AvenRelayAvenRelay
Legal

Privacy Policy

How AvenRelay collects, uses, protects, and retains information across our platform, AI features, and connected messaging channels.

01

1. Introduction & Scope

AvenRelay (“AvenRelay”, “we”, “our”, or “us”) is an AI-powered customer support platform. Businesses use it to manage customer conversations across the messaging channels they connect — including the website chat widget, email, and Telegram, with Meta messaging channels (WhatsApp, Messenger, and Instagram) being rolled out — from one shared inbox, with AI support agents grounded in each business's own knowledge base.

This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you, across the AvenRelay public website (https://www.avenrelay.com), the web application and dashboard (app.avenrelay.com), the embeddable website chat widget, and the backend infrastructure that powers the service.

It is important to distinguish the different roles we play. When you create an AvenRelay account or contact us directly, AvenRelay is the data controllerof that account and website information. When a business (an “Organization”) uses AvenRelay to support its own customers, the Organization remains responsible for the customer data processed in its workspace, and AvenRelay processes that data on the Organization's behalf and under its instructions as a data processor (or service provider).

02

2. Information We Collect

We collect only the information needed to operate, secure, and improve the platform. It falls into the categories below.

A. Information you provide us

  • Account & profile information — when you create an account, we receive your name, email address, and account identifiers, authenticated and managed through Clerk. We do not store plain-text account passwords.
  • Workspace & organization information — organization name, URL slug, member assignments, and workspace preferences you configure in the dashboard.
  • Billing & subscription information — the plan you choose, subscription and customer identifiers, and invoice records, managed throughPaddle. AvenRelay never receives or stores payment card numbers; those are processed directly by Paddle as merchant of record.
  • Contact & inquiry information — your name, email address, and message contents when you contact us through the contact page or by email.
  • Feedback — any feedback, suggestions, or feature requests you voluntarily share with us.

B. End-customer and visitor information

  • Contact profiles & sessions — the name, email address, and phone number a visitor chooses to share, alongside basic session metadata captured by the chat widget (user agent, language, platform, screen resolution, timezone, referrer, and the page they were viewing).
  • Conversations & messages — transcripts of messages exchanged between visitors, human agents, AI agents, and system notes.
  • Attachments & files — files and attachments uploaded by users or visitors into a conversation or a workspace.

C. Connected channel and third-party platform data

  • When an Organization connects a messaging channel (email, Telegram, and Meta channels as they become available), AvenRelay receives the messages and contact information the platform exposes through its official APIs and syncs them into the workspace so the team can respond from one place.
  • This is limited to what the platform itself shares — for example email addresses, phone numbers, or platform user and page identifiers — and is handled subject to that platform's own terms and policies.

D. Knowledge base information

  • Knowledge sources— documents, text, and web addresses uploaded or added to an Organization's knowledge base.
  • Chunks & embeddings — content is split into smaller chunks and converted into vector embeddings using a Google Gemini embedding model so the AI can retrieve relevant context for answers.

E. Voice assistant data (when enabled)

  • When an Organization enables the voice assistant, we process call metadata, phone numbers, call duration, transcripts, and recording URLs through the Vapi voice platform.

F. Technical and log information

  • Standard server request logs, IP addresses, browser and device information, event and webhook logs, and rate-limit records used to operate the service and protect against abuse.
03

3. How We Use Information

We use the information we collect for the following purposes:

  • Operating, maintaining, securing, and improving the AvenRelay platform, dashboard, and embeddable widget.
  • Processing authentication, session management, and workspace access permissions.
  • Enabling AI features, including automated replies, knowledge-base retrieval, and vector embeddings, using Google Gemini models.
  • Routing multi-channel conversations and syncing messages across the channels an Organization has connected.
  • Handling billing, subscriptions, and payment lifecycle events through Paddle.
  • Enforcing usage and credit limits, rate limiting, and other safeguards that protect the service and its users.
  • Sending service notifications and responding to support, privacy, and other inquiries.
  • Improving the product, such as understanding how the platform is used in aggregate.
  • Complying with applicable legal obligations.

What we do not do: we do not sell personal information, and we do not use customer conversation content or Organization knowledge bases to train general-purpose third-party AI foundation models. Conversation data and knowledge are used only to provide the services you request.

04

4. AI Processing & Google Gemini

AvenRelay integrates Google Geminimodels through Google's Generative Language APIs to power AI chat responses, agent reasoning, and knowledge embeddings.

  • What is sent to the AI provider — when an AI response is requested, the conversation messages and any relevant knowledge-base context retrieved by vector search are transmitted securely over HTTPS to Google Gemini. Embeddings of knowledge-base content are generated the same way.
  • What we record — token usage, estimated cost, and credit consumption reported by the provider are recorded in our usage records so we can enforce limits and manage billing.
  • Your responsibility — AI-generated answers can occasionally be inaccurate. Organizations remain responsible for supervising their AI agents and reviewing automated responses before critical use.
05

5. How We Share Information

We share information only in the circumstances described below, and only to the extent needed for each purpose. We do not sell your personal information.

Service providers

We rely on the following verified providers to deliver the service. Where they process personal data on our behalf, they are bound by appropriate data protection obligations:

  • Convex — cloud backend hosting our database, vector index, file storage, and serverless functions.
  • Clerk — authentication and user identity management.
  • Google (Google Cloud / Gemini API) — AI model inference and vector embedding generation.
  • Paddle — merchant of record, subscription billing, and payment processing.
  • Vapi — voice assistant and telephony infrastructure, when enabled by an Organization.

Messaging platforms

To send and receive messages through a connected channel, we exchange message data with the platform the Organization has connected (such as an email provider, Telegram, or Meta for WhatsApp, Messenger, and Instagram), in accordance with that platform's terms and applicable platform agreements.

Other circumstances

  • With an Organization — information about end-customers is available to the Organization that operates the workspace they contacted.
  • Legal compliance & safety — when we reasonably believe disclosure is required by law, regulation, legal process, or to protect the rights, property, or safety of AvenRelay, our users, or others.
  • Business transactions — in connection with a merger, sale of assets, or similar transaction, in which case we will require the recipient to honor this policy (or provide notice of a change).
06

6. Cookies and Local Storage

AvenRelay uses essential cookies and browser storage for operational purposes:

  • Authentication cookies — set by Clerk and the dashboard to keep you signed in and to remember your workspace.
  • Widget session storage— used by the embeddable widget to keep a visitor's contact session and conversation state across page navigation.
  • Preference storage — remembers UI preferences such as theme and widget display settings.

We do not deploy third-party advertising trackers or behavioral profiling cookies. You can control cookies through your browser settings, though disabling essential cookies may affect authentication and widget functionality.

07

7. Data Security

We implement reasonable technical and organizational measures designed to protect information against unauthorized access, loss, alteration, or disclosure, including:

  • Encryption of traffic in transit (HTTPS/TLS) across the website, dashboard, APIs, and widget embeds.
  • Encryption at rest provided by our cloud infrastructure hosts.
  • Least-privilege access controls for administrative and staff access.
  • Encrypted storage of channel credentials and voice platform keys.
  • Signature verification of billing webhooks to prevent tampering.
  • Rate limiting and credit-guard safeguards that limit misuse and abuse.

While we work to protect your information, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

08

8. Data Retention

We retain personal data and workspace records for as long as an Organization has an active account, or as long as reasonably necessary to provide the services, comply with legal obligations, resolve disputes, enforce our agreements, and protect against fraud or abuse.

When an Organization closes its account or requests deletion, workspace records — such as contacts, conversations, messages, knowledge sources, and voice call logs — enter a 30-day recovery period and are then removed or anonymized in bounded stages. Minimal pseudonymized accounting, fraud-prevention, dispute, refund/cancellation, and security/deletion audit records may be retained for a target period of seven years, subject to applicable law and final legal/accounting review. These retained records cannot be used to access the product and do not retain message content, knowledge content, provider credentials, or unnecessary personal information.

Our operational backup policy targets removal from encrypted backup rotation within 90 days. Backup copies are not available through the normal product, and any disaster restore must reapply permanent-deletion tombstones before restored services become available. Production backup-provider configuration and restore behavior are verified separately as an operational control; this policy statement is not a claim that a particular provider configuration has completed that verification. Learn more on our Data Deletion page.

09

9. Data Deletion

We provide a clear process for requesting the deletion of personal data. If you are an Organization or account holder, you can request deletion of your workspace and its associated data; if you are an end-customer of a business using AvenRelay, you should contact that business directly, as it controls the workspace data associated with your conversations.

Please see our Data Deletion page for details on what can be deleted, how to submit a request, and what may need to be retained.

10

10. Your Privacy Rights & Choices

Depending on where you are located, and subject to applicable law, you may be able to exercise the following rights in relation to your personal information:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data under certain conditions.
  • Restriction & objection — request that we restrict or stop certain processing.
  • Portability — request a copy of your data in a structured, machine-readable format where applicable.

For end-customers: if you are a customer of a business that uses AvenRelay, the business is the controller of your conversation data. To exercise your rights regarding those conversations, please contact the business directly. If you contact us instead, we will coordinate with, or refer your request to, the relevant Organization.

We will respond to verifiable requests in accordance with applicable law. If you are not satisfied with our response, you may also have the right to lodge a complaint with your local data protection authority.

11

11. International Data Transfers

We operate using cloud infrastructure providers that may process data in regions outside the country where you are located. When personal information is transferred internationally, we take reasonable steps intended to keep it protected to the standard described in this policy. Information shared with connected messaging platforms is processed in line with the transfer practices of each platform.

12

12. Children's Privacy

AvenRelay is a business-to-business service and is not directed to children. We do not knowingly collect, use, or solicit personal information from children under the age of 16. If we learn that we have collected personal information from a child, we will take steps to delete it promptly.

13

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, provide additional notice. Please review this page periodically. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.

14

14. Contact & Privacy Requests

If you have questions about this Privacy Policy or wish to exercise your privacy rights with respect to data controlled directly by AvenRelay, contact us at:

Questions about this document?

Reach out to our team and we'll be happy to help clarify anything.