pebzy legal
Privacy policy
This policy explains what pebzy collects, how we use it, who we share it with, and how to delete it. The public Shopify App Store product is embedded in Shopify Admin. Disclosures for Google Ads, Meta, customer-service email, connected-email reporting, and external merchant-chat channels apply only to existing legacy or separately contracted custom accounts where that feature is explicitly offered and enabled.
Last updated 11 July 2026 · Tollemache Group Pty Ltd (ABN 95 683 886 535)
Who we are
pebzy is operated by Tollemache Group Pty Ltd (ABN 95 683 886 535, ACN 683 886 535), a company registered in Australia (“we”, “us”, the “Company”). We are the data controller for merchant account and service-administration data. For shopper data we receive from a connected store, the merchant is the controller and we process that data on the merchant’s instructions. You can reach us any time at dylan@toldyouicoulddoit.com.
pebzy is a Shopify operations assistant. The public app provides embedded reports and owner chat, with optional supported Shopify write permissions. A proposed action is not executed until the merchant confirms that specific action inside the authenticated app.
What we collect, by source
Your account with us. When your store is connected, we store its domain and display name, your settings, and the messages you exchange with the assistant.
Shopify.With your authorisation we read your products, inventory, orders, customers, and fulfilment and return status so the assistant can answer the merchant’s questions. We request Shopify’s protected Name, Email, and Address fields. Runtime GraphQL uses the protected Address field only for the shipping address on the individual order the merchant asks about; pebzy never queries, stores, or processes billing address. We do not request Phone, payment-card data, or access to orders older than Shopify’s standardread_orders window. The public app installs with read access. Customer-service context can also include the customer account creation date, order count, aggregate order spend, and latest order identifier; those are customer/order facts rather than additional directly identifying fields. A merchant may later grant optional write access for products, inventory, discounts, and orders. Every write follows propose, review, and confirm; no proposal changes the store before that confirmation. Refund and cancellation actions are sent to Shopify with Shopify customer notifications suppressed.
Customer-service email (existing legacy/custom accounts only). Where this separately contracted feature is offered and enabled, the assistant can draft a reply. If the merchant explicitly clicks Send, Resend delivers only the exact reply text shown and approved by that merchant. The assistant does not send a customer reply autonomously. If a merchant connects Klaviyo, we can read reporting and create a draft campaign after approval. Real Klaviyo send and scheduling are disabled by default and are not available unless that capability has been separately reviewed, disclosed, enabled, and confirmed by the merchant.
Merchant-chat channels (existing legacy/custom accounts only).Where a separately contracted account is offered and links Telegram, Slack, or WhatsApp, the channel provider processes the channel/account identifier and messages needed to carry your conversation with the assistant. These external channels are restricted to non-customer product, inventory, and location operations. They cannot retrieve or receive Shopify customer or order records, Meta advertising data, connected-email data, stored private memory, or protected customer context. New-ticket alerts contain no customer identity or message content; sales, order, and refund summaries are sent only to the owner’s email. Proposed changes can be approved or cancelled only inside pebzy’s authenticated dashboard surface. The channel is optional and can be unlinked. These channels are not part of, or linked from, the public embedded Shopify App Store product.
Google Ads (existing legacy/custom accounts only). Where this separately contracted feature is offered and you connect Google Ads, we use the Google Ads API scope https://www.googleapis.com/auth/adwords. We use it to read campaigns, spend, conversions, return on ad spend (ROAS), and the account/customer IDs needed to query them. Ad management is off by default. If the merchant separately enables it, pebzy can propose a campaign budget or status change, then waits for the merchant to confirm the exact change. Campaign creation remains unavailable unless it completes a separate review and is explicitly enabled.
Meta (Facebook & Instagram; existing legacy/custom accounts only). Where this separately contracted feature is offered, a reporting connection requests ads_read. If the merchant enables Meta ad management, the connection also requests ads_management, pages_show_list, and pages_read_engagement. We use the ad permissions for account and campaign performance and, only after separate opt-in and per-action confirmation, campaign status and budget changes. Campaign creation is disabled pending separate review. For Page context we read the first completely readable Page granted to the app, including its name, category, follower and talking-about counts, and latest published post, so the merchant can see that context beside ad performance. This is read-only; we do not publish, edit, or delete Page content.
Advertising reports and the assistant (existing legacy/custom accounts only).For separately contracted accounts with those connections enabled, Google and Meta data can appear in the merchant’s private owner chat, where Anthropic processes the context needed to answer the merchant’s question. The merchant can also request a session-protected CSV export of their own report. Ad data is therefore used for the visual report, private owner chat, and owner-requested exports; we do not send it to shoppers. While a Meta connection is active, every retained owner-chat session is treated as potentially containing Meta data. That chat removes Shopify, Google, Klaviyo, email, undo, and other non-Meta mutation tools; only confirmation-gated Meta campaign status and daily-budget proposals remain available.
How we use it
We use the data above only to provide the features enabled for your account:
- to show Shopify reports and answer the authenticated owner’s questions about the shop;
- to prepare a supported Shopify proposal and execute it only after per-action confirmation;
- for existing legacy/custom accounts only, to provide the separately contracted connections described above;
- to operate, secure, support, and bill for your account.
We do not use your connected-platform data for advertising or retargeting, we do not sell it, we do not transfer it to data brokers, and we do not use it to make credit or lending decisions. We do not use connected-platform data to train our own generalised AI or machine-learning model. We require our assistant API provider to process submitted data under its commercial terms rather than for general model training.
The assistant answers and proposes; it does not make a solely automated decision with legal or similarly significant effect on a shopper. The merchant reviews and confirms supported actions.
Cookies and local device storage
The public embedded Shopify app authenticates each API request with a short-lived Shopify token and does not mint a standalone pebzy dashboard cookie. We use essential first-party cookies only where needed for OAuth security state or an existing legacy/custom signed-in session. Browser local or session storage is limited to interface state. We do not use advertising or cross-site tracking cookies on pebzy.
Legal bases and international processing
For merchant account data, we process information to perform our contract with you, follow your instructions and consent for optional connections, secure and improve the service, and meet legal obligations. For Shopify shopper data, we act as the merchant’s processor or service provider and rely on the merchant to establish the appropriate legal basis and give required notices.
We operate from Australia and the providers listed below may process data in other countries. We limit transfers to what is needed for the selected feature and use the provider’s applicable contractual and data-protection terms. Contact us if you need information about a provider or transfer relevant to your account.
Google user data - Limited Use
pebzy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means: we only use Google Ads data to provide and improve the user-facing reporting and merchant-approved management features you asked for; we do not transfer it except as needed to provide those features, to comply with the law, or as part of a merger or acquisition (with your prior consent); we do not use it for advertising; and we do not let humans read it except where you give consent, where it is necessary for security or to comply with the law, or in aggregated and anonymised form.
Who we share it with
We do not sell your data. We share it only with service providers and connected-platform providers that help us run pebzy, under their applicable contractual and platform terms and only as needed for the feature you use. Providers for optional connections process data only when that connection or channel is enabled:
- Vercel Inc. - Application hosting, server execution, and content delivery; processes requests and responses needed to provide the service.
- Cloudflare, Inc. - Inbound support-email routing and worker execution; receives customer-service email only for merchants who configure forwarding.
- Neon Inc. - Managed Postgres database hosting for merchant accounts, encrypted credentials, service records, and customer-service content.
- Anthropic PBC - Claude API processing for the assistant; receives only the context needed for the merchant's request, which can include a shopper's name, email, shipping address, customer-service message, and relevant order data, plus connected advertising or email-reporting data.
- Shopify Inc. - Connected-store API, embedded-app platform, compliance webhooks, and Shopify App Pricing for App Store installs.
- Meta Platforms, Inc. - Facebook and Instagram advertising data and approved ad-management actions; WhatsApp Business separately carries merchant prompts and assistant responses for the restricted non-customer operations available in that channel.
- Google LLC - Google Ads reporting and merchant-enabled, approval-gated ad-management actions.
- Resend, Inc. - Delivery of the exact customer-service reply a merchant explicitly approves by clicking Send, plus merchant notification-email fallback when enabled.
- Klaviyo, Inc. - Connected email reporting and draft campaign creation; real send or scheduling remains disabled unless separately reviewed, disclosed, enabled, and approved by the merchant.
- Telegram Messenger Inc. - Merchant prompts and assistant responses for the restricted non-customer product, inventory, location, and discount operations available when Telegram is linked.
- Slack Technologies, LLC - Merchant prompts and assistant responses for the restricted non-customer product, inventory, location, and discount operations available when Slack is linked.
We may also disclose data to comply with the law or a valid legal request, or to protect the rights, safety, and security of our users and the service.
How we store and protect it
Data is encrypted in transit using HTTPS. Connected-account credentials and persisted customer-service fields, assistant transcripts and generated exports, plus legacy/custom voice-profile content where separately enabled, are protected with application-level envelope encryption at rest. Requests are scoped to the authenticated merchant, and production access is limited by role and need. Our internal security policy distinguishes code-backed controls from provider settings that require separate operational verification.
Retention and deletion
Browser demo workspaces and generated exports are retained for up to 30 days. While an account remains active, assistant sessions and chat history for up to 90 days, and proposals and audit records for up to 365 days. Existing legacy/custom accounts may also retain local customer-service tickets, taught facts, and learned-voice profiles for up to 365 days. Webhook deduplication records are retained for up to 7 days, and expired rate-limit counters are removed by the same daily retention process. These are maximum periods; records may be removed earlier when they are no longer needed.
On a legacy/custom account, you can disconnect Google Ads or Meta in Connections, which stops future access and removes that platform’s stored credentials. For the public Shopify app, uninstall in Shopify Admin to stop future access, or use the owner-only Privacy and account section to permanently delete pebzy-held account data. You can also ask us to delete it by emailing dylan@toldyouicoulddoit.com. Account deletion erases merchant data and connected credentials, leaving only a non-identifying deletion event needed to prove completion.
Shopify’s authenticated customers/redact webhook conservatively removes stored customer-derived support and assistant-memory containers for that shop; shop/redact removes the shop account. An authenticated customers/data_request webhook creates encrypted, owner-only JSONL export parts of matching stored data for the merchant to retrieve and provide to the shopper.
For step-by-step instructions, including how to ask us to delete your data, see our Data deletion page. A Meta deletion callback removes the associated Meta connection and conservatively clears stored assistant-history, proposal, audit, taught-fact, and export containers that could include Meta-derived data; use in-app account deletion or contact us for deletion of the whole pebzy account.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these, email dylan@toldyouicoulddoit.com and we’ll respond within the period required by applicable law. If you are a shopper, the Shopify merchant is the controller of your store data; contact that merchant first. We will assist the merchant with authenticated requests and will route a direct request appropriately.
Changes to this policy
If we make material changes, we’ll update the date at the top and, where appropriate, notify you. Your continued use of pebzy after a change means you accept the updated policy.
Contact
Questions about this policy or your data? Email dylan@toldyouicoulddoit.com, or write to Tollemache Group Pty Ltd, ABN 95 683 886 535, Australia.