AI Assistant security and GDPR
August 14, 2026
Data handling
The AI Assistant sends your prompts and relevant store data to Storeborn's AI sub-processor, listed in your Storeborn Terms of Service §21. The platform manages the sub-processor relationship; you don't see or configure it.
What gets sent
- Your message text
- The current admin route + entity context (e.g. "viewing product X")
- By default, customer-data tools include full names, emails and addresses when the AI requests them. Enabling Strict PII mode (below) masks these.
What does NOT get sent
- Other merchants' data (row-level security enforces tenant isolation at the database level)
- Payment card details (tokenised by the payment provider — they never reach the AI path)
- Your account credentials
Strict PII mode (opt-in)
In AI Settings → Strict PII you can enable Strict PII mode. When on, customer-related tools return only IDs and initials — never full names, emails or addresses. Recommended if you handle sensitive customer data or want to minimise PII exposure to the sub-processor.
EU AI Act Article 50 — disclosure
Every AI write is recorded in your audit log. Storeborn also offers an opt-in storefront badge that labels AI-authored copy on product, category and content pages for your customers. Configure under AI Settings → Storefront AI badge.
Audit trail + 24-hour undo
Every AI write is logged. Within 24 hours you can undo any AI write directly from the chat panel or the activity page.
Pausing AI
If you need to limit what the AI can do, owners can disable individual tools via AI Settings → Tool allowlist — the assistant then refuses to run them. Storeborn's platform operations team also maintains a three-level kill switch for platform-wide incidents.