1. Scope and Core Roles
1.1. Application. This Privacy Policy ("Policy") governs the processing of personal data by Gruvi Software, Inc., a Delaware corporation (herein referred to as "Gruvi", "we", "us", or "our") via our website, software-as-a-service platform, and our embeddable artificial intelligence-driven communication widgets and messengers (collectively, the "Services").
1.2. Binding Agreement. By accessing or using our Services, you acknowledge that you have read and understood this Policy. This Policy does not apply to the practices of third parties that we do not own or control.
1.3. Relationship of the Parties.
- (a) Gruvi as Controller: We act as a Data Controller for personal data related to our direct business relationship with you, including account management, billing, and usage metadata.
- (b) Gruvi as Processor: When you use our Services to interact with your own customers ("End-Users"), we act as a Data Processor. Our processing of that data is governed by our Data Processing Addendum (DPA).
- (c) Customer Responsibility: You are the Data Controller for End-User data. You are responsible for providing all necessary notices and obtaining all required consents from End-Users.
2. Data Collection Sources
2.1. Information Provided Directly. We collect information you provide directly to us when you register for an account, such as name, email address, physical address, company name, and phone number.
2.2. Third-Party Integrations. If you link our Services to third-party tools or use social media login features, we may receive information from those services (e.g., profile photos, user IDs) in accordance with their specific privacy settings and policies.
2.3. Information from Advertisers and Partners. We may receive information about you from third-party sources, including advertising partners and data enrichment services, to help us better understand our demographics and provide a more personalized experience.
2.4. Automatically Collected Data. We collect technical data when you interact with the Services, including IP addresses, browser types, operating system versions, device identifiers, and clickstream data indicating your navigation patterns through our platform.
3. Widget and Messenger Data Collection
3.1. Collection via the Widget. When an End-User interacts with a Gruvi.ai widget or messenger deployed on a Customer's website or application, we automatically collect data on behalf of the Customer, including unique identifier cookies to track the conversation, full transcripts of the dialogue, IP addresses, approximate geographic location, and interaction timestamps.
3.2. Customer Insight Analytics. If Customer activates the "Customer Insight Analytics" feature, our AI Agents are configured to perform sentiment analysis, conversion tracking, and behavior modeling. These Agents track granular interaction patterns, including dwell time, click paths, and intent classification.
3.3. Disclosure Responsibility. You acknowledge that particular jurisdictions and their applicable laws may require you to inform your End-Users, via a notice on your own website, as to the nature of the personal data collected through the Gruvi.ai Services. You may need to obtain the End-User's prior consent before activating certain tracking or analytics features.
4. Unsolicited Sensitive Information
4.1. Non-Intended Use. The Services and AI Agents are not intended to process "Restricted Data" (as defined in the Master Subscription Agreement), including but not limited to health information, financial account numbers, or government identifiers.
4.2. End-User Input. Customer acknowledges that End-Users may voluntarily provide sensitive personal information within the chat messenger or integrated channels. Customer is strictly prohibited from encouraging, prompting, or requiring End-Users to provide Restricted Data via the Services.
4.3. Customer Responsibility. If an End-User provides unsolicited sensitive information, Customer is the Data Controller for that information. Customer is responsible for implementing its own redaction or deletion protocols and ensuring that its use of AI Agents does not repeat this sensitive information to other users.
4.4. Vendor Disclaimer. Gruvi.ai does not proactively monitor or filter chat transcripts for unsolicited sensitive information. Gruvi.ai disclaims all liability for any Restricted Data submitted by End-Users to the Services in violation of this Policy and the Master Subscription Agreement.
5. Third-Party Messaging Channels
5.1. External Integrations. If Customer integrates the Services with third-party messaging platforms (e.g., WhatsApp Business, Telegram API, or Facebook Messenger), Customer acknowledges that these platforms are independent data controllers.
5.2. Compliance Burden and Control. Customer is solely responsible for complying with the terms and privacy requirements of these platforms. Each platform, including Meta, runs its own service and decides how it retains and processes data on its own systems, and Gruvi does not control that. Gruvi does control the data it receives and stores through these channels: we act as a Data Processor for it, as described in Section 1.3, and we retain, use and delete it as set out in this Policy and in our Data Processing Addendum.
6. Data from WhatsApp and Meta
6.1. What We Receive. When a business connects its WhatsApp Business account to Gruvi, we receive and store the following through the WhatsApp Business Platform: the WhatsApp Business account identifier and phone number identifiers, the access key for that account (which we store encrypted), and, for each conversation, the customer's WhatsApp phone number, WhatsApp profile name, messages and media, and delivery and read receipts.
6.2. How We Use It. We use this data only to show the conversations as threads in the business's inbox, to send the replies and message templates that the business sends, and, where the business turns on AI agents, to let our AI service providers draft or send replies on that business's behalf.
6.3. What We Never Do. We do not sell this data, we do not use it for advertising or ad targeting, and we do not share it with anyone other than the service providers we need to run Gruvi, such as hosting, storage and AI model providers. Section 2.3 (Information from Advertisers and Partners) and Section 7.2 (Analytics and Advertising) never apply to data received from WhatsApp or Meta.
6.4. WhatsApp Notifications for Gruvi Users. If a Gruvi user links WhatsApp to receive alerts from Gruvi, we store that user's WhatsApp phone number and profile name, and we use them only to send the alerts that user has chosen. The user can stop the alerts at any time by replying STOP to any of them, or by unlinking WhatsApp in notification settings.
6.5. Deletion. To stop new data reaching us, or to delete what we already hold, see Section 13 (How to delete your data).
7. Tracking Technologies
7.1. Essential Cookies. We use cookies strictly necessary for the operation of the Services, such as session identifier cookies required for the chat widget to maintain conversation history across page refreshes.
7.2. Analytics and Advertising. We and our third-party partners may use cookies, pixels, and web beacons to track activity across different websites to deliver targeted advertisements.
7.3. Customer Compliance. You are solely responsible for disclosing the Gruvi.ai widget and any associated tracking pixels in your own Cookie Policy. You must ensure your cookie banner allows End-Users to opt-out where required by applicable regulations.
7.4. Product Analytics (Microsoft Clarity). If you join our improvement program, we use Microsoft Clarity, a service from Microsoft Corporation, to see how you use the Gruvi web app so we can find problems and improve it. Clarity records your sessions in the app: the pages you open, clicks, scrolls, mouse movements, and technical details such as your device, browser, and approximate location. Message content shown in the app is masked and is not recorded. We link these recordings to your Gruvi account using your user ID and email address. Clarity sets first-party cookies (_clck and _clsk), and Microsoft may set its own cookies, such as MUID. Our legal basis is your consent. You can withdraw it at any time in your account settings, which stops future recordings. Clarity keeps session recordings for 30 days, and usage data and saved recordings for up to 9 months. Microsoft's use of this data is described in the Microsoft Privacy Statement.
8. Information Usage and Optimization
8.1. Operations. We use collected information to provide, maintain, and support the platform and AI Agents.
8.2. Optimization. We use de-identified and aggregated data to monitor the performance of our AI workflows. We do not use Customer Data to train third-party global models in a manner that exposes your proprietary data or personally identifiable information.
9. Information Sharing and Disclosure
9.1. Sub-processors. We share data with trusted third-party service providers only as necessary to provide the Services.
9.2. Law Enforcement. We may disclose personal data to law enforcement, government agencies, or authorized third parties if required by applicable law, including United States federal or state law, or a valid court order or subpoena.
9.3. Business Transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred as a business asset.
10. International Transfers
10.1. Global Infrastructure. Gruvi is established in the United States, and your data may be processed there and in any other country where Gruvi or its Sub-processors maintain facilities. For transfers of personal data from the EEA, the UK or Switzerland to countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum.
11. Security and Best Efforts
11.1. Technical Measures. Gruvi employs commercially reasonable technical and organizational measures designed to protect data.
11.2. Liability Limitations. Customer acknowledges that Gruvi provides the Services on a "Best Efforts" security basis and does not currently maintain SOC 2 or ISO 27001 certifications. Use of the Services is at the Customer's sole risk.
12. Retention and Deletion
12.1. Retention. We retain personal data for as long as necessary to fulfill the purposes outlined in this Policy, or as required by the Agreement.
12.2. Account Delinquency. Notwithstanding any other provision, if an account remains in a state of non-payment or unaddressed overage for six (6) months, Gruvi will permanently and irreversibly delete all associated data. Customer waives any claim for damages related to deletion under this provision.
13. How to delete your data
13.1. Open to Everyone. Anyone can ask us to delete the data we hold about them. This section is not limited to residents of the EEA, the UK or California.
13.2. Businesses Using Gruvi. To stop new data reaching us, disconnect WhatsApp in your Gruvi settings. To delete the data we already hold for your WhatsApp Business account, email legal@gruvi.ai from the address on your account. We delete it within 30 days.
13.3. Customers of a Business Using Gruvi. If you messaged a business through WhatsApp and want your data deleted, ask that business. The business decides what happens to its conversations, and we delete the data on its instruction.
13.4. Gruvi Users with WhatsApp Notifications. Unlink WhatsApp in your notification settings, or email legal@gruvi.ai, and we delete the phone number and profile name we stored for those alerts.
14. Children's Privacy
14.1. Minimum Age. Our Services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take immediate steps to delete it.
15. Data Subject Rights (EU and UK GDPR)
15.1. Rights. If you are in the EEA or the UK, you have the right to access, rectify, or erase your data, to object to or restrict processing, and to data portability. To exercise these rights, email legal@gruvi.ai. You also have the right to lodge a complaint with your local supervisory authority. To delete data we hold, see Section 13 (How to delete your data).
16. California and US State Rights
16.1. CCPA. If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect and how we use it, to request its deletion or correction, and to be free from discrimination for exercising those rights. We do not "sell" or "share" personal information for cross-context behavioral advertising. Residents of other US states with comparable privacy laws have similar rights. To exercise them, email legal@gruvi.ai. To delete data we hold, see Section 13 (How to delete your data).
17. Contact Information
Email: legal@gruvi.ai
Address: Gruvi Software, Inc., 2810 N Church St STE 90490, Wilmington, DE 19802, United States