TikoZap Guide
Is AI Customer Service Safe for a Small Business?
If you let an AI assistant talk to your customers, what happens to everything they tell it?
The quick answer
That is one of the first questions a small-business owner should ask before using AI customer service.
Your customers may share names, order information, questions, preferences, and details about problems they are trying to solve. At the same time, you may teach the AI about your products, policies, and the way your business works.
So security and privacy aren't side issues. They are part of deciding whether an AI assistant deserves a place on your team.
The good news is that using AI for customer service does not have to mean giving an AI system unlimited access to your business.
A well-designed AI customer-service system should work much more like a carefully managed employee: it gets the information it needs to do its job, the permissions appropriate for that job, and clear limits on what it can do.
How is the risk being managed?
The National Institute of Standards and Technology (NIST) treats cybersecurity and privacy as risk-management responsibilities, including for small businesses. Its small-business guidance is designed specifically to help organizations with limited security resources identify and manage those risks.
For AI customer service, that means looking at a few practical questions:
- What information does the AI need?
- Where is that information stored?
- Who can access it?
- What outside providers receive it?
- What is the AI allowed to do?
- What happens when the AI shouldn't make a decision by itself?
Security isn't about promising that AI has zero risk. It's about understanding what information the AI needs, how that information is handled, what the AI is allowed to do, and whether the business remains in control.
What information does an AI customer-service assistant need?
An AI assistant needs information to be useful.
If a customer asks about shipping, it may need your shipping policy. If someone asks whether a product is available, it may need product information. If a customer continues an earlier conversation, the assistant may need enough conversation history to understand what is being discussed.
But needing some information does not mean needing everything.
An AI customer-service system should be designed around the information required for the task rather than unrestricted access to an entire business.
That distinction becomes more important as AI systems become capable of doing more than answering questions.
The safest AI assistant isn't the one that knows everything and can do everything. It's the one that has the information and authority it needs—and no more.
Privacy and security are related, but they aren't the same thing
Security is largely about protecting information and systems from unauthorized access, misuse, alteration, or loss.
Privacy asks another set of questions: what information is collected, why it is collected, how it is used, who receives it, and how long it is kept.
A system can therefore have strong technical security and still raise legitimate privacy questions.
NIST makes this distinction explicitly: good cybersecurity is important, but cybersecurity alone cannot address every privacy risk.
For a small-business owner, this means you should look beyond a statement such as "your data is encrypted."
You should also ask what data the service collects and what it does with that data.
Sometimes the safest data is data the system doesn't need
Small businesses have a simple security advantage available to them: don't give a system information it doesn't need to perform its job.
The Federal Trade Commission has long encouraged businesses to think carefully about the personal information they collect and retain. The same principle is especially useful when evaluating AI.
For example, an assistant answering questions about a store's return policy probably doesn't need access to every customer record in the business.
An assistant helping customers find products may need a product catalog. That does not automatically mean it needs permission to edit those products, view customers, or change orders.
This is often called the principle of least privilege: give a person or system the access necessary for the job, rather than giving broad access simply because it might be useful someday.
Good AI security isn't only about keeping hackers out. It's also about deciding what the AI should know, who should have access, and what the AI should be allowed to do.
What happens when another AI company processes the conversation?
Many AI customer-service products don't build their own large AI models. They use models provided through APIs by companies specializing in AI.
That means a business should ask an important question:
What does the AI provider do with the information sent to it?
The Federal Trade Commission has specifically warned AI companies that they must honor their privacy and confidentiality commitments, including promises about how customer information is used.
And "not used for training" should not automatically be interpreted as "never retained anywhere."
Those are different questions.
For example, OpenAI states that data submitted through its API is not used to train or improve its models by default unless the customer explicitly opts in. OpenAI also states that standard API inputs and outputs are generally removed after 30 days unless longer retention is legally required.
Different providers and configurations can have different policies.
So when evaluating an AI customer-service service, don't simply ask:
"Does it use AI?"
Ask which AI providers receive information, what they receive, and what their data policies are.
Who controls access to the business?
An AI assistant is only one part of the security picture.
The people using the system matter too.
A customer-service platform should distinguish between businesses, users, and permissions so that one account cannot simply access another business's information.
Sensitive actions should receive stronger protection than ordinary actions.
Deleting an account, changing billing, connecting another business system, or eventually allowing an AI assistant to take actions on behalf of a store should not be treated like answering a product question.
This becomes increasingly important as AI evolves from answering questions to performing work.
The more an AI assistant is allowed to do, the more important it becomes to control what it can access and what actions it is authorized to take.
What about connecting AI to your online store?
Connections to ecommerce platforms deserve special attention because they can potentially give software access to important business information.
A good question to ask is not merely:
"Can this AI connect to my store?"
Ask instead:
What permission does the connection actually request?
If an AI assistant only needs to read product information, there may be no reason to give it permission to modify products, access customers, or change orders.
Permissions should grow only when the job actually requires them.
Don't give an AI employee tomorrow's authority to do today's job.
AI should know when not to act
Security isn't only about data.
It is also about behavior.
An AI assistant may be perfectly capable of answering: "What is your return policy?"
That does not mean it should automatically have authority to issue a refund.
It might explain shipping options without having permission to change a shipment. It might help a customer understand an order problem while leaving an unusual decision to a person.
This is where human involvement becomes a security feature rather than a weakness.
The goal isn't to make the AI independent at all costs. The goal is to let AI handle the work it can handle safely while keeping people in control of decisions that need human judgment or additional authority.
AI handles what it can; people handle what they should.
Seven questions to ask before choosing an AI customer-service service
A small-business owner doesn't need to become a cybersecurity engineer to make a sensible decision.
Ask the provider:
- What business and customer information does your AI need?
- Is my business's information separated from other businesses?
- Which outside AI or cloud providers receive my information?
- Is my data used to train public AI models?
- How are sensitive credentials, such as store access tokens, protected?
- What permissions does the AI receive when I connect my store?
- Can I keep control of important actions and bring a person into the conversation when necessary?
Clear answers matter more than impressive security vocabulary.
So, is AI customer service safe for a small business?
It can be—but the answer should never be based simply on the word "AI."
Look at the system around the AI.
A trustworthy AI customer-service service should limit access, protect credentials, explain how information is used, choose responsible technology providers, separate businesses from one another, and keep people in control of important decisions.
Small-business owners already make similar trust decisions about payment processors, ecommerce platforms, email providers, accountants, employees, and other services.
AI deserves the same thoughtful approach.
You don't need an AI assistant that has access to everything.
You need one that has enough access to do its job well—and clear boundaries around everything else.
Good AI customer service isn't about giving AI control of your business. It's about giving it the right responsibilities while keeping the business in control.
The TikoZap approach
Where TikoZap fits
TikoZap is built around the idea that an AI assistant should work as an employee of the store—not as an AI system with unlimited authority.
The assistant uses the business knowledge and conversation context needed to help customers, with structured and bounded context rather than unrestricted access to the merchant's entire database.
Business data belongs to the merchant. TikoZap's privacy policy states that it does not sell or rent personal, business, or customer data and does not use merchants' business data or customer conversations to train public AI models.
TikoZap uses OpenAI's API to generate AI responses. OpenAI states that API data is not used to train its models by default.
Access inside TikoZap is tied to authenticated users and their authorized stores. Important actions can require stronger authorization; for example, account deletion is restricted to the actual store owner and requires explicit confirmation.
TikoZap's current Shopify integration follows the same limited-access approach. Shopify access credentials are encrypted before database storage and decrypted only in server-side code when needed.
The production Shopify connection currently requests only read_products permission—the access needed to read product information. It does not currently request customer, order, or product-writing permissions.
That last point is intentional.
As an AI employee becomes capable of doing more work in the future, additional permissions should be added only when the job actually requires them.
See how TikoZap works →Sources & further reading
This guide was informed by current guidance on small-business cybersecurity, privacy, AI data handling, and ecommerce access controls.
- NIST — Cybersecurity Framework 2.0: Small Business Quick-Start Guide
- NIST — Privacy Framework resources for small and medium businesses
- Federal Trade Commission — AI Companies: Uphold Your Privacy and Confidentiality Commitments
- Federal Trade Commission — Protecting Personal Information: A Guide for Business
- OpenAI — Business data privacy, security, and compliance
- OpenAI — Data controls in the OpenAI platform
- Shopify — API access scopes