the EU Standard Contractual Clauses, with the UK and Swiss addenda, as described in our DPA.

Is shopper data used to train AI models?

Our AI subprocessor processes conversations to generate responses and does not use the data to train or improve its models. We do not use one merchant’s shopper conversations to train AI models for other merchants.

What happens when we uninstall?

API keys stop working when a store uninstalls or is suspended. Shopify’s shop-redact and customer-redact webhooks govern deletion requests. On termination, the DPA commits to deletion or return within 90 days, except where the law requires retention. You may request earlier deletion.

YOUR NEXT CHAPTER

Great conversations.
Extraordinary commerce.

Bring your store’s knowledge, care, and personality
to every customer conversation.

7-day trial · No credit card required