Privacy Policy
How we collect, use, and protect your information
Last updated: September 5, 2026
Introduction
Ravvio (“we,” “our,” or “us”) provides AI-powered customer support, lead qualification, order tracking, and engagement solutions (“the Service”) to businesses. This Privacy Policy describes how personal information is collected, used, and shared when you use our platform, including our website widget, dashboard, our AI assistant, and connected third-party integrations such as Shopify and Google Calendar.
Use of information from Google (Limited use)
When you connect a Google account or authorize Google APIs (for example, Google Calendar for demo booking, or Google Sign-In to log in), the information we receive from Google is used only to provide or improve the specific features of the Service that rely on that connection—such as showing which account is connected, checking availability, creating calendar events and meeting links, and authenticating your session.
We do not use data received from Google APIs to serve you advertisements, for behavioral or targeted advertising, or for unrelated marketing. We do not sell that data. We do not use Google user data to train generalized artificial intelligence or machine learning models.
Other sections below (such as marketing or advertising) apply only to categories of data not obtained from Google APIs, and do not change these limits for Google user data.
Ravvio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Personal Information the App Collects
Information from your Shopify account
When you install the App, it requests the following Shopify access: read and write access to products and themes; read and write access to orders; read access to customers; and unauthenticated Storefront access to product listings, inventory and checkouts. From this access we actually use: product catalog data (to answer product questions and recommend products); order number, order and fulfilment status, tracking details, line items, order totals and currency (for order tracking and merchant revenue analytics); and the customer’s email address (see “Order tracking” and “Order attribution and merchant analytics” below). We do not access customer names, addresses, or phone numbers.
Merchant information
Information about you and others who access the App on behalf of your store, such as your name, email address, phone number, and billing information.
Visitor technical information
Information about individuals who visit a store where the assistant is installed, such as IP address, browser details, time zone, and cookie identifiers, collected using technologies such as cookies, log files, tags and pixels.
Conversation data
Messages exchanged with the AI assistant are stored as conversation history, associated with a visitor session and the merchant’s assistant. A shopper may choose to type personal information into the chat — for example an email address or order number to track an order — and anything they type is stored as part of that history. To generate replies, recent messages from a conversation are sent to our AI provider (Google — see “Service Providers and Subprocessors”).
Google Calendar data
If you choose to connect your Google Calendar through our platform, we access limited calendar data to power the AI-assisted demo booking feature. Specifically, we access:
- Free/Busy availability — to check your calendar for open time slots before suggesting them to visitors.
- Event creation — to create calendar events with Google Meet video links on your behalf when a visitor confirms a booking.
- Calendar list — to identify which calendar to use for bookings.
- Account email — to display the connected Google account in your dashboard.
We store your Google OAuth refresh token securely, encrypted at rest in our database, solely to maintain your calendar connection. We do not read, store, or analyze the content of your existing calendar events. Your Google Calendar data is never shared with third parties, used for advertising, or accessed for any purpose other than the booking functionality you have explicitly enabled.
How the AI Assistant Features Use Data
Order tracking
When a shopper asks the assistant to track an order, they provide an order number and an email address in the chat. Ravvio looks up that order in the merchant’s Shopify store using the order number, and uses the email address only to confirm that the shopper is the person who placed the order. The email address is not sent to Shopify. If it matches, the assistant returns the order’s status, fulfilment status and tracking information. The order-tracking service does not store the order details or the email address; we keep an internal access-log entry containing a one-way (SHA-256) hash of the email address, the order number, whether a match was found, and the time of the request.
Order attribution and merchant analytics
If a shopper interacts with the assistant and later places an order, Ravvio receives that order’s data from Shopify through webhooks (order created, updated, cancelled, and refund created). Ravvio links eligible orders to the chat session that assisted them, using a hidden reference stored on the cart at checkout or a time-limited match on the purchased product. For repeat-customer analytics, the customer’s email address is converted to a one-way SHA-256 hash; the email address itself is not stored, and customer name, address and phone are not stored. For each attributed order we store the order number, status, totals, currency, purchased line items (product, quantity, price), the linked session identifier, and the email hash. Merchants see this as revenue and attribution analytics. Refunds and cancellations update these records.
Conversation history and context
We use conversation history to operate the assistant, maintain context within and across a visitor’s sessions, provide features such as order tracking and product recommendations, and produce aggregated analytics for the merchant. Recent messages from a conversation are sent to our AI provider (Google) to generate responses; they are not used to train generalized AI models.
Protected customer data vs. de-identified analytics
We distinguish protected customer data we obtain from Shopify (order data accessed for order tracking and attribution) — retained only as long as needed for those features and subject to Shopify’s data-deletion webhooks — from de-identified conversation analytics we generate from interactions, which contains no direct customer identifiers after the retention periods described below and is retained to give merchants historical insight into their assistant’s performance.
How Do We Use Your Personal Information?
Service provision
We use the personal information we collect from you, your store, and your customers to provide and operate the Service — including answering product and order questions, tracking orders, recommending products, and producing merchant analytics.
Communication
To communicate with you (the merchant) about the App, send service updates and security alerts, and respond to your inquiries.
Optimization
To optimize and improve the Service using aggregated, non-identifiable usage data. Google user data obtained through Google APIs is never used for this purpose.
Marketing
Where permitted by law, we may send merchants information about Ravvio products or services (which you can opt out of). We do not use Shopify customer data, conversation data, or data received from Google APIs for marketing or advertising.
Service Providers and Subprocessors
We use the following third parties to operate the Service. We do not sell personal information, and we do not share conversation data or Shopify customer data with advertising or analytics vendors for their own purposes.
Supabase — database hosting (AWS)
Stores merchant account data, conversation history, attributed-order records (including the SHA-256 email hash), and lead records.
Google (Gemini API)
AI response generation, intent classification, and text embeddings. Receives the shopper’s messages and recent conversation context (which may contain information a shopper has typed, such as an email address or order number) and the merchant’s catalog and knowledge-base content. This is separate from, and does not affect, the Google Calendar / Google Sign-In data described in “Use of information from Google (Limited use)”.
Shopify
Source of product and order data; processes order lookups initiated by the assistant. The shopper’s email address is not sent to Shopify during order tracking.
Qdrant — vector search hosting
Stores embeddings and text of the merchant’s own catalog and knowledge-base content only. It does not receive shopper or conversation data.
Dodo Payments
Merchant subscription billing only. Does not receive shopper data.
Infrastructure providers
We also use providers for application hosting, caching, and transactional email to Ravvio account holders.
Legal compliance and business transfers
We may share information to comply with applicable laws, respond to a lawful request, or protect our rights. In the event of a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
Behavioral Advertising
This section applies only to our public marketing website. Shopify customer data, conversation data, and information we receive from Google APIs are never used for behavioral or targeted advertising.
Targeted advertising
Where we use cookies or similar technologies on our marketing website, we may work with partners to show relevant ads. For more information about how targeted advertising works, visit the Network Advertising Initiative’s educational page at networkadvertising.org.
Opt-out options
You can opt out of targeted advertising via the Digital Advertising Alliance’s opt-out portal at optout.aboutads.info.
Data Security
Encryption
Data is transmitted over encrypted connections (TLS) and stored in a database that encrypts data at rest.
Access controls
Merchant data is isolated per organization with row-level access rules, and access requires authentication.
Access logging
Order lookups and privacy/redaction requests are recorded in an internal audit log.
Ongoing review
We review and update our security practices to protect against unauthorized access.
Revoking Third-Party Access
Google Calendar
You can disconnect your Google Calendar at any time from the Integration page in your Ravvio dashboard by clicking Disconnect. This immediately deletes your stored OAuth tokens and stops all calendar access. You can also revoke access from your Google Account at myaccount.google.com/permissions.
Shopify
Uninstalling the App from your Shopify admin revokes its access. When a merchant uninstalls the App, we delete that store’s configuration, connected data, and attributed-order records.
Your Rights
Access and deletion
You can ask us to access, correct, or delete personal information we hold about you by contacting us at the address below. Shoppers who interacted with a store’s assistant can also make the request through that store.
What we do on a redaction request
When a store’s platform (Shopify) notifies us of a customer data-deletion request, we anonymise the email hash on any attributed orders for that customer and remove the email address and phone number the shopper entered from stored conversations for that store, within the time Shopify requires.
European residents
If you are a European resident, our legal basis for processing is the performance of our contract with the merchant and our legitimate business interests described above. Your information may be transferred outside of Europe, including to the United States.
Data Retention
Conversation data
Direct identifiers a shopper types into a conversation — such as an email address or an order number — are removed from that conversation 90 days after the session’s last activity. The de-identified conversation (the messages, timing, and products discussed, with identifiers removed) is retained for merchant analytics while the merchant’s account is active, and in any case no longer than 24 months after the session’s last activity, after which it is deleted.
Shopify order data
We do not store the order details returned by order-tracking lookups; we keep only an internal access-log entry containing a one-way hash of the email address. For revenue attribution, the one-way hash of a customer’s email address is removed from an attributed-order record after 13 months; the remaining non-identifying order and revenue figures are retained while the merchant’s account is active.
Deletion requests and uninstall
When a store’s platform notifies us of a customer data-deletion request, we remove that customer’s identifiers (including email, phone, and any other identifying details they provided) from stored conversations for that store and anonymise their attributed-order records, regardless of the periods above. When a merchant uninstalls the App, we delete that store’s configuration, connected data, attributed-order records, and conversation history.
Privacy / redaction request records
Deleted 30 days after the request has been processed.
Merchant account data
Retained while the account is active and for as long as needed to meet legal, tax and accounting obligations.
Contact Us
If you have any questions about this Privacy Policy or our data practices, or to exercise a privacy right, please contact us:
Support
nithin@ravvio.inPhone
+91 7680054781
Changes
We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal or regulatory reasons.