E-commerce
July 1, 2026
When a customer can no longer log in, they want to regain access quickly. But a password reset affects account security, personal data, and sometimes orders or saved payment methods.
The chatbot must guide the user without bypassing the procedure. It can explain how to receive the link, what to do if the email does not arrive, why a link expires, and when to transfer to support.
This guide explains how to manage a password reset with an AI chatbot, helping the customer without compromising security.
Summary
Why does safety come before speed?
A password protects access to the account, addresses, order history, credits, and sometimes subscriptions. The chatbot must therefore never grant access to the account simply because someone claims to own it.
It must explain the procedure and reassure the customer: verification serves to protect their information, not to complicate their journey.
A successful account recovery is fast, but never at the cost of bypassing security.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
Which situations to recognize?
Common cases include a password reset email not received, an expired link, an unknown email address, an account created with a different email, a lockout after too many attempts, or a suspected hack.
The bot must distinguish between a forgotten password, an email error, and unauthorized access. These situations do not require the same response.
How do you guide the customer?
The chatbot can ask the client to check the email address used, spam, the last email received, and then submit a new request from the official page.
It must never ask for the current password, offer a temporary password in the chat, or send a link to an unverified address.
How to explain an expired link?
A reset link expires to prevent it from being used too late or by another person. The bot can explain that the customer needs to generate a new link from the login page.
If multiple links have been requested, it should remind them to use the most recent one, as older ones may become invalid.
What should I do if the email does not arrive?
The bot must suggest checking spam, the address entered, common typos, the existence of a guest account, or logging in via another provider like Google or Apple if the store allows it.
If the account still cannot be found or if the customer no longer has access to the email, it must be escalated to a secure procedure.
Which flow to follow?
The flow must guide without taking control of the account.
Identify the problem: missing email, expired link, account not found, or suspicious access.
Direct towards the official reset page.
Explain simple checks: address, spam, latest link, login provider.
Avoid any collection of passwords or sensitive data.
Transfer blocked accounts, lost emails, or suspected hacking.
Which messages should be used?
To guide: "I cannot reset the password in the chat, but I can guide you through the secure procedure."
For an expired link: "To protect your account, links expire. Request a new link and use the most recent one."
For a lost email: "If you no longer have access to this address, I will forward you to a secure verification."
When to transfer?
The transfer is necessary if the client no longer has access to the email, if the account is blocked, if a suspicious connection is reported, if multiple accounts exist, or if the reset fails despite the normal steps.
The bot must transmit the masked email, the affected account, steps already attempted, the date of the last attempt, and the level of urgency.
Which KPIs should be monitored?
Track expired links, unreceived emails, blocked accounts, security transfers, accounts not found, and requests related to suspected hacking.
This data shows whether the recovery process is clear or too fragile.
Which mistakes should be avoided?
Avoid asking for a password, bypassing the verified email, sending an unsecure manual link, or treating a suspected hack as a simple forgotten password.
The chatbot should make the procedure simpler, not less secure.
How can Qstomy help?
Qstomy can connect the chatbot to accounts, orders, payments, security statuses, and support rules to answer clearly, then transfer sensitive cases with an actionable summary.
The chatbot helps the customer move forward without exposing unnecessary data or bypassing protections related to the account or payment.
Explore AI support, the AI sales agent, or request a demo.
Key takeaways
Takeaways
The password reset process must guide the customer without bypassing security checks.
What the customer needs to understand
The customer needs to know why the link expires, what to check, and when a secure procedure is required.
The chatbot's correct limit
The chatbot can assist with the steps, but it must escalate blocked accounts, lost emails, and suspected hacking.

Enzo
July 1, 2026


