AI Chat and GDPR: A Practical Checklist for Online Stores
· 6 min read · AskMerra
An AI chat on your store talks to your customers, so it handles their data. If you sell in the EU, the first question from your team, your data protection officer or a careful customer will be about GDPR. This checklist covers the points worth checking before you switch an assistant on, using AskMerra as the example: what the chat collects, where it is stored, how long it is kept and how to delete it on request.
One note before we start: this is a practical guide to the product's controls, not legal advice. Your obligations depend on your business, so check your final setup with your own legal advisor.
First: who is responsible for what
For conversations between your visitors and the assistant, your shop is the controller and AskMerra acts as a processor on your behalf, under a data processing agreement (DPA). For your own merchant account data, AskMerra is the controller.
That split has two practical consequences. You decide how long chat data is kept. And when a shopper asks to see or delete their data, the request comes to you, and AskMerra helps you answer it.
1. Know exactly what the chat collects
You cannot describe processing you do not understand. When a visitor chats, AskMerra processes:
- a random visitor identifier stored in the browser's local storage, and the conversation id;
- the messages exchanged, the products recommended and clicked, and thumbs up or down feedback;
- the page URL and language, and an approximate country derived from network headers;
- a name and email address only if the visitor fills in the contact form, or if you have enabled identification of logged-in customers.
The widget stores nothing in the shopper's browser until they open the chat or start typing. After that it keeps a short-lived session token and the current conversation in local storage, and remembers whether the panel is open in session storage. It sets no cookies and does no fingerprinting. AskMerra treats these items as strictly necessary for the chat the shopper asks for; national rules differ, so confirm with your legal advisor. Our cookie policy lists every item with its purpose and lifetime, ready to copy into your own cookie policy.
2. Check where data is hosted and who else processes it
AskMerra hosts its application and data in the EU. Like any AI product, it relies on a few service providers: hosting, AI inference and embeddings, email delivery and payments. Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses, and the current sub-processor list is part of the DPA.
Chat messages that need the AI are sent to an AI model provider to generate the answer. Providers are contractually prohibited from using this data to train their models.
To do: read the sub-processor list and add it to your records of processing.
3. Confirm raw IP addresses are not stored
AskMerra never stores raw IP addresses. A one-way hash is used briefly for rate limiting, the visitor's country comes from CDN headers, and logs carry no client IP. That is one less category of data to explain, protect and delete.
4. Choose a retention period and let deletion run by itself
Chat data should not live forever. In AskMerra you choose a retention period per shop: 30, 90 or 365 days. A daily job then deletes, automatically:
- conversations older than your setting, together with their messages;
- widget events such as chat opens and product clicks;
- visitor records with no conversations left, including any names and emails attached through identification.
Pick the shortest period that still lets you review conversations, follow up on escalations and spot recurring questions. Then write that period into your privacy notice.
5. Be ready to delete a shopper's data on request
AskMerra gives you two routes for deletion requests.
From the dashboard
Shop admins can use the Delete a shopper's data card in Settings, by email address or visitor id. The email matches both contact form submissions and identified customers. In the conversations inbox, the Delete visitor data button does the same for the conversation you are reading.
Deletion removes the visitor with their conversations, messages and events, plus any cached answers learned from their questions. The audit log records that an erasure happened without keeping the email itself, only a hash of it.
Self-service with AskMerra.forget()
You can also let shoppers do it themselves. The JavaScript API includes AskMerra.forget(), which deletes the current visitor's conversations, activity and identity, clears the chat and continues under a new anonymous id. A developer can connect it to a "Delete my chat data" button on your privacy page in a few lines. The JavaScript API docs include the example.
For other requests, such as access, the inbox can export conversations to CSV, which can help when you need to give a shopper a copy of their chat.
6. Keep visitor identification off unless you need it
Visitors are anonymous by default. If your store has customer accounts, the JavaScript API's identify() method can pre-fill the contact form with a logged-in customer's name and email. That pre-fill happens in the browser. The identity is only stored with the visitor if you switch on visitor identification in Settings, and only once the visitor actually chats.
Identification can speed up follow-ups, but it turns anonymous conversations into identified ones. If you enable it, mention it in your privacy notice.
7. Tell shoppers they are talking to an AI, and link your privacy notice
Every AskMerra widget shows an AI disclosure line, so visitors know they are chatting with an AI and not a person. That line links to your privacy policy. Set the address under Privacy policy URL in the widget's behavior settings, and make sure the page it points to describes the chat: what is collected, why, how long it is kept and who processes it.
8. Send the AI only what it needs
Data minimisation is easier when not every message reaches the AI. AskMerra's router answers greetings, thanks and "are you a bot?" with fixed rules, and close matches to your FAQ with your own text, without calling the AI model. The answer cache only stores generic first answers, without prices or personal data.
A few habits help further:
- Keep the knowledge base to policies and product facts. Its documents are included in the assistant's context, so leave out internal notes and personal details, such as a colleague's mobile number.
- Let the contact form handle personal matters. Names, emails and order details go to your team by email, where a person deals with them.
- Steer the conversation. Use your greeting and suggested questions to point shoppers toward product and policy questions.
9. Get the DPA and keep it on file
AskMerra signs a DPA for your compliance file. Request it through [email protected] or the contact form, and keep it with your records of processing, next to the sub-processor list.
Security belongs on the list too
Privacy controls only help if the data is also protected. On AskMerra's side: encryption in transit, tenant isolation enforced on every database query and covered by automated tests, passwords hashed with argon2id, and optional two-factor login for your dashboard. The widget only works on your own domains. Turn on two-factor login for everyone on your team; the security page has the details.
The checklist in short
- Know what the chat collects, and describe it in your privacy notice.
- Read the sub-processor list in the DPA.
- Choose a retention period of 30, 90 or 365 days.
- Know how to delete a shopper's data, and consider adding
AskMerra.forget()to your privacy page. - Leave visitor identification off unless you need it.
- Set the privacy policy URL in the widget.
- Get the DPA, and review the whole setup with your legal advisor.
You can configure all of this as soon as you create your account, before a single real shopper sees the widget. If you have questions about your setup, book a demo. The documentation and our privacy policy have the full details.
Put AskMerra to work on your store
Connect your catalog, test the assistant in the playground and go live when you are ready.
Get startedKeep reading
- What Is an AI Shopping Assistant? How It Works on Your StoreAn AI shopping assistant answers shoppers in their own words and recommends real products. Here is how one works on an online store, from question to sale.
- Accurate AI Answers on Your Store, Grounded in Your CatalogAI on a store is risky when it invents products or quotes wrong prices. See how AskMerra keeps every answer tied to your real catalog, stock and policies.
- Conversational Product Search vs Keyword Search: What WorksKeyword search and filters fail shoppers who describe needs, not product names. Learn how conversational product search helps and when to use each one.