Who this policy covers
Arvin provides AI assistants that businesses add to their websites. This policy explains how Arvin handles information on our website and dashboard, and when an assistant is used on a customer's website. The business that installs an assistant decides what its visitors may submit and how it uses the resulting conversations, leads, and bookings. Its own privacy notice also applies to those interactions.
For account, billing, and Arvin website data, Arvin determines how information is used. For visitor conversations, leads, bookings, and website content handled on behalf of a business, we generally act as its service provider or processor, subject to its instructions and applicable law. If you interacted with an assistant on another business's site, that business may be the best first contact for a request about that interaction.
Information we collect
- Accounts and teams: email address, authentication identifiers, profile and business details, team roles and invitations, and support communications.
- Business setup: website URL, public pages and material you provide for the assistant, assistant settings, approved domains, and integration settings.
- Visitor interactions: chat messages and replies, conversation identifiers, lead names and contact details when offered, booking details such as date, name, email, phone and notes, and messages sent by a human operator.
- Payments: subscription status, purchase and invoice identifiers, and transaction records. Stripe handles payment card entry; Arvin does not receive full card numbers.
- Technical activity: the site domain where a widget loads, requests, device and browser information, IP address in service or hosting logs, error and security records, and aggregate usage counts.
- Optional analytics and preferences: site analytics when enabled and allowed, cookie choice, theme, and locally stored dashboard preferences. The widget uses session storage to remember whether its greeting bubble was dismissed during a visit.
We obtain this information from account holders, their team members and visitors; from public web pages an account holder asks us to read; from authentication, payment and connected platform providers; and automatically when the service is used. Please do not submit passwords, payment card numbers, medical records, or other sensitive information in a chat or source unless you and the business have a lawful reason and an appropriate arrangement for doing so.
How we use information
We use information to create and secure accounts; read and index selected public website pages; retrieve relevant content and produce assistant replies; show citations; run chats, live handoffs, leads, bookings, calendars and notifications; provide billing and support; measure service use and reliability; detect abuse; and meet legal obligations. We may use feedback and aggregated or deidentified statistics to improve the service. We do not use a business's visitor conversations for our own targeted advertising.
Assistant replies are generated by AI and can be inaccurate. A business should review its content and settings, and visitors should confirm important details with the business. Arvin does not make decisions with legal or similarly significant effects about visitors solely through the widget.
Who receives information
The business operating an assistant and its authorized team can view its conversations, leads, bookings and analytics. When a business enables an integration, information needed for that feature can go to its connected Shopify or Wix site, WordPress installation, Google Calendar, or the webhook destination it selects. Webhooks may include lead or appointment details; the business controls the receiving address.
We use service providers to operate Arvin, including Google Cloud and Firebase for hosting, authentication and storage; OpenAI for AI replies, embeddings and optional tracing; ElevenLabs for spoken replies when enabled; Stripe for payments; and Vercel for the dashboard. Optional Google Analytics or Google Tag Manager may run on our own site when configured. These providers receive only information needed for their services, under their applicable terms. We may also disclose information to comply with law, protect rights and safety, or in a business transfer.
Arvin does not sell personal information or share it for cross-context behavioral advertising as those terms are used in California privacy law. If that practice changes, we will update this policy and provide any required choices before it begins.
Cookies and local storage
Authentication and security features use cookies or similar browser storage. If optional analytics is configured, our consent control keeps analytics storage denied until you select “Allow”; “No thanks” leaves it denied. You can clear that choice in your browser's site data to be asked again. A customer's website may use its own cookies, governed by its policy. The Arvin widget itself stores a greeting dismissal in session storage for the current browser session.
Retention and security
Account and team records are kept while an account is active and as needed afterward for support or legal obligations. Business sources and assistant settings remain while an assistant is active or until changed or removed. Conversations, leads and bookings remain available to the business until deletion is requested or an applicable retention arrangement requires removal; we do not currently offer an automatic fixed expiry for every conversation. Billing records are kept as long as tax, accounting or dispute obligations require. Service logs and backups may persist for limited operational periods after active records are removed. Contact us to request deletion or discuss retention for your account.
We use access controls, tenant separation and other reasonable safeguards appropriate to the service. No internet service can promise absolute security. Customers should restrict team access and protect any connected webhook or calendar destination.
Your choices and privacy rights
You may update account details and assistant settings in the dashboard, decline optional analytics, and ask for access, correction or deletion of personal information. Depending on where you live, you may also have rights to know about disclosures, obtain a copy, limit certain uses of sensitive information, or appeal a denied request. We will verify requests as required by law and will not discriminate for exercising an applicable privacy right. Some information may be retained where law permits or requires it.
For a conversation on another business's website, please identify that business and, if available, the date or conversation details in your request. We may direct you to the business or assist it in responding. Email privacy requests to [email protected]. An authorized agent may make a request where permitted by law; we may ask for proof of authority.
California residents
In the preceding 12 months, the categories of personal information we may have collected are identifiers and contact details; account and payment transaction information; internet or network activity; general location inferred from an IP address; professional or business information; and the content of communications, leads and bookings. The sources, purposes and recipients for those categories are described above. We do not use or disclose sensitive personal information to infer characteristics about individuals. We do not knowingly sell or share the personal information of people under 16.
If California privacy law applies to a request, you may ask to know, access, correct or delete covered information, and to receive information about our collection and disclosure practices. Because we do not sell or share personal information for cross-context behavioral advertising, there is currently no sale or sharing opt-out to exercise. You may use the email above to make a request or appeal a response. We will explain any applicable exception and how to appeal when we respond.
Children, location and changes
Arvin is intended for businesses and general audiences, not children under 13. Customers must not deploy it on a service directed to children under 13 without a separate, appropriate arrangement. If we learn that we collected a child's information contrary to this policy, contact us so we can investigate and delete it as appropriate.
Our providers and operations may process data in the United States and other locations where they operate. We will post material changes here with a new update date and provide any additional notice required by law. Please also read our Terms of Service.

