Privacy Policy
VartaFlow ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered sales assistant platform and embedded chat widget.
1 Information We Collect
We collect information in three categories: (a) information from Store Owners who use our platform, (b) information from Website Visitors who interact with the chat widget, and (c) information we automatically scrape from store websites.
1.1 Information from Store Owners (Account Holders)
When you register for a VartaFlow account, we collect:
| Data Type | Purpose | Retention |
|---|---|---|
| Email Address | Account identification, communication | Until account deletion |
| Display Name | Personalization | Until account deletion |
| Profile Photo URL | Account display | Until account deletion |
| Authentication ID | Secure account identification | Until account deletion |
| Subscription Plan | Service delivery, billing | Until account deletion |
1.2 Information from Website Visitors (Chat Widget Users)
When visitors interact with the chat widget, the following data is collected and stored locally in their browser (localStorage):
| Data Type | Purpose | Retention |
|---|---|---|
| Session ID | Identify unique browsing sessions | 24 hours (auto-expires) |
| Chat Messages | Conversation history with AI | Until browser data cleared |
| Pages Visited (URLs) | Context for personalized recommendations | 24 hours |
| Time on Page | Understanding engagement level | 24 hours |
| Scroll Depth | Understanding content consumption | 24 hours |
| Page Type Detection | Tailored AI responses | 24 hours |
Important: Visitor browsing data is stored only in the visitor's browser using localStorage. We do not transmit or store individual visitor journey data on our servers. Only anonymized, aggregated usage counts are stored server-side.
1.3 Scraped Website Content
When store owners configure VartaFlow, we scrape publicly available content from their websites:
2 How We Use Your Information
Service Delivery
Provide AI-powered chat functionality, generate personalized product recommendations, and answer visitor questions.
Platform Operation
Authenticate accounts, enforce plan limits, process website content for AI training, and maintain service reliability.
Communication
Send service-related notifications, respond to support inquiries, and provide account updates.
Improvement
Analyze aggregated usage patterns, improve AI response quality, and develop new features.
3 Third-Party Services
We use the following categories of third-party services to operate VartaFlow:
Authentication Services
Secure user login and account management using industry-standard OAuth 2.0 authentication.
AI and Machine Learning Services
Powering intelligent chat responses, content analysis, and semantic search. Our AI service providers do not use customer data to train their models.
Database Services
Secure storage of account information, bot configurations, and product data.
Search Infrastructure
Enabling fast, relevant product and content search using text embeddings (mathematical representations, not raw content).
4 Data Storage and Security
Data Locations
- storage Visitor Data: Stored locally in browser (localStorage) - never transmitted to our servers
- cloud Account Data: Secure cloud-hosted databases
- search Search Embeddings: Dedicated vector database infrastructure
Security Measures
- check_circle All data transmission uses HTTPS/TLS encryption
- check_circle Database access requires authentication
- check_circle OAuth 2.0 secure authentication flows
- check_circle API keys and secrets stored securely (never exposed client-side)
- check_circle No passwords stored (managed by authentication provider)
Data Retention
| Data Category | Retention Period |
|---|---|
| Visitor session data (browser) | 24 hours (auto-expiry) |
| Visitor chat history (browser) | Until visitor clears browser data |
| Account information | Until account deletion |
| Scraped product/support data | Until deleted by store owner |
| Usage statistics | 12 months rolling |
5 Cookies and Tracking
VartaFlow does not use cookies. We use browser localStorage for session persistence, which stays within the visitor's browser and can be cleared at any time.
What We Don't Do
- cancel We do not use tracking pixels
- cancel We do not use third-party analytics on the widget
- cancel We do not share visitor data with advertisers
- cancel We do not sell any user data
- cancel We do not track visitors across different websites
6 Data Subject Rights
For Store Owners (Account Holders)
You have the right to:
- Access: Request a copy of your account data
- Correction: Update your account information
- Deletion: Delete your account and all associated data
- Export: Download your bot configurations and scraped data
- Restriction: Disable bots without deleting data
To exercise these rights, contact us at: support@vartaflow.app or call +91 8308888056
For Website Visitors
Since visitor data is stored locally in your browser, you have full control. To clear your data:
- Open browser Developer Tools (F12)
- Go to Application → Local Storage
- Delete items starting with
chatWidget_session_
7 Children's Privacy
VartaFlow is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child under 13, please contact us immediately.
8 International Data Transfers
If you are located outside the regions where our service providers operate, your information may be transferred to and processed in other countries. We ensure appropriate safeguards are in place for such transfers.
9 Store Owner Responsibilities
As a store owner using VartaFlow, you are responsible for:
- arrow_right Informing your website visitors that an AI chat assistant is in use
- arrow_right Including appropriate disclosures in your own privacy policy
- arrow_right Ensuring scraped content does not contain sensitive personal information
- arrow_right Complying with applicable privacy laws (GDPR, CCPA, etc.)
Recommended Disclosure for Your Privacy Policy:
"This website uses VartaFlow, an AI-powered chat assistant. When you interact with the chat widget, your conversation and browsing activity are processed locally in your browser to provide personalized assistance. Chat messages are sent to AI services for response generation."
10 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify account holders of material changes via email. The "Last Updated" date at the top indicates when changes were last made.
11 Contact Us
If you have questions about this Privacy Policy or our data practices:
Response Time: We typically respond within 48 hours.
12 Summary of Key Points
| Question | Answer |
|---|---|
| Do you use cookies? | No, we use localStorage (browser-only) |
| Is visitor data sent to your servers? | Chat messages yes (for AI), browsing data no |
| Who can see my chat history? | Only stored in your browser |
| Does AI learn from my data? | No, our AI providers do not train on customer data |
| Can I delete my data? | Yes, clear browser data or delete account |
| Do you sell data? | No, never |
| Do you share data with advertisers? | No |