Introduction
AB Collection LLC ("we", "us", "our") operates Solvias, an AI-assisted customer support platform for ecommerce businesses ("Service"). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have in relation to it.
By using Solvias you agree to the practices described in this policy. If you do not agree, do not use the Service.
Who This Policy Covers
This policy applies to two groups of people:
- Store owners / team members — ecommerce brand owners and their staff who create a Solvias account, connect integrations, and manage support tickets ("Users"). Users are the data controllers for End Customer data processed through their connected mailboxes; AB Collection LLC acts as a data processor with respect to that End Customer data.
- End Customers — individuals who send emails to a store's support address and whose email content is processed by Solvias on behalf of the store owner who controls that mailbox ("End Customers"). End Customers do not have a Solvias account and do not have a direct contractual relationship with AB Collection LLC.
For data Users provide to us directly (account information, integration credentials, billing data, usage of the Solvias dashboard), AB Collection LLC is the data controller.
Data We Collect
Account and Profile Data
When you register for Solvias we collect:
- Full name and email address
- Password (stored as a scrypt hash — we never store plaintext passwords)
- Two-factor authentication secret and backup codes, when 2FA is enabled (stored encrypted)
- Organisation / store name
Store Integration Data
When you connect third-party services we collect the credentials and tokens necessary to access those services on your behalf:
| Integration | Data collected |
|---|---|
| Gmail | OAuth 2.0 refresh token (AES-256-GCM encrypted at rest); Gmail history ID for change polling; the email messages described below |
| Outlook (Microsoft Graph) | OAuth 2.0 refresh token and short-lived access token (both AES-256-GCM encrypted at rest); delta link for change polling; the email messages described below |
| IMAP / SMTP | Server hostname, port, username, and password (password AES-256-GCM encrypted at rest); the email messages described below |
| Shopify | Store domain; API client ID and secret (encrypted at rest) |
| ParcelPanel | API key (encrypted at rest) |
Mailbox Data (Sensitive and Restricted Scopes)
Gmail
Solvias accesses your Gmail mailbox using two scopes:
| Scope | What is accessed |
|---|---|
| gmail.readonly | Email message metadata (sender address, recipient address, subject line, date, thread ID, message ID) and message body content of inbound emails received at the connected mailbox |
| gmail.send | The ability to send a reply email on your behalf using the connected mailbox's address |
Scope of access in practice. Although the gmail.readonly scope grants technical access to all messages in the connected mailbox, our application code only reads messages that arrive in the connected mailbox's primary inbox after the connection date, and only for the purpose of creating support tickets. We do not index, search, retrieve, or expose historical messages, archived messages, sent items, drafts, or other Gmail folders or labels. We strongly recommend connecting a dedicated support mailbox (e.g., support@yourstore.com) rather than a personal mailbox to ensure clear separation between support correspondence and personal email.
Outlook
Solvias accesses Outlook mailboxes using Microsoft Graph with the Mail.Read, Mail.Send, offline_access, and User.Read scopes. The same per-mailbox, post-connection, primary-inbox-only access discipline described for Gmail applies.
IMAP / SMTP
Solvias connects to your IMAP server with read-only credentials for inbound polling and to your SMTP server for sending replies. The same per-mailbox, post-connection access discipline applies.
Specifically, for any connected mailbox we read and process:
- Inbound email subject lines and body text (plain text and HTML)
- Sender name and email address
- Provider-specific thread IDs and message IDs (used to associate messages with support tickets and to send replies into the correct thread)
- Email attachment metadata (file name, content type, size) and attachment files where present
Support Ticket and Message Data
When an inbound customer email arrives, Solvias creates a support ticket. We store:
- The full email content (subject, body, sender) associated with that ticket
- AI-generated draft replies and the final sent reply
- Agent actions (draft approval, edits, manual replies)
- Attachments uploaded to object storage (Vercel Blob on legacy infrastructure, Amazon S3 on AWS-hosted stages)
Order and Tracking Data
When a ticket is related to an order (shipping, return, etc.) we fetch and temporarily store:
- Shopify order data: order number, items, fulfilment status, customer name and address
- ParcelPanel tracking data: carrier, tracking number, delivery status events
This data is fetched in real time per ticket and stored alongside the ticket for support purposes.
Usage and Log Data
We collect:
- Activity logs (who approved a draft, who sent a reply, AI mode changes)
- AI token usage logs: model used, token counts, action type (classify / generate / refine)
- AI generation audit logs: the system prompt used, the customer email, the AI response, confidence score, and which knowledge-base articles were referenced
- Security audit events: sign-in success and failure, password change, 2FA enrollment, OAuth connect/disconnect, authorization denials
These logs are used for billing, debugging, auditability, and security incident response.
Technical Data
Standard server and application logs: IP address, browser type, pages visited, timestamps. Used for security monitoring and debugging. Personally identifiable email addresses appearing in operational console logs are redacted at write time.
How We Use Your Data
Core Service Delivery
We use the data described in section 3 to:
- Operate the support ticketing inbox — create tickets from inbound emails, display them in the Solvias dashboard
- Generate AI-assisted draft replies using the email content, order context, and your store's knowledge base
- Send approved replies on your behalf via the connected mailbox provider (gmail.send for Gmail, Mail.Send for Outlook, SMTP for IMAP/SMTP) so the reply appears in the customer's existing email thread from your store's support address
- Fetch Shopify order data and ParcelPanel tracking data to enrich relevant tickets
- Log activity and AI usage for your own auditing and billing purposes
AI Processing of Mailbox Data
Solvias passes the text content of inbound customer emails to the Anthropic Claude API for two purposes:
- Classification — identifying the ticket category (e.g., shipping inquiry, return request) and extracting an order number if present
- Draft generation — producing a suggested reply based on the email, order context, and your store's knowledge base and instructions
This processing is performed in real time, on a per-ticket basis, solely to produce a reply for the authenticated store account that owns that email thread.
Anthropic data handling. Under Anthropic's commercial terms applicable to the Claude API, Anthropic does not use API inputs or outputs to train or improve its models. Anthropic retains API inputs and outputs for up to 30 days for Trust & Safety and abuse-monitoring purposes, after which the data is automatically deleted from Anthropic's systems. Anthropic acts as our sub-processor under a data processing agreement and is not permitted to use this data for any purpose other than providing the Claude API service to us.
Mailbox message content is never used to train, fine-tune, or improve any AI or machine learning model — whether our own, Anthropic's, or any other third party's.
Service Improvement
We may use aggregated, de-identified usage statistics (counts, durations, error rates — never linked to individual email content or identifiable users) to improve the platform.
Legal and Safety
We may use or disclose data where required by law, court order, or to protect the rights, property, or safety of AB Collection LLC, our users, or others.
Google API Services — Limited Use
The use of information received from Google Workspace APIs (including data obtained via gmail.readonly and gmail.send) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In compliance with Google's Limited Use requirements, Solvias affirms that Gmail user data:
- Is used only to provide the customer support ticketing features described in this policy and visible to the authenticated user who authorised access
- Is not transferred, sold, or used to serve advertisements — including personalised, interest-based, or retargeted advertising
- Is not transferred or sold to third parties, except to the sub-processors listed in Section 5, who process data on our behalf under data processing agreements solely for the purpose of delivering the Service
- Is not used to determine creditworthiness or for lending purposes
- Is not used to build permanent profiles beyond what is necessary to operate the support inbox for the authenticated account
- Is not used to train, fine-tune, or improve any generalised AI or machine learning model — whether our own systems, Anthropic's models, or any other third-party model
- Is passed to the Anthropic Claude API solely for real-time, per-ticket response generation for the account that authorised access; this is a user-directed processing action equivalent to the user pasting an email into a tool to draft a reply, and does not constitute training data use
- Is subject to human access only where the user who authorised access explicitly requests support, where we believe in good faith that human access is necessary for security incidents or legal obligations, or where required by law — and only to the minimum necessary extent
Data Retention
Active Accounts
While your Solvias account is active, we retain data as follows. Retention windows below are enforced by an automated nightly job at 04:00 UTC.
| Data type | Retention period |
|---|---|
| Email message PII fields (plain-text and HTML body, subject line, sender and recipient email addresses, AI draft, conversation summary) | 90 days, then every PII field is cleared to NULL. Only the immutable ticket linkage, internal message ID, direction, and timestamps survive past 90 days. |
| Email attachments stored in object storage (Vercel Blob / Amazon S3) | 90 days, deleted in bulk from the underlying object store before the message row is cleared, so no orphaned blobs remain |
| AI generation logs (LLM prompt + response, used for quality monitoring) | 180 days from creation |
| AI token usage logs (LLM token-usage records, used for billing meter input) | 90 days from creation |
| Activity logs (agent actions, AI mode changes, member-management events) | 365 days from creation |
| Historical inbox import (one-time import of pre-existing inbox history at onboarding) | 365 days from import |
| Security and authentication audit log (security_events) | Retained indefinitely as a permanent audit record, excluded from the nightly purge — required to support breach investigations and dispute resolution |
| OAuth refresh tokens (Gmail, Outlook) | Deleted immediately upon mailbox disconnection |
| IMAP/SMTP credentials, Shopify credentials, ParcelPanel API keys | Deleted immediately upon integration disconnection |
Every purge run — successful or failed — is recorded to an internal data_retention_purges audit table including the target dataset, retention window applied, cutoff timestamp, rows affected, and execution duration. This provides a complete history of retention enforcement available on regulator request.
Users may request earlier deletion of any of the above at any time by emailing privacy@solvias.io.
Account Deletion
When you request deletion of your Solvias account, the request enters a 7-day grace window. During the grace window:
- You can cancel the deletion via the link in the confirmation email or by signing back in.
- The app remains read-only for your account; auto-respond is paused; billing is paused.
After 7 days the nightly delete-accounts job runs the deletion. For every organisation where you are the sole owner, the job — before the database cascade runs — calls Google's OAuth revocation endpoint to terminate the Gmail grant on Google's side, deletes the Stripe customer record and cancels the subscription immediately (which cascades through payment methods and tax IDs on the Stripe side), and purges every blob/S3 attachment referenced by the organisation's messages. The database delete then cascades through every store, satellite credential (Gmail, Outlook, IMAP/SMTP, Shopify, ParcelPanel), ticket, message, AI log, email template, and funnel configuration. For organisations where you are one of several owners, only your own membership is removed; the organisation continues under the remaining owners.
Microsoft does not expose a programmatic refresh-token revocation endpoint for personal accounts; the encrypted Outlook refresh token is deleted from our store at the same step, and the grant naturally expires per your Microsoft account settings.
The data deletion timeline is therefore:
| Data type | Deletion timeline (from initial request) |
|---|---|
| Cancellation window during which deletion can be reversed | 7 days |
| OAuth refresh tokens (Gmail, Outlook), IMAP/SMTP credentials, Shopify credentials, ParcelPanel API keys | Within 7 days (deleted as part of the cascade at the end of the grace window) |
| Stripe subscription cancelled and customer deleted (for sole-owned organisations) | Within 7 days |
| Email message content (ticket messages), attachments, AI generation logs, account profile, activity logs | Within 7 days (organisation cascade) |
| 2FA secrets and backup codes | Within 7 days |
| Better Auth user row, sessions | Within 7 days |
We retain de-identified, aggregated statistics (counts of tickets processed, total token usage) that cannot be linked back to you or your End Customers.
We may retain limited records longer where strictly necessary to comply with legal obligations, resolve disputes, or enforce our agreements; in such cases, only the minimum necessary records are retained, and Gmail-derived content is excluded from any such retention.
Data Security
We implement the following technical and organisational measures to protect your data:
- Encryption in transit — All connections between your browser, our servers, and third-party APIs use TLS 1.2 or higher. HSTS is enforced (max-age=63072000; includeSubDomains; preload).
- Encryption at rest — OAuth tokens, API keys, and other secrets stored in our database are encrypted using AES-256-GCM with a 32-byte key held in a separate environment secret. Aurora itself is also encrypted at the cluster level using an AWS-managed KMS key. Amazon S3 buckets use SSE-S3 (AES-256) at rest. Solvias supports an ENCRYPTION_KEY_V<n> versioned scheme to enable key rotation without re-encrypting the entire database in a single operation.
- Access controls — Multi-tenant architecture: each store's data is scoped to that store's account. Cross-tenant access is prevented at the application route layer (withStoreAccess, withOrgMemberAccess) and verified independently at the database query level.
- Least-privilege API access — We request only the OAuth scopes required for the described features. We do not request write access beyond gmail.send / Mail.Send.
- Audit logging — All AI actions, draft approvals, sent replies, sign-in events, and authorization denials are logged with timestamps and user identifiers in dedicated audit tables.
- No plaintext secrets — Credentials are never logged in plaintext; runtime logs are sanitised at write time (email addresses are redacted; subjects and bodies are not emitted to console).
- Vulnerability disclosure — We accept security reports at security@solvias.io and aim to acknowledge within 5 business days.
Your Rights
Rights Applicable to All Users
Subject to applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and associated data (deletion timelines are listed in section 7)
- Data portability — request an export of your data in a machine-readable format
- Objection / restriction — object to or request restriction of certain processing
To exercise these rights, email us at privacy@solvias.io.
Revoking Mailbox Access
You can disconnect Solvias from your mailbox at any time:
- In Solvias: go to Store Settings → Integrations and click Disconnect.
- Alternatively for Gmail: visit myaccount.google.com/permissions, find Solvias, and click Remove Access.
- Alternatively for Outlook: visit account.live.com/consent/Manage, find Solvias, and click Remove these permissions.
Upon disconnection, Solvias calls the identity provider's revocation endpoint (where available — Google supports this; Microsoft does not expose a programmatic revoke for personal accounts) and deletes the stored encrypted refresh token from our database in the same step. Existing ticket message records follow the active-account retention schedule in section 7. To request immediate deletion of all mailbox-derived data without deleting your account, email privacy@solvias.io.
End Customer Rights
End Customers (individuals who emailed a store's support address) who wish to exercise data rights regarding their personal data should contact the store owner directly, since the store owner is the data controller for that data. We will support store owners in fulfilling such requests. End Customers may also contact us at privacy@solvias.io and we will route the request appropriately.
California Residents (CCPA/CPRA)
California residents have the right to:
- Know what personal information is collected, disclosed, or sold
- Delete personal information (subject to legal exceptions)
- Opt out of the sale or sharing of personal information — we do not sell or share personal information
- Non-discrimination for exercising these rights
To submit a verifiable consumer request, email privacy@solvias.io from the email address associated with your account.
European / UK Residents (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, your personal data is processed on the following legal bases:
- Contract performance — processing necessary to deliver the Service you signed up for
- Legitimate interests — security monitoring, fraud prevention, aggregate analytics
- Legal obligation — where required by law
You have the right to lodge a complaint with your local supervisory authority.
International Data Transfers
AB Collection LLC is based in the United States. Solvias's primary infrastructure runs in eu-central-1 (Frankfurt, Germany) on Amazon Web Services. Some sub-processors (Anthropic, Stripe, Resend, Vercel, Sentry) process data in the United States. Transfers to those processors rely on Standard Contractual Clauses (SCCs) signed in each Data Processing Agreement and, where applicable, adequacy decisions. A list of which sub-processors operate under SCCs is available on request to privacy@solvias.io.
Children's Privacy
Solvias is not directed at children under the age of 13. We do not knowingly collect personal data from children. End Customer emails received via connected mailboxes are processed under the store owner's existing relationship with that End Customer; we do not collect End Customer ages, do not direct support communications at children, and rely on the store owner to comply with applicable child-protection laws (such as COPPA) in their relationship with their customers. If you believe we have inadvertently collected data from a child, contact us at privacy@solvias.io and we will delete it promptly.
Third-Party Links
The Service may contain links to third-party websites (e.g., Shopify, Gmail). This policy does not cover third-party sites. We encourage you to read the privacy policies of any site you visit.
Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and update the "Last updated" date at the top of this document. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
Contact Us
If you have questions, requests, or complaints about this privacy policy or our data practices:
AB Collection LLC — Attn: Privacy — 15442 Ventura Blvd. Ste 201-2072, Sherman Oaks, California 91403, United States of America
| Purpose | |
|---|---|
| Privacy rights and complaints (GDPR / CCPA / general privacy questions) | privacy@solvias.io |
| Security disclosures and vulnerability reports | security@solvias.io |
| General business inquiries, DPA requests, signed-copy requests | info@solvias.io |
We aim to respond to all privacy requests within 30 days.