Privacy policy · Updated April 25, 2026

How Clawviyo handles personal data.

This policy applies to clawviyo.com, the merchant dashboard, every per-merchant trust page, and the inbound MCP gateway that AI assistants use on behalf of their users. It tells you what we collect, why, who else sees it, how long we keep it, and how to exercise your rights under the EU and UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and similar laws.

An AI assistant contacted a business on your behalf

If you asked ChatGPT, Claude, Gemini, or another AI assistant to reach out to a company and the company is a Clawviyo merchant, your inquiry passed through us before reaching the business. You may not have known we existed. This is normal, but the GDPR requires us to tell you. We hold your email address and the inquiry text, we shared them with the business, and you can ask us to delete them at any time using the form at privacy/delete-my-data or by emailing [email protected]. The full picture is below.

Data controller

Clawviyo, Inc. (“Clawviyo”, “we”) is the data controller for personal data we collect about merchant account holders, agent operators, cross-merchant fraud signals, and visitors to our website. We act as a data processor for inquiry content the merchant receives through our platform — see section 4.

Privacy contact: [email protected]. We do not currently have a designated DPO; we will appoint one if our processing activities cross the GDPR Article 37 threshold.

Categories of personal data

  • Merchant account data: email address, display name, Supabase user ID, the company you administer, and the role you hold.
  • Merchant company data: company name, website, logo, industry, inquiry email, slug, scraped public website content, custom-domain configuration, and onboarding milestones.
  • Inquiry content: title, free-text body, qualification fields, and the email address of the human the AI assistant said was on the other end (the “verified human”).
  • Verification records: magic-link tokens, the timestamp the verified human clicked through, and a per-domain fingerprint of the AI assistant.
  • OAuth records: registered AI-assistant clients (name, redirect URIs, contact email), short-lived authorization codes (hashed), and bearer-session metadata (scope, expiry).
  • Operational telemetry: tool-call records, request rate-limit state, server logs, IP address and user-agent on handoff-link redirects, and timestamps for every step of the inquiry pipeline.
  • Cross-merchant reputation: per-(agent, merchant) score plus an append-only signal log (e.g. “converted”, “marked spam”).
  • Email audit log: recipient address, subject, body, Resend delivery ID, and open events for every transactional email we send.

We do not collect special-category data on purpose (health, religion, political opinions, biometrics, sexual orientation, children’s data). We instruct AI assistants not to submit special-category data through our gateway. If you discover an inquiry that contains it, contact us and we will delete it.

Lawful basis (GDPR Article 6)

  • Merchant accounts and dashboard: performance of a contract (Art. 6(1)(b)).
  • Inquiries on the merchant’s behalf: performance of the merchant’s contract with you, executed by us as their processor.
  • Verified-human magic-link verification: consent (Art. 6(1)(a)) given when you click the link in the email we send you. You can withdraw consent at any time by deleting your verification record.
  • Spam, abuse, and reputation signals: our legitimate interest in keeping the platform usable and free of fraud (Art. 6(1)(f)). Documented in section 9 along with how to object.
  • Operational telemetry, rate limiting, and security: our legitimate interest in operating a secure, reliable service (Art. 6(1)(f)).
  • Compliance with legal obligations: Art. 6(1)(c) where applicable.

Who’s in charge of what

For your merchant account, your company profile, our cross-merchant reputation system, and our operational telemetry, Clawviyo is the controller.

For the inquiry content a merchant receives (title, body, qualification answers, the human-behind-the-agent’s email), Clawviyo is the processor and the merchant is the controller. The merchant decides what to do with the inquiry, retains it in its own CRM context, and is on the hook for its own GDPR obligations toward the inquirer. Our standard Data Processing Addendum governs that relationship.

Who else sees the data

The merchant receives inquiry content addressed to them and the verified-human email associated with that inquiry. Beyond that, we share data only with the sub-processors listed at /sub-processors (Supabase for the database and authentication, Resend for transactional email, Anthropic for onboarding-time website scraping of public merchant sites, Railway for hosting). We do not sell personal data and do not share it with advertisers, data brokers, or third-party AI training pipelines.

We may disclose personal data if compelled by lawful process, to enforce our terms, or to protect the rights, property, or safety of Clawviyo, our users, or others. We will resist over-broad requests to the extent the law allows.

Data leaves the EEA / UK

Our infrastructure runs in the United States (Supabase on AWS us-west-2; Resend, Anthropic, and Railway are US-headquartered). Where personal data is transferred from the EEA, UK, or Switzerland to the US, the transfer is governed by the EU Standard Contractual Clauses (Module 2 for processor relationships, Module 3 for controller-to-controller flows) and, for UK transfers, the UK International Data Transfer Addendum, both incorporated into our agreements with each sub-processor.

How long we keep data

A daily automated sweep enforces these windows. Backups follow standard rotation and are deleted at the next cycle, no later than 90 days after the live row is removed.

  • Inquiry body, qualification fields, and admin notes: stripped after 24 months; metadata retained for analytics.
  • Inquiry rows in full: deleted after 36 months.
  • Verified-human records with no live inquiry reference: deleted 12 months after creation.
  • Handoff-link click logs (IP, user-agent, referer): deleted after 90 days.
  • Email body content in the audit log: stripped after 90 days; metadata retained.
  • MCP tool-call payloads and results: stripped after 90 days; status retained.
  • Per-event reputation signals: deleted after 12 months. Aggregate scores persist as long as the agent is active.
  • Expired OAuth authorization codes and pre-scrape profile cache: deleted nightly.
  • Merchant accounts and companies: retained while the account is active; deletion is self-serve in the dashboard.

What you can do

If GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify data that is inaccurate or incomplete (Art. 16).
  • Erase your data, subject to limited exceptions (Art. 17).
  • Restrict processing in certain situations (Art. 18).
  • Receive a portable copy of data you provided (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time, where consent is the basis (Art. 7(3)).
  • Lodge a complaint with your local supervisory authority (Art. 77).

Merchant account holders can use the dashboard to access, edit, export, and delete their data. Humans-behind-agents can use privacy/delete-my-data to request erasure of inquiries and verification records tied to their email. For anything else — access requests, objections, supervisory-authority complaints — email [email protected]. We respond within 30 days, extendable by two months for complex requests as Art. 12(3) allows.

How the reputation score is used

We maintain a per-agent, per-merchant reputation score plus a cross-merchant aggregate, used to deprioritize obviously fraudulent or low-quality agent traffic. The score is one input among several and is never the sole basis for a decision with legal or significant effect on you (GDPR Art. 22). To object to your score or request a manual review, email [email protected].

What feeds the cross-merchant aggregate: only signal counts (“submitted”, “converted”, “marked spam”, “honeypot triggered”, “filter rejected”, “handoff clicked”) plus the agent identifier. Inquiry titles, bodies, qualification data, and merchant-side tags or notes are never used as inputs to the cross-merchant score and are not visible to other merchants. A merchant that wants to be excluded from contributing to the cross-merchant aggregate can email us to opt out.

What we set and why

Clawviyo sets only strictly-necessary cookies: the Supabase authentication cookie (so merchant sessions persist across page loads) and a locale preference cookie for translated UI. We do not use analytics, advertising, retargeting, fingerprinting, or session-replay cookies, and we do not load third-party scripts that set them. Because we do not set non-essential cookies, no cookie consent banner is required under the ePrivacy Directive; this section is the disclosure.

How we protect data

See the security overview for our technical and organizational measures. In short: TLS in transit, AES-256 at rest in the database, row-level security and least-privilege access, encrypted Slack tokens, hashed bearer tokens, and a daily retention sweep.

Age

Clawviyo is not directed to children under 16 (or under 13 in the United States), and we do not knowingly process their data. If you believe a child has submitted data through us, contact [email protected] and we will delete it.

For users in the United Kingdom

The rights and obligations described above apply equivalently under the UK GDPR. UK users may complain to the Information Commissioner’s Office at ico.org.uk.

For California residents

We do not sell personal information and do not share personal information for cross-context behavioral advertising. California residents have the right to know, delete, correct, and (where applicable) limit use of sensitive personal information, and to be free from retaliation for exercising these rights. To exercise them, email [email protected]; we will verify your identity by confirming control of the email address you transact under.

Updates to this policy

We update this policy from time to time. The “Updated” date in the header reflects the latest revision; material changes are announced by email to merchant account holders before they take effect.