Conversations
The chat on your site is where people ask the questions they never put in a form. StorePilot receives those conversations from your chat provider and shows them beside the lead they belong to, so one person's messages, their checkout and the errors they hit are on one screen.
The direction is one way, always. Your provider sends transcripts to StorePilot. StorePilot never sends a message, never replies, and holds no credential for your provider — you keep answering your customers exactly where you do today.
Supported provider: Brevo Conversations. Connect it in Settings → Integrations.
Where conversations appear
| Screen | What you see |
|---|---|
| Leads → Conversations | Every chat: who, the last message, the page it began on, how many messages, and the lead it matched |
| A conversation | The whole transcript, in order, with the page and the matched lead |
| A lead's page | The chats that person had, under the form they filled in |
| A visitor's page | The same, for a visitor whose chat may never have met a form |
A chat provider usually ends a conversation the moment the visitor leaves the page, so one exchange reaches us in pieces. StorePilot keeps the pieces together as a single conversation for up to 24 hours between messages, and the transcript marks where the visitor left and came back — what you read is what the two of you said, in order. A reply from your own team is the one exception to the 24 hours: a stretch that begins with an agent's message joins that visitor's most recent conversation however long the pause, because an answer belongs with its question.
A conversation is open until its most recent stretch has ended, so a visitor who comes back and writes again reopens it rather than starting a second one.
How a chat finds its lead
By email address first, against the newest lead on that site with the same address — and, when the chat carried no email, by the visitor identifier the StorePilot collector handed your chat widget (see what StorePilot tells the widget).
That runs in both directions, because a chat usually arrives first:
- A chat comes in and a lead with that email already exists → the chat attaches immediately.
- A chat comes in with no email, from a browser that already has a lead → it attaches to that visitor's newest lead.
- A chat comes in and no lead matches yet → it is stored unmatched and stays in the list. Use Only without a lead to see just those. It still lands on the visitor's page, and points at the recording of the visit it began in when there is one.
- The person later fills in a form or a checkout — with the same address, or from the same browser → the new lead picks up every unmatched chat of theirs.
A chat is never dropped for want of a lead, and a chat on your site never matches a lead on somebody else's — every lookup is scoped to the site the webhook key belongs to.
What is stored, and what is masked
The messages as they were typed, the visitor's name and email as your provider reported them, and the page the chat began on (with its query string scrubbed, as every URL here is).
Two things are masked before the message is stored:
- Payment card numbers — 13 to 19 digits, with or without spaces and dashes, become
[card]. - Credential-shaped values — bearer tokens, JWTs and provider API keys.
Email addresses and telephone numbers inside a message are kept. They are the contact detail you read the transcript for, and the same values already sit on the lead beside it. That is a deliberate difference from error reports and form fields, where the same free text is redacted; the reasoning is published in the Privacy Policy.
Consent
A chat is not gated on cookie consent. Someone who types into a chat window and presses send has deliberately given you that message, which is the same reasoning that applies to a contact form submitted through a form plugin. Whether that is the right lawful basis for your shop is your judgement as the Controller — you can disconnect the provider at any time.
Retention, export and erasure
A transcript is the same person's own words as the form beside it, so it follows the same window as your leads: kept indefinitely unless you set a lead retention limit, in which case a conversation is swept when its last message passes that limit.
- Export — a visitor's data export includes their transcripts, messages and all.
- Erasure — erasing a visitor deletes their transcripts. They are found both by the visitor identifier and by the email addresses their leads carry, so a chat whose lead was already erased still goes with them.
- Delete one — an admin can delete a single conversation from its own page. Your provider keeps its own copy; this removes StorePilot's.