Privacy Policy
Last updated: July 20, 2026
Who we are
Sona AI (“Sona”, “we”, “us”) provides an AI-assisted customer support tool for e-commerce businesses. This policy explains what data we process when you or your customers use Sona, why we process it, and what rights you have.
What data we process
To draft replies to your support tickets, Sona processes:
- Customer support messages you forward to Sona (sender, subject, body, attachments)
- Order, payment and shipping data from your connected store (e.g. Shopify)
- Your team's account data — name, email and login activity — via Clerk
- Drafts, edits and approvals your team makes, used to improve future replies
Why we process it
We process this data to read a ticket, look up the relevant order, and draft a reply grounded in your store data and policies. A customer's data is used only to answer that customer's own tickets — never to answer someone else's, and never sold or shared with other businesses using Sona.
Where data is processed
Sona's application and database run in the EU. Some processing steps use sub-processors outside the EU, under appropriate safeguards (standard contractual clauses).
- DigitalOcean (EU) — application hosting
- Supabase (EU) — database & backend
- Postmark (EU) — inbound email delivery
- OpenAI (US) — drafts replies. Content sent to OpenAI's API is not used to train its models.
- Clerk (US) — team login and authentication
- Shopify — your own store's order and customer data, accessed with the permissions you grant
How long we keep it
We keep ticket and order data for as long as your workspace is active, so Sona can reference past tickets and keep improving its answers. If you close your account, we delete or anonymise your data within a reasonable period, except where we're required to keep it longer by law.
Your rights
If you're in the EU/EEA, you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise any of these rights, contact us at [email protected].
Security
We use encryption in transit and at rest, scoped access controls, and give every workspace its own isolated data. Nothing reaches a customer without your team's approval, unless you've explicitly turned on autopilot for that ticket type.
Changes to this policy
We may update this policy as Sona evolves. We'll update the date below when we do. If a change is material, we'll let active customers know directly.
Questions about this page? Email [email protected].
[email protected]