Privacy Policy
This draft has not yet been published — no effective date has been set.
Draft notice: this page is a working draft, not a reviewed legal document. The bracketed placeholder (operating entity, contact address) needs real information — and this notice removed — before Anchor is offered to real business customers. It has not been reviewed by a lawyer, and does not yet cover jurisdiction-specific obligations (e.g. GDPR/CCPA data-subject request mechanics) beyond the general description below.
1. Who this policy covers
This policy is issued by [Pinevon legal entity name and jurisdiction — same value as the Terms of Service] for Anchor (the "Service"). It covers two kinds of people: the business owners and team members who have an Anchor account, and the end customers of those businesses who talk to a business's Anchor-powered chat widget. For the second group, the business you contacted is the one who controls that relationship — Anchor processes that chat data on the business's behalf, as described below.
2. What we collect
- Account data: email address and authentication credentials (handled by Supabase Auth — we never see or store your raw password).
- Business data you provide: business name, product catalog (names, prices, stock, photos, specs), orders, and quotations.
- Customer chat data: messages sent through a business's chat widget, and any contact details a customer voluntarily provides during that conversation.
- Usage data: which AI calls were made, their approximate cost, and request logs (method, path, status, latency, a request ID) — used for reliability and billing, not sold or shared beyond the sub-processors below.
3. How we use it
To provide the Service: authenticate you, store and retrieve your catalog/order data, generate grounded AI answers from that data, and run the automations you enable (e.g. low-stock detection). We do not use your business's or its customers' data to train AI models for other customers.
4. AI processing, specifically
When a customer asks a question in the chat widget, or a business owner asks the owner-AI a question, the relevant retrieved data (e.g. matching product records, or the specific order rows a query needs) is sent to the configured third-party AI provider to generate a response. That provider processes the request under its own API terms; Anchor does not send your entire catalog or order history on every request, only what a given query retrieves as relevant.
5. Who we share data with
We use the following sub-processors to run the Service. None of them are permitted to use your data for their own purposes.
We don't sell your data or your customers' data to third parties, and we don't share it for anyone else's advertising purposes.
6. Data retention and deletion
We retain your data for as long as your account is active. If you close your account, we delete your business's data within a reasonable period, except where we're required to retain records (e.g. billing history) for legal or accounting reasons. [Set an exact retention window here once decided — e.g. "30 days after account closure."]
7. Security
Every business's data is isolated by both database-level row-level security and independent authorization checks in the API — see the Security page for the technical detail. Uploaded files are validated before storage; secrets are never bundled into frontend code.
8. Your rights
You can access, correct, or export your business's data from your dashboard at any time, or by contacting us. If you're an end customer who chatted with a business's Anchor widget and want your conversation data removed, contact that business directly, or reach us and we'll route the request.
9. Cookies
The dashboard uses a small number of essential cookies to keep you signed in (issued by Supabase Auth). We don't use third-party advertising or tracking cookies.
10. Children's privacy
The Service is intended for business use and isn't directed at children. We don't knowingly collect data from children under 13 (or the relevant local minimum age).
11. Changes to this policy
We may update this policy as the Service evolves. We'll post the updated version here with a new effective date.
12. Contact
Questions about this policy, or a data request: privacy@pinevon.com (placeholder address — deliberately non-functional until a real inbox exists, same convention as the rest of this site).