Skip to main content
Security & Trust

Your store's data, handled carefully

You're connecting Vosaire to real orders, customers, and — if you choose — a Gmail inbox. Here's exactly how that data is protected, in plain language, with the full legal detail linked below.

Encrypted everywhere

TLS 1.3 in transit, AES-256 at rest. Gmail OAuth credentials are encrypted at rest using the same controls.

Known data residency

Primary data on servers in the EU (Hetzner, Germany). File storage in the US (Cloudflare R2). No undisclosed regions.

Role-based access

Internal access to merchant data is scoped by role — nobody on our team has blanket access by default.

72-hour breach notice

If a data breach affects your personal data, we notify you and, where required, supervisory authorities within 72 hours of becoming aware.

GDPR webhooks, actually implemented

All three Shopify-required compliance webhooks are live — data requests, customer redaction, and full shop redaction on uninstall.

No training on your data

Your store data, Gmail content, and conversations are never used to train Vosaire's systems or OpenAI's foundation models.

Sub-processors

Who else touches your data, and why

Sub-processorPurposeCountry
OpenAIAI response generation, including replies to Gmail messagesUS
Amazon Web Services (SES)Transactional email deliveryUS
Cloudflare R2File and knowledge-base storageUS
HetznerServer infrastructureGermany
Google (Analytics)vosaire.com website traffic analytics — only after you accept in the cookie bannerUS

Every sub-processor above is bound by a data processing agreement. Full detail in our Privacy Policy.

Retention

How long we keep it

Data categoryRetentionBasis
Store & conversation data (including Gmail-derived replies)Duration of install + 30 days after uninstallContract
Knowledge base contentUntil re-synced or 30 days after uninstallContract
Gmail OAuth connectionUntil the merchant disconnects the channel, removes the connection in Integrations, or revokes access via their Google Account, or the app is uninstalledContract
Cookie-consent decisions (vosaire.com)24 months from the decision, or until you change your choiceLegal compliance
Security / audit logs12 monthsLegitimate interest
Support communications3 yearsLegitimate interest
Questions

Security & data FAQ

Does Vosaire sell or share my store's data?+

No, never. We do not sell or share personal information — see our Privacy Policy's California/CCPA section for the specific legal commitment.

What happens to my data if I connect Gmail?+

Vosaire only reads the connected inbox to detect and draft replies to customer emails — never Sent mail, Trash, contacts, or calendar. It adheres to Google's API Services User Data Policy, including the Limited Use requirements: no ads, no selling, no training a generalized AI model on that data.

Is my data used to train OpenAI's models?+

No. OpenAI's API data-usage terms prohibit training on API inputs by default, and we don't use your store data, Gmail content, or conversations to train or fine-tune any AI model — Vosaire's own systems included.

What happens to my data if I uninstall?+

Everything tied to your store — conversations, knowledge sources, revenue records, Gmail-derived data, your organization record — is permanently deleted within 30 days, via our shop/redact GDPR webhook.

Where can I see the full legal detail?+

This page is a plain-language summary. The binding terms — including sub-processor DPAs, retention periods, and your rights under GDPR, CCPA, and India's DPDP Act — are in our Privacy Policy.

Found a security issue?

Email privacy@vosaire.comwith details — we read every report and aim to respond within 5 business days. Please don't test against merchant stores you don't own or have permission to test.

Start free today

Install free