This Privacy Policy explains how Aeyora collects, uses, stores, and shares personal information when individuals visit the website, create an account, use the dashboard, connect stores or applications, install tracking snippets or SDKs, interact with support, or use the AI analytics and reporting services. This policy is written for a software-as-a-service platform and is intended to support disclosure requirements commonly associated with GDPR, UK GDPR, CCPA/CPRA, and similar privacy laws.
This policy applies to the Aeyora website, dashboard, onboarding flows, integrations, APIs, pixels, scripts, SDKs, analytics features, AI chat features, and related support or billing interactions. It covers both information Aeyora collects directly from account holders and information processed on behalf of customers through event tracking, analytics, and conversational analysis features.
Aeyora may collect account and identity data such as name, email address, company name, billing details, login identifiers, authentication metadata, and support communications when users sign up or contact the service.
Aeyora may also collect technical and usage information such as IP address, browser type, device identifiers, approximate location, cookie or local storage identifiers, pages viewed, referring URLs, events generated by connected websites or applications, product interactions, session activity, and query history within the service.
When customers connect stores, websites, or apps, Aeyora may process customer content and analytics data such as event payloads, transaction information, product metadata, campaign parameters, identifiers, and question prompts submitted to the AI analysis tools.
Aeyora may use personal information to provide the service, authenticate users, process subscriptions, generate analytics, answer AI questions, maintain chat history, troubleshoot errors, detect abuse, enforce contracts, communicate with users, and improve product performance and security.
Aeyora may use service data and interaction data to maintain conversational continuity, store prior chat messages server-side, preserve agent memory, and improve the reliability and safety of analysis workflows.
Where GDPR or UK GDPR applies, Aeyora may rely on one or more legal bases including performance of a contract, legitimate interests, consent, and compliance with legal obligations depending on the processing activity.
Aeyora may share information with infrastructure, hosting, cloud database, payment, email, authentication, analytics, and support vendors that process data on its behalf, as well as with professional advisers, auditors, insurers, and law enforcement or regulators where legally required.
Aeyora may disclose information in connection with a merger, financing, acquisition, corporate reorganization, sale of assets, or insolvency proceeding, subject to applicable confidentiality and legal requirements.
If Aeyora transfers personal information across borders, it may rely on lawful transfer mechanisms such as adequacy decisions, standard contractual clauses, or other recognized safeguards where required.
Aeyora retains information for as long as reasonably necessary to provide the service, maintain security, meet contractual obligations, resolve disputes, comply with law, and preserve business records. Retention periods vary by data type, business need, and legal requirement.
Aeyora may retain account records, billing records, audit logs, security logs, and support records longer where necessary for legal, tax, fraud prevention, or security purposes. Analytics event data, chat history, and memory records may also be retained according to product settings, contractual commitments, or internal retention schedules.
Aeyora uses administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authentication controls, encrypted transport where appropriate, monitoring, and incident handling procedures.
No system can be guaranteed perfectly secure, and users should also protect credentials, use strong passwords, and notify Aeyora promptly of suspected unauthorized access.
Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or port certain personal information, and may also have rights related to consent withdrawal and marketing preferences.
California residents may also have rights to know categories of information collected, sources, purposes, and categories of third parties involved, and to exercise applicable deletion, correction, or non-discrimination rights under California law.
Aeyora may use cookies, local storage, pixels, session storage, and similar technologies for authentication, security, preferences, fraud prevention, product analytics, and performance measurement. Where applicable, these may be paired with a cookie notice or consent mechanism.
Aeyora is not directed to children and is not intended for use by children under the age required by applicable law to use the service independently.
Aeyora may update this Privacy Policy from time to time to reflect service, vendor, legal, or operational changes. The revised version will be posted with an updated effective date.
Privacy requests, questions, and complaints should be directed to Aeyora using the designated privacy or support contact listed on the website or customer agreement.