Privacy Policy

Last updated: July 20, 2026

Who we are

Sona AI (“Sona”, “we”, “us”) provides an AI-assisted customer support tool for e-commerce businesses. This policy explains what data we process when you or your customers use Sona, why we process it, and what rights you have.

What data we process

To draft replies to your support tickets, Sona processes:

  • Customer support messages you forward to Sona (sender, subject, body, attachments)
  • Order, payment and shipping data from your connected store (e.g. Shopify)
  • Your team's account data — name, email and login activity — via Clerk
  • Drafts, edits and approvals your team makes, used to improve future replies

Why we process it

We process this data to read a ticket, look up the relevant order, and draft a reply grounded in your store data and policies. A customer's data is used only to answer that customer's own tickets — never to answer someone else's, and never sold or shared with other businesses using Sona.

Where data is processed

Sona's application and database run in the EU. Some processing steps use sub-processors outside the EU, under appropriate safeguards (standard contractual clauses).

  • DigitalOcean (EU) — application hosting
  • Supabase (EU) — database & backend
  • Postmark (EU) — inbound email delivery
  • OpenAI (US) — drafts replies. Content sent to OpenAI's API is not used to train its models.
  • Clerk (US) — team login and authentication
  • Shopify — your own store's order and customer data, accessed with the permissions you grant

How long we keep it

We keep ticket and order data for as long as your workspace is active, so Sona can reference past tickets and keep improving its answers. If you close your account, we delete or anonymise your data within a reasonable period, except where we're required to keep it longer by law.

Your rights

If you're in the EU/EEA, you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise any of these rights, contact us at [email protected].

Security

We use encryption in transit and at rest, scoped access controls, and give every workspace its own isolated data. Nothing reaches a customer without your team's approval, unless you've explicitly turned on autopilot for that ticket type.

Changes to this policy

We may update this policy as Sona evolves. We'll update the date below when we do. If a change is material, we'll let active customers know directly.

Questions about this page? Email [email protected].

[email protected]
Sona AI