Privacy Policy
Last updated: June 26, 2026 · Version 2.1
1. Introduction and scope
This Privacy Policy explains how Vosaire (“Vosaire”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you use our AI customer support platform at vosaire.com and associated services (the “Service”).
This policy covers two distinct groups: (A) Account Holders — businesses and individuals who register for and use Vosaire directly; and (B) End Users — visitors and customers of our Account Holders who interact with Vosaire-powered chat widgets embedded on third-party websites. If you are an End User, the Account Holder who deployed the widget is the primary data controller for your information; Vosaire processes that data only as a data processor on their behalf.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Who we are
Vosaire is an AI chatbot SaaS platform. Our primary contact for privacy matters is privacy@vosaire.com. For queries under India's Digital Personal Data Protection Act 2023, our Grievance Officer can be reached at the same address; we will respond within 72 hours and resolve within 30 days.
3. Information we collect
3.1 Account Holder data
Account information: Name, email address, company name, and any profile details you provide during registration or account updates.
Knowledge base content: Documents, URLs, and text you upload to train your AI agents. Stored in Cloudflare R2 (US-based object storage) and indexed for retrieval.
Usage data: Pages visited, features used, API call volumes, error logs, session timestamps, and IP addresses — collected to monitor platform health and inform product development.
Billing information: Payment card details are collected and processed exclusively by Razorpay. Vosaire receives only a tokenized reference and billing summary — we never store raw card numbers.
Google OAuth data: If you sign in via Google, we receive your name, email address, and profile picture. We request only the minimum scopes necessary (profile and email). We do not access your Google Drive, Gmail, or any other Google services unless you explicitly grant integration access.
Support communications: Emails or messages you send to our support team.
3.2 End User data (via embedded widget)
When visitors interact with a Vosaire-powered widget, we may collect: conversation messages and metadata (timestamps, session IDs), browser type and version, referring URL, and device type. This data is collected on behalf of the Account Holder who deployed the widget. We process it only to deliver the AI agent response and provide analytics to the Account Holder.
3.3 What we do NOT collect
We do not collect health or medical data, government-issued ID numbers, biometric data, financial account credentials, or special category data as defined under GDPR Article 9. You must not submit such data through any Vosaire service.
4. Legal bases for processing (GDPR)
For users in the EEA, UK, and Switzerland, we process personal data under the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Providing and maintaining the Service | Contract (Art. 6(1)(b)) |
| Processing payments | Contract (Art. 6(1)(b)) |
| Transactional emails (receipts, password resets) | Contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Product analytics and improvement | Legitimate interest (Art. 6(1)(f)) |
| Analytics cookies (Google Analytics) | Consent (Art. 6(1)(a)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
5. How we use your information
We use collected information to: authenticate you and deliver the Service; process and fulfil your subscription; send transactional emails (receipts, password resets, security alerts, important product notices); generate AI responses to your end users' queries; produce the analytics visible in your dashboard; identify bugs and prioritize product improvements; comply with legal obligations; and respond to your support requests.
We may send product update emails and tips. You can unsubscribe at any time using the link in any such email. We do not sell, rent, or share your personal data with third parties for their advertising purposes.
6. AI and LLM processing
Vosaire uses OpenAIas its primary large language model provider. When your AI agents process a user query, the conversation context (including relevant knowledge base snippets) is transmitted to OpenAI's API over an encrypted connection to generate a response.
We do not use your conversation data or knowledge base content to train, fine-tune, or improve any AI model— including Vosaire's own systems or OpenAI's foundation models. Data sent to OpenAI is processed subject to OpenAI's API data usage terms, which prohibit training on API inputs by default.
AI-generated responses may occasionally be inaccurate, incomplete, or outdated. You are responsible for reviewing outputs before relying on them for any consequential decision.
7. Data retention
| Data category | Retention period | Basis |
|---|---|---|
| Account information | Duration of account + 30 days post-deletion | Contract |
| Conversation logs | Duration of subscription + 30 days post-termination | Contract |
| Knowledge base content | Until deleted by Account Holder or 30 days post-termination | Contract |
| Billing records | 7 years from transaction date | Legal obligation (tax law) |
| Security / audit logs | 12 months | Legitimate interest |
| Support communications | 3 years | Legitimate interest |
| Analytics data (aggregated) | 26 months (Google Analytics default) | Consent |
8. Data storage and security
Your data is stored primarily on servers in the European Union (Hetzner, Germany) with file storage in the United States (Cloudflare R2). We employ TLS 1.3 encryption in transit, AES-256 encryption at rest, and role-based access controls.
In the event of a data breach affecting your personal information, we will notify affected users and, where required, relevant supervisory authorities within 72 hours of becoming aware. Notifications will include the nature of the breach, categories of data affected, and measures taken.
9. International data transfers
We transfer personal data to sub-processors in the United States (OpenAI, AWS SES, Cloudflare, Google), India (Razorpay), and Germany (Hetzner). For transfers from the EEA, UK, or Switzerland to countries without an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism. You may request a copy by emailing privacy@vosaire.com.
10. Sub-processors
We use the following third-party sub-processors to deliver the Service. All are bound by data processing agreements and prohibited from using your data for their own independent purposes.
| Sub-processor | Purpose | Country | Transfer basis |
|---|---|---|---|
| OpenAI | LLM / AI response generation | US | SCCs |
| Razorpay | Payment processing | India | SCCs |
| Amazon Web Services (SES) | Transactional email delivery | US | SCCs / DPF |
| Cloudflare R2 | File and knowledge base storage | US | SCCs / DPF |
| Google (OAuth) | Authentication | US | SCCs / DPF |
| Hetzner | Server infrastructure | Germany | EU adequacy |
We will notify Account Holders at least 14 days before adding a new sub-processor that handles personal data. Objections may be raised via email within that window.
11. Cookies and tracking
We use cookies and similar technologies on the Vosaire marketing site and application. Cookies are categorized as follows:
Session management, authentication tokens, CSRF protection, load balancing. Essential for the Service to function — cannot be disabled.
Google Analytics (G-BKYY41NLRG) — tracks page views, scroll depth, and outbound clicks. Data is anonymized and stored in the US. No cross-site tracking. Consent is requested via our cookie banner on first visit.
We do not use advertising or retargeting cookies.
You can withdraw analytics consent at any time by clicking “Cookie settings” in the footer. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
12. Your rights
12.1 GDPR rights (EEA, UK, Switzerland)
You have the right to: access a copy of your personal data; rectify inaccurate data; erase your data (right to be forgotten); restrict processing in certain circumstances; receive your data in a portable machine-readable format (JSON or CSV); object to processing based on legitimate interest; withdraw consent at any time; and lodge a complaint with your national supervisory authority. Deletion requests are fulfilled within 30 days, except where retention is required by law.
12.2 CCPA / CPRA rights (California residents)
California residents may: know what personal information we collect and how it is used; access and receive a copy of their personal information; correct inaccurate personal information; delete their personal information (subject to legal exceptions); and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioural advertising. We do not discriminate against users who exercise their privacy rights. To exercise these rights, email privacy@vosaire.com with the subject line “CCPA Request”.
12.3 India DPDP Act rights
Under the Digital Personal Data Protection Act 2023 (India), you have the right to access a summary of your personal data; correct or erase your data; nominate a representative; and grieve to the Data Protection Board of India. Contact our Grievance Officer at privacy@vosaire.com. We will acknowledge within 72 hours and resolve within 30 days.
13. Automated decision-making
Our AI AI agents process and respond to end-user queries automatically. This constitutes automated processing but does not produce legal or similarly significant effects on individuals — responses are informational only. You have the right to request human review of any automated process that affects you significantly. Contact us at privacy@vosaire.com.
14. Children's privacy
The Vosaire platform is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@vosaire.com and we will delete it promptly. Account Holders must not deploy Vosaire widgets on websites directed at children under 13 without appropriate parental consent mechanisms.
15. Business transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity. We will provide reasonable prior notice before your personal data becomes subject to a different privacy policy.
16. Changes to this policy
For material changes — such as new data collection practices, new sub-processors, or changes to legal bases — we will notify Account Holders by email at least 14 daysbefore the changes take effect. The “Last updated” date at the top reflects the most recent revision. Prior versions are available on request.
17. Shopify App — Caro
Vosaire offers a separate Shopify application called Caro(available on the Shopify App Store), which installs directly into a merchant's Shopify admin. Caro is a distinct product with its own account context and is governed by the following additional terms:
17.1 Separate product identity
Caro (Shopify app) and the Vosaire web platform (dash.vosaire.com) are separate products with separate workspaces and billing. A user who installs Caro on Shopify and also registers on the Vosaire web platform will have two entirely independent accounts — one per product. Data from a merchant's Shopify workspace is never surfaced on the web platform and vice versa.
17.2 Shopify merchant data collected by Caro
When a merchant installs Caro, we collect and process the following data from the merchant's Shopify store, solely to deliver the app's features:
- Store information: shop name, shop owner email, store URL, and shop GID
- Products, collections, pages, blog posts, store policies, and legal policy content (for AI knowledge base training)
- Live inventory and stock levels (for real-time availability checks in chat, on qualifying plans)
- Order data including order number, line items, and fulfillment status (for order lookup tool)
- Customer email addresses associated with orders (for order lookup and coupon attribution)
- Customer notes, tags, and email/SMS marketing consent, written back to the customer record when a merchant enables these features (on qualifying plans)
- Discount codes and draft orders created on the merchant's behalf when a merchant enables the Sales agent (on qualifying plans)
- Theme structure metadata, read only to guide the merchant through activating the storefront widget — Caro never writes to a merchant's theme
- Conversation transcripts between the AI agent and store visitors
- Revenue attribution data linking AI agent conversations to completed orders
All data listed above is transmitted to OpenAI for AI response generation. See Section 6 for our AI and LLM processing policy.
17.3 Billing
Caro uses Shopify App Pricing(formerly known as Managed Pricing) for subscription billing. Plan selection, charges, and subscription management are all handled by Shopify directly as part of the merchant's standard Shopify invoice — Caro does not integrate with the Billing API or any custom billing flow. Caro merchants are never charged through Stripe, Paddle, Razorpay, or any other external payment processor.
17.4 GDPR compliance webhooks
Caro implements all three Shopify-required GDPR compliance webhooks:
- customers/data_request — We acknowledge the request within 30 days and notify the merchant of all data held for that customer.
- customers/redact — Customer PII (email, name) is anonymized and coupon records are removed within 30 days of receiving the request.
- shop/redact — All data associated with the merchant's store (conversations, messages, knowledge sources, revenue records, and the organization record) is permanently deleted within 30 days of app uninstallation.
17.5 Shopify OAuth scopes
Caro requests only the Shopify API scopes necessary to deliver its features:
read_products— product and collection catalog sync for AI training and product cardsread_orders/write_orders— order status lookup and adding notes/tags to an order (e.g. flagging a cancellation request)read_all_orders— extends order status lookup beyond Shopify's standard 60-day window, so the AI agent can answer questions about older orders tooread_customers/write_customers— resolving a logged-in shopper's identity, and saving notes, tags, or marketing consent when a merchant enables that featureread_content— pages and blog posts, for AI knowledge base trainingread_legal_policies— store policies (returns, shipping, privacy), for AI knowledge base trainingread_themes— read-only, used to guide merchants through activating the storefront widget embed. Caro never writes to a theme.read_inventory— live stock levels for real-time availability checks (on qualifying plans)read_discounts/write_discounts— generating one-time discount codes via the Sales agent (on qualifying plans)read_draft_orders/write_draft_orders— building a draft order with a direct checkout link via the Sales agent (on qualifying plans)
We do not request access to any other store resource beyond what is listed above and disclosed to Shopify during app submission.
18. Contact us
For any questions, data requests, or complaints, contact privacy@vosaire.com. We aim to respond within 5 business days.
If you are in the EEA and we have not resolved your concern within 30 days, you may lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.