Legal · last updated August 22, 2026

Privacy Policy

How we look after personal data when you use datavessel — yours and your clients’ — and your rights under the law.

01

Introduction

datavessel ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website and use the datavessel operations center, and tell you about your privacy rights and how the law protects you.

datavessel is used by businesses that run one or more e-commerce stores, including agencies that run stores on behalf of clients. For data inside a connected store (orders, customers, products), the business that owns the store is the controller and datavessel acts as a processor on the instructions of the account that connected it.

02

Information We Collect

Personal Data

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • 01Identity Data includes first name, last name, username or similar identifier.
  • 02Contact Data includes email address and telephone numbers.
  • 03Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • 04Usage Data includes information about how you use our website and services.
  • 05Operational Data includes the stores and sources you connect, the policies you define, agent runs and their transcripts, proposed and approved actions, and the ledger of actions performed — scoped to the store each belongs to.

Store data

When you connect a Shopify, WooCommerce or Shopware store, we access the data needed for the policies and agents you enable on that store — orders, products, inventory, customers, fulfilments, refunds and related events — through the platform's API with the scopes you grant. We read this data to evaluate policies and to let agents propose actions, and we write to the store only for actions you approved or enabled under a policy. We keep the minimum needed for the ledger and for the transcript of each run.

Google User Data

When you connect a Google account to datavessel, you grant us access to specific data from Google services via Google's official OAuth flow. We request only the OAuth scopes listed below, and only the data they cover is collected.

  • Google Search Console (webmasters.readonly): verified site list, search analytics (queries, pages, impressions, clicks, CTR, average position), URL inspection results, sitemap lists and details, and performance breakdowns by country and device.
  • Google Analytics 4 (analytics.readonly): account and property summaries, custom dimensions and metrics, standard and real-time reports for the properties you select, and Google Ads link information.
  • Google Ads (adwords): accessible customer accounts, campaign, ad-group, and keyword performance metrics, and search terms reports for the accounts you select.
  • Google Merchant Center (content): accessible Merchant Center accounts, product performance reports (impressions, clicks, conversions and conversion value per product), price benchmarks, and product listing status and issues for the accounts you select. Where you ask an agent to act, we write product overrides, regional or local inventory and promotions through the Merchant API — each such change is approval-gated in datavessel and never rewrites your own feed file.
  • Google account profile (openid email profile): your email address and basic profile information to create and identify your datavessel account.

We do not access any Google data outside the scopes listed above. You can revoke datavessel's access at any time from your Google account permissions page or by disconnecting the source inside datavessel.

Meta (Facebook) advertising data

When you connect a Meta account via Facebook Login, we request the ads_read, ads_management and business_management permissions and access only the data they cover: the Business Portfolios you belong to and the ad accounts they own (so you can choose which account to connect), and for the ad accounts you connect, campaign, ad-set and ad structure, status, budgets, and performance insights such as impressions, clicks, spend, conversions and ROAS.

This data is shown in your workspace and analyzed by the agents you configure. Management actions are limited to pausing or resuming a campaign, ad set or ad, and updating daily budgets (capped server-side) — each executed only after your explicit approval in datavessel or as a direct command you issue yourself. We never create or delete ads, campaigns or audiences and never change targeting or creative. Meta advertising data is never sold, never used to train machine-learning models, never used by us for advertising or profiling, and is shared only with the sub-processors listed below at your direction. You can revoke access at any time by disconnecting Meta inside datavessel or by removing the app under Facebook Business Integrations settings. Our use of Meta data complies with the Meta Platform Terms and Developer Policies.

How we use Google user data

Google user data is used exclusively to provide and improve the features you have asked datavessel to perform on your behalf. Specifically:

  • To evaluate the policies you configured and to let the agents you deployed propose actions — for example pausing an ad group that points at a sold-out product, or compiling a weekly SEO audit — by retrieving the relevant Google data and passing it, with the task, to your selected LLM provider.
  • To run scheduled agents and event-driven policies that you have explicitly configured on a store.
  • To populate dashboards, reports, and the public citations page if you have opted to make your report public.

We do not use Google user data or Meta advertising data to train, fine-tune, or develop machine-learning models, including any models operated by us or by third parties. We do not use it for advertising, ad personalization, or profiling. We do not sell Google user data or Meta advertising data under any circumstances.

Sub-processors that may receive Google user data

To deliver the AI features you request, datavessel transmits Google user data to the following sub-processors at your direction. Each request is initiated by your explicit configuration (a policy you enabled, an agent you deployed, a schedule you set, or an action you approved).

  • LLM providers you select inside datavessel: Anthropic (Claude), OpenAI (ChatGPT), and Google (Gemini). Data sent is limited to what the specific agent step requires.
  • Google Cloud Platform: hosts datavessel's backend, database (PostgreSQL), and attachment storage (Google Cloud Storage). Data is stored in the EU region (europe-west3).
  • Lemon Squeezy: handles subscription billing. Does not receive Google user data — only your email and subscription metadata.
  • Slack and email (optional): if a policy includes a notify step, datavessel posts the message you configured to the channel or address you specified. Only the contents of that notification are sent.

LLM API Keys

datavessel operates on a Bring Your Own Keys (BYOK) model for the LLM providers above. You provide your own API keys (Anthropic, OpenAI, Google). Your API keys are encrypted at rest using AES-256 and are only decrypted at the moment a request is made to the corresponding provider on your behalf. We never share your API keys with third parties and they are not used for any purpose other than executing your requested AI operations.

03

We do not sell your data

We do not sell your personal data, Google user data, or Meta advertising data under any circumstances. The only third parties that receive your data are the sub-processors listed above (LLM providers, cloud hosting, billing, optional Slack), and they receive only the minimum data required to fulfil the specific action you took. Your data is never disclosed to other customers and is not used for advertising or profiling.

Isolation between customers and between stores

Every account's stores, connectors, policies, agent runs and ledger are scoped to that account. Within an account, each store is a separate scope: a policy, agent or run belongs to exactly one store, and data from one client store is never used to act on another. Agencies acting on behalf of clients remain responsible for having the authority to connect each client's store.

04

Service improvement and agent quality

datavessel learns what “good” looks like from your decisions. To improve the accuracy of policy suggestions and agent proposals, we may use operational signals you generate inside the product — for example whether a proposed action was approved, denied or edited, which policy conditions were chosen, and aggregate outcome statistics — to evaluate, tune and improve our agents and suggestion models.

  • Such use is limited to data that has been pseudonymised and stripped of customer names, email addresses, order contents, credentials and any Google user data. Google user data is never used for this purpose (see below).
  • The raw content processed by the LLM provider you selected is governed by that provider's terms under your own API key; we do not forward it to any other model provider.
  • You can opt out of service-improvement use for your account at any time by contacting us; opting out does not affect the service you receive.
  • Improved models and suggestions are provided back to all customers; your data is never disclosed to another customer.
05

How We Use Your Information

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • To provide and maintain our service
  • To communicate with you about our service
  • To improve our website and service
  • To comply with legal obligations
06

Data Security

We have put in place appropriate technical and organisational measures to prevent your personal data and Google user data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed.

  • All data in transit between your browser, datavessel, and any sub-processor is encrypted using TLS 1.2 or higher.
  • Google user data, OAuth tokens, and LLM API keys are encrypted at rest in our database using AES-256.
  • Access to production systems is limited to a small number of named operators and requires multi-factor authentication.
  • Production data is hosted on Google Cloud Platform in the EU (europe-west3) region.
07

Data Retention and Deletion

We retain only what we need to keep the product working for you, with clear ceilings:

  • OAuth tokens are deleted immediately when you disconnect a source or revoke access from your Google account.
  • Cached Google user data (query results, report snapshots, scan history) is retained while the source is connected so you can see historical trends, and is deleted within 30 days after you disconnect the source.
  • Run transcripts and attachments are retained with their ledger row while the account exists, so the audit record stays complete; attachments you upload are deleted after 90 days or when you delete them.
  • Disconnecting a store revokes our access immediately; cached store data is deleted within 30 days, while the ledger rows for actions already performed are kept as part of your audit record until you delete the account.
  • Account deletion: when you delete your datavessel account, your personal data and all associated Google user data are permanently removed within 30 days. We may retain minimal records (e.g., invoices) where required by law.
  • Manual deletion at any time: visit our account deletion page for the two paths (in-app self-service if you can sign in, email if you can't) and the SLA. Manual email requests to contact@datavessel.io are actioned within 30 days.
08

Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data:

Request access

to your personal data

Request correction

of your personal data

Request erasure

of your personal data

Object to processing

of your personal data

Request restriction

of processing your personal data

Request transfer

of your personal data

Right to withdraw

consent at any time

09

Compliance with Google API Services User Data Policy

datavessel's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10

Contact Us

If you have any questions about this privacy policy or our privacy practices, please contact us at contact@datavessel.io.