Privacy Policy
How Cervito handles merchant and visitor data.
- Last updated
- Entity
- The Growth Locker FZC · SPC Freezone, Sharjah, United Arab Emirates
Interim policy, pending final legal review. This is a good-faith interim version. Questions: [email protected]
1. Who we are
Cervito is a service of The Growth Locker FZC, SPC Freezone (Sharjah Publishing City Free Zone), Sharjah, United Arab Emirates ("Cervito", "we", "us"). Cervito provides an AI sales associate that runs on e-commerce storefronts, plus a merchant dashboard.
Contact: [email protected].
2. Who is responsible for your data (controller vs processor)
- If you are a shopper who chatted with the associate on a store, that store (the merchant) is the controller of your personal data. Cervito processes it on the merchant's behalf, as a processor. Requests about shopper data are best directed to the store you shopped on; we will assist that store (and you can use the self-service tools in section 5).
- If you are a Cervito merchant / account holder, The Growth Locker FZC is the controller of your account data.
3. Where your data is hosted
Our production application and database are hosted in the European Union (currently the Netherlands). We will keep production hosting within the EU/EEA; if we ever change the specific country we will keep it within the EU/EEA or update this page.
4. What we process
- Conversation messages between storefront visitors and the associate
- Anonymous session and visitor identifiers used to keep a conversation coherent
- Email addresses (and, optionally, a phone number) a visitor provides, e.g. for back-in-stock alerts or to be contacted
- Order and catalog metadata your store shares with us to ground the associate's answers
- Your merchant account details
- Encrypted platform credentials (stored encrypted at rest)
We are an AI shopping assistant, not an advertising network. We do not sell your data or your visitors' data, and we do not use it to train shared or third-party AI models.
5. The associate is AI, and what it sends to our AI providers
The associate is an artificial-intelligence assistant, not a human (see our AI disclosure). To answer a shopper, the text of the conversation is sent to our AI sub-processor (Anthropic, United States) and, for catalog search, to our embeddings sub-processor (OpenAI, United States: catalog text, not visitor identifiers).
Before sending conversation text for AI inference, we automatically remove email addresses, phone numbers, and payment-card numbers. We do not remove names or other details a shopper chooses to type into the chat box, so please do not enter sensitive personal information in the chat.
6. Captured emails and marketing
Where a visitor gives an email (for example, to be notified when an item is back in stock), that email is used for the purpose the visitor requested. The merchant is responsible for the lawful basis and any marketing-consent rules (e.g. EU ePrivacy / PECR, US CAN-SPAM, Canada CASL) for any further messaging, and for honoring unsubscribe requests.
7. How long we keep data
A daily automated job deletes data on these fixed schedules. These windows are not currently merchant-configurable.
| Data | Retention |
|---|---|
| Anonymous visitor chat sessions | 90 days |
| Chat sessions linked to an identified contact | 365 days |
| On-store interaction events | 365 days |
| Attribution touches | 365 days |
| AI conversation analyses | 365 days |
| Dormant anonymous visitor profiles (no linked contact) | deleted after 730 days inactive |
| Security event logs | 180 days |
| Administrative audit logs | 365 days |
| API cost / usage logs | 90 days |
| In-app notifications | 90 days |
Aggregated, de-identified metrics that no longer identify any individual may be retained longer.
8. Cookies and analytics
This website (cervito.io). Our marketing website uses Cloudflare Web Analytics, a privacy-preserving measurement that sets no cookies, stores nothing on your device, does not fingerprint you, and does not track you across sites. We see only aggregate, de-identified metrics (page views, approximate country, referring source, and device type) to understand traffic and improve the site, under our legitimate interest (GDPR Art. 6(1)(f)) in operating and improving it. Because our analytics stores nothing on, and reads nothing from, your device, it needs no cookie banner. We run no advertising or cross-site tracking on this site. The one place a third party may set its own cookies is our booking page. See Booking a demo below.
Booking a demo. Our booking page (/book) embeds Google Calendar's appointment scheduler so you can pick a time without leaving our site, and booking schedules a 30-minute video call over Google Meet with the founder. When you join the call, Google processes your audio, video, and connection data to run the meeting, as a video-conferencing provider under Google's terms. The scheduler loads from Google only on the /book page, and only because you went there to book. When it loads, Google may set its own cookies. We don't take payment through it, and the booking gives us only the appointment details you submit (such as your name and email). We do not record demo calls unless we tell you and you agree at the start of the call.
On a merchant's storefront. The associate may set cookies or similar storage on a storefront. A strictly-necessary sealed-session cookie keeps a single conversation coherent and bound to the correct store. Some storage (e.g. attribution/analytics events) is not strictly necessary and requires consent where the law of the shopper's location applies. Where consent is required, the merchant is responsible for obtaining it (including running a consent platform). Cervito reads consent signals from common consent platforms and restricts non-essential storage where the merchant enables consent gating.
A merchant may also run an A/B visibility test (showing the associate to only a portion of visitors and holding the rest back as a "control group") to measure its effect on conversion. This compares only anonymized, aggregate conversion rates between the two groups; it collects no additional personal data beyond the interaction events described above, relies on the same storefront storage, and is subject to the same consent rules.
9. International data transfers
Our application and database are hosted in the EU. Some sub-processors are located outside the EU/EEA (notably in the United States, see our DPA sub-processor list). Where personal data is transferred to them, we rely on the European Commission's Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum), together with additional safeguards. We are finalizing the formal transfer documentation with legal counsel and will make the relevant clauses available to merchants on request.
10. Your rights
If you are in the EU, EEA, or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability.
Shoppers can use the self-service portal to get a copy of, or delete, their data across every Cervito-powered store that holds their email, after verifying control of that email address.
California residents: we do not sell or share (as defined under California law) your personal information, and we do not use it for cross-context behavioral advertising. You may exercise access and deletion rights via the self-service portal (shoppers) or by emailing [email protected] (merchants).
To exercise rights, email [email protected] with the email or session associated with your data and the store domain. We respond within the timelines the law requires.
11. Children
The service is not intended to knowingly process the personal data of children. Merchants must not direct the associate at children, and must represent that their store is not directed at children where their jurisdiction's children's-data rules (e.g. GDPR Art. 8, the UK Age-Appropriate Design Code, or US COPPA) would otherwise apply. If you believe a child's data has been collected, contact [email protected].
12. EU representative
As a non-EU operator serving EU/EEA data subjects, we are confirming our obligation to appoint an EU representative under GDPR Art. 27 with legal counsel, and will name our representative and their EU address here once appointed.
13. Contact
Privacy questions and data-rights requests: [email protected].