Draft — pending legal review. This page is a complete first draft written to match what VeloBot actually does, with a few placeholders (marked in brackets) that need your company's real details. Have a lawyer review it before relying on it.
Privacy Policy
Last updated [DATE]
This policy explains how [YOUR COMPANY LEGAL NAME] (“VeloBot”) handles personal data. It covers two different groups, because VeloBot sits between them: Customers (the businesses who sign up for a VeloBot account, and the teammates they invite), and Visitors (people who chat with a VeloBot widget embedded on a Customer's website). If you're a Visitor with a question about a specific conversation, the business you were chatting with — not VeloBot — is usually the right first contact, since they configured that bot; see “Your rights” below either way.
1. Data we collect from Customers
- Account data: email, name, organization name, role (admin or agent).
- Billing data: plan, billing address, and payment details — payment card details are handled directly by Razorpay and never touch our servers.
- Content you provide: crawled or uploaded knowledge-base content, bot configuration (guardrails, workflow rules, canned replies, custom instructions), and any external API credentials you add under Connections.
- Usage data: login activity, feature usage, and the Super Admin support/audit trail if you contact support.
2. Data we collect from Visitors, on a Customer's behalf
When someone chats with an embedded VeloBot widget, we process, on behalf of the Customer running that bot:
- The conversation itself — every message sent and received, including any file or screenshot attached.
- An email address, if the Visitor provides one (e.g. to reach an agent, or to leave a message when no one's online).
- The page URL the widget was embedded on, and an IP-derived approximate location, for context shown to the agent handling the conversation.
- A post-conversation satisfaction rating (1–5 stars, plus an optional comment), if the Visitor chooses to leave one.
- If the Customer has enabled it, an AI-generated best-effort guess at the conversation's intent, sentiment, and any entities (like an order number) mentioned — always shown to the Customer's agents as an unverified hint, never treated as fact.
- A random session identifier stored in the Visitor's browser (localStorage), so a returning Visitor sees their own conversation history rather than starting over.
For this Visitor-facing data, the Customer is the data controller and VeloBot is the data processor — we handle it under the Customer's instructions (their bot configuration) and Terms of Service with us, not under a direct relationship with the Visitor.
3. How we use this data
- To operate the service: answering chats, routing escalations, showing agents the conversation history and context they need.
- To send transactional email: team invites, notifications about an unassigned or offline conversation, billing receipts.
- To enforce plan limits and prevent abuse (rate limiting).
- To improve the platform, using aggregated and de-identified data only.
4. Who we share it with
We share data with the sub-processors who help us run the service — OpenAI (generating chat responses and the optional intent/sentiment extraction), Supabase (database, authentication, file storage, realtime messaging), Razorpay (billing), Resend (transactional email), and Upstash (rate limiting) — each bound by their own data-processing terms. See the full Sub-processors list. We don't sell personal data, ever.
5. Data retention
Account data is kept for as long as your account is active. Conversation data is kept to give Customers a usable support history and to power features like returning-visitor context — see our data retention notes for the current stance, and contact [SUPPORT EMAIL] if you need something deleted sooner. If a bot has the optional PII-redaction guardrail enabled, credit-card- and SSN-like number patterns are stripped from the assistant's stored replies before they're saved — this is a narrow, best-effort safety net, not a general data-minimization guarantee for everything a Visitor might type.
6. Cookies and local storage
The widget stores a session identifier in the Visitor's browser (localStorage, not a tracking cookie) purely to remember their own conversation. If a Customer enables the optional consent banner, the widget shows a short notice the first time it opens — this is a courtesy notice the Customer configures, not a substitute for whatever cookie-consent tooling the Customer's own website already uses.
7. Security
Data is stored with row-level access controls scoped per organization, service-role credentials are never exposed to the browser, and origin allowlisting restricts which websites can embed a given bot. No method of transmission or storage is 100% secure, but we design around the principle that one Customer's data should never be reachable by another.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you. Customers can reach us at [SUPPORT EMAIL] (or [DPO CONTACT] for data protection officer inquiries). A Visitor asking about a specific conversation should generally start with the business they chatted with, since that business configured and controls that bot — we'll assist them in fulfilling a verified request either way.
9. Children
VeloBot isn't directed at children, and Customers shouldn't knowingly deploy a bot to collect personal data from children without appropriate consent under applicable law.
10. International transfers
Data may be processed in countries other than your own, using our sub-processors' own safeguards for international transfers.
11. Changes to this policy
We'll update the date at the top of this page and notify account admins by email for material changes.
12. Contact
[YOUR COMPANY LEGAL NAME], [ADDRESS] — [SUPPORT EMAIL].