Política de privacidad

Última actualización: 5 de octubre de 2026

Quién trata tus datos

Parlo es un servicio de The Wise Brands LLC, con domicilio postal en 11820 Miramar Pkwy, Unit 204, Miramar, FL 33025 (Estados Unidos), EIN 98-1896488. Para cualquier cosa relacionada con tus datos, escribe a info@parlodesk.com. Los datos de la empresa están en el aviso legal.

Esta política cubre el sitio web parlodesk.com y la aplicación de Parlo en app.parlodesk.com.

No hemos designado delegado de protección de datos porque no estamos obligados; para todo, info@parlodesk.com.

Dos papeles distintos

Parlo lee el buzón de atención al cliente de una tienda online, entiende cada correo con ayuda de un modelo de inteligencia artificial, busca el pedido en la tienda de Shopify y deja preparado un borrador de respuesta. Una persona de la tienda lo revisa y lo envía desde su propio buzón.

Si la tienda lo elige, algunas respuestas salen solas, sin que las revise una persona, también desde el buzón de la tienda y firmadas como agente de IA. Lo explicamos en «Qué hace la inteligencia artificial».

Por eso tratamos datos en dos papeles:

  • Como responsable. Los datos de las personas que usan Parlo dentro de cada tienda (su cuenta), los de quien se da de alta, los de facturación, los que nos mandas si nos escribes, los de quien visita la web y los datos técnicos para que el servicio funcione y sea seguro. Aquí decidimos nosotros para qué y cómo, y esta política te lo explica.
  • Como encargado. Los correos que llegan al buzón de la tienda y los datos de los pedidos de sus clientes. Esos datos son de la tienda: ella es la responsable y nosotros los tratamos solo por su cuenta, siguiendo sus instrucciones y el contrato de encargo de tratamiento que forma parte de nuestros términos del servicio. Lo explicamos en el apartado «Si eres cliente de una tienda que usa Parlo».

Qué datos tratamos como responsable, y por qué

  • Si usas Parlo en tu tienda. Tu correo, tu nombre si lo das, tu contraseña (guardada de forma que nadie, tampoco nosotros, puede leerla), la tienda a la que perteneces y tu papel en ella, la fecha de alta y la de tu último acceso. También queda constancia de qué respuestas aprobaste, editaste o contestaste, de cuándo consultaste la dirección de envío de un pedido, de si se te quitó el acceso y de las invitaciones y enlaces para poner contraseña que se crearon para ti. Si te invitó quien lleva tu tienda, tu correo nos lo dio esa persona. Lo usamos para que puedas entrar, para controlar quién ve qué y para dejar rastro de la actividad. La base legal es el contrato con tu empresa y nuestro interés legítimo en prestarle el servicio a ella a través de ti.
    • Queda también constancia de quién cambió el modo de respuesta de la tienda o las situaciones que pueden salir solas, y cuándo; de quién encendió la valoración de las respuestas, el portal de la tienda, su enlace al pie de las respuestas o la tarjeta del equipo, y cuándo, mientras siga encendido; de quién cambió por última vez lo que los clientes pueden hacer en el portal, y cuándo; de quién aprobó o no un cambio de dirección pedido desde el portal, y cuándo; y de quién marcó como hecha en Shopify la cancelación o el cambio de dirección de un pedido.
    • La tarjeta del equipo. Viene apagada. Si quien lleva tu tienda la enciende, verá en la analítica, junto a tu correo, cuántas respuestas aprobaste y cuántas editaste en el periodo, y cuánto tardaste de media en aprobarlas. Antes de encenderla, la aplicación le pide que se lo diga a las personas que contestan con él. Para qué usa tu empresa esa información lo decide ella.
  • Si te das de alta tú mismo. Antes de pedir el alta pasas una comprobación contra robots de Cloudflare (Turnstile): tu navegador se conecta a Cloudflare, que ve tu dirección IP, tu navegador y señales técnicas de la conexión; nuestro servidor solo le manda la respuesta del reto, ni tu correo ni tu dirección IP. Después, tu correo, para mandarte el enlace con el que creas la cuenta, y la dirección IP de la conexión, para frenar abusos (hay un límite de peticiones por dirección y por conexión cada hora). Esa petición se borra a los 7 días, la siguiente vez que alguien pide un alta. La cuenta nace cuando abres el enlace del correo y eliges tu contraseña. Al crear la tienda guardamos su nombre y la aceptación de nuestros términos: qué versión aceptaste, una huella del documento de esa versión, cuándo, quién y desde qué conexión, y te mandamos por correo una copia en PDF. También guardamos la dirección IP con la que se creó la tienda, para frenar abusos (como mucho 3 tiendas por conexión cada 24 horas). Al crear la tienda eliges cómo contesta Parlo; si eliges un modo distinto de Borrador, queda apuntado que lo elegiste tú y cuándo, como cualquier cambio del modo de respuesta. La base legal es la aplicación de medidas precontractuales a petición tuya y, para la dirección IP, nuestro interés legítimo en proteger el servicio.
  • Si conectas el buzón de la tienda. Con Microsoft 365 guardamos la dirección del buzón sobre el que se dio el permiso, para comprobar que Parlo lee y contesta desde el buzón correcto. Y leemos los datos básicos del perfil de la cuenta que lo autoriza, para enseñar en pantalla quién lo hizo. La base legal es el contrato.
    • Con Gmail, cuya conexión está en pruebas, guardamos la dirección del buzón y la contraseña de aplicación que creas en tu cuenta de Google, cifrada. No usamos el inicio de sesión con Google ni sus permisos: según Google, una contraseña de aplicación da acceso a tu cuenta de Google, y con ella se puede leer y enviar todo el correo de esa cuenta, no solo el de la tienda, aunque Parlo solo la usa para leer y enviar el correo de ese buzón. Puedes retirarla en cualquier momento en la página de contraseñas de aplicación de tu cuenta de Google, y desconectando el buzón en Parlo, que la borra de nuestra base. Si cambias la contraseña de tu cuenta de Google, Google borra todas las contraseñas de aplicación. Si Google frena el acceso aunque la contraseña valga (porque el acceso por IMAP está cerrado o porque pide entrar desde el navegador), guardamos cuál de las dos cosas es, desde cuándo y cuándo lo probamos por última vez, para decírtelo en la aplicación; lo volvemos a probar cada 15 minutos o cuando pulsas «Volver a probar».
  • Si usas el asistente. Lo que le escribes se envía al modelo de inteligencia artificial con los correos, los teléfonos y los números largos tapados, junto con un resumen de los ajustes de tu tienda. La conversación no se guarda en ningún sitio: solo se guardan los cambios que decides aplicar. La base legal es el contrato.
  • Intentos fallidos de entrar. El correo que se tecleó y la dirección IP de la conexión, para frenar a quien prueba contraseñas. Los de más de 24 horas se borran la siguiente vez que alguien intenta entrar. La base legal es nuestro interés legítimo en proteger las cuentas.
  • Si tu tienda se suscribe. El correo de quien lleva la tienda y el identificador de la tienda van a Stripe, que gestiona el pago, junto con el plan y la forma de pago elegidos (mensual o anual) y, si lo usas, el código de quien te recomendó Parlo, que queda en tu suscripción para calcular su comisión. La tarjeta, las facturas y la dirección de cobro las escribes tú directamente en la página de Stripe: no pasan por Parlo ni las vemos. De Stripe recibimos el estado de la suscripción (activa, en prueba, en pausa, cancelada, con un pago pendiente), su plan, sus fechas, si tiene una forma de pago puesta (nunca cuál) y si lleva un descuento. La base legal es el contrato y, para conservar las facturas, nuestro interés legítimo en cumplir las obligaciones fiscales y contables que nos aplican.
  • Lo que tu tienda configura. Al poner a punto la tienda leemos de Shopify su nombre, su correo público de contacto, su dominio, su país de facturación y sus políticas públicas de envío y devolución. Y guardamos lo que la tienda nos cuenta para redactar a su manera: plazos, tono, firma, idiomas, lo que ofrece y lo que no dice nunca. Si quien lleva la tienda los pone, también el código postal y las cuatro últimas cifras del teléfono de remitente de sus etiquetas de SEUR, que damos a 17TRACK para seguir esos envíos. La base legal es el contrato.
  • Si tu tienda conecta Slack. Guardamos cifrada la dirección del canal de Slack que nos das. A ese canal mandamos avisos con el nombre de la tienda, cuentas (cuántos correos esperan a una persona y por qué tipo de consulta, cuántos tienen riesgo alto de contracargo, si el buzón ha dejado de responder) y un enlace a la aplicación, y el informe de la semana: cifras y los nombres de los productos y de los transportistas de la tienda con más consultas. También los avisos de que la tienda llega al 80 % o al 100 % de las conversaciones de su plan, del día en que acaba la prueba (sin el importe, porque el canal lo lee todo el equipo) y de la suscripción en pausa. Nunca el texto de un correo ni un dato de un comprador, salvo el número del pedido en los avisos del portal que explicamos más abajo. Slack lo elige y lo contrata tu tienda, y lo que pase en ese canal se rige por su contrato con Slack. La base legal es el contrato.
  • Si te escribimos por correo. A quien lleva la tienda, desde una dirección de Parlo (avisos@parlodesk.com) y a través de nuestro proveedor de correo (Resend): los avisos del servicio (que tu tienda llega al 80 % o al 100 % de las conversaciones de su plan, que se acerca el primer cobro, con el día, lo que se cobrará y si falta una tarjeta, o que la suscripción está en pausa); si te das de alta tú mismo, el enlace para crear tu cuenta, el aviso de que ya tienes una si es el caso y la copia en PDF de los términos que aceptas; y, si tu tienda lo recibe por correo, el informe de la semana (cifras y los nombres de los productos y transportistas de tu tienda con más consultas); y, si tu tienda tiene encendidos los avisos del portal de sus clientes, los cambios de dirección y las peticiones de reembolso que hacen desde él, con el número del pedido y, si es la dirección, de cuál a cuál, o el motivo del reembolso. Si contestas a uno de estos correos, tu respuesta nos llega a info@parlodesk.com. Nuestros correos no llevan imágenes, píxeles ni nada que se cargue de fuera, y no medimos si los abres ni en qué enlaces pulsas. De cada aviso guardamos a quién le llegó con una huella de su dirección en lugar de la dirección, para no mandarlo dos veces. Nunca escribimos a los clientes de las tiendas. La base legal es el contrato.
  • Si nos escribes. Tu nombre, tu correo y lo que nos cuentes. Lo usamos para contestarte. La base legal es tu propia solicitud y nuestro interés en atenderla.
  • Datos técnicos. Cuando algo falla, nuestro servicio de avisos de errores recibe el tipo de error y la primera línea de su mensaje, con los correos, los teléfonos, las direcciones IP y lo que va entre comillas tapados; identificadores internos de la tienda; la dirección de la página sin sus parámetros; el navegador y datos técnicos del sistema; y un rastro breve de los pasos que llevaron al error (clics, peticiones y páginas). El sistema está construido para que no salgan el asunto ni el texto de los correos, ni cookies, ni grabaciones de la sesión, aunque un filtro automático no puede descartar del todo que se cuele un nombre suelto. Si la aplicación falla en tu navegador, el aviso sale directamente de tu navegador hacia ese servicio, que ve tu dirección IP para recibirlo y está configurado para no guardarla. La base legal es nuestro interés legítimo en que el servicio funcione.

No compramos listas, no hacemos perfiles publicitarios y no tomamos decisiones automatizadas sobre ti.

Dar tus datos de cuenta es necesario para usar Parlo: sin un correo y una contraseña no se puede entrar.

Si visitas parlodesk.com

Navegar por parlodesk.com no requiere darnos ningún dato: no tiene formularios, cookies, analítica, publicidad, píxeles ni contenidos de terceros. Lo único que guarda en tu navegador es el idioma que eliges con el botón de idioma, si lo pulsas (lo explicamos en la página de cookies). Nuestro proveedor de red (Cloudflare), que sirve la web, ve la dirección IP y el navegador de cada visita para entregar la página y frenar abusos.

En app.parlodesk.com, sin iniciar sesión solo se pueden ver la página de entrada, la de crear una cuenta, la página donde un comprador valora una respuesta y el portal donde los clientes de una tienda miran su pedido. Nuestro proveedor de red (Cloudflare) recibe la dirección IP y los datos técnicos de cada visita porque todo el tráfico pasa por él. La aplicación no guarda esas visitas, salvo los intentos fallidos de entrar, las peticiones de alta, las consultas del portal, que se explican más abajo, y los avisos de errores que hemos explicado arriba. Dentro de la aplicación, las imágenes de los productos se cargan desde los servidores de Shopify, que ven tu dirección IP al servirlas.

Si eres cliente de una tienda que usa Parlo

Si has escrito a una tienda que usa Parlo, la responsable de tus datos es esa tienda. Nosotros los tratamos por su cuenta para ayudarla a contestarte, y no los usamos para nada nuestro. Parlo no te escribe nunca: la respuesta te llega de la tienda, desde su buzón.

Si la tienda lo ha elegido, algunas respuestas te llegan sin que las haya revisado una persona. Hoy solo pueden ser respuestas en castellano, inglés, portugués, francés, italiano o alemán sobre dónde está tu pedido, cuando va en camino dentro de plazo o ya consta entregado. Esas respuestas van firmadas «The [nombre de la tienda] AI Customer Care Agent», para que sepas que te ha contestado un sistema de inteligencia artificial.

Lo que tratamos por cuenta de la tienda:

  • Tu correo. Dirección, nombre, asunto, texto y fecha, y los datos que enlazan la conversación. Si en el correo pegas un número de tarjeta, el sistema lo detecta y lo tapa antes de guardar el correo. Se guardan también los correos de quien escribe a la tienda sin ser cliente (proveedores, transportistas, boletines), para que la tienda pueda revisarlos.
  • Desde cuándo. Solo se leen los correos que llegan, y los que la tienda envía, desde que conecta su buzón. Las excepciones son que la tienda pida expresamente analizar su historial, o que autorice por escrito una prueba con correos anteriores antes de empezar o nos entregue una exportación de su buzón.
  • Lo que la tienda envía. Para no contestarte dos veces, Parlo mira la carpeta de enviados del buzón: guarda las cabeceras de esas respuestas y una huella de tu dirección que no se puede revertir.
  • Tu pedido. Si identificamos con certeza tu pedido de los últimos 60 días: número, fecha, importe, estado del pago y del envío, tu nombre y correo, la dirección de envío, los productos, el seguimiento del envío y la valoración de riesgo que hace Shopify. Del pedido no leemos tu tarjeta, y tu teléfono solo si cambias la dirección desde el portal de la tienda (más abajo).
  • Por dónde va tu envío. Cuando preguntas por tu pedido y Shopify no sabe decir por dónde va, Parlo se lo pregunta al transportista a través de 17TRACK. A 17TRACK le damos el número de seguimiento, el transportista cuando lo sabemos y un identificador nuestro que no dice nada de ti; con el transportista PostNL, también el país de destino. Solo con GLS España, Paack, Envialia, Ontime, TIPSA, Mondial Relay e InPost España, también el código postal de la dirección de entrega de tu pedido, para seguir el envío, y nada más de ti: ni tu nombre, ni la calle, ni tu correo, ni tu teléfono. Ese código postal lo tomamos de tu pedido al consultar y no lo guardamos aparte. Con SEUR le damos el código postal y las cuatro últimas cifras del teléfono de la propia tienda, que es quien envía, nunca los tuyos. De su respuesta guardamos el estado, las fechas de los movimientos y el país de destino, nunca los lugares ni la dirección.
  • Lo que se deduce de tu correo. Qué pides (por ejemplo, dónde está tu pedido o una devolución), en qué idioma escribes y si el correo trae señales que conviene que vea una persona: enfado, una amenaza legal, una disputa de pago, un problema de salud o un daño. También un nivel de riesgo de que el pago acabe en una reclamación a tu banco, con sus motivos. Con esto se decide qué se prepara, qué pasa directamente a una persona de la tienda y, si la tienda lo ha elegido, qué puede salir solo. No tiene efectos jurídicos sobre ti: solo ordena el trabajo de la tienda.
  • Si no quieres que te escriban. Si tu dirección rebota, se queja o pide no recibir más correos, queda en una lista de direcciones a las que no se escribe.
  • La respuesta. El borrador, la versión que corrige la persona de la tienda y la que se envía. Si la tienda lo activa, Parlo analiza también cómo contesta su equipo para proponerle mejoras solo para esa tienda. Se guarda también si la respuesta salió sola o la aprobó una persona. Cuando el buzón de la tienda lo permite, cada respuesta redactada por Parlo lleva en el correo una marca técnica, que no se ve en el texto, que dice que la ha redactado un sistema de IA y si la revisó una persona; lo que sale solo la lleva siempre.
  • Tu valoración. Si la tienda lo enciende, al final de la respuesta aparece un enlace para decir si te hemos ayudado. Si votas, guardamos tu voto (sí o no), el comentario que escribas si quieres y la fecha, ligados a esa respuesta. Se puede votar una vez y durante 30 días. La página donde votas es nuestra (app.parlodesk.com) y lleva el nombre de la tienda; no guarda tu dirección IP. El voto se borra con la respuesta.
  • Plazos de entrega. Para saber cuánto tardan de verdad los envíos, de los pedidos entregados se usan solo el país y las fechas, y se guarda el resultado sumado por país.
  • Para contar las conversaciones del plan de la tienda. Por cada mes, el número del pedido o, si no hay pedido, una huella de tu dirección que no se puede revertir.
  • Si usas el portal de la tienda. Algunas tiendas tienen una página (en app.parlodesk.com/p/...) donde, con tu número de pedido y tu correo, ves en qué punto está tu pedido y puedes pedir por escrito un cambio de dirección (si aún no ha salido nada) o una devolución (si ya te ha llegado algo); si la tienda lo tiene encendido, también puedes cambiar tú la dirección de envío o pedir un reembolso, como explicamos abajo. Desde el portal no se puede cancelar un pedido. Antes de buscar pasas una comprobación contra robots de Cloudflare (Turnstile): tu navegador se conecta a Cloudflare, que ve tu dirección IP, tu navegador y señales técnicas de la conexión; nuestro servidor solo le manda la respuesta del reto. Con tu número y tu correo buscamos el pedido en la tienda de Shopify y solo te enseñamos el número, el día de compra, en qué punto está y, de cada paquete, el transportista, el número y el enlace de seguimiento y el día del último movimiento y, si puedes cambiar la dirección, el país de entrega; nunca tu dirección, los importes ni los artículos. Leemos también el idioma del pedido, para escribirte en él el código del que hablamos abajo. Si el número y el correo no son de un pedido, la página dice lo mismo que si no existiera. Para frenar abusos hay un límite de búsquedas por conexión, por correo, por pedido y por tienda, y la respuesta siempre tarda al menos 2 segundos. Lo que pides por escrito no hace nada por sí solo: llega a la tienda como un correo tuyo, sin respuesta preparada, y una persona de la tienda lo revisa, lo hace en Shopify si procede y te contesta con un correo. Qué guardamos y cuánto tiempo:
    • El número y el correo que escribes: si no son de un pedido, se borran en cuanto tenemos la respuesta; si lo son, a la media hora, porque durante ese rato puedes pedir algo.
    • Una huella de la dirección IP de tu conexión (un seudónimo, no anonimato): una hora, para contar el límite.
    • Una huella (un seudónimo, no anonimato) de tu correo y otra del número de pedido, cada una junto con la tienda: un día, para contar los límites. Quien tuviera la base y adivinara un correo o un número de pedido podría comprobarlo. Si el pedido se encontró, también su identificador en Shopify, con la fecha de la consulta, durante ese mismo día.
    • Si pides algo por escrito, el texto que escribes queda en la bandeja de la tienda como cualquier otro correo tuyo, junto con el pedido y qué pediste.
    • Al final de las respuestas de la tienda puede ir un enlace a ese portal. Es el mismo para todos los clientes de la tienda: no lleva nada tuyo. Si en tu correo pides cambiar la dirección de un pedido que no ha salido, o el reembolso de uno enviado, y la tienda tiene esa opción encendida, la respuesta lleva al final el enlace para hacerlo tú desde el portal; lo decide nuestro código con el texto de tu correo, no el modelo de IA.
  • Si cambias la dirección de envío desde el portal. Si la tienda lo tiene encendido y tu pedido no ha salido, puedes cambiar tú su dirección de envío, dentro del mismo país y la misma provincia, y se cambia en el pedido de Shopify de la tienda, al momento o después de que la tienda dé su visto bueno. Antes, para que nadie más pueda cambiar la dirección de tu pedido, la tienda te manda desde su buzón un código de 6 cifras al correo del pedido, como sus respuestas: el correo lo envía el proveedor de correo de la tienda (Microsoft o Google), en el idioma de tu pedido o, si no es uno de los seis en los que escribimos, en el de la página. Del código guardamos solo una huella, no el código, y solo mientras vale: caduca a los 10 minutos, se puede escribir mal 5 veces como mucho y sirve una vez; al usarlo, agotarlo o caducar, la borramos. Guardamos también cuántas veces lo has escrito, cuándo se pidió y se mandó, y en qué idioma; todo eso se borra al día. Para frenar abusos, como mucho se mandan 3 códigos por pedido a la hora y 5 al día, y 30 por tienda a la hora y 100 al día. Al cambiarla guardamos la dirección nueva que escribes (nombre y apellidos si los cambias, calle, piso, código postal, ciudad y, si lo das o la tienda lo pide, tu teléfono) y la que tenía el pedido en Shopify justo antes (también su teléfono y su empresa, si los tenía), para que la tienda sepa qué cambió, junto con el número del pedido, cuándo lo pediste, quién de la tienda lo aprobó y lo que contestó Shopify. A los 90 días borramos la dirección nueva y la de antes, y se queda qué pasó y cuándo. En la bandeja de la tienda queda además un correo con las dos direcciones, que se conserva como cualquier otro correo tuyo.
  • Si pides un reembolso desde el portal. Si la tienda lo tiene encendido y tu pedido ya ha salido, puedes pedirle el reembolso con un motivo. Es solo una petición: la decide la tienda, y desde el portal no se devuelve dinero. Guardamos el motivo, el número del pedido, cuándo lo pediste y el resultado; a los 90 días borramos el motivo, y en la bandeja de la tienda queda un correo con él, que se conserva como cualquier otro correo tuyo.
  • Lo que avisamos a la tienda. De cada cambio de dirección o petición de reembolso, la tienda recibe un aviso con el número del pedido y, si es la dirección, de cuál a cuál, o el motivo del reembolso: por correo a quien lleva la tienda (a través de nuestro proveedor de correo, Resend) y, si la tienda lo conectó, en su Slack (en Slack, sin la dirección ni el motivo). Nunca tu correo ni tu teléfono.

Si quieres ejercer tus derechos sobre esos datos, dirígete a la tienda. Si nos escribes a nosotros, le pasamos tu petición a la tienda y la ayudamos a contestarte.

Qué hace la inteligencia artificial

Para leer cada correo y redactar el borrador usamos Gemini, de Google, a través de Vertex AI en su multirregión de la Unión Europea, que mantiene el procesamiento dentro de la UE.

  • Para clasificar un correo, el modelo recibe su asunto y su texto, con los números de tarjeta tapados.
  • Para redactar, el modelo recibe el texto de tu correo tal como lo escribiste (solo se tapan los números de tarjeta), las instrucciones de la tienda y, de los datos que Parlo saca de Shopify, solo una lista cerrada: el número de pedido, el nombre de pila, los productos, los plazos y el seguimiento. De Shopify no recibe apellidos, dirección, correo, importes ni la valoración de riesgo.
  • Si tu correo no está en castellano, la persona de la tienda que lo revisa puede pedir verlo traducido al castellano. Para eso, el mismo modelo recibe el texto de tu correo guardado (con las tarjetas tapadas) y el borrador. La traducción solo se enseña en pantalla: no se guarda, no se envía y no cambia el borrador.
  • Si Parlo no identifica tu pedido con certeza, el borrador no puede afirmar nada sobre él: si lo hace, se descarta y el correo pasa a una persona.
  • La tienda elige cómo contesta Parlo: en «Borrador», que es lo de fábrica, una persona revisa y envía cada respuesta; en «Automático por temas», salen solas las situaciones que la tienda elige, y cada una solo después de que la tienda haya aprobado sin cambios un número de borradores de ese tipo (20, 50 o 100); en «Automático», salen solas todas las situaciones que lo permiten, con la confirmación expresa de quien lleva la tienda. En los tres, cada correo pasa las mismas comprobaciones, y lo que no las pasa queda como borrador para una persona. Solo quien lleva la tienda puede pasar a un modo automático; Parlo, por su cuenta, solo puede volver a «Borrador», y lo hace si un correo de la tienda rebota de forma permanente o alguien lo marca como spam, si la tienda se da de baja, o si tenemos que restaurar una copia de seguridad de la base de datos, que deja todas las tiendas en «Borrador», y apunta el motivo. Lo que sale solo:
    • Va firmado «The [nombre de la tienda] AI Customer Care Agent», en todos los idiomas. Esa firma la pone nuestro código, no el modelo, y la tienda no la puede quitar. Lo que aprueba una persona no la lleva.
    • Espera unos minutos antes de salir, y en ese tiempo cualquier persona de la tienda lo puede parar y devolverlo a borrador.
    • Nunca incluye reembolsos, devoluciones, cancelaciones, cambios ni quejas; lo que pide dinero o trae una reclamación legal, una disputa del pago, un problema de salud o un daño; lo que ofrece algo o promete gestiones; ni la respuesta a quien ya ha escrito otro correo en las últimas 72 horas; ni lo escrito en un idioma que todavía no sale solo (hoy, todo lo que no está en castellano, inglés, portugués, francés, italiano o alemán). La tienda no puede cambiar esto. Tampoco sale solo un correo con un riesgo de contracargo por encima del que la tienda acepta en sus ajustes. Y no sale solo lo que no puede llevar la marca técnica de la IA que explicamos arriba: vuelve a borrador para una persona.
  • Los correos sobre temas legales (denuncias, abogados o derechos como consumidor) pasan siempre a una persona, sin borrador. Los que hablan de una disputa de pago, de salud o de un daño a una persona también pasan a una persona sin borrador, salvo que la tienda lo cambie en sus ajustes; aun así, nunca salen solos.
  • Quien lleva la tienda puede usar un asistente para contarle a Parlo cómo trabaja su tienda; lo que le escribe se envía al modelo con datos de contacto tapados, como explicamos arriba.
  • No entrenamos ni ajustamos ningún modelo de IA con los datos de las tiendas. Lo que Parlo aprende de cómo contesta una tienda solo se usa para esa tienda y nunca pasa a otra.
  • Nuestros registros técnicos no guardan lo que se envía al modelo ni lo que contesta: solo tamaños, tiempos y coste. El registro del proceso que trabaja los correos sí apunta el asunto de cada correo que procesa; ese registro se sobrescribe solo por volumen.

Con quién los compartimos

Solo con los proveedores que necesitamos para prestar el servicio. La lista completa, con qué hace cada uno, dónde y con qué garantía, está en nuestra página de encargados del tratamiento. En resumen:

  • Hetzner, que aloja el servidor, la base de datos y las copias de la máquina en Núremberg (Alemania).
  • Google Cloud (Vertex AI), el modelo de IA, en la Unión Europea.
  • Cloudflare, que gestiona el dominio y por donde pasa el tráfico de la aplicación, y que comprueba que no eres un robot (Turnstile) al crear una cuenta y en el portal de los clientes de una tienda.
  • Sentry, que nos avisa de los errores, en su región de la Unión Europea. Como un aviso de error puede llevar de forma ocasional algún dato de una tienda, para esos datos actúa como encargado ulterior. Esos avisos nos llegan también a Discord ya filtrados, sin datos de los clientes de las tiendas.
  • 17TRACK, que consulta a los transportistas el estado de los envíos. Contratamos con su empresa de Singapur (VASTAR SINGAPORE TECHNOLOGY PTE. LTD), que, según su propia política de privacidad, guarda los datos en Estados Unidos y los trata en China. De nosotros recibe el número de seguimiento, el transportista cuando lo sabemos y un identificador nuestro sin datos tuyos (con el transportista PostNL, también el país de destino; con algunos transportistas, el código postal de entrega de tu pedido, como explicamos arriba).
  • Stripe, que cobra las suscripciones.
  • Resend, que entrega los correos que Parlo manda a las personas que llevan cada tienda y a quien se da de alta. Envía desde su región de Irlanda, pero guarda los datos de la cuenta y de cada envío en Estados Unidos. De los clientes de las tiendas solo recibe lo que llevan los avisos del portal que explicamos arriba (el número del pedido y, si es un cambio de dirección, de cuál a cuál, o el motivo del reembolso), y para esos datos actúa como encargado ulterior.
  • El proveedor del buzón en el que recibimos info@parlodesk.com, que recibe las consultas y peticiones que nos mandas.

Además, Parlo se conecta al proveedor de correo de cada tienda (Microsoft 365 y, en pruebas, Gmail) y a su tienda de Shopify, siempre con el permiso que la propia tienda da y que puede retirar cuando quiera; en Shopify, además de leer, cambia la dirección de envío de un pedido cuando su cliente lo hace desde el portal y la tienda lo tiene encendido. Si la tienda conecta su Slack, le mandamos allí los avisos que ella elige; Slack es un servicio que contrata la tienda, no un proveedor nuestro.

No vendemos ni cedemos tus datos a nadie. Solo los entregaríamos a una autoridad si nos obliga una norma aplicable y, si son datos de una tienda, se lo diremos antes a la tienda salvo que nos lo prohíban.

Dónde se tratan

Los datos se guardan en un servidor en Alemania, con una copia de seguridad cifrada en el ordenador de la persona que administra el servicio, en la Unión Europea, y el modelo de IA trabaja dentro de la Unión Europea. Pero somos una empresa de Estados Unidos, el servicio se administra en remoto, y algunos de nuestros proveedores (Google, Cloudflare, Sentry, Stripe, Resend y Discord) son empresas de Estados Unidos. Cloudflare, además, puede tratar el tráfico en cualquier punto de su red mundial. Por eso, aunque los datos estén guardados en Europa, la ley considera que hay transferencias fuera del Espacio Económico Europeo.

Para esas transferencias nos apoyamos en las cláusulas contractuales tipo de la Comisión Europea que recogen los contratos de tratamiento de cada proveedor y, cuando el proveedor está adherido, en el Marco de Privacidad de Datos UE-EE. UU., salvo con Discord: con Discord no tenemos contrato de tratamiento ni cláusulas contractuales tipo, y por eso solo le llega el nombre del error, la tienda y la página, sin datos de los compradores. La transferencia a nosotros mismos de los datos que tratamos por cuenta de cada tienda se apoya en las cláusulas contractuales tipo de la Comisión Europea, módulo dos (de responsable a encargado), que la tienda y nosotros celebramos al aceptar el contrato de encargo de tratamiento. Puedes pedirnos una copia de las garantías en info@parlodesk.com.

Para consultar el estado de los envíos usamos 17TRACK. Contratamos con su empresa de Singapur (VASTAR SINGAPORE TECHNOLOGY PTE. LTD), que, según su propia política de privacidad, guarda los datos en Estados Unidos y los trata en China. Singapur y China no tienen decisión de adecuación de la Comisión Europea, y la de Estados Unidos solo cubre a las empresas adheridas al Marco de Privacidad de Datos. De nosotros recibe el número de seguimiento, el transportista cuando lo sabemos y un identificador nuestro sin datos tuyos (con el transportista PostNL, también el país de destino; con algunos transportistas, el código postal de entrega de tu pedido). Con el número, 17TRACK obtiene del transportista los movimientos del envío, que pueden incluir la dirección de entrega, y los conserva hasta que le pedimos que los borre. Esta transferencia se apoya en las cláusulas contractuales tipo de la Comisión Europea que recoge su contrato de tratamiento y en nuestra evaluación de la transferencia.

Cuánto tiempo los guardamos

  • Cuentas de las personas que usan Parlo: mientras la cuenta exista. Si quieres que borremos la tuya, escríbenos. Aunque borres tu cuenta, conservamos el registro de lo que hiciste en la tienda (qué respuestas aprobaste, cuándo consultaste direcciones y cuándo se te quitó el acceso) mientras la tienda use Parlo, porque la tienda lo necesita para controlar quién accedió a los datos de sus clientes.
  • Intentos fallidos de entrar: 24 horas; se borran la siguiente vez que alguien intenta entrar.
  • Peticiones de alta: 7 días; se borran la siguiente vez que alguien pide un alta. Aceptación de los términos y dirección IP con la que se creó la tienda: mientras la tienda use Parlo.
  • Datos de la suscripción: mientras dure la relación con la tienda y después el tiempo que exijan las obligaciones fiscales y contables. Los avisos técnicos que nos manda Stripe se borran pasados 90 días, cuando llega el siguiente aviso.
  • Ajustes de la tienda, incluido el registro de cada cambio del modo de respuesta: mientras la tienda use Parlo. Quién encendió una función se guarda mientras siga encendida; al apagarla se borra.
  • Avisos a la tienda por Slack o por correo: qué aviso se mandó, cuándo y la huella de las direcciones a las que llegó, mientras la tienda use Parlo.
  • Correos y pedidos que tratamos por cuenta de la tienda: mientras la tienda use Parlo, con estas excepciones:
    • La dirección de envío de un pedido se borra sola 60 días después de la última vez que leímos ese pedido.
    • El texto de las respuestas que usamos para aprender se borra en cuanto se analiza, y como mucho a los 30 días.
    • El rastro de los correos enviados que aún no hemos enlazado se borra pasados 14 días, la siguiente vez que Parlo lee la carpeta de enviados de la tienda.
    • La copia temporal que usa el proceso interno para leer cada correo se borra una hora después de terminar, o a los 14 días si no se ha podido procesar. El correo guardado se conserva como el resto.
    • Tu voto y tu comentario se conservan con la respuesta que valoraste y se borran con ella.
    • Lo que escribes en el portal para buscar tu pedido: el número y el correo, media hora como mucho; la huella de la dirección IP, una hora; las huellas para los límites y, si el pedido se encontró, su identificador en Shopify, un día. Lo que pides por escrito desde el portal se conserva como un correo más.
    • El código para cambiar la dirección: su huella, hasta que se usa, se agota o caduca (a los 10 minutos); el resto de su registro, un día. La dirección nueva y la de antes de un cambio hecho desde el portal, y el motivo de un reembolso pedido desde él: 90 días. El registro de qué se pidió y qué pasó se conserva mientras la tienda use Parlo, y el correo que queda en la bandeja de la tienda, como el resto de los correos.
    • Lo que consultamos a 17TRACK sobre un envío (el número dado de alta y su respuesta) se borra a los 150 días de empezar a seguirlo. Si 17TRACK no confirma que lo ha borrado allí, lo borramos igualmente de nuestro sistema como mucho a los 157 días. El estado y las fechas de los movimientos que pasan a la ficha de tu pedido se conservan como el resto del pedido.
    • Cuando sabemos que un envío se ha entregado, pedimos a 17TRACK que deje de seguirlo a las 24 horas, y a los 150 días de darlo de alta le pedimos que lo borre.
  • Registros técnicos del servidor: se sobrescriben solos por volumen.
  • Avisos de errores (Sentry y Discord): hasta 90 días.
  • Cuando una tienda deja Parlo: cuando una tienda pide la baja, dejamos de leer su buzón, no sale nada más en su nombre y borramos todas sus credenciales de acceso. El borrado de la tienda entera se hace a mano, a petición suya, en el plazo que fija el contrato de encargo de tratamiento. Las facturas que emite Stripe se conservan por obligación contable.
  • Copias de seguridad: las copias de la base de datos que hacemos nosotros van cifradas y se borran solas en un máximo de 30 días. Nuestro proveedor de servidor guarda además imágenes diarias de la máquina entera durante 7 días.
  • Mensajes que nos mandas: un año, salvo que acaben en un contrato, y entonces lo que dure la relación.

Tus derechos

Puedes pedirnos acceso a tus datos, su rectificación o su supresión, oponerte al tratamiento, pedir que lo limitemos o que te los demos en un formato portable. Basta con escribir a info@parlodesk.com; te contestamos en un mes como mucho. Si el caso es complejo, la ley permite alargarlo dos meses más, y te avisaríamos.

Si tus datos nos llegaron a través de una tienda (porque le escribiste), la responsable es la tienda: le pasamos tu petición y la ayudamos a contestarte.

Si estás en la Unión Europea y crees que no lo hemos hecho bien, puedes reclamar ante tu autoridad de protección de datos. En España es la Agencia Española de Protección de Datos (aepd.es).

Seguridad

  • Los datos de cada tienda están separados de los de las demás en la propia base de datos.
  • Las claves de acceso que nos da cada tienda (de Shopify y de su buzón y, si lo conecta, la dirección de su canal de Slack) se guardan cifradas, y la parte de la aplicación que ves en pantalla no puede leerlas.
  • Las contraseñas se guardan de forma que nadie, tampoco nosotros, puede leerlas, y hay un límite de intentos para entrar.
  • A la aplicación solo se llega por una conexión cifrada, y la base de datos no está expuesta a internet.
  • Las copias de la base de datos que hacemos nosotros van cifradas.

Si una brecha de seguridad afecta a datos de los que somos responsables y supone un alto riesgo para ti, te lo comunicaremos como exige la ley. Si afecta a datos que tratamos por cuenta de una tienda, avisamos a la tienda, que es quien decide cómo informarte.

Menores

Parlo es un servicio entre empresas. No está dirigido a menores de 18 años y no recogemos sus datos a sabiendas.

Cambios

Si cambiamos esta política, actualizamos la fecha de arriba. Si el cambio es importante, avisamos por correo a las tiendas.


The Wise Brands LLC · 11820 Miramar Pkwy, Unit 204 · Miramar, FL 33025 · Estados Unidos · EIN 98-1896488 · info@parlodesk.com

Privacy policy

Last updated: October 5, 2026

Who processes your data

Parlo is a service of The Wise Brands LLC, with postal address at 11820 Miramar Pkwy, Unit 204, Miramar, FL 33025 (United States), EIN 98-1896488. For anything related to your data, write to info@parlodesk.com. Our company details are in the legal notice.

This policy covers the website parlodesk.com and the Parlo application at app.parlodesk.com.

We have not appointed a data protection officer because we are not required to; for everything, info@parlodesk.com.

The Spanish version of this policy is the reference text; this English version is provided for convenience.

Two different roles

Parlo reads an online store's customer support inbox, understands each email with the help of an artificial intelligence model, looks up the order in the Shopify store and prepares a draft reply. A person at the store reviews it and sends it from their own inbox.

If the store chooses so, some replies go out on their own, without being reviewed by a person, also from the store's inbox and signed as an AI agent. We explain this in "What the artificial intelligence does".

That is why we process data in two roles:

  • As controller. The data of the people who use Parlo within each store (their account), of whoever signs up, billing data, what you send us if you write to us, data of website visitors, and the technical data needed for the service to work and be secure. Here we decide why and how, and this policy explains it to you.
  • As processor. The emails that arrive in the store's inbox and the order data of its customers. That data belongs to the store: the store is the controller and we process it only on its behalf, following its instructions and the data processing agreement that is part of our terms of service. We explain this in the section "If you are a customer of a store that uses Parlo".

What data we process as controller, and why

  • If you use Parlo at your store. Your email address, your name if you give it, your password (stored so that nobody, including us, can read it), the store you belong to and your role in it, your sign-up date and your last access. We also keep a record of which replies you approved, edited or answered, when you looked up an order's shipping address, whether your access was removed, and the invitations and password links created for you. If the person who runs your store invited you, that person gave us your email address. We use this so you can log in, to control who sees what and to keep a trail of activity. The legal basis is the contract with your company and our legitimate interest in providing the service to it through you.
    • We also record who changed the store's reply mode or the situations that can go out on their own, and when; who turned on the rating of the replies, the store's portal, its link at the foot of the replies or the team card, and when, while it stays on; who last changed what customers can do in the portal, and when; who approved or rejected an address change requested from the portal, and when; and who marked an order's cancellation or address change as done in Shopify.
    • The team card. It comes switched off. If the person who runs your store turns it on, they will see in the analytics, next to your email address, how many replies you approved and how many you edited in the period, and how long you took on average to approve them. Before turning it on, the application asks them to tell the people who answer with them. What your company uses that information for is up to your company.
  • If you sign up yourself. Before requesting sign-up you go through a bot check by Cloudflare (Turnstile): your browser connects to Cloudflare, which sees your IP address, your browser and technical signals from the connection; our server only sends it the answer to the challenge, neither your email address nor your IP address. Then, your email address, to send you the link with which you create the account, and the IP address of the connection, to curb abuse (there is a limit on requests per address and per connection each hour). That request is deleted after 7 days, the next time someone requests a sign-up. The account is created when you open the link in the email and choose your password. When you create the store we keep its name and your acceptance of our terms: which version you accepted, a fingerprint of that version's document, when, who and from which connection, and we email you a PDF copy. We also keep the IP address the store was created from, to curb abuse (at most 3 stores per connection every 24 hours). When creating the store you choose how Parlo replies; if you choose a mode other than Draft, we record that you chose it and when, like any change of reply mode. The legal basis is taking steps at your request before entering into a contract and, for the IP address, our legitimate interest in protecting the service.
  • If you connect the store's inbox. With Microsoft 365 we keep the address of the mailbox the permission was given for, to check that Parlo reads and replies from the right mailbox. And we read the basic profile data of the account that authorizes it, to show on screen who did it. The legal basis is the contract.
    • With Gmail, whose connection is in testing, we keep the mailbox address and the app password you create in your Google account, encrypted. We do not use Sign in with Google or its permissions: according to Google, an app password gives access to your Google account, and with it all the email of that account can be read and sent, not only the store's, although Parlo only uses it to read and send that mailbox's email. You can revoke it at any time on your Google account's app passwords page, and by disconnecting the mailbox in Parlo, which deletes it from our database. If you change your Google account password, Google deletes all app passwords. If Google blocks access even though the password is valid (because IMAP access is closed or because it asks you to sign in from the browser), we keep which of the two it is, since when, and when we last tried, to tell you in the application; we try again every 15 minutes or when you press "Try again".
  • If you use the assistant. What you write to it is sent to the artificial intelligence model with email addresses, phone numbers and long numbers masked, together with a summary of your store's settings. The conversation is not stored anywhere: only the changes you decide to apply are saved. The legal basis is the contract.
  • Failed login attempts. The email address typed and the IP address of the connection, to stop people trying passwords. Those older than 24 hours are deleted the next time someone tries to log in. The legal basis is our legitimate interest in protecting accounts.
  • If your store subscribes. The email address of the person who runs the store and the store's identifier go to Stripe, which handles payment, together with the chosen plan and billing period (monthly or yearly) and, if you use one, the code of whoever referred you to Parlo, which stays on your subscription to calculate their commission. You enter your card, invoices and billing address directly on Stripe's page: they do not go through Parlo and we do not see them. From Stripe we receive the subscription's status (active, trialing, paused, canceled, with a payment pending), its plan, its dates, whether it has a payment method set (never which one) and whether it has a discount. The legal basis is the contract and, for keeping invoices, our legitimate interest in meeting the tax and accounting obligations that apply to us.
  • What your store configures. When setting up the store we read from Shopify its name, its public contact email, its domain, its billing country and its public shipping and return policies. And we keep what the store tells us so we can write its way: delivery times, tone, signature, languages, what it offers and what it never says. If the person who runs the store enters them, also the postal code and the last four digits of the sender phone number on its SEUR labels, which we give to 17TRACK to track those shipments. The legal basis is the contract.
  • If your store connects Slack. We keep, encrypted, the address of the Slack channel you give us. To that channel we send alerts with the store's name, counts (how many emails are waiting for a person and for what type of request, how many have a high chargeback risk, whether the mailbox has stopped responding) and a link to the application, and the weekly report: figures and the names of the store's products and carriers with the most requests. Also the alerts that the store has reached 80% or 100% of its plan's conversations, of the day the trial ends (without the amount, because the whole team reads the channel) and of a paused subscription. Never the text of an email nor any shopper data, except the order number in the portal notices we explain below. Your store chooses and contracts Slack, and what happens in that channel is governed by its contract with Slack. The legal basis is the contract.
  • If we email you. To the person who runs the store, from a Parlo address (avisos@parlodesk.com) and through our email provider (Resend): service alerts (that your store has reached 80% or 100% of its plan's conversations, that the first charge is coming up, with the day, what will be charged and whether a card is missing, or that the subscription is paused); if you sign up yourself, the link to create your account, the notice that you already have one if that is the case, and the PDF copy of the terms you accept; and, if your store receives it by email, the weekly report (figures and the names of your store's products and carriers with the most requests); and, if your store has the notices of its customers' portal turned on, the address changes and refund requests they make from it, with the order number and, if it is the address, from which to which, or the reason for the refund. If you reply to one of these emails, your reply reaches us at info@parlodesk.com. Our emails carry no images, pixels or anything loaded from elsewhere, and we do not measure whether you open them or which links you click. For each alert we keep who received it with a fingerprint of their address instead of the address, so as not to send it twice. We never write to the stores' customers. The legal basis is the contract.
  • If you write to us. Your name, your email address and what you tell us. We use it to answer you. The legal basis is your own request and our interest in handling it.
  • Technical data. When something fails, our error alert service receives the type of error and the first line of its message, with email addresses, phone numbers, IP addresses and anything in quotes masked; internal store identifiers; the page address without its parameters; the browser and technical system data; and a short trail of the steps that led to the error (clicks, requests and pages). The system is built so that neither the subject nor the text of emails, nor cookies, nor session recordings go out, although an automatic filter cannot fully rule out a stray name slipping through. If the application fails in your browser, the alert goes directly from your browser to that service, which sees your IP address to receive it and is configured not to store it. The legal basis is our legitimate interest in the service working.

We do not buy lists, we do not build advertising profiles and we do not make automated decisions about you.

Providing your account data is necessary to use Parlo: without an email address and a password you cannot log in.

If you visit parlodesk.com

Browsing parlodesk.com does not require giving us any data: it has no forms, cookies, analytics, advertising, pixels or third-party content. The only thing it stores in your browser is the language you choose with the language button, if you press it (we explain this on the cookies page). Our network provider (Cloudflare), which serves the website, sees the IP address and browser of each visit in order to deliver the page and curb abuse.

On app.parlodesk.com, without logging in you can only see the login page, the sign-up page, the page where a shopper rates a reply and the portal where a store's customers look up their order. Our network provider (Cloudflare) receives the IP address and technical data of each visit because all traffic goes through it. The application does not keep those visits, except the failed login attempts, the sign-up requests, the portal searches, explained below, and the error alerts explained above. Inside the application, product images are loaded from Shopify's servers, which see your IP address when serving them.

If you are a customer of a store that uses Parlo

If you have written to a store that uses Parlo, the controller of your data is that store. We process it on its behalf to help it answer you, and we do not use it for anything of our own. Parlo never writes to you: the reply comes from the store, from its inbox.

If the store has chosen so, some replies reach you without having been reviewed by a person. Today they can only be replies in Spanish, English, Portuguese, French, Italian or German about where your order is, when it is on its way within the expected time or already shows as delivered. Those replies are signed "The [store name] AI Customer Care Agent", so you know an artificial intelligence system answered you.

What we process on the store's behalf:

  • Your email. Address, name, subject, text and date, and the data that links the conversation. If you paste a card number into the email, the system detects it and masks it before the email is stored. Emails from people who write to the store without being customers (suppliers, carriers, newsletters) are also kept, so the store can review them.
  • From when. Only the emails that arrive, and the ones the store sends, from the moment it connects its inbox, are read. The exceptions are that the store expressly asks to analyze its history, or authorizes in writing a test with earlier emails before starting, or gives us an export of its mailbox.
  • What the store sends. So as not to answer you twice, Parlo looks at the mailbox's sent folder: it keeps the headers of those replies and a fingerprint of your address that cannot be reversed.
  • Your order. If we identify your order from the last 60 days with certainty: number, date, amount, payment and shipping status, your name and email address, the shipping address, the products, the shipment tracking and Shopify's risk assessment. From the order we do not read your card, and your phone number only if you change the address from the store's portal (below).
  • Where your shipment is. When you ask about your order and Shopify cannot tell where it is, Parlo asks the carrier through 17TRACK. We give 17TRACK the tracking number, the carrier when we know it and an identifier of ours that says nothing about you; with the carrier PostNL, also the destination country. Only with GLS Spain, Paack, Envialia, Ontime, TIPSA, Mondial Relay and InPost Spain, also the postal code of your order's delivery address, to track the shipment, and nothing else about you: not your name, the street, your email address or your phone number. We take that postal code from your order when we ask and do not store it separately. With SEUR we give the postal code and the last four digits of the phone number of the store itself, which is the sender, never yours. From its answer we keep the status, the dates of the movements and the destination country, never the places or the address.
  • What is inferred from your email. What you are asking for (for example, where your order is or a return), what language you write in, and whether the email shows signs that a person should see it: anger, a legal threat, a payment dispute, a health problem or harm. Also a level of risk that the payment ends up in a claim with your bank, with its reasons. This decides what is prepared, what goes directly to a person at the store and, if the store has chosen so, what can go out on its own. It has no legal effects on you: it only organizes the store's work.
  • If you don't want to be written to. If your address bounces, complains or asks not to receive more emails, it goes on a list of addresses that are not written to.
  • The reply. The draft, the version the person at the store edits and the one that is sent. If the store turns it on, Parlo also analyzes how its team replies in order to suggest improvements for that store only. Whether the reply went out on its own or was approved by a person is also kept. When the store's mailbox allows it, every reply written by Parlo carries a technical mark in the email, not visible in the text, saying it was written by an AI system and whether a person reviewed it; what goes out on its own always carries it.
  • Your rating. If the store turns it on, a link appears at the end of the reply to say whether we helped you. If you vote, we keep your vote (yes or no), the comment you write if you want and the date, linked to that reply. You can vote once and within 30 days. The page where you vote is ours (app.parlodesk.com) and carries the store's name; it does not store your IP address. The vote is deleted with the reply.
  • Delivery times. To know how long shipments really take, only the country and the dates of delivered orders are used, and the result is kept aggregated by country.
  • To count the store's plan conversations. For each month, the order number or, if there is no order, a fingerprint of your address that cannot be reversed.
  • If you use the store's portal. Some stores have a page (at app.parlodesk.com/p/...) where, with your order number and your email address, you see where your order is and can ask in writing for an address change (if nothing has shipped yet) or a return (if something has already reached you); if the store has it turned on, you can also change the shipping address yourself or request a refund, as we explain below. An order cannot be canceled from the portal. Before searching you go through a bot check by Cloudflare (Turnstile): your browser connects to Cloudflare, which sees your IP address, your browser and technical signals from the connection; our server only sends it the answer to the challenge. With your number and your email address we look up the order in the store's Shopify and only show you the number, the purchase date, where it is and, for each package, the carrier, the tracking number and link and the day of the last event and, if you can change the address, the delivery country; never your address, the amounts or the items. We also read the order's language, to write you in it the code we talk about below. If the number and the email address are not from an order, the page says the same as if it did not exist. To curb abuse there is a limit on searches per connection, per email address, per order and per store, and the answer always takes at least 2 seconds. What you ask for in writing does nothing by itself: it reaches the store as an email from you, without a prepared reply, and a person at the store reviews it, does it in Shopify if appropriate and answers you with an email. What we keep and for how long:
    • The number and the email address you type: if they are not from an order, they are deleted as soon as we have the answer; if they are, after half an hour, because during that time you can ask for something.
    • A fingerprint of your connection's IP address (a pseudonym, not anonymity): one hour, to count the limit.
    • A fingerprint (a pseudonym, not anonymity) of your email address and another of the order number, each together with the store: one day, to count the limits. Whoever had the database and guessed an email address or an order number could check it. If the order was found, also its identifier in Shopify, with the date of the search, during that same day.
    • If you ask for something in writing, the text you write stays in the store's inbox like any other email from you, together with the order and what you asked for.
    • A link to that portal can go at the end of the store's replies. It is the same for all the store's customers: it carries nothing of yours. If in your email you ask to change the address of an order that has not shipped, or for a refund of one that has shipped, and the store has that option turned on, the reply carries at the end the link to do it yourself from the portal; our code decides this from the text of your email, not the AI model.
  • If you change the shipping address from the portal. If the store has it turned on and your order has not shipped, you can change its shipping address yourself, within the same country and the same province, and it is changed in the store's Shopify order, immediately or after the store approves it. Before that, so that nobody else can change your order's address, the store sends from its mailbox a 6-digit code to the order's email address, like its replies: the email is sent by the store's email provider (Microsoft or Google), in your order's language or, if it is not one of the six we write in, in the page's language. Of the code we keep only a fingerprint, not the code, and only while it is valid: it expires after 10 minutes, it can be mistyped 5 times at most and it works once; when it is used, exhausted or expired, we delete it. We also keep how many times you have typed it, when it was requested and sent, and in which language; all of that is deleted after a day. To curb abuse, at most 3 codes per order per hour and 5 per day, and 30 per store per hour and 100 per day are sent. When you change it we keep the new address you type (first name and surname if you change them, street, floor, postal code, city and, if you give it or the store asks for it, your phone number) and the one the order had in Shopify right before (also its phone number and company, if it had them), so the store knows what changed, together with the order number, when you asked for it, who at the store approved it and what Shopify answered. After 90 days we delete the new address and the previous one, and what happened and when remains. In the store's inbox there is also an email with both addresses, which is kept like any other email from you.
  • If you request a refund from the portal. If the store has it turned on and your order has already shipped, you can ask it for a refund with a reason. It is only a request: the store decides it, and no money is returned from the portal. We keep the reason, the order number, when you asked for it and the result; after 90 days we delete the reason, and in the store's inbox there is an email with it, which is kept like any other email from you.
  • What we notify the store of. For each address change or refund request, the store receives a notice with the order number and, if it is the address, from which to which, or the reason for the refund: by email to the person who runs the store (through our email provider, Resend) and, if the store connected it, in its Slack (in Slack, without the address or the reason). Never your email address or your phone number.

If you want to exercise your rights over that data, contact the store. If you write to us, we pass your request on to the store and help it answer you.

What the artificial intelligence does

To read each email and write the draft we use Gemini, by Google, through Vertex AI in its European Union multi-region, which keeps processing within the EU.

  • To classify an email, the model receives its subject and its text, with card numbers masked.
  • To write, the model receives the text of your email as you wrote it (only card numbers are masked), the store's instructions and, of the data Parlo takes from Shopify, only a closed list: the order number, the first name, the products, the delivery times and the tracking. From Shopify it does not receive surnames, address, email address, amounts or the risk assessment.
  • If your email is not in Spanish, the person at the store who reviews it can ask to see it translated into Spanish. For that, the same model receives the text of your stored email (with cards masked) and the draft. The translation is only shown on screen: it is not stored, not sent and does not change the draft.
  • If Parlo does not identify your order with certainty, the draft cannot state anything about it: if it does, it is discarded and the email goes to a person.
  • The store chooses how Parlo replies: in "Draft", the default, a person reviews and sends each reply; in "Automatic by topic", the situations the store chooses go out on their own, each one only after the store has approved unchanged a number of drafts of that type (20, 50 or 100); in "Automatic", all situations that allow it go out on their own, with the express confirmation of the person who runs the store. In all three, each email goes through the same checks, and what fails them stays as a draft for a person. Only the person who runs the store can switch to an automatic mode; Parlo, on its own, can only switch back to "Draft", and it does so if one of the store's emails bounces permanently or someone marks it as spam, if the store leaves, or if we have to restore a database backup, which puts every store back in "Draft", and it records the reason. What goes out on its own:
    • Is signed "The [store name] AI Customer Care Agent", in every language. That signature is added by our code, not by the model, and the store cannot remove it. What a person approves does not carry it.
    • Waits a few minutes before going out, and during that time any person at the store can stop it and send it back to draft.
    • Never includes refunds, returns, cancellations, exchanges or complaints; anything that asks for money or brings a legal claim, a payment dispute, a health problem or harm; anything that offers something or promises actions; nor the reply to someone who has already written another email in the last 72 hours; nor anything written in a language that does not yet go out on its own (today, everything that is not in Spanish, English, Portuguese, French, Italian or German). The store cannot change this. Nor does an email go out on its own with a chargeback risk above what the store accepts in its settings. And what cannot carry the AI's technical mark explained above does not go out on its own: it goes back to draft for a person.
  • Emails about legal matters (lawsuits, lawyers or consumer rights) always go to a person, without a draft. Those about a payment dispute, health or harm to a person also go to a person without a draft, unless the store changes this in its settings; even then, they never go out on their own.
  • The person who runs the store can use an assistant to tell Parlo how their store works; what they write is sent to the model with contact data masked, as explained above.
  • We do not train or fine-tune any AI model with the stores' data. What Parlo learns from how a store replies is used only for that store and never passes to another.
  • Our technical logs do not keep what is sent to the model or what it answers: only sizes, times and cost. The log of the process that handles emails does record the subject of each email it processes; that log is overwritten automatically by volume.

Who we share it with

Only with the providers we need to provide the service. The full list, with what each one does, where and with what safeguard, is on our subprocessors page. In short:

  • Hetzner, which hosts the server, the database and the machine backups in Nuremberg (Germany).
  • Google Cloud (Vertex AI), the AI model, in the European Union.
  • Cloudflare, which manages the domain and through which the application's traffic passes, and which checks that you are not a robot (Turnstile) when you create an account and in a store's customers' portal.
  • Sentry, which alerts us to errors, in its European Union region. Since an error alert may occasionally carry some store data, for that data it acts as a sub-processor. Those alerts also reach us on Discord already filtered, with no data about the stores' customers.
  • 17TRACK, which asks carriers for the status of shipments. We contract with its Singapore company (VASTAR SINGAPORE TECHNOLOGY PTE. LTD), which, according to its own privacy policy, stores the data in the United States and processes it in China. From us it receives the tracking number, the carrier when we know it and an identifier of ours with no data about you (with the carrier PostNL, also the destination country; with some carriers, the postal code of your order's delivery address, as we explain above).
  • Stripe, which collects subscriptions.
  • Resend, which delivers the emails Parlo sends to the people who run each store and to whoever signs up. It sends from its Ireland region, but stores account data and the data of each send in the United States. Of the stores' customers it only receives what the portal notices explained above carry (the order number and, if it is an address change, from which to which, or the reason for the refund), and for that data it acts as a sub-processor.
  • The provider of the mailbox where we receive info@parlodesk.com, which receives the queries and requests you send us.

In addition, Parlo connects to each store's email provider (Microsoft 365 and, in testing, Gmail) and to its Shopify store, always with the permission the store itself gives and can withdraw whenever it wants; in Shopify, besides reading, it changes an order's shipping address when the customer does so from the portal and the store has it turned on. If the store connects its Slack, we send it there the alerts it chooses; Slack is a service the store contracts, not a provider of ours.

We do not sell or transfer your data to anyone. We would only hand it to an authority if an applicable law obliges us to and, if it is a store's data, we will tell the store first unless we are prohibited from doing so.

Where it is processed

The data is stored on a server in Germany, with an encrypted backup on the computer of the person who administers the service, in the European Union, and the AI model works within the European Union. But we are a United States company, the service is administered remotely, and some of our providers (Google, Cloudflare, Sentry, Stripe, Resend and Discord) are United States companies. Cloudflare can also process traffic at any point of its global network. Therefore, even though the data is stored in Europe, the law considers that there are transfers outside the European Economic Area.

For those transfers we rely on the European Commission's standard contractual clauses included in each provider's data processing agreement and, where the provider is certified, on the EU-U.S. Data Privacy Framework, except with Discord: we have no data processing agreement or standard contractual clauses with Discord, and that is why it only receives the error name, the store and the page, without shopper data. The transfer to ourselves of the data we process on behalf of each store relies on the European Commission's standard contractual clauses, module two (controller to processor), which the store and we enter into when accepting the data processing agreement. You can ask us for a copy of the safeguards at info@parlodesk.com.

To check the status of shipments we use 17TRACK. We contract with its Singapore company (VASTAR SINGAPORE TECHNOLOGY PTE. LTD), which, according to its own privacy policy, stores the data in the United States and processes it in China. Singapore and China have no adequacy decision from the European Commission, and the one for the United States only covers companies certified under the Data Privacy Framework. From us it receives the tracking number, the carrier when we know it and an identifier of ours with no data about you (with the carrier PostNL, also the destination country; with some carriers, the postal code of your order's delivery address). With the number, 17TRACK obtains the shipment's movements from the carrier, which may include the delivery address, and keeps them until we ask it to delete them. This transfer relies on the European Commission's standard contractual clauses included in its data processing agreement and on our transfer assessment.

How long we keep it

  • Accounts of the people who use Parlo: while the account exists. If you want us to delete yours, write to us. Even if you delete your account, we keep the record of what you did at the store (which replies you approved, when you looked up addresses and when your access was removed) while the store uses Parlo, because the store needs it to control who accessed its customers' data.
  • Failed login attempts: 24 hours; they are deleted the next time someone tries to log in.
  • Sign-up requests: 7 days; they are deleted the next time someone requests a sign-up. Acceptance of the terms and IP address the store was created from: while the store uses Parlo.
  • Subscription data: while the relationship with the store lasts and afterwards for as long as tax and accounting obligations require. The technical notifications Stripe sends us are deleted after 90 days, when the next one arrives.
  • Store settings, including the record of each change of reply mode: while the store uses Parlo. Who turned on a feature is kept while it stays on; when it is turned off, it is deleted.
  • Alerts to the store by Slack or email: which alert was sent, when and the fingerprint of the addresses it reached, while the store uses Parlo.
  • Emails and orders we process on the store's behalf: while the store uses Parlo, with these exceptions:
    • An order's shipping address is deleted automatically 60 days after the last time we read that order.
    • The text of the replies we use for learning is deleted as soon as it is analyzed, and at most after 30 days.
    • The trail of sent emails we have not yet linked is deleted after 14 days, the next time Parlo reads the store's sent folder.
    • The temporary copy the internal process uses to read each email is deleted one hour after finishing, or after 14 days if it could not be processed. The stored email is kept like the rest.
    • Your vote and your comment are kept with the reply you rated and deleted with it.
    • What you type in the portal to look up your order: the number and the email address, half an hour at most; the fingerprint of the IP address, one hour; the fingerprints for the limits and, if the order was found, its identifier in Shopify, one day. What you ask for in writing from the portal is kept as one more email.
    • The code to change the address: its fingerprint, until it is used, exhausted or expired (after 10 minutes); the rest of its record, one day. The new address and the previous one of a change made from the portal, and the reason for a refund requested from it: 90 days. The record of what was asked for and what happened is kept while the store uses Parlo, and the email left in the store's inbox, like the rest of the emails.
    • What we ask 17TRACK about a shipment (the number registered and its answer) is deleted 150 days after we start tracking it. If 17TRACK does not confirm it has deleted it there, we delete it from our system anyway at most after 157 days. The status and dates of the movements that go into your order's record are kept like the rest of the order.
    • When we know a shipment has been delivered, we ask 17TRACK to stop tracking it after 24 hours, and 150 days after registering it we ask it to delete it.
  • Server technical logs: overwritten automatically by volume.
  • Error alerts (Sentry and Discord): up to 90 days.
  • When a store leaves Parlo: when a store asks to leave, we stop reading its mailbox, nothing more goes out in its name and we delete all its access credentials. Deleting the whole store is done manually, at its request, within the period set by the data processing agreement. The invoices Stripe issues are kept as required by accounting rules.
  • Backups: the database backups we make are encrypted and deleted automatically within 30 days at most. Our server provider also keeps daily images of the whole machine for 7 days.
  • Messages you send us: one year, unless they lead to a contract, and then for as long as the relationship lasts.

Your rights

You can ask us for access to your data, its rectification or erasure, object to the processing, ask us to restrict it or to give it to you in a portable format. Just write to info@parlodesk.com; we answer within one month at most. If the case is complex, the law allows extending it by two more months, and we would let you know.

If your data reached us through a store (because you wrote to it), the controller is the store: we pass your request on to it and help it answer you.

If you are in the European Union and believe we have not done it right, you can complain to your data protection authority. In Spain it is the Agencia Española de Protección de Datos (aepd.es).

Security

  • Each store's data is separated from the others' in the database itself.
  • The access keys each store gives us (Shopify's and its mailbox's and, if it connects it, the address of its Slack channel) are stored encrypted, and the part of the application you see on screen cannot read them.
  • Passwords are stored so that nobody, including us, can read them, and there is a limit on login attempts.
  • The application can only be reached over an encrypted connection, and the database is not exposed to the internet.
  • The database backups we make are encrypted.

If a security breach affects data for which we are the controller and poses a high risk to you, we will notify you as the law requires. If it affects data we process on behalf of a store, we notify the store, which decides how to inform you.

Minors

Parlo is a business-to-business service. It is not aimed at people under 18 and we do not knowingly collect their data.

Changes

If we change this policy, we update the date above. If the change is significant, we notify the stores by email.


The Wise Brands LLC · 11820 Miramar Pkwy, Unit 204 · Miramar, FL 33025 · United States · EIN 98-1896488 · info@parlodesk.com