Skip to content
Ouviro

Legal

Privacy policy

Last updated:

This policy explains the data used to provide Ouviro, including website chat, the merchant dashboard and prepaid billing. It should be read with the privacy notice of the merchant whose website you visit.

Draft for legal review. The operating legal entity, contact details and governing law must be confirmed before these texts take effect.

Who is responsible for your data

The merchant operating the website is the controller of its visitors’ personal data: it decides why to offer chat and how to use the information. Ouviro acts as that merchant’s service provider and processor for visitor data. For merchant registration, account administration, security and billing records, Ouviro acts as controller. The legal name and postal address of the entity operating Ouviro remain to be confirmed before this draft takes effect.

Visitor conversations and context

We process messages, uploaded image attachments, conversation and visitor identifiers, language preferences, timestamps, service status, feedback and human-agent replies. If you or the merchant provide contact details, order information or page context in a message or an integration, those details also form part of the support data. This does not mean the widget automatically collects every page URL or browsing history. Submit only information needed for your request.

Merchant accounts and operational records

Account data includes names, email addresses, authentication and session records, organization membership, roles, knowledge-base content and service settings. We also process usage and diagnostic records, AI operations and any tool-step or tool-call information included in the support record. This description does not promise that a separate tool-call audit log exists. Billing data includes top-up orders, wallet addresses, transaction identifiers, amounts, credit balances and ledger entries; we do not ask for wallet private keys or seed phrases.

Technical data and browser storage

Network requests expose technical information such as IP addresses and browser or device information to the hosting infrastructure. Raw IP addresses are used for rate limiting, and merchant sign-in sessions may store IP addresses and User-Agent strings; this is not a claim that a device profile or precise location is stored for every visitor. Authentication cookies and browser storage keep sessions, visitor continuity and language choices working. The widget does not include third-party advertising trackers.

Why we process data

We use data to deliver chat and human support, retrieve knowledge, generate AI replies, translate and summarize content, operate accounts, verify payments, prevent abuse and investigate service faults. Merchant-account processing is based, where applicable, on performing the service contract, legal obligations and legitimate interests in operating and securing the service. The merchant determines the lawful basis and any required consent for visitor data and provides the corresponding notice. We do not sell personal data or use conversations to train Ouviro’s own models.

Infrastructure and AI providers

Cloudflare provides hosting and processing infrastructure, including Workers, D1 databases, R2 object storage, Durable Objects, queues and Vectorize search. Cloudflare Workers AI processes relevant text for AI replies and knowledge embeddings. When the Anthropic provider is configured, relevant prompts and conversation content are sent directly to Anthropic. Depending on the operation, inputs include messages, retrieved knowledge and content needed for translation or summarization. Our own-model training statement does not describe every model provider’s separate retention or training terms; contact us for the provider configuration relevant to your service.

Email, payment and other recipients

Cloudflare Email Service sends account emails, such as verification and password-reset links, and processes recipient addresses and their content; Resend is kept only as a fallback sender. For USDT-TRC20 payment verification, TronGrid is queried for public transfers to our receiving address; this query does not send visitor conversations or merchant email addresses. The public blockchain exposes wallet addresses, amounts and transaction identifiers. Merchants and their authorized support staff access visitor records within their permissions. Data may also be disclosed where legally required or necessary to address fraud or protect legal rights.

History windows and retention

The dashboard lets merchants view the last 30 days of conversation history on the free tier, or 90 days after unlocking. These are visibility windows, not automatic deletion deadlines: older records and attachments can remain stored, and ongoing conversations are not hidden by this window. Account, security and billing records may also remain for service operation, dispute handling or legal obligations. A universal storage-expiry schedule and automatic purge are not currently implemented. Request deletion through the merchant or the contact below; the applicable scope, legal exceptions and handling need to be assessed. We cannot erase public blockchain records.

Access, correction and deletion requests

Depending on your location and the law that applies, including GDPR, CCPA/CPRA or LGPD, you may request access or a copy, correction, deletion, portability, restriction or objection, or withdraw consent where consent is the basis. You may also complain to the relevant authority and, where applicable, exercise rights without discrimination. Some rights have legal exceptions. Visitors should first contact the merchant controlling their data; Ouviro assists with requests relating to data it processes for that merchant. Account holders can contact us directly. Include the relevant merchant and enough information to locate the record; proportionate identity verification may be necessary. Do not email passwords or private keys.

International processing

Cloudflare, AI and email providers may process data in countries other than your own. This service does not offer a customer-selected storage region. International transfers require the safeguards and legal mechanism applicable to the particular transfer. Destinations and contractual transfer arrangements must be confirmed with the service provider before use where required; this draft does not represent that a specific transfer agreement has already been signed. Contact us for information needed to assess your use.

Security and your responsibilities

Implemented controls include authenticated sessions, tenant and role-based access checks, authorization checks before attachment retrieval, input validation and rate limits on relevant endpoints. Public service connections use HTTPS. No system can guarantee absolute security. Merchants must protect their accounts, limit staff access and avoid putting unnecessary sensitive data into knowledge sources or tool responses. Do not submit passwords, wallet secrets, financial account credentials or protected medical information.

Children, changes and contact

The service is intended for business use by adults and is not directed at children. Merchants must not use it to solicit personal data from children; if you believe a child has supplied data, contact the merchant and us to request review and deletion where appropriate. We may update this policy as the service changes and will identify the revision date above. Privacy requests can be sent to [email protected]. This address is a provisional contact that must be confirmed before the draft takes effect.

Privacy and support contact: [email protected]

Related document: Terms of service