Vereli Privacy Policy
Published 20 August 2026. Accurate against what Vereli actually does, and reviewed against the code rather than adapted from a template and left there — see the correction history below.
Correction history, kept rather than tidied away:
- 20 August 2026 — corrected against the code after FR-23 (email as a customer channel) shipped. Three statements had become false: that email addresses are held only as a one-way hash, that they are "never used to contact you directly", and a processing list that omitted the email provider entirely. Also added: Anthropic's 30-day API retention (verified against their published terms), the separate email/SMS opt-out treatment, and cross-border disclosure stated plainly rather than in passing.
- 17 August 2026 — corrected two retention claims that matched no implemented mechanism ("12 months", "30 days after uninstall"); the real behaviour is the 90-day purge described below. Added email address to the collected-data list, which the draft had omitted despite the schema carrying it.
- 9 August 2026 — updated for the AI-subprocessor switch.
ABN and registered address are deliberately not included (founder decision, 18 August 2026): neither is a legal requirement for this document, and Vereli is a sole trader — an ABN is registered under the individual's own name, and publishing it here would de-anonymise the founder for no compliance benefit. A merchant whose procurement needs it can be given it directly.
Last updated: 20 August 2026
Who we are
Vereli is operated by Vereli ("Vereli", "we", "us", "our"), an Australian sole trader. Vereli is a Shopify app that helps Australian merchants recover abandoned checkouts using two-way SMS. This policy explains what personal information we collect, why, and what rights you have over it — whether you're the merchant who installed Vereli, or a customer of that merchant who received a recovery message.
Two different relationships, and why that matters
Vereli sits between a merchant and their customer, and handles personal information in two distinct capacities:
- As the merchant's data processor, for their customers' information — the phone number, name, cart contents, and SMS conversation of someone who abandoned a checkout on the merchant's store. The merchant is the data controller for this information; we process it only to provide the Service, under the merchant's instructions and Shopify's own terms.
- As a data controller in our own right, for the merchant's own account information — the store's Shopify domain, settings, and billing details.
If you're a shopper who received a text from a store using Vereli, your relationship for privacy purposes is with that store, not with us — see "If you're a shopper" below for what you can still do directly with us.
Personal information we collect or process
On behalf of merchants, about their customers:
- Phone number (must be a real Australian mobile number to receive SMS)
- First name, where the merchant's checkout captured one
- Email address, where the merchant's checkout captured one. Held two ways, for two different jobs: a one-way hash used to recognise you and to honour an unsubscribe, and — email being the base channel on every plan — the address itself, encrypted, so a recovery email can actually be sent to you. The address is only ever decrypted at the moment a message is sent, and is never written into a log, a report, or our own records in readable form.
- Cart contents and value, at the time of abandonment
- SMS consent status, and the record of how and when it was given (from Shopify's own checkout/customer consent fields)
- The content of SMS messages exchanged as part of a recovery conversation
- Order and refund data, where a recovery conversation resulted in a purchase
About merchants themselves:
- Shopify store domain, name, and country
- Contact and billing information via the Shopify Billing API
- App settings (tone, quiet hours, discount ceiling, report recipients)
- SMS provider account details (BYO Twilio or equivalent), stored encrypted
Automatically, from both:
- Technical logs (IP address, request metadata) for security and debugging
- Delivery and error data from the SMS provider and from our AI provider (Anthropic/Claude)
How we use it
- To detect an abandoned checkout and decide whether — and when — to send a recovery SMS, subject to consent, opt-out, and quiet-hours rules that cannot be overridden by either the merchant or the AI.
- To generate and send the message itself — by SMS, or by email where the merchant has enabled it — and to classify and respond to a reply, including offering a single, capped discount code where a merchant has enabled one and a customer has objected on price. A conversation runs on one channel; you are not messaged twice about the same abandoned cart.
- To hand a conversation to a human at the merchant's business, when the AI determines it should not continue (abuse, a legal threat, low confidence, or a request outside what SMS recovery covers).
- To calculate and report a merchant's recovered revenue.
- To operate, secure, and improve Vereli itself.
Your data is never used to train AI models. As of publication our AI provider is Anthropic (Claude), whose commercial terms state plainly that "Anthropic may not train models on Customer Content from Services." That covers everything Vereli sends them.
They do hold it briefly, and you should know that. Anthropic automatically deletes API inputs and outputs from their systems within 30 days, unless a zero-data-retention arrangement is in place. Vereli does not currently hold one. So a recovery conversation may exist on Anthropic's infrastructure for up to 30 days after it happens, purely for their operational and abuse-prevention purposes — never for training, and never longer than that window.
Verified against Anthropic's published commercial terms and platform documentation on 20 August 2026. If we change AI provider, or take up a zero-retention arrangement, this section changes with it.
Where your information is stored
Vereli's database is hosted in Sydney, Australia. Some processing necessarily happens outside Australia, and we only send each provider what that provider needs to do its specific job — never raw account credentials:
- SMS delivery — Twilio, or another provider the merchant has connected. Receives the message and the phone number. Where the message is sent from an account Vereli runs on the store's behalf, it is processed in Twilio's Ireland region, chosen over the US default as the more privacy-protective of the options available; no Australian region exists for SMS. Where a store has connected its own Twilio account, the processing location is whichever region that account is configured for — a setting the store controls and Vereli does not. Twilio's own default is the United States, so unless the store has chosen otherwise, that is where its messages are processed. A store that wants Irish processing can configure its own Twilio account for Ireland; a store that would rather keep the US default may.
- AI generation and classification — Anthropic (Claude). Receives the conversation content needed to produce or classify a single reply.
- Email delivery (every plan) — Resend. Receives the recipient's email address and the message content. Processed in Resend's Ireland region, chosen for the same reason as Twilio's; again, no Australian region exists.
Stated plainly rather than buried: sending your information to a provider outside Australia is a cross-border disclosure under Australian privacy law, and we remain accountable for how those providers handle it. We choose providers with recognised data protection standards and, where a provider offers a choice of region and the choice is ours to make, we choose the more privacy-protective one rather than the default.
The qualifier matters and is not a hedge. Where a store connects its own messaging account, that account's region is the store's setting, not ours. We would rather say so than imply a guarantee we are not in a position to keep.
How long we keep it
- A customer's personal information — including the content of the SMS and email messages exchanged with them — is purged 90 days after their last conversation closes. Aggregate statistics (that a message was sent, when, whether it converted) are kept for reporting; the personal information behind them is not.
- Two clarifications added 26 August 2026, after checking this section against what the code actually does. Both mean information is sometimes held longer than the sentence above on its own would suggest, so they are stated rather than left to be inferred. First, where a customer has had more than one conversation, the 90 days runs from the most recent one to close, not from each conversation separately. Second, while any conversation with that customer is still open, the clock has not started — an open conversation is one still being actively recovered.
- This 90-day purge applies whether or not the merchant has since uninstalled Vereli. Uninstalling stops any further messages and marks the store inactive, but does not itself trigger a separate, faster purge beyond the 90-day window above.
- Webhook delivery records are kept 90 days for fraud and reliability purposes only.
Your rights
If you're a shopper who received a message from a store using Vereli:
- Reply STOP at any time to immediately and permanently opt out of further SMS from that store through Vereli. This is honoured before any other processing, and you'll receive a confirmation.
- Unsubscribe from an email the same way, using the link in it. Email and SMS are kept as separate choices on purpose: stopping texts does not silently stop emails you may still want, and vice versa. If you want both stopped, use both — or ask us and we'll do it for you.
- You can ask the merchant, or contact us directly at support@vereliapp.com, to request a copy of the information we hold about you, or to have it deleted. We action these directly, whether the request reaches us through the merchant or directly.
If you're a merchant:
- You control your own account settings at any time from within the app.
- Uninstalling the app triggers deletion of your store's data as described above.
- You can request an export of your account data by contacting support@vereliapp.com.
General rights (where applicable under the Privacy Act 1988 or another
law that applies to you): access, correction, and complaint. To make a
complaint about how we've handled your information, contact us first at
support@vereliapp.com; if unresolved, Australian individuals can complain to
the Office of the Australian Information Commissioner (OAIC),
oaic.gov.au.
Who we share information with
- Shopify — the platform Vereli is built on; Shopify processes
information about your use of the app under its own privacy terms
(
shopify.com/legal/privacy). - Twilio (or another SMS provider the merchant has connected) — to transmit and receive SMS messages.
- Anthropic (Claude) — to generate and classify message content, as described above.
- Resend — to deliver email. Email is the base channel on every plan, so this applies to every merchant, not only those who opt into it.
- Supabase — our database and backend infrastructure provider, hosted in Sydney.
- We do not sell personal information, and we do not share it for third-party advertising or marketing purposes.
- We may disclose information if required by law, or to protect the rights, safety, or property of Vereli, our merchants, or others.
Children
Vereli is a business tool used by merchants and is not directed at children. We do not knowingly collect personal information from children.
Security
We use industry-standard measures to protect personal information, including encryption of stored credentials and Australian data residency for our own database. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to us.
Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date above and, for material changes, take reasonable steps to notify merchants.
Contact
Questions about this policy, or to exercise any of the rights above, contact us at support@vereliapp.com.