Effective date: 18 August 2026
Morvo Ltd (“Morvo”, “we”, “our” or “us”) provides an AI shopping assistant that merchants add to their own online stores. This policy explains what we do with personal data, in which role, and what your choices are.
It is written in two halves, because we handle personal data in two different capacities and the difference matters.
Section 3 covers shoppers on a merchant’s store. There we act as a processor on the merchant’s instructions: the merchant decides why the assistant is there and what it is used for, and our processing is governed by our Data Processing Agreement with them. Section 4 covers everything we do in our own right, as a controller: merchant accounts, billing, marketing, previews, support and our own website.
If you are a shopper, please refer to the store’s privacy policy. In Section 3, we explain what we do on their behalf.
Morvo Ltd is a company registered in England and Wales, company number 16457191. Registered office: Jactin House, 24 Hood Street, Ancoats, Manchester, M4 6WX, United Kingdom.
Contact: support@morvo.co.uk
| Processor (section 3) | Controller (section 4) | |
|---|---|---|
| Whose data | Shoppers on a merchant’s storefront | Merchant staff, prospects, preview requesters, our own website visitors |
| Who decides the purpose | The merchant | Morvo |
| Governed by | Our DPA with the merchant | This policy |
| First point of contact | The merchant | Us |
Where a merchant’s own privacy notice and this policy differ on shopper data, the merchant’s notice governs their relationship with the shopper.
We do not ask shoppers for their name, email address, telephone number, postal address or payment details, and the assistant has no field for them. We do not read the store’s customer or order records.
Two things a shopper may tell us anyway, which we state plainly. First, someone may type personal data into the chat, for example “where is my order, I’m jane@example.com”. That is the main route by which shopper personal data reaches us, and 3.2 explains how it is handled. Second, where a shopper is buying for someone else, the assistant may ask about that person, most commonly the age of a child a gift is for. That information is processed as part of the conversation and used to pick suitable products.
Conversation content is processed in two places, and the distinction matters.
In the live conversation, the message goes to our AI providers as the shopper typed it. It has to: the assistant cannot answer a question it has not been given, and filtering the live message risks corrupting a genuine query. Section 6 sets out which providers receive what.
Before anything is kept, we mask contact details. Email addresses, long digit sequences of the kind used for telephone and payment card numbers, and full postcodes in recognisable formats (UK postcodes, nine-digit US ZIP codes and Canadian postal codes) are replaced with a placeholder such as [email] before the message is written to our database, before it is included in any stored summary, and before it appears in any report or email. The mask is deliberately conservative so prices, quantities and order references are not caught by it.
So: contact details a shopper types are seen by the AI provider in the moment, and are masked everywhere they would otherwise be retained. We state the two separately because they are different, and a policy that blurred them would mislead.
Conversation content is stored against the random session identifier so the merchant can see how their assistant is performing. It is not linked to an identity in our systems, and no table in our database joins a visitor or session identifier to a name or email address.
On the shopper’s own device, the browser keeps a copy of the current conversation and an archive of up to twenty previous ones, so a chat can be picked up where it was left. That copy is removed when the shopper starts a new chat or clears their browsing data. It is separate from, and additional to, the copy we hold.
Where a merchant enables it, a shopper can ask about their own order. We retrieve the order from the merchant’s store platform at that moment, check it against the email address the shopper gives, and show the result to them directly. Those details are not sent to the AI providers and are not stored by us: we keep only a record that a lookup happened, with the order reference, the shop and the time. Addresses are shown in shortened form.
The assistant selects and ranks products. It does not make decisions producing legal or similarly significant effects within the meaning of Article 22 of the GDPR. It does not set prices individually, assess creditworthiness, or determine access to any service.
The assistant sets seven first-party cookies on the store’s own domain, to keep a conversation going across pages, to attribute revenue for the merchant, and to run the measurement in 3.6. The merchant may be responsible for obtaining consent under applicable privacy laws. Section 5.2 lists them individually.
To show a merchant what the assistant is worth, we compare shoppers who can see it against a randomly selected group who cannot, about one in ten by default; the merchant can adjust that proportion. Assignment is random, is not derived from anything about the person, and lasts up to twelve months; if the merchant changes the proportion, assignment is re-randomised.
Shoppers in the held-out group are measured but never shown the assistant. They are counted and their purchases attributed in the same way, because otherwise the comparison would not work. We say so explicitly because it is not apparent from using the store. The measurement is subject to the same consent rules as everything else in this section. It is the merchant’s responsibility to comply with the consent rules.
The assistant’s chat endpoint is public, so we count requests per store and per IP address to stop automated abuse. The IP address is used for that counter and nothing else. It never reaches the AI providers, is never attached to a conversation, and is not used to locate or profile anyone. Counters are cleared at least daily and usually within the hour.
Where a shopper buys after using the assistant, we record the order reference, the total and currency, and the random identifiers set earlier, so the merchant can measure revenue. We do not read the buyer’s name, email address, telephone number or delivery address, and we do not access the store’s customer or order records to do it.
On Shopify the mechanism is a checkout pixel that reads values the assistant itself placed in the shopper’s basket earlier in the session. If those values are absent, which is the case for any shopper whose consent was refused, the pixel records nothing.
One flow in the other direction, which we disclose because it is easy to miss. The values the assistant places in the basket are carried by Shopify onto the merchant’s order record, which does contain the buyer’s identity. So although Morvo holds no buyer identity, our random session identifier appears alongside one in the merchant’s own systems.
We may collect a variety of personal data from or about you or your devices from various sources, as described below. Where applicable, we indicate whether and why you must provide us with your personal data, as well as the consequences of failing to do so. If you do not provide personal data when requested, you may not be able to benefit from our services if that information is necessary to provide you with them or if we are legally required to collect it.
What we hold: account email address, company name, contact name where given, optional billing address, subscription and plan information, the record of sign-ins to the dashboard, role, and multi-factor authentication settings where enabled. We also hold support correspondence.
Why, and on what basis: to operate the account, provide support, run billing and keep the service secure. Performance of our contract with you, and our legitimate interests in securing and administering the service.
How long: for the life of the account. Sign-in audit records and email delivery records are deleted after 12 months. Records needed for accounting and tax are kept for six years.
What deletes it: deletion of the account, which we carry out on request. See 10.2.
What we hold: business contact details given to us through a form or in correspondence, held in our customer relationship management system, with the source of the enquiry and our record of dealings.
Why, and on what basis: to respond to enquiries and send occasional business-to-business marketing, on the basis of our legitimate interests as a business communicating with other businesses, and consent where required.
How long: while the enquiry or relationship remains live, and for 24 months after the last meaningful contact.
Unsubscribing: every marketing email carries an unsubscribe link, and you can write to support@morvo.co.uk. Where you unsubscribe we keep the minimum record needed to ensure we do not contact you again.
What we hold: the store address, the email address given, the IP address the request came from, the store’s publicly available product listings, and statistics about how the preview was used, including the questions asked during it.
What we do not do: we do not access the store’s admin, its customers or its order data. We fetch only what any visitor to the store could see, and nothing is installed on the store.
How it runs: the catalogue is fetched and stored on our servers and the assistant runs there; only the display is local to the viewer’s browser.
How long: preview access ends after seven days, or a longer period where we extend it at the requester’s request. The imported catalogue copy is deleted within a further seven days. The request record and usage statistics are retained so we can follow up the enquiry, on the basis in 4.2.
Deleting it: every preview email carries a manage link, and the requester can delete the preview and its data at any time from it.
Lawful basis: our legitimate interests in allowing a prospective customer to evaluate the service before purchase, and in following up an enquiry we were invited to make.
What we hold: subscription references, plan and status, invoice records, payment outcomes and failure reasons.
What we do not hold: card numbers, bank account numbers and any other payment credentials. Those stay with the payment provider and never reach our systems.
How long: six years, for accounting and tax.
Payments taken directly with us are processed by Stripe. Where a merchant subscribes through the Shopify App Store, Shopify charges them and Shopify’s own billing terms apply. Invoicing and accounting records are held in Xero.
Lawful basis: our legitimate interests in administering our business, and complying with our compliance obligations (for instance, those arising under tax legislation).
We and our third-party partners collect information about your activities on our website using, for example, cookies, pixel tags, SDKs, or other tracking and analytics technologies (collectively, “Cookies”). Our third-party partners, such as our analytics and advertising partners, may also use these technologies to collect information about your online activities over time and across different services. For more information, please see Section 5 of this Privacy Policy, which includes information on how to control or opt out of these Cookies.
One thing we disclose for completeness: our analytics tag loads on page view with all storage permissions denied. In that state it writes no cookie, but it does send a request to Google containing your IP address, the page address and basic browser information.
Forms: details you submit go to our customer relationship management system as in 4.2. Our CRM provider’s scripts also record page views and, where enabled, capture details submitted through forms on our site.
We use data generated by the service, in aggregated and de-identified form, to maintain and improve it. Aggregates are constructed so that no individual shopper and no individual merchant can be identified or inferred, no merchant’s data is visible to any other merchant, and nothing is used to train AI models.
Before a merchant’s data is removed at the end of the retention period in section 8, we may keep an aggregate snapshot: counts, theme summaries, and the questions shoppers most commonly asked, with contact details masked. The snapshot carries no identifiers and no conversation history.
Merchants can opt out of contributing to cross-merchant aggregates by writing to support@morvo.co.uk.
Our own storage and application compute are single-region: the database is in Ireland and the application is pinned to London. AI processing takes place outside the UK and EEA, as do some of the other providers above.
We may transfer your personal data to countries which have been found to provide adequate protection by the competent supervisory authorities as appropriate, use contractual protections for the transfer of personal data, transfer to recipients who have adopted Binding Corporate Rules, or rely on an appropriate legal derogation, to the extent necessary to comply with applicable data protection laws. To the extent applicable, if you are located in the EEA or the United Kingdom, you may contact us as specified below for more information about the safeguards we use to transfer personal data outside of the UK or EEA.
| What | How long |
|---|---|
| Shopper conversation content and identifiers, while a subscription is active | Retained in full, so the merchant’s analytics work |
| Shopper conversation content and identifiers, after a subscription ends | The conversation text and the visitor identifier are removed 90 days after the subscription is deactivated. Reactivating within 90 days preserves everything |
| Where a merchant uninstalls our Shopify app | Shopify requires this about 48 hours after uninstall, without the 90-day window, and we honour it |
| Where a merchant asks us to delete everything | Carried out on request |
| Shopper IP addresses | Rate-limiting counters only, cleared at least daily and usually within the hour |
| Operational session records | 30 days |
| Aggregate insight snapshot (4.6) | Retained, with contact details masked and no identifiers |
| Statistical and transaction records: counts, values, currencies, order references and random session identifiers | Retained while the subscription remains active, so historical revenue reporting continues to work. After a subscription ends, order references and session and visitor identifiers are removed on the deletion timeline in our DPA |
| Merchant account data | Life of the account |
| Sign-in audit and email delivery records | 12 months |
| Accounting and tax records | Six years |
| Preview request records | See 4.3 |
We make reasonable efforts to protect your personal data by using physical and electronic safeguards designed to improve the security of the personal data we maintain. However, because no electronic transmission or storage of personal information can be entirely secure, we can make no guarantees as to the security or privacy of your personal data.
You can read more about our security practices in our Trust Centre.
You have rights to be informed, to access a copy of your data, to have it corrected or erased, to restrict or object to processing, to portability, and to withdraw consent where processing relies on it. How to exercise them depends on whether we process your personal data as a controller or as a processor.
The merchant whose store you were using is the controller. Contact them first and they can instruct us.
Write to support@morvo.co.uk.
Please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or to the supervisory authority where you live.
As a controller, we do not knowingly collect, maintain, or use personal data from children under 13 years of age, and no part of our website or services is directed to children. If you learn that a child has provided us with personal data in violation of this Privacy Policy, then you may alert us at support@morvo.co.uk.
We may update this policy. The current version is always at morvo.co.uk/privacy with its effective date at the top.
support@morvo.co.uk. Morvo Ltd, Jactin House, 24 Hood Street, Ancoats, Manchester, M4 6WX, United Kingdom.