Legal
Privacy Policy
Last updated: July 14, 2026
This Privacy Policy explains how Axvelo (“Axvelo,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the Axvelo AI support chatbot and related services (the “Service”), including the embeddable chat widget that merchants add to their websites and online stores.
Axvelo provides an AI-powered support chatbot that answers questions using a merchant’s own published content (such as web pages, product information, policies, and FAQs). This policy describes our practices for two groups: Merchants (businesses that create an Axvelo account and add the widget) and Shoppers / end visitors (people who interact with the widget on a merchant’s site).
1. Information we collect
1.1 Information from merchants
When a merchant signs up for and uses Axvelo, we collect and store: account information (business name, account email, securely hashed password); configuration data (chatbot display name, accent color, allowed domains, chosen AI model, merchant-authored system prompt); content you provide for training (website URLs you ask us to crawl and documents you upload, which we process into searchable content — raw uploaded file bytes are discarded after processing, and the extracted text is stored to power your chatbot); and usage data (aggregate counts of chatbot interactions and processing usage).
1.2 Information from shoppers (end visitors)
When a shopper interacts with the Axvelo chat widget: Message content — the text a shopper types is transmitted to our systems and to the third-party AI providers in Section 3 to generate a response. We store the text of shopper messages and the chatbot’s answers in our database so that merchants can review their chatbot’s conversations, and to operate and improve the Service. These conversation records are associated with the opaque session identifier described below, not with a shopper’s name or personal identity, and are automatically deleted after 90 days. Session identifier — the widget generates a random, opaque identifier stored in the shopper’s browser local storage, not linked to any name, email, or personal identity, regenerated if browser storage is cleared. Timestamps — the date and time of interactions.
We do not intentionally collect a shopper’s name, email, or other personal identifiers through the widget. However, if a shopper voluntarily types personal information into a chat message, that text will be transmitted to the third-party AI providers in Section 3 as part of generating a response. Shoppers should avoid entering sensitive personal information into the chat.
We do not use cookies to track shoppers through the widget, we do not collect a shopper’s IP address, browser user-agent, referring page, or browsing history in our application database, and we do not operate third-party advertising or analytics trackers within the widget.
1.3 Operational logs
Our hosting and infrastructure providers may automatically generate operational logs (for example, server request logs) that can include technical information such as network addresses, as part of running and securing the Service. These logs are managed by our infrastructure providers and retained according to their log-retention practices. We do not store this information in our application database.
2. How we use information
We use information to: provide, operate, and maintain the Service, including generating chatbot responses from a merchant’s content; configure and personalize each merchant’s chatbot; enforce security controls (including restricting each chatbot to authorized domains) and prevent abuse such as rate limiting; measure aggregate usage for billing, capacity, and product improvement; communicate with merchants about their account and the Service; and comply with legal obligations and enforce our terms.
3. How we share information (sub-processors)
We do not sell personal information. We share information with the following third-party service providers (“sub-processors”) strictly to operate the Service. Some receive the text of shopper messages to generate responses.
Sub-processors that may receive shopper message content: OpenAI — converts messages into numerical representations (embeddings) and generates chatbot responses; the shopper’s message plus relevant passages from the merchant’s content is sent to produce an answer. Cohere — ranks the most relevant passages of the merchant’s content for a question; receives the shopper’s message with candidate passages. Langfuse — monitoring and quality assurance of responses; receives records of interactions that may include the full text of shopper questions and chatbot answers, associated with the opaque session identifier in Section 1.2.
Other infrastructure providers:Qdrant — vector database storing the merchant’s processed content and matching it to questions; receives numerical representations, not raw message text. Neon (PostgreSQL) — primary database storing merchant account data, shopper session identifiers and timestamps, and the text of shopper messages and chatbot answers (automatically deleted after 90 days). Railway — application hosting, which may process operational logs as in Section 1.3. Redis (managed) — short-term caching that may temporarily hold generated answer text for a brief period (minutes) before it automatically expires.
Each sub-processor processes information under its own terms. Several are located in the United States, so information may be processed in the United States and other countries. We may also disclose information if required by law, to protect our rights, or in connection with a business transfer.
4. Data retention
Merchant account and configuration data — retained while the merchant maintains an account, deleted when the account is deleted. Merchant training content — retained as long as needed to operate the chatbot; removed when the merchant deletes it or their account; raw uploaded file bytes are discarded shortly after processing. Shopper session identifiers, timestamps, and aggregate usage records — retained until the associated merchant account is deleted. Cached data (temporarily cached answer text and embeddings) — automatically expires within minutes to an hour. Shopper message and answer text — stored in our database and automatically deleted 90 days after the interaction. Records held by our monitoring provider (Langfuse) are retained per that provider’s settings. Operational logs — retained per our infrastructure providers’ practices.
5. Your rights and choices
Depending on your location, you may have rights under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA), including rights to access, correct, delete, or restrict processing of your personal information, and to object to certain processing.
For merchants: you can access and update most account and configuration information in your Axvelo dashboard, including viewing the conversations shoppers have had with your chatbot, and request deletion of your account and associated data by contacting us.
For shoppers:because interactions are associated only with an opaque, non-identifying session identifier, we are generally unable to link chat activity to a specific individual. If you are a shopper who wishes to make a request, or who interacted with an Axvelo-powered chatbot on a merchant’s store, please contact the merchant that operates that store, or contact us and we will work with the relevant merchant to address your request.
We honor data access and deletion requests submitted by merchants on behalf of their customers, including requests received through the Shopify platform’s mandatory data-request, customer-redaction, and shop-redaction processes.
To exercise any of these rights, contact us using the details below. We may need to verify your identity before acting on a request.
6. Security
We take reasonable technical and organizational measures to protect information, including encrypting stored passwords, restricting each chatbot to authorized domains, and limiting access to systems. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
7. Children’s privacy
The Service is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
8. International users
We operate the Service using providers located in the United States and other countries. If you access the Service from outside these regions, your information may be transferred to, stored, and processed in countries whose data-protection laws may differ from those of your country.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated through the Service or by other appropriate means. Your continued use of the Service after an update constitutes acceptance of the revised policy.
10. Contact us
If you have questions or requests regarding this Privacy Policy or your information, contact us at:
Axvelo
Email: axvelo.ai@gmail.com
Website: https://axvelo.ai