Solvias
Privacy Policy

Privacy at Solvias.

How we collect, use, and protect data — for our customers and the customers they serve. Operated by AB Collection LLC.

EFFECTIVE · JUNE 11, 2026·VERSION 1.1
01

Introduction

AB Collection LLC ("we", "us", "our") operates Solvias, an AI-assisted customer support platform for ecommerce businesses ("Service"). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have in relation to it.

By using Solvias you agree to the practices described in this policy. If you do not agree, do not use the Service.

02

Who This Policy Covers

This policy applies to two groups of people:

  • Store owners / team members — ecommerce brand owners and their staff who create a Solvias account, connect integrations, and manage support tickets ("Users"). Users are the data controllers for End Customer data processed through their connected mailboxes; AB Collection LLC acts as a data processor with respect to that End Customer data.
  • End Customers — individuals who send emails to a store's support address and whose email content is processed by Solvias on behalf of the store owner who controls that mailbox ("End Customers"). End Customers do not have a Solvias account and do not have a direct contractual relationship with AB Collection LLC.

For data Users provide to us directly (account information, integration credentials, billing data, usage of the Solvias dashboard), AB Collection LLC is the data controller.

03

Data We Collect

Account and Profile Data

When you register for Solvias we collect:

  • Full name and email address
  • Password (stored as a scrypt hash — we never store plaintext passwords)
  • Two-factor authentication secret and backup codes, when 2FA is enabled (stored encrypted)
  • Organisation / store name

Store Integration Data

When you connect third-party services we collect the credentials and tokens necessary to access those services on your behalf:

IntegrationData collected
GmailOAuth 2.0 refresh token (AES-256-GCM encrypted at rest); Gmail history ID for change polling; the email messages described below
Outlook (Microsoft Graph)OAuth 2.0 refresh token and short-lived access token (both AES-256-GCM encrypted at rest); delta link for change polling; the email messages described below
IMAP / SMTPServer hostname, port, username, and password (password AES-256-GCM encrypted at rest); the email messages described below
ShopifyStore domain; API client ID and secret (encrypted at rest)
ParcelPanelAPI key (encrypted at rest)

Mailbox Data (Sensitive and Restricted Scopes)

Gmail

Solvias accesses your Gmail mailbox using two scopes:

ScopeWhat is accessed
gmail.readonlyEmail message metadata (sender address, recipient address, subject line, date, thread ID, message ID) and message body content of inbound emails received at the connected mailbox
gmail.sendThe ability to send a reply email on your behalf using the connected mailbox's address

Scope of access in practice. Although the gmail.readonly scope grants technical access to all messages in the connected mailbox, our application code only reads messages that arrive in the connected mailbox's primary inbox after the connection date, and only for the purpose of creating support tickets. We do not index, search, retrieve, or expose historical messages, archived messages, sent items, drafts, or other Gmail folders or labels. We strongly recommend connecting a dedicated support mailbox (e.g., support@yourstore.com) rather than a personal mailbox to ensure clear separation between support correspondence and personal email.

Outlook

Solvias accesses Outlook mailboxes using Microsoft Graph with the Mail.Read, Mail.Send, offline_access, and User.Read scopes. The same per-mailbox, post-connection, primary-inbox-only access discipline described for Gmail applies.

IMAP / SMTP

Solvias connects to your IMAP server with read-only credentials for inbound polling and to your SMTP server for sending replies. The same per-mailbox, post-connection access discipline applies.

Specifically, for any connected mailbox we read and process:

  • Inbound email subject lines and body text (plain text and HTML)
  • Sender name and email address
  • Provider-specific thread IDs and message IDs (used to associate messages with support tickets and to send replies into the correct thread)
  • Email attachment metadata (file name, content type, size) and attachment files where present

Support Ticket and Message Data

When an inbound customer email arrives, Solvias creates a support ticket. We store:

  • The full email content (subject, body, sender) associated with that ticket
  • AI-generated draft replies and the final sent reply
  • Agent actions (draft approval, edits, manual replies)
  • Attachments uploaded to object storage (Vercel Blob on legacy infrastructure, Amazon S3 on AWS-hosted stages)

Order and Tracking Data

When a ticket is related to an order (shipping, return, etc.) we fetch and temporarily store:

  • Shopify order data: order number, items, fulfilment status, customer name and address
  • ParcelPanel tracking data: carrier, tracking number, delivery status events

This data is fetched in real time per ticket and stored alongside the ticket for support purposes.

Usage and Log Data

We collect:

  • Activity logs (who approved a draft, who sent a reply, AI mode changes)
  • AI token usage logs: model used, token counts, action type (classify / generate / refine)
  • AI generation audit logs: the system prompt used, the customer email, the AI response, confidence score, and which knowledge-base articles were referenced
  • Security audit events: sign-in success and failure, password change, 2FA enrollment, OAuth connect/disconnect, authorization denials

These logs are used for billing, debugging, auditability, and security incident response.

Technical Data

Standard server and application logs: IP address, browser type, pages visited, timestamps. Used for security monitoring and debugging. Personally identifiable email addresses appearing in operational console logs are redacted at write time.

04

How We Use Your Data

Core Service Delivery

We use the data described in section 3 to:

  • Operate the support ticketing inbox — create tickets from inbound emails, display them in the Solvias dashboard
  • Generate AI-assisted draft replies using the email content, order context, and your store's knowledge base
  • Send approved replies on your behalf via the connected mailbox provider (gmail.send for Gmail, Mail.Send for Outlook, SMTP for IMAP/SMTP) so the reply appears in the customer's existing email thread from your store's support address
  • Fetch Shopify order data and ParcelPanel tracking data to enrich relevant tickets
  • Log activity and AI usage for your own auditing and billing purposes

AI Processing of Mailbox Data

Solvias passes the text content of inbound customer emails to the Anthropic Claude API for two purposes:

  • Classification — identifying the ticket category (e.g., shipping inquiry, return request) and extracting an order number if present
  • Draft generation — producing a suggested reply based on the email, order context, and your store's knowledge base and instructions

This processing is performed in real time, on a per-ticket basis, solely to produce a reply for the authenticated store account that owns that email thread.

Anthropic data handling. Under Anthropic's commercial terms applicable to the Claude API, Anthropic does not use API inputs or outputs to train or improve its models. Anthropic retains API inputs and outputs for up to 30 days for Trust & Safety and abuse-monitoring purposes, after which the data is automatically deleted from Anthropic's systems. Anthropic acts as our sub-processor under a data processing agreement and is not permitted to use this data for any purpose other than providing the Claude API service to us.

Mailbox message content is never used to train, fine-tune, or improve any AI or machine learning model — whether our own, Anthropic's, or any other third party's.

Service Improvement

We may use aggregated, de-identified usage statistics (counts, durations, error rates — never linked to individual email content or identifiable users) to improve the platform.

Legal and Safety

We may use or disclose data where required by law, court order, or to protect the rights, property, or safety of AB Collection LLC, our users, or others.

05

How We Share Your Data

We do not sell your data. We do not transfer mailbox data to advertising platforms, data brokers, or information resellers. We share data only in the following circumstances:

Sub-processors

We share data with the following service providers who process data strictly on our behalf, under data processing agreements, and solely for the purpose of delivering the Service:

Sub-processorPurposeData sharedRegion
Amazon Web Services, Inc.Primary hosting (Lambda compute, Aurora PostgreSQL, S3 object storage, CloudFront CDN, Secrets Manager, EventBridge schedules)All Solvias-stored data, encrypted at resteu-central-1 (Frankfurt, Germany)
Anthropic, PBC (Claude API)AI classification and draft generationEmail body text, order context, knowledge-base contentUnited States
Vercel, Inc.Hosting (legacy production environment) and Blob Storage (legacy attachments until AWS cutover)Application traffic; encrypted credentials via environment variablesUnited States
Neon, Inc. (PostgreSQL)Local development database and legacy production database (being migrated to Aurora)All structured data including email message recordsUnited States
Stripe, Inc.Subscription billing and payment processingOrganisation name, billing email, country, tax ID, Stripe-tokenized payment method; ticket-usage counters for metered billingUnited States
Upstash, Inc. (Redis)Short-lived caching of poll state and rate-limit countersGmail / Outlook poll cursor (history ID, delta link); no email contentGlobal edge
ResendTransactional email (account invitations, password reset, deletion confirmations)User email addresses; no mailbox-derived contentUnited States
ParcelPanel Technology LimitedShipment tracking lookups for order-related ticketsOrder tracking IDs only; no mailbox-derived contentHong Kong / Cloudflare
Microsoft CorporationMicrosoft Graph API for Outlook mailbox integration (only when a store owner connects an Outlook inbox)OAuth refresh token (encrypted at rest); message metadata fetched per pollMultiple, depending on user's Microsoft tenant
Functional Software, Inc. (Sentry)Error tracking and runtime observabilitySanitized error events; no email bodies, no AI prompts (server-side PII scrubber strips payloads before send)United States
Google LLCOAuth provider for store owners who sign in with Google or connect a Gmail mailboxAuthentication tokens (encrypted at rest); Gmail data per Section 3Multiple

Each sub-processor is contractually obligated to maintain confidentiality and security standards consistent with this policy and is prohibited from using data received from us for any purpose other than providing their services to us. A current list of sub-processors and signed Data Processing Agreements is available on request to privacy@solvias.io.

Legal Requirements

We may disclose data if required to do so by law or in response to valid legal process.

Business Transfer

If AB Collection LLC is involved in a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will notify affected users before data is transferred and becomes subject to a different privacy policy.

06

Google API Services — Limited Use

The use of information received from Google Workspace APIs (including data obtained via gmail.readonly and gmail.send) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In compliance with Google's Limited Use requirements, Solvias affirms that Gmail user data:

  • Is used only to provide the customer support ticketing features described in this policy and visible to the authenticated user who authorised access
  • Is not transferred, sold, or used to serve advertisements — including personalised, interest-based, or retargeted advertising
  • Is not transferred or sold to third parties, except to the sub-processors listed in Section 5, who process data on our behalf under data processing agreements solely for the purpose of delivering the Service
  • Is not used to determine creditworthiness or for lending purposes
  • Is not used to build permanent profiles beyond what is necessary to operate the support inbox for the authenticated account
  • Is not used to train, fine-tune, or improve any generalised AI or machine learning model — whether our own systems, Anthropic's models, or any other third-party model
  • Is passed to the Anthropic Claude API solely for real-time, per-ticket response generation for the account that authorised access; this is a user-directed processing action equivalent to the user pasting an email into a tool to draft a reply, and does not constitute training data use
  • Is subject to human access only where the user who authorised access explicitly requests support, where we believe in good faith that human access is necessary for security incidents or legal obligations, or where required by law — and only to the minimum necessary extent
07

Data Retention

Active Accounts

While your Solvias account is active, we retain data as follows. Retention windows below are enforced by an automated nightly job at 04:00 UTC.

Data typeRetention period
Email message PII fields (plain-text and HTML body, subject line, sender and recipient email addresses, AI draft, conversation summary)90 days, then every PII field is cleared to NULL. Only the immutable ticket linkage, internal message ID, direction, and timestamps survive past 90 days.
Email attachments stored in object storage (Vercel Blob / Amazon S3)90 days, deleted in bulk from the underlying object store before the message row is cleared, so no orphaned blobs remain
AI generation logs (LLM prompt + response, used for quality monitoring)180 days from creation
AI token usage logs (LLM token-usage records, used for billing meter input)90 days from creation
Activity logs (agent actions, AI mode changes, member-management events)365 days from creation
Historical inbox import (one-time import of pre-existing inbox history at onboarding)365 days from import
Security and authentication audit log (security_events)Retained indefinitely as a permanent audit record, excluded from the nightly purge — required to support breach investigations and dispute resolution
OAuth refresh tokens (Gmail, Outlook)Deleted immediately upon mailbox disconnection
IMAP/SMTP credentials, Shopify credentials, ParcelPanel API keysDeleted immediately upon integration disconnection

Every purge run — successful or failed — is recorded to an internal data_retention_purges audit table including the target dataset, retention window applied, cutoff timestamp, rows affected, and execution duration. This provides a complete history of retention enforcement available on regulator request.

Users may request earlier deletion of any of the above at any time by emailing privacy@solvias.io.

Account Deletion

When you request deletion of your Solvias account, the request enters a 7-day grace window. During the grace window:

  • You can cancel the deletion via the link in the confirmation email or by signing back in.
  • The app remains read-only for your account; auto-respond is paused; billing is paused.

After 7 days the nightly delete-accounts job runs the deletion. For every organisation where you are the sole owner, the job — before the database cascade runs — calls Google's OAuth revocation endpoint to terminate the Gmail grant on Google's side, deletes the Stripe customer record and cancels the subscription immediately (which cascades through payment methods and tax IDs on the Stripe side), and purges every blob/S3 attachment referenced by the organisation's messages. The database delete then cascades through every store, satellite credential (Gmail, Outlook, IMAP/SMTP, Shopify, ParcelPanel), ticket, message, AI log, email template, and funnel configuration. For organisations where you are one of several owners, only your own membership is removed; the organisation continues under the remaining owners.

Microsoft does not expose a programmatic refresh-token revocation endpoint for personal accounts; the encrypted Outlook refresh token is deleted from our store at the same step, and the grant naturally expires per your Microsoft account settings.

The data deletion timeline is therefore:

Data typeDeletion timeline (from initial request)
Cancellation window during which deletion can be reversed7 days
OAuth refresh tokens (Gmail, Outlook), IMAP/SMTP credentials, Shopify credentials, ParcelPanel API keysWithin 7 days (deleted as part of the cascade at the end of the grace window)
Stripe subscription cancelled and customer deleted (for sole-owned organisations)Within 7 days
Email message content (ticket messages), attachments, AI generation logs, account profile, activity logsWithin 7 days (organisation cascade)
2FA secrets and backup codesWithin 7 days
Better Auth user row, sessionsWithin 7 days

We retain de-identified, aggregated statistics (counts of tickets processed, total token usage) that cannot be linked back to you or your End Customers.

We may retain limited records longer where strictly necessary to comply with legal obligations, resolve disputes, or enforce our agreements; in such cases, only the minimum necessary records are retained, and Gmail-derived content is excluded from any such retention.

08

Data Security

We implement the following technical and organisational measures to protect your data:

  • Encryption in transit — All connections between your browser, our servers, and third-party APIs use TLS 1.2 or higher. HSTS is enforced (max-age=63072000; includeSubDomains; preload).
  • Encryption at rest — OAuth tokens, API keys, and other secrets stored in our database are encrypted using AES-256-GCM with a 32-byte key held in a separate environment secret. Aurora itself is also encrypted at the cluster level using an AWS-managed KMS key. Amazon S3 buckets use SSE-S3 (AES-256) at rest. Solvias supports an ENCRYPTION_KEY_V<n> versioned scheme to enable key rotation without re-encrypting the entire database in a single operation.
  • Access controls — Multi-tenant architecture: each store's data is scoped to that store's account. Cross-tenant access is prevented at the application route layer (withStoreAccess, withOrgMemberAccess) and verified independently at the database query level.
  • Least-privilege API access — We request only the OAuth scopes required for the described features. We do not request write access beyond gmail.send / Mail.Send.
  • Audit logging — All AI actions, draft approvals, sent replies, sign-in events, and authorization denials are logged with timestamps and user identifiers in dedicated audit tables.
  • No plaintext secrets — Credentials are never logged in plaintext; runtime logs are sanitised at write time (email addresses are redacted; subjects and bodies are not emitted to console).
  • Vulnerability disclosure — We accept security reports at security@solvias.io and aim to acknowledge within 5 business days.
09

Your Rights

Rights Applicable to All Users

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your account and associated data (deletion timelines are listed in section 7)
  • Data portability — request an export of your data in a machine-readable format
  • Objection / restriction — object to or request restriction of certain processing

To exercise these rights, email us at privacy@solvias.io.

Revoking Mailbox Access

You can disconnect Solvias from your mailbox at any time:

  • In Solvias: go to Store Settings → Integrations and click Disconnect.
  • Alternatively for Gmail: visit myaccount.google.com/permissions, find Solvias, and click Remove Access.
  • Alternatively for Outlook: visit account.live.com/consent/Manage, find Solvias, and click Remove these permissions.

Upon disconnection, Solvias calls the identity provider's revocation endpoint (where available — Google supports this; Microsoft does not expose a programmatic revoke for personal accounts) and deletes the stored encrypted refresh token from our database in the same step. Existing ticket message records follow the active-account retention schedule in section 7. To request immediate deletion of all mailbox-derived data without deleting your account, email privacy@solvias.io.

End Customer Rights

End Customers (individuals who emailed a store's support address) who wish to exercise data rights regarding their personal data should contact the store owner directly, since the store owner is the data controller for that data. We will support store owners in fulfilling such requests. End Customers may also contact us at privacy@solvias.io and we will route the request appropriately.

California Residents (CCPA/CPRA)

California residents have the right to:

  • Know what personal information is collected, disclosed, or sold
  • Delete personal information (subject to legal exceptions)
  • Opt out of the sale or sharing of personal information — we do not sell or share personal information
  • Non-discrimination for exercising these rights

To submit a verifiable consumer request, email privacy@solvias.io from the email address associated with your account.

European / UK Residents (GDPR / UK GDPR)

If you are located in the European Economic Area or the United Kingdom, your personal data is processed on the following legal bases:

  • Contract performance — processing necessary to deliver the Service you signed up for
  • Legitimate interests — security monitoring, fraud prevention, aggregate analytics
  • Legal obligation — where required by law

You have the right to lodge a complaint with your local supervisory authority.

10

International Data Transfers

AB Collection LLC is based in the United States. Solvias's primary infrastructure runs in eu-central-1 (Frankfurt, Germany) on Amazon Web Services. Some sub-processors (Anthropic, Stripe, Resend, Vercel, Sentry) process data in the United States. Transfers to those processors rely on Standard Contractual Clauses (SCCs) signed in each Data Processing Agreement and, where applicable, adequacy decisions. A list of which sub-processors operate under SCCs is available on request to privacy@solvias.io.

11

Children's Privacy

Solvias is not directed at children under the age of 13. We do not knowingly collect personal data from children. End Customer emails received via connected mailboxes are processed under the store owner's existing relationship with that End Customer; we do not collect End Customer ages, do not direct support communications at children, and rely on the store owner to comply with applicable child-protection laws (such as COPPA) in their relationship with their customers. If you believe we have inadvertently collected data from a child, contact us at privacy@solvias.io and we will delete it promptly.

12

Third-Party Links

The Service may contain links to third-party websites (e.g., Shopify, Gmail). This policy does not cover third-party sites. We encourage you to read the privacy policies of any site you visit.

13

Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and update the "Last updated" date at the top of this document. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14

Contact Us

If you have questions, requests, or complaints about this privacy policy or our data practices:

AB Collection LLC — Attn: Privacy — 15442 Ventura Blvd. Ste 201-2072, Sherman Oaks, California 91403, United States of America

PurposeEmail
Privacy rights and complaints (GDPR / CCPA / general privacy questions)privacy@solvias.io
Security disclosures and vulnerability reportssecurity@solvias.io
General business inquiries, DPA requests, signed-copy requestsinfo@solvias.io

We aim to respond to all privacy requests within 30 days.

Need a signed copy or a DPA?
Email info@solvias.io and we'll turn it around within 2 business days.
Contact legal