BoostGlobal

Privacy Policy

Last updated: March 5, 2026

1. Introduction

BoostGlobal ("we", "us", or "our") is operated by Boost Media Ltd, a company registered in Israel at Shulamit Aloni 11, Rishon LeZion, 4597545. This Privacy Policy describes how we collect, use, store, and protect your information when you use the BoostGlobal application ("the App"), available as a Shopify app and as a standalone web application at boostglobal.boostmedia.co.il.

By installing or using BoostGlobal, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Merchant Information (Shopify Store Owners)

When you install BoostGlobal on your Shopify store, we collect:

  • Shop information: Store name, domain, owner name, and email address (from Shopify API)
  • OAuth access tokens: Encrypted and stored securely to access your store's data on your behalf
  • Product and content data: Product titles, descriptions, pages, and blog articles — indexed for AI knowledge base functionality
  • Account information: Email address, name (for standalone dashboard users)

2.2 Visitor Information (Your Customers)

When visitors interact with the BoostGlobal chat widget on your store, we collect:

  • Conversation data: Messages sent and received during chat sessions
  • Visitor identifiers: Anonymous session-based identifiers (no personal tracking across sites)
  • Form submissions: Name, email, phone number, and message content when visitors submit lead capture forms
  • Meeting bookings: Name, email, preferred time, and meeting notes
  • Analytics events: Widget interactions (open, close, message sent), page URL, timestamp

2.3 Information We Do Not Collect

  • Payment or credit card information (billing is handled entirely by Shopify)
  • Customer passwords
  • Cross-site tracking cookies
  • IP addresses of store visitors

3. How We Use Your Information

  • Provide AI chatbot services: Process messages, generate AI responses using your indexed content, and display product recommendations
  • Knowledge base indexing: Index your store's products, pages, and articles so the AI can answer customer questions accurately
  • Lead management: Store and display leads captured through chat forms
  • Meeting scheduling: Process meeting bookings and sync with your calendar
  • Analytics: Generate usage statistics and performance metrics for your dashboard
  • Service improvement: Aggregate, anonymized data may be used to improve our AI models and service quality

4. AI Processing and Third-Party Services

BoostGlobal uses Google Gemini (via Google's AI API) to generate responses to visitor messages. When a visitor sends a message:

  • The message and relevant knowledge base context are sent to Google Gemini for response generation
  • Google processes this data according to their Terms of Service
  • We do not send personal customer information (email, phone, name) to the AI service — only the conversation context needed for generating a response

5. Data Storage and Security

  • Database: All data is stored in a PostgreSQL database hosted on Neon (cloud-hosted, SOC 2 compliant)
  • Encryption: Shopify access tokens are encrypted at rest using AES-256-GCM encryption
  • Transport: All data in transit is encrypted using TLS/HTTPS
  • Authentication: Shopify merchants are authenticated via Shopify session tokens (JWT); standalone users use secure password hashing (bcrypt)
  • HMAC verification: All Shopify webhooks and OAuth callbacks are verified using HMAC-SHA256 signatures

6. Data Retention

  • Active accounts: Data is retained for as long as the app is installed and the account is active
  • After uninstallation: Data is preserved for 48 hours to allow for reinstallation. After 48 hours, Shopify triggers a shop data deletion webhook and all shop data is permanently deleted
  • Customer data requests: Customer-specific data is deleted within 30 days of a GDPR deletion request from Shopify
  • Conversations: Chat conversations are retained for as long as the account is active. Merchants can delete individual conversations from the dashboard

7. GDPR Compliance

BoostGlobal fully complies with Shopify's mandatory GDPR requirements. We handle the following webhooks automatically:

  • Customer data request (customers/data_request): We compile all data associated with a customer's email address and make it available for the merchant
  • Customer data deletion (customers/redact): We permanently delete all data associated with the specified customer, including conversations, messages, leads, and meetings
  • Shop data deletion (shop/redact): We permanently delete all data associated with the shop, including the site, bots, personalities, knowledge base, conversations, leads, meetings, analytics, subscriptions, and all related records

8. Data Sharing

We do not sell, rent, or share your personal data with third parties, except:

  • Google Gemini: Conversation context (not personal data) is sent for AI response generation
  • Shopify: We interact with the Shopify API using your OAuth token to read store data and manage metafields
  • Legal requirements: We may disclose data if required by law, legal process, or governmental request

9. Your Rights

You have the right to:

  • Access your personal data stored by BoostGlobal
  • Correct inaccurate personal data
  • Delete your personal data (by uninstalling the app or contacting us)
  • Export your data in a machine-readable format
  • Withdraw consent at any time by uninstalling the app

To exercise any of these rights, contact us at office@boost-media.co.il.

10. Cookies

The BoostGlobal chat widget does not use cookies on your customers' browsers. Session identification is handled through in-memory session identifiers that are not persisted across browser sessions. The BoostGlobal dashboard uses standard authentication cookies (NextAuth session tokens) for logged-in merchants.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the App after changes constitutes acceptance of the revised policy. For material changes, we will notify merchants via email.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us:

Boost Media Ltd

Shulamit Aloni 11, Rishon LeZion, Israel 4597545

Email: office@boost-media.co.il

Contact: Ofer Chekroun (ofer@boost-media.co.il)