Social Chat Toolkit
FAQ
English 中文

Privacy & data protection

Privacy Policy

This policy explains what Social Chat Toolkit processes, why it is needed, how long it is kept, and the controls available to SHOPLINE merchants and storefront visitors.

Last updated August 31, 2026 Operator: Toolkit Fans Analytics off by default
Contents 1. Scope 2. Merchant data 3. Storefront analytics 4. Customer and app support data 5. How data is used 6. Retention and deletion 7. Service providers 8. Security 9. International processing 10. Your choices 11. Contact
Plain-language summary. Social Chat Toolkit does not read conversations on WhatsApp, Messenger, Telegram, LINE, Viber, or other external platforms. The optional paid Customer Support feature can use SHOPLINE order access to verify an order number and checkout email and return limited order-status and tracking information. It does not expose Admin API credentials to shoppers.
01

Scope and roles

Social Chat Toolkit is a storefront social chat launcher operated by Toolkit Fans. The app helps SHOPLINE merchants configure chat channels, assign rules to markets, control device visibility, and optionally view privacy-aware interaction analytics.

For merchant account and configuration data, Toolkit Fans acts as the service provider operating the app. Merchants remain responsible for the content they configure and for their use of third-party messaging services.

02

Merchant and store data

When a merchant installs and uses the app, we may process:

  • store ID, store handle, store name, primary domain, country or region, and default language;
  • app installation status, granted scopes, access-token lifecycle metadata, and webhook subscription status;
  • theme and market metadata required to open the Theme App Embed and target rules by market;
  • rules, channel types, contact destinations, labels, device visibility, button appearance, and other settings entered by the merchant;
  • administrative locale preferences and operational diagnostics such as request IDs and error codes.

The Customer Support feature may request SHOPLINE order-read permission. Order access is used only for support workflows such as verifying an order number together with the checkout email and returning limited payment, fulfillment, cancellation, update, and tracking status. The app does not provide storefront visitors with unrestricted order or customer-list access.

03

Optional storefront analytics

Anonymous interaction analytics are disabled by default. A merchant must actively enable them in the app. When enabled, the app may record aggregated events such as widget views, launcher clicks, channel clicks, copy attempts, and whether a browser accepted an external handoff action.

When SHOPLINE Customer Privacy API consent and browser settings permit tracking, a random browser identifier may be hashed and used only to estimate unique visitors. We do not store the raw identifier. If tracking is not permitted, the app does not create a persistent visitor identifier.

Analytics do not include chat content, customer names, phone numbers, email addresses, destination URLs, page content, order information, or proof that a third-party messaging app ultimately loaded or a message was sent.

Pre-chat form processing

If a merchant enables the optional pre-chat form, shoppers may select a request type and enter an order reference or additional details before opening a messaging channel. Those answers are processed only in the shopper’s browser to create a message or clipboard copy. Social Chat Toolkit does not send the answers to its servers or store them in its database.

When anonymous analytics are enabled, the app may count form opens, submissions, skips, and cancellations. These events do not contain the selected request type, order reference, free-text details, or generated message.

04

Customer Support and App Support data

Customer Support for a merchant's shoppers

If a merchant enables the paid Customer Support feature, the app may process merchant-authored FAQs and support settings. For secure order lookup, a shopper submits an order number and checkout email. These values are used to verify the requested order against SHOPLINE. Lookup audit records retain only keyed hashes of the submitted values for abuse prevention and troubleshooting, not the plain values.

After a successful order verification, the shopper may choose the browser-saved recent-order experience. The browser stores only a limited order-status snapshot and a signed, store-and-order-scoped refresh credential so the same order can be refreshed without re-entering the checkout email. The checkout email is not persisted in browser storage by this feature. The refresh credential expires and cannot be used for another store or order.

Customer Support does not store shopper-to-merchant chat messages. When a shopper needs a person, the widget hands off to the merchant's configured ChatLink channel. Legacy customer-message records created by earlier app versions are no longer accepted by the storefront and remain subject to the existing retention and deletion policy until removed.

App Support for merchants

When a merchant uses the in-app App Support feature, we process the report subject, message content, category, priority, status, timestamps, and the store associated with the request. If the merchant chooses to include diagnostics, the app may also receive the page path, browser type, browser language, and app version.

Limited installation and App Support summaries may be sent to private WeCom robot channels used by the operator for internal notification. Access tokens, session tokens, app secrets, and passwords are not included in those notifications.

Do not submit secrets. Merchants should never include access tokens, passwords, API secrets, or private keys in an App Support report.
05

How we use data

Data is used only to provide and secure the app, maintain authorization and webhook state, deliver storefront configuration, route market-specific rules, provide merchant-enabled FAQ and order-support workflows, generate merchant-requested analytics, respond to support requests, prevent abuse, diagnose errors, and meet legal or platform obligations.

We do not sell merchant or visitor data and do not use anonymous visitor identifiers to build cross-store advertising profiles.

06

Retention, export, and deletion

Merchants may choose a 30, 90, or 180-day analytics retention period, export aggregated analytics as CSV, or permanently delete all analytics without deleting chat rules. Expired analytics records are automatically removed using database expiration controls.

Legacy Customer Support message records created by earlier app versions remain configured for automatic expiration, normally within 180 days. Order-lookup audit hashes are automatically removed after 30 days. Resolved or closed App Support reports are normally retained for up to 180 days. Operational logs are retained only as long as reasonably needed for security and troubleshooting.

After uninstall, the widget stops receiving active configuration and the app deactivates access credentials. SHOPLINE customer-redaction requests delete or anonymize matching Customer Support records when they can be identified from the webhook payload. Merchant-redaction requests delete the corresponding store configuration, tokens, market cache, analytics, customer-support data, App Support data, and notification jobs, subject to limited legal backup retention.

07

Service providers and third-party platforms

The app relies on service providers that may include SHOPLINE for platform authentication and theme integration, Railway for application hosting, MongoDB for database services, and WeCom for internal installation and support notifications.

When a shopper selects WhatsApp, Messenger, Telegram, LINE, Viber, email, phone, or another configured destination, the shopper leaves the app environment. The receiving platform processes information under its own privacy policy and terms. Social Chat Toolkit is not affiliated with or endorsed by those third-party platforms.

08

Security measures

We use HTTPS, encrypted storage for access credentials, SHOPLINE App Bridge SessionToken authentication for the embedded admin, restricted support-administrator sessions, request IDs, rate limiting, redaction of sensitive log fields, backups, and operational monitoring.

No online system can guarantee absolute security. We maintain reasonable technical and organizational safeguards and investigate suspected incidents that may affect app data.

09

International data processing

Depending on the infrastructure region selected by the operator and the locations of service providers, data may be processed outside the merchant's or visitor's country. We use contractual and technical safeguards appropriate to the services involved and limit processing to what is needed to operate the app.

10

Merchant and visitor choices

  • Merchants can keep analytics disabled, change the retention period, export analytics, or delete analytics at any time.
  • Merchants can edit or delete rules and channel destinations from the app, and Pro merchants can manage Customer Support settings and FAQs.
  • Storefront visitors can use SHOPLINE privacy controls and browser Do Not Track settings where supported.
  • Merchants may uninstall the app or request access, correction, or deletion through the contact channels below.
11

Contact us

For privacy requests, product support, or questions about this policy, contact Toolkit Fans through the in-app App Support page or by email.

Privacyprivacy@toolkit.fans
Supportsupport@toolkit.fans
© 2026 Toolkit Fans. Social Chat Toolkit.
PrivacyFAQTerms