Legal

Privacy Policy

Effective date: 18 August 2026

Overview

Morvo Ltd (“Morvo”, “we”, “our” or “us”) provides an AI shopping assistant that merchants add to their own online stores. This policy explains what we do with personal data, in which role, and what your choices are.

It is written in two halves, because we handle personal data in two different capacities and the difference matters.

Section 3 covers shoppers on a merchant’s store. There we act as a processor on the merchant’s instructions: the merchant decides why the assistant is there and what it is used for, and our processing is governed by our Data Processing Agreement with them. Section 4 covers everything we do in our own right, as a controller: merchant accounts, billing, marketing, previews, support and our own website.

If you are a shopper, please refer to the store’s privacy policy. In Section 3, we explain what we do on their behalf.

1. Who we are and how to contact us

Morvo Ltd is a company registered in England and Wales, company number 16457191. Registered office: Jactin House, 24 Hood Street, Ancoats, Manchester, M4 6WX, United Kingdom.

Contact: support@morvo.co.uk

2. The two roles in short

Processor (section 3)Controller (section 4)
Whose dataShoppers on a merchant’s storefrontMerchant staff, prospects, preview requesters, our own website visitors
Who decides the purposeThe merchantMorvo
Governed byOur DPA with the merchantThis policy
First point of contactThe merchantUs

Where a merchant’s own privacy notice and this policy differ on shopper data, the merchant’s notice governs their relationship with the shopper.

3. Shoppers on a merchant's store, where Morvo is a processor

3.1 What the assistant processes

  • Conversation content. The messages a shopper types and the replies the assistant gives.
  • Random identifiers. A visitor identifier and a session identifier, both randomly generated. Neither is derived from anything about the person, and nothing in our systems links them to a name, email address, telephone number or account.
  • Interaction data. Which products were shown and clicked, with the product name, link and price; timestamps; the type of device; and which part of the assistant a question came from.
  • Store context. The shop’s domain, and the product or category page the shopper is on, passed to us as an identifier rather than as a page address or page text.
  • Purchase attribution data. Where a purchase follows a session: the order reference, the total and currency, and the random identifiers set earlier.
  • Measurement group. Whether this visit is in the measured or held-out group, see 3.6.
  • IP address, for rate limiting only. See 3.7.

We do not ask shoppers for their name, email address, telephone number, postal address or payment details, and the assistant has no field for them. We do not read the store’s customer or order records.

Two things a shopper may tell us anyway, which we state plainly. First, someone may type personal data into the chat, for example “where is my order, I’m jane@example.com”. That is the main route by which shopper personal data reaches us, and 3.2 explains how it is handled. Second, where a shopper is buying for someone else, the assistant may ask about that person, most commonly the age of a child a gift is for. That information is processed as part of the conversation and used to pick suitable products.

3.2 Conversation content, and what happens to contact details

Conversation content is processed in two places, and the distinction matters.

In the live conversation, the message goes to our AI providers as the shopper typed it. It has to: the assistant cannot answer a question it has not been given, and filtering the live message risks corrupting a genuine query. Section 6 sets out which providers receive what.

Before anything is kept, we mask contact details. Email addresses, long digit sequences of the kind used for telephone and payment card numbers, and full postcodes in recognisable formats (UK postcodes, nine-digit US ZIP codes and Canadian postal codes) are replaced with a placeholder such as [email] before the message is written to our database, before it is included in any stored summary, and before it appears in any report or email. The mask is deliberately conservative so prices, quantities and order references are not caught by it.

So: contact details a shopper types are seen by the AI provider in the moment, and are masked everywhere they would otherwise be retained. We state the two separately because they are different, and a policy that blurred them would mislead.

Conversation content is stored against the random session identifier so the merchant can see how their assistant is performing. It is not linked to an identity in our systems, and no table in our database joins a visitor or session identifier to a name or email address.

On the shopper’s own device, the browser keeps a copy of the current conversation and an archive of up to twenty previous ones, so a chat can be picked up where it was left. That copy is removed when the shopper starts a new chat or clears their browsing data. It is separate from, and additional to, the copy we hold.

3.3 Order status

Where a merchant enables it, a shopper can ask about their own order. We retrieve the order from the merchant’s store platform at that moment, check it against the email address the shopper gives, and show the result to them directly. Those details are not sent to the AI providers and are not stored by us: we keep only a record that a lookup happened, with the order reference, the shop and the time. Addresses are shown in shortened form.

3.4 Automated decision-making

The assistant selects and ranks products. It does not make decisions producing legal or similarly significant effects within the meaning of Article 22 of the GDPR. It does not set prices individually, assess creditworthiness, or determine access to any service.

3.5 Cookies and browser storage on merchant stores

The assistant sets seven first-party cookies on the store’s own domain, to keep a conversation going across pages, to attribute revenue for the merchant, and to run the measurement in 3.6. The merchant may be responsible for obtaining consent under applicable privacy laws. Section 5.2 lists them individually.

3.6 Measurement, including the held-out group

To show a merchant what the assistant is worth, we compare shoppers who can see it against a randomly selected group who cannot, about one in ten by default; the merchant can adjust that proportion. Assignment is random, is not derived from anything about the person, and lasts up to twelve months; if the merchant changes the proportion, assignment is re-randomised.

Shoppers in the held-out group are measured but never shown the assistant. They are counted and their purchases attributed in the same way, because otherwise the comparison would not work. We say so explicitly because it is not apparent from using the store. The measurement is subject to the same consent rules as everything else in this section. It is the merchant’s responsibility to comply with the consent rules.

3.7 IP addresses

The assistant’s chat endpoint is public, so we count requests per store and per IP address to stop automated abuse. The IP address is used for that counter and nothing else. It never reaches the AI providers, is never attached to a conversation, and is not used to locate or profile anyone. Counters are cleared at least daily and usually within the hour.

3.8 Purchase attribution

Where a shopper buys after using the assistant, we record the order reference, the total and currency, and the random identifiers set earlier, so the merchant can measure revenue. We do not read the buyer’s name, email address, telephone number or delivery address, and we do not access the store’s customer or order records to do it.

On Shopify the mechanism is a checkout pixel that reads values the assistant itself placed in the shopper’s basket earlier in the session. If those values are absent, which is the case for any shopper whose consent was refused, the pixel records nothing.

One flow in the other direction, which we disclose because it is easy to miss. The values the assistant places in the basket are carried by Shopify onto the merchant’s order record, which does contain the buyer’s identity. So although Morvo holds no buyer identity, our random session identifier appears alongside one in the merchant’s own systems.

4. Where Morvo is a controller

We may collect a variety of personal data from or about you or your devices from various sources, as described below. Where applicable, we indicate whether and why you must provide us with your personal data, as well as the consequences of failing to do so. If you do not provide personal data when requested, you may not be able to benefit from our services if that information is necessary to provide you with them or if we are legally required to collect it.

4.1 Merchant account users

What we hold: account email address, company name, contact name where given, optional billing address, subscription and plan information, the record of sign-ins to the dashboard, role, and multi-factor authentication settings where enabled. We also hold support correspondence.

Why, and on what basis: to operate the account, provide support, run billing and keep the service secure. Performance of our contract with you, and our legitimate interests in securing and administering the service.

How long: for the life of the account. Sign-in audit records and email delivery records are deleted after 12 months. Records needed for accounting and tax are kept for six years.

What deletes it: deletion of the account, which we carry out on request. See 10.2.

4.2 Prospects and marketing contacts

What we hold: business contact details given to us through a form or in correspondence, held in our customer relationship management system, with the source of the enquiry and our record of dealings.

Why, and on what basis: to respond to enquiries and send occasional business-to-business marketing, on the basis of our legitimate interests as a business communicating with other businesses, and consent where required.

How long: while the enquiry or relationship remains live, and for 24 months after the last meaningful contact.

Unsubscribing: every marketing email carries an unsubscribe link, and you can write to support@morvo.co.uk. Where you unsubscribe we keep the minimum record needed to ensure we do not contact you again.

4.3 Self-serve preview requesters

What we hold: the store address, the email address given, the IP address the request came from, the store’s publicly available product listings, and statistics about how the preview was used, including the questions asked during it.

What we do not do: we do not access the store’s admin, its customers or its order data. We fetch only what any visitor to the store could see, and nothing is installed on the store.

How it runs: the catalogue is fetched and stored on our servers and the assistant runs there; only the display is local to the viewer’s browser.

How long: preview access ends after seven days, or a longer period where we extend it at the requester’s request. The imported catalogue copy is deleted within a further seven days. The request record and usage statistics are retained so we can follow up the enquiry, on the basis in 4.2.

Deleting it: every preview email carries a manage link, and the requester can delete the preview and its data at any time from it.

Lawful basis: our legitimate interests in allowing a prospective customer to evaluate the service before purchase, and in following up an enquiry we were invited to make.

4.4 Billing and finance

What we hold: subscription references, plan and status, invoice records, payment outcomes and failure reasons.

What we do not hold: card numbers, bank account numbers and any other payment credentials. Those stay with the payment provider and never reach our systems.

How long: six years, for accounting and tax.

Payments taken directly with us are processed by Stripe. Where a merchant subscribes through the Shopify App Store, Shopify charges them and Shopify’s own billing terms apply. Invoicing and accounting records are held in Xero.

Lawful basis: our legitimate interests in administering our business, and complying with our compliance obligations (for instance, those arising under tax legislation).

4.5 Visitors to morvo.co.uk

We and our third-party partners collect information about your activities on our website using, for example, cookies, pixel tags, SDKs, or other tracking and analytics technologies (collectively, “Cookies”). Our third-party partners, such as our analytics and advertising partners, may also use these technologies to collect information about your online activities over time and across different services. For more information, please see Section 5 of this Privacy Policy, which includes information on how to control or opt out of these Cookies.

One thing we disclose for completeness: our analytics tag loads on page view with all storage permissions denied. In that state it writes no cookie, but it does send a request to Google containing your IP address, the page address and basic browser information.

Forms: details you submit go to our customer relationship management system as in 4.2. Our CRM provider’s scripts also record page views and, where enabled, capture details submitted through forms on our site.

4.6 Aggregated and de-identified data

We use data generated by the service, in aggregated and de-identified form, to maintain and improve it. Aggregates are constructed so that no individual shopper and no individual merchant can be identified or inferred, no merchant’s data is visible to any other merchant, and nothing is used to train AI models.

Before a merchant’s data is removed at the end of the retention period in section 8, we may keep an aggregate snapshot: counts, theme summaries, and the questions shoppers most commonly asked, with contact details masked. The snapshot carries no identifiers and no conversation history.

Merchants can opt out of contributing to cross-merchant aggregates by writing to support@morvo.co.uk.

5. Cookies and similar technologies

5.1 On our own website, morvo.co.uk

We show a consent banner to every visitor, wherever they are. Accept, decline and customise are given equal prominence, and the analytics and marketing options are off until you switch them on. Declining leaves the site fully usable. You can change or withdraw your choice at any time using the “Cookie preferences” link in the footer.

Essential

NameTypeSet byPurposeLifetime
morvo_cookie_consentBrowser storageMorvo, first partyRemembers your cookie choicesUntil you clear it

Analytics, set only after you accept analytics cookies

NameTypeSet byPurposeLifetime
_gaCookieGoogle Analytics, first partyTells one browser from another so visits are not double countedAbout 13 months
_ga_85YX2F6NZTCookieGoogle Analytics, first partyHolds the analytics session state for our propertyAbout 13 months

Marketing, set only after you accept marketing cookies

NameTypeSet byPurposeLifetime
_fbpCookieMeta, first partyMeta’s browser identifier, used to measure our advertising90 days
__hstcCookieHubSpot, first partyRecords first visit, last visit and visit countAbout 6 months
hubspotutkCookieHubSpot, first partyLinks a form you submit to your browsing history in our CRMAbout 6 months
__hsscCookieHubSpot, first partySession counter, resets after 30 minutes of inactivity30 minutes
__hssrcCookieHubSpot, first partyFlags whether this is a new browser sessionUntil you close the browser

Accepting marketing cookies also loads the LinkedIn Insight Tag and HubSpot’s tracking scripts. The LinkedIn tag sets its identifiers on linkedin.com rather than on our site, so those are third-party cookies controlled by LinkedIn.

Third-party, set by LinkedIn on linkedin.com after you accept marketing cookies, with lifetimes as published by LinkedIn

NameTypeSet byPurposeLifetime
bcookieCookieLinkedIn, third partyBrowser identifier1 year
bscookieCookieLinkedIn, third partySecure browser identifier1 year
lidcCookieLinkedIn, third partyRoutes requests to the right LinkedIn data centre24 hours
li_gcCookieLinkedIn, third partyStores guest consent status6 months
UserMatchHistoryCookieLinkedIn, third partyAdvertising measurement and matching30 days
AnalyticsSyncHistoryCookieLinkedIn, third partyRecords when an analytics sync last ran30 days

5.2 On merchant stores, set by the assistant

First-party, on the merchant’s own domain. All hold either a random identifier or a technical flag.

NamePurposeLifetime
morvo_visitor_idRandom identifier so returning visits are counted once365 days
morvo_session_idRandom identifier for the current session1 day
morvo_experiment_groupWhether this visit is measured or held out365 days
morvo_first_touch_tsTime of the first interaction with the assistant365 days
morvo_last_touch_tsTime of the most recent product click365 days
morvo_last_touch_typeThe kind of the most recent interaction365 days
morvo_shop_idThe store’s own domain365 days

5.3 Browser storage on merchant stores

Not cookies, but treated the same way by privacy law.

KeyPurposeLifetime
chatHistoryThe current conversation, so it survives moving between pagesUntil cleared
morvo_conversationsUp to 20 previous conversations, so they can be reopenedUntil cleared
session_idA random identifier for the conversation, sent with each messageUntil cleared
Display state and technical flagsPanel state, page context, first-visit flagsUntil cleared

All are removed when the shopper starts a new chat or clears their browsing data.

6. Who we share data with

We do not sell personal data and we do not share it for advertising.

ProviderWhat they doWhere
Anthropic PBCGenerates assistant repliesUnited States
Google LLCKnowledge search and fallback reply generationUnited States and EU
Supabase, Inc.Database and file storageData held in Ireland
Vercel Inc.Application hosting and computeCompute pinned to London
Cloudflare, Inc.Network routing, security and backup storageUnited States
ResendTransactional and preview emailIreland
HubSpotOur customer relationship management systemIreland, EU data centre
Shopify Inc.App platform and billing for Shopify merchantsCanada
XeroInvoicing and accountingUnited Kingdom
StripeSubscription payments taken directly with usUnited States and United Kingdom

We also disclose personal data where required by law, and to professional advisers.

7. International transfers

Our own storage and application compute are single-region: the database is in Ireland and the application is pinned to London. AI processing takes place outside the UK and EEA, as do some of the other providers above.

We may transfer your personal data to countries which have been found to provide adequate protection by the competent supervisory authorities as appropriate, use contractual protections for the transfer of personal data, transfer to recipients who have adopted Binding Corporate Rules, or rely on an appropriate legal derogation, to the extent necessary to comply with applicable data protection laws. To the extent applicable, if you are located in the EEA or the United Kingdom, you may contact us as specified below for more information about the safeguards we use to transfer personal data outside of the UK or EEA.

8. How long we keep things

WhatHow long
Shopper conversation content and identifiers, while a subscription is activeRetained in full, so the merchant’s analytics work
Shopper conversation content and identifiers, after a subscription endsThe conversation text and the visitor identifier are removed 90 days after the subscription is deactivated. Reactivating within 90 days preserves everything
Where a merchant uninstalls our Shopify appShopify requires this about 48 hours after uninstall, without the 90-day window, and we honour it
Where a merchant asks us to delete everythingCarried out on request
Shopper IP addressesRate-limiting counters only, cleared at least daily and usually within the hour
Operational session records30 days
Aggregate insight snapshot (4.6)Retained, with contact details masked and no identifiers
Statistical and transaction records: counts, values, currencies, order references and random session identifiersRetained while the subscription remains active, so historical revenue reporting continues to work. After a subscription ends, order references and session and visitor identifiers are removed on the deletion timeline in our DPA
Merchant account dataLife of the account
Sign-in audit and email delivery records12 months
Accounting and tax recordsSix years
Preview request recordsSee 4.3

9. Security

We make reasonable efforts to protect your personal data by using physical and electronic safeguards designed to improve the security of the personal data we maintain. However, because no electronic transmission or storage of personal information can be entirely secure, we can make no guarantees as to the security or privacy of your personal data.

You can read more about our security practices in our Trust Centre.

10. Your rights

You have rights to be informed, to access a copy of your data, to have it corrected or erased, to restrict or object to processing, to portability, and to withdraw consent where processing relies on it. How to exercise them depends on whether we process your personal data as a controller or as a processor.

10.1 If you are a shopper and we act as a processor for your personal data

The merchant whose store you were using is the controller. Contact them first and they can instruct us.

10.2 If you are a merchant user, a prospect or a preview requester and we act as a controller for your personal data

Write to support@morvo.co.uk.

  • Access and correction are handled by our support team.
  • Deletion of a merchant account is carried out by us on request. It removes the account, the conversation records and identifiers held for that store, uploaded knowledge content, catalogue copies and the aggregate snapshot. Records we must keep for accounting and tax, and emails already delivered, sit outside that process and we will tell you what has been kept and why.
  • Preview deletion is self-service through the manage link in your preview emails.
  • Portability is provided on request rather than as a download in the product.

10.3 Complaints

Please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or to the supervisory authority where you live.

11. Children

As a controller, we do not knowingly collect, maintain, or use personal data from children under 13 years of age, and no part of our website or services is directed to children. If you learn that a child has provided us with personal data in violation of this Privacy Policy, then you may alert us at support@morvo.co.uk.

12. Changes to this policy

We may update this policy. The current version is always at morvo.co.uk/privacy with its effective date at the top.

13. Contact

support@morvo.co.uk. Morvo Ltd, Jactin House, 24 Hood Street, Ancoats, Manchester, M4 6WX, United Kingdom.