Your Privacy Matters

Privacy Policy

Last updated: June 18, 2026

1Introduction

Trexa ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Shopify application and related services.

By using Trexa, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use our services.

2Information We Collect

Store Information: When you install Trexa, we access your Shopify store data including store name, domain, orders, and store policies to provide our services.

Order Data: We collect order information including order numbers, shipping details, tracking numbers, and order status to power the tracking page and AI assistant.

Customer Interactions: We collect chat conversations between your customers and our AI assistant to improve response quality and provide support escalation capabilities.

Analytics Data: We collect anonymized usage data including page visits, AI session counts, and deflection metrics to provide analytics and improve our services.

Account Information: We store your email address and billing information to manage your subscription and communicate with you about our services.

3Connected Email Accounts (Gmail and Microsoft 365)

Merchants may optionally connect a Gmail or Microsoft 365 mailbox to Trexa so that customer support replies sent through Trexa are delivered from the merchant's own inbox, and so that customer replies are routed back into the matching Trexa conversation thread.

Data we access

When you connect a Gmail account, Trexa requests the following Google OAuth scopes:

  • gmail.send — send replies from your inbox on your behalf
  • gmail.readonly — read incoming messages to match customer replies to the originating conversation
  • openid email profile — identify the connected account

When you connect a Microsoft 365 account, Trexa requests the following Microsoft Graph scopes:

  • Mail.Send — send replies from your inbox on your behalf
  • Mail.Read — read incoming messages to match customer replies to the originating conversation
  • offline_access — refresh access without re-prompting
  • User.Read — identify the connected account

How we use this data

  • Match inbound customer email replies to the originating Trexa support conversation
  • Send outbound replies on the merchant's behalf from the connected inbox
  • Display message content within the merchant's Trexa conversation view to the merchant and their authorized staff

We do not use Gmail or Microsoft 365 data to train AI or machine-learning models, sell or share it with third parties, or serve advertising.

Google API Services User Data Policy — Limited Use

Trexa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use restricted-scope data for serving advertisements, we do not allow humans to read this data unless we have your affirmative agreement for specific messages (for example when you escalate a support thread for review) or it is necessary for security purposes or to comply with applicable law, and we do not transfer this data to others except as needed to provide or improve user-facing features, comply with law, or as part of a merger, acquisition, or sale of assets with notice to users.

Storage, encryption, and retention

OAuth access tokens and refresh tokens for connected inboxes are encrypted at rest using AES-256-GCM and are accessible only to the Trexa application server processing your requests. Email message bodies fetched to match a customer reply are processed in memory; only the minimum metadata required to render the conversation (subject, snippet, sender, internal message ID) is persisted, and that metadata is encrypted at the field level alongside the rest of the conversation record.

Disconnection and revocation

You can disconnect a mailbox at any time from Trexa's Settings → Inbox page. On disconnect, Trexa stops all polling and webhook subscriptions for that account, revokes the stored OAuth tokens with the upstream provider, and deletes the encrypted credentials within 24 hours. You can additionally revoke Trexa's access directly from your Google Account permissions or from your Microsoft account security settings.

4How We Use Your Information

We use the collected information to:

  • Provide branded order tracking pages for your customers
  • Power AI-assisted customer support responses
  • Generate FAQs based on your store policies
  • Display analytics and performance metrics in your dashboard
  • Process and manage your subscription
  • Send important service updates and notifications
  • Improve and optimize our services
  • Respond to your support requests

5Data Storage and Security

We implement multiple layers of security to protect your data, going well beyond industry standards.

Field-Level Encryption

Sensitive data fields — including customer email addresses, customer names, conversation message content, and store access tokens — are individually encrypted using AES-256-GCM, a military-grade encryption standard. Each value is encrypted with a unique initialization vector, making it computationally infeasible to decrypt without the encryption key.

This means that even if someone were to gain access to the database, the encrypted fields would appear as meaningless ciphertext. No one — including Trexa administrators, database administrators, or hosting providers — can read your customers' personal information.

AI Privacy Protection (PII Tokenization)

Before any customer question or conversation context is sent to our AI provider for processing, all personally identifiable information (PII) is automatically detected and replaced with anonymous tokens. This includes:

  • Email addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • Credit card numbers

For example, an email like "jane@example.com" would be replaced with a token like "[EMAIL_1]" before being sent to the AI. The AI generates its response using these tokens, and we then replace the tokens back with the original values before showing the response to the customer. The AI never sees or processes any personal information.

We use Supabase for data storage, which provides enterprise-grade security including encryption at rest and in transit, regular backups, and SOC 2 compliance.

For query purposes, certain fields (such as email addresses) are stored as one-way cryptographic hashes (SHA-256), allowing us to look up records without ever storing the plaintext value in a searchable form.

While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

6Data Sharing

We do not sell, trade, or rent your personal information to third parties. We may share your information with:

  • Service Providers: Third-party services that help us operate our application (e.g., hosting, AI processing, email delivery)
  • Legal Requirements: When required by law or to protect our rights and safety
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

7Your Rights

You have the right to:

  • Access and receive a copy of your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability

To exercise any of these rights, please contact us at support@trexa.app.

8Data Retention

We retain your data for as long as your account is active or as needed to provide you services. If you uninstall our app, we will delete your data within 30 days, except where we are required to retain it for legal or regulatory purposes.

9Cookies and Tracking

We use cookies and similar tracking technologies to maintain session information and improve user experience. These are essential for the proper functioning of our tracking pages and AI chat features.

10Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

11Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

12Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Trexa Support

Email: support@trexa.app