Privacy Policy
This policy describes what personal data HelpMe Social handles, why, and what happens to it. It is written from our actual system design rather than from a template, and it states our limitations as plainly as our practices.
1. Who we are
HelpMe Social is a customer-support inbox for online merchants, operated by Nine to Never LLC (“we”, “us”). You can reach us at privacy@helpme.social.
2. Two different roles
We handle two distinct kinds of personal data, and our responsibilities differ for each.
- Merchant users are the people who log in to HelpMe Social to answer support messages. For their account data we are the controller.
- Merchant end-customers are the shoppers who email or message a merchant. For their data we are a processor, acting on the merchant’s instructions. The merchant is the controller.
That distinction matters in practice: when a merchant instructs us to erase a shopper’s data, our job is to carry that out, not to assess whether it is warranted. If you are a shopper and want your data removed, contact the merchant you were messaging. They can instruct us, and we will act on it.
3. What we hold
For merchant users (we are controller)
- Name and email address
- A hashed password, stored with bcrypt. We never store the password itself
- Which workspace you belong to and your role in it
For merchant end-customers (we are processor)
| Data | Where it comes from |
|---|---|
| Name, and any profile picture URL | The messaging channel |
| Email address, social handle or phone number | The messaging channel |
| Message content, inbound and outbound | The conversation itself |
| The raw message as the provider delivered it, including mail headers and the recipient address | The messaging channel |
| Files a customer sent. For email, we store the file itself in a private storage bucket (Cloudflare R2) so the agent can view it; for social channels we store the filename and a link, and the contents stay with the channel provider | The messaging channel |
| Satisfaction rating and any free-text comment | Our post-resolution survey |
| An AI-generated summary of the conversation | Generated by us (see §5) |
| Order details and a cached copy of customer records | The merchant’s Shopify store |
| Links between identities we believe belong to the same person | Derived by us from a matching order |
Each merchant’s data lives in its own dedicated database schema rather than in shared tables distinguished by a customer column.
What we deliberately do not hold
- We do not store AI prompts or responses. We record only metadata about each AI call. That is which model, how many tokens, what it cost, how long it took, and whether it errored. The message text sent to the model is not retained by us.
- No payment card data. Billing is not yet implemented; when it is, payment details will be handled by Shopify or Stripe and will not reach us.
- No advertising or analytics tracking of shoppers. There is no third-party analytics or advertising code in our application.
4. Why we process it
- To provide the service. That means receiving, displaying, organising and sending support messages
- To show the agent relevant order context from the merchant’s store
- To generate suggested replies, summaries, tags and routing (see §5)
- To measure support performance for the merchant
- To secure the service. That means rate limiting, abuse prevention, and diagnosing faults
For merchant end-customer data, the lawful basis is the merchant’s, and we act under their instructions. For merchant user accounts, we process on the basis of performing our contract with the merchant and our legitimate interest in running and securing the service.
5. Artificial intelligence
HelpMe Social can draft replies, summarise threads, categorise messages and apply tags using a large language model provided by Anthropic. When those features are enabled, the relevant conversation text is sent to Anthropic to produce that output.
- A human sends every reply. AI output is a suggestion an agent reviews, edits and chooses to send. We do not send unattended automated replies.
- We do not retain the prompts or the responses. We keep only the metadata described in §3.
- Merchant data is not used to train models. We do not train models on merchant or shopper data, and we do not permit our AI subprocessor to do so.
6. Subprocessors
We use the following third parties to deliver the service. Each processes personal data only as needed for its function.
| Subprocessor | Purpose | Notes |
|---|---|---|
| Anthropic | AI drafts, summaries, triage and tagging | Only where AI features are enabled |
| Mailgun (United States) | Sending and receiving email | Inbound mail is forwarded to us rather than stored as a mailbox; Mailgun keeps its own delivery logs |
| Shopify | Reading orders, fulfilments and customer records | Read-only access, granted by the merchant on install |
| Meta Platforms | Instagram direct messages | Only where a merchant connects that channel |
| Cloudflare | Encryption in transit, content delivery, protection against attack, and storage of email attachments (R2) | Sees traffic in transit; holds files sent to a merchant by email at rest in a private bucket |
| ReliableSite | Hosting the application, database and cache | Our servers run here |
We will give merchants notice before adding or replacing a subprocessor, so there is an opportunity to object.
7. International transfers
Our infrastructure and our subprocessors are located in the United States. If you are in the UK, EEA or Switzerland, using the service involves transferring personal data to the United States. Where required, those transfers rely on the European Commission’s Standard Contractual Clauses, incorporated into our data processing agreement.
8. How long we keep it
Conversation history is kept for a period set by the merchant’s plan: one year on Starter, two years on Growth, three years on Scale. The clock runs from the last message a customer sent or an agent wrote on a conversation; once a finished conversation (resolved, or marked as spam) is older than that, it is deleted whole by a nightly process. That covers the messages, the notes, and any attachments we store ourselves. Open conversations are never deleted by that process. The period applies only while a workspace is on a paid subscription: a trial, an unpaid, or a paused workspace keeps its history unchanged. Moving to a plan with a shorter period is confirmed on screen, with the number of conversations that would become eligible, before it takes effect. Everything else we hold about a merchant is kept for as long as the merchant’s workspace exists. A merchant can instruct us to delete specific data at any time, and Shopify merchants can do so through Shopify’s own privacy request tools, which we act on automatically.
What deletion actually does, stated precisely
When we receive an erasure instruction for a shopper, we destroy their identity and their own words: contact details, every channel identity we hold for them, our cached copy of their store customer record, the content of the messages they sent, their attachments, their survey comment, and the AI summary of the conversation. We clear the delivery details of messages sent to them, including the recipient address and mail headers.
What remains is the merchant’s operational record: that a conversation happened, when, its status and tags, and the replies the merchant’s own agents wrote.
We do not describe this as complete erasure, because it is not. If an agent’s reply quoted the customer, repeating their name or address back to them, that text is part of the merchant’s own message and is not rewritten. Separately, files sent by a customer remain wherever the messaging provider stores them; we delete our record of them, not the provider’s copy.
We keep encrypted backups of our databases. A backup taken before an erasure can still contain the erased data, so deleted data may persist in backup copies for up to 30 days before those backups age out.
9. Security
We implement appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 of the GDPR. Merchants who need a description of those measures for their own compliance records can request one at privacy@helpme.social.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to it.
- If you are a shopper who contacted a merchant: please contact that merchant. They control the data and can instruct us. If you contact us directly we will refer you to them, and assist them in responding.
- If you are a merchant user: email privacy@helpme.social.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
11. Children
HelpMe Social is a business tool and is not directed at children. We do not knowingly collect personal data from children.
12. This website
These pages use Umami, analytics software we run on our own server rather than a third-party service. It sets no cookies; for each page view it records the page address, the address you arrived from, and your browser’s language, screen size, browser and operating system.
Your IP address is used to derive an approximate location, meaning country, region and city, never a street address. It is also used to derive a daily-rotating one-way hash so we can tell a repeat visit from a new one. The address itself is not stored. We do this to see which pages are useful, on the basis of our legitimate interest in improving them.
13. Changes
If we change this policy we will update the date at the top, and we will tell merchants directly about material changes rather than relying on them to notice.