ZaloBot Privacy Policy

Last updated: October 6, 2026

What we collect

When a store installs ZaloBot, Shopify issues an API access token, a refresh token, and the granted access scopes, which we store together with the store's myshopify domain. We use these only to access the store's data on the merchant's behalf. If a staff member opens the app with an online session, Shopify also provides that staff member's name, email, locale, user ID, and account-owner/collaborator status — session staff data we keep until the app is uninstalled (see Retention).

The app relays Zalo messages to the store. For every conversation we store the Zalo user id and display name of the person messaging the bot, the message content (text, photo and caption, sticker, voice), and the media URLs that point at photos and voice notes. We also store each bot's configuration (bot name and Zalo bot id); Zalo bot tokens and secrets are held encrypted at rest.

How we use it

We use this data only to run the app for the installing store — showing the merchant the Zalo chat and answering the messages their bots receive. It is never sold or shared for advertising.

Third parties

Messages travel through the Zalo Bot Platform operated by Zalo Platforms (VNG): the app receives customers' messages from it and sends the merchant's replies to it, using the merchant's own bot token. Zalo processes that data under its own terms and privacy policy. ZaloBot is not affiliated with or endorsed by Zalo or VNG.

Retention

Staff session data is deleted when the app is uninstalled, and again when Shopify sends the shop/redact request. When the app is uninstalled it stops receiving and sending Zalo messages for the store straight away (messages Zalo still delivers are discarded). The Zalo user ids, display names, message content and media URLs already stored are deleted when Shopify sends the shop/redact request, which happens about 48 hours after uninstall.

Your rights and GDPR requests

We answer Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Zalo users are not linked to Shopify customers in this version of the app, so a customers/data_request reports no customer records and customers/redact deletes nothing. Shop deletion (shop/redact) removes all Zalo conversation data and staff session data for the store, as described under Retention. Shoppers with questions about their data should contact the store owner, and merchants can contact us directly using the details below.

Changes

This policy is updated whenever new features start processing new data, and the date above changes to reflect that.

Contact

Questions about this policy or a data request/deletion can be sent to hoangtrongtaitb95@gmail.com.