BuzzDesk reads your store's orders, pages, products and settings so it can answer your shoppers accurately, and stores the resulting conversations for you. It never sees card details. It never sells data. Your AI key is encrypted and never shown again. A shopper cannot see anything about an order until they prove it is theirs.
Who this covers
Two groups: merchants who install BuzzDesk on their OpoShop store, and the shoppers who use the chat widget on that merchant's storefront. The merchant is the controller of their shoppers' data; BuzzDesk processes it on their behalf.
Store data we read (with your permission)
When you install BuzzDesk you grant it OAuth access to your store. It reads:
- Orders — status, order number, items, shipping address, and each shipment's carrier, tracking number, tracking link and shipped/delivered dates. Used to answer "where is my order?".
- Pages — the text of the policy pages you choose to import (returns, shipping, FAQ), so answers quote your own wording.
- Products — names, options and per-variant availability, to answer stock and variant questions.
- Store settings — your business address, return window, timezone and currency.
- Your OpoShop user identity — only to confirm you own the store you are installing on.
BuzzDesk holds one write permission, used to apply an order change (an address correction or a cancellation) after you personally approve it. It is never used automatically.
Shopper data
- Chat messages — what a shopper types and what BuzzDesk answers, stored so you can read the conversation in your desk.
- Email address and order number — collected only when a shopper chooses to look up an order. The email is checked against that order; if it matches, it is stored on the conversation so you can reply.
- Failed lookup attempts — stored as a one-way hash of the email (never the address itself) purely to rate-limit guessing, and deleted automatically after 24 hours.
- The page path the chat was opened on, without any query string.
We do not collect card or payment details, and BuzzDesk has no access to them. A shopper who does not verify an order sees nothing about any order.
Your AI key
BuzzDesk runs on your own OpenAI or Anthropic API key. When you paste it, it is validated once, encrypted at rest with AES-256-GCM, and stored in a field that is excluded from every ordinary read. No endpoint can return it and it is never displayed again — only its last four characters. It is sent to exactly one place: the AI provider you chose, when answering your shoppers.
Your shoppers' messages and the grounded store facts needed to answer them are sent to that provider under your account and their terms. Nothing is sent to any other AI service.
Where data lives, and for how long
Data is stored in BuzzDesk's own database, scoped per store — one store can never read another's conversations, settings or knowledge. Conversations are kept while the app is installed so your history survives a reinstall; failed-lookup hashes expire after 24 hours. Ask us to delete your store's data at any time and we will.
What we never do
- We never sell, rent or share your data with advertisers or data brokers.
- We never use your store's data or your shoppers' conversations to train any model.
- We never write to an order without your explicit approval.
- We never log your AI key, your store token, or a shopper's raw email in our logs.
Analytics
We record anonymous product events (for example "a conversation was opened") to understand whether BuzzDesk is working. These are keyed to your store's identifier, never to a person, and never contain message content.
Uninstalling
Uninstalling BuzzDesk immediately stops the widget on your storefront and revokes its access to your store. Your conversation history is retained so a reinstall picks up where you left off; email brandon@tryfound.io to have it erased instead.
Contact
Questions, data requests or deletion: brandon@tryfound.io.