Where your data lives, and what we have not finished.
Everything below is reproduced from the documents that bind us, our Data Processing Agreement and our Privacy Policy, plus our Terms where an item is still open. Nothing here is new. It is the same posture, laid out so you can read it in one pass, with the source named under every section.
“If we cannot measure it, we will not claim it.”
The mission statement of our claims registry. Every number this site states about the shipped product carries the date we measured it and a one line method you can follow to reach the same number. Where a number appears on this page, its receipt is printed underneath it.
EU hosting, and what happens when data leaves.
- Production
Our production application and database are hosted in the European Union, currently the Netherlands.
- Commitment
We will keep production hosting within the EU/EEA. If we ever change the specific country, we will keep it within the EU/EEA or update the Privacy Policy.
- Host
Railway, for application and database hosting in production, in the European Union (Netherlands).
- Transfers out
Some sub-processors sit outside the EU/EEA, notably in the United States. Where personal data is transferred to them we rely on the European Commission’s Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, with additional safeguards. We are finalizing the formal transfer documentation with legal counsel and will make the relevant clauses available on request.
Source: Privacy Policy, sections 3 and 9, and the DPA, sections 4 and 5
Every sub-processor, with purpose and processing location.
We engage the 7 sub-processors below. This list reflects production today.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Railway | Application and database hosting (production). | European Union (Netherlands) |
| Anthropic | LLM inference for the associate’s replies. Visitor-typed first names may be included in the conversation text sent for inference. Email, phone and card numbers are removed first. | United States |
| OpenAI | Text-embedding generation for catalog and product search. Your catalog text, not visitor identifiers. | United States |
| Resend | Transactional email: verification links, data-export deliveries and notifications. Receives visitor email addresses and exported personal-data files. | United States |
| Cloudflare | DNS, edge delivery, network security, and privacy-preserving (cookieless) analytics for our marketing website. The analytics is Cloudflare Web Analytics: no cookies, nothing stored on your device, no fingerprinting, no cross-site tracking. | Global edge network |
Business email (Google Workspace; e.g. [email protected]); the appointment scheduler embedded on our marketing site’s /book page; and Google Meet for the 30-minute demo video call a prospect books, together receiving the booking and meeting details they choose to submit. | United States / EU | |
| Shopify | Your connected store platform: catalog, orders and customer data for stores you connect. | Per Shopify’s terms |
The Google appointment-scheduler and Google Meet entries cover demo bookings on our marketing site, where we (The Growth Locker FZC) are the controller of the prospect’s own data. They are listed for transparency, not as processing carried out on a merchant’s behalf.
We will give at least 30 days’ notice before a new sub-processor begins processing your visitors’ personal data. You may object on reasonable data-protection grounds within that period at [email protected]; if we cannot address the objection, you may terminate the affected service for the unused portion of any prepaid term.
What we strip out, and what we do not.
The associate is an artificial-intelligence assistant, not a human. To answer a shopper, the text of the conversation is sent to Anthropic in the United States and, for catalog search, catalog text is sent to OpenAI in the United States.
Removed automatically
- Email addresses
- Phone numbers
- Payment-card numbers
Not removed
- Names
- Any other detail a shopper chooses to type into the chat box
Which is why we ask shoppers not to enter sensitive personal information in the chat, rather than implying the redaction catches everything.
We are an AI shopping assistant, not an advertising network. We do not sell your data or your visitors’ data, and we do not use it to train shared or third-party AI models.
Source: Privacy Policy, sections 4 and 5
The technical and organizational measures, named.
We apply measures appropriate to the risk. These are the ones our DPA commits us to, in its own words.
- Platform credentials
Encrypted at rest with AES-256-GCM.
- Tenant separation
Tenant isolation at the database layer.
- Sessions
Sealed, rotating session binding.
- Administrative actions
Audit logging.
- Conversation text
Email, phone and card numbers removed before AI inference.
We require our sub-processors to maintain appropriate measures.
A daily job deletes on these fixed schedules.
These windows are not currently merchant-configurable.
| Data | Retention |
|---|---|
| Anonymous visitor chat sessions | 90 days |
| Chat sessions linked to an identified contact | 365 days |
| On-store interaction events | 365 days |
| Attribution touches | 365 days |
| AI conversation analyses | 365 days |
| Dormant anonymous visitor profiles (no linked contact) | deleted after 730 days inactive |
| Security event logs | 180 days |
| Administrative audit logs | 365 days |
| API cost and usage logs | 90 days |
| In-app notifications | 90 days |
Aggregated, de-identified metrics that no longer identify any individual may be retained longer.
Two of these windows are in our claims registry, read from the prune job itself:
90 days
Measured 2026-08-10. The anonymous-session window in the retention prune job that runs daily against production. Check the retention table in our privacy policy
365 days
Measured 2026-08-10. The identified-session window in the retention prune job that runs daily against production. Check the retention table in our privacy policy
Source: Privacy Policy, section 7
What the associate costs your storefront.
One script, loaded once. This is the file your shoppers actually download, measured with the same method our build gate uses to enforce the ceiling it sits under.
110.76 KB gzipped, against a budget of 116 KB we enforce at build time
Measured 2026-08-10. Run gzip at level 6 over the shipped file, the same method our build gate uses. Check the file we measured
Consent on your storefront is yours to collect.
This is the part a trust page is tempted to blur. We would rather you read it here than discover it in the DPA after signing.
- On your storefront
The associate may set cookies or similar storage. A strictly-necessary sealed-session cookie keeps a single conversation coherent and bound to the correct store. Some storage, such as attribution and interaction events, is not strictly necessary.
- Your responsibility
Where the law of your shoppers’ location requires consent for non-essential storage, for example EU ePrivacy or UK PECR, you, the merchant, are responsible for obtaining that consent, including running a consent platform if needed.
- What we do about it
Cervito reads consent signals from common consent platforms, and where you enable consent gating the associate restricts non-essential storage accordingly.
- Captured emails
Where a visitor gives an email, for example to be notified when an item is back in stock, it is used for the purpose the visitor requested. You are responsible for the lawful basis and any marketing-consent rules for further messaging, and for honoring unsubscribe requests.
- On this website
Our own analytics sets no cookies and stores nothing on your device, which is why this page carries no cookie banner. The one place a third party may set its own cookies is our booking page, where Google’s appointment scheduler loads because you went there to book.
Source: DPA, section 11, and the Privacy Policy, sections 6 and 8
Send the questionnaire. A person answers it.
We make available the information reasonably necessary to demonstrate compliance, including, on request, a description of our technical and organizational measures and responses to a reasonable security questionnaire, no more than once per 12 months.
Where a documented review is insufficient and an on-site or third-party audit is genuinely required, it will be on at least 30 days’ written notice, during business hours, under a confidentiality agreement, limited to systems relevant to your data, conducted so as not to disrupt our operations or compromise other customers’ confidentiality, and at your cost.
A counter-signed copy of the DPA for your records is available on request.
Security questionnaires: [email protected]
DPA and data-protection matters: [email protected]
The legal work we have not finished.
Our EU Article 27 representative is not yet appointed and the governing-law clause in our Terms is not yet final. Both are with counsel. We publish this here so you find it from us rather than in a diligence memo.
EU Article 27 representative
Target: with counsel
Not yet appointed. We are confirming the obligation with legal counsel and will name the representative and their EU address in the Privacy Policy once appointed.
Governing law and dispute forum
Target: with counsel
Not final. The governing law, the dispute forum and any arbitration seat are being finalized with legal counsel and will be published in the Terms of Service.
When one of these lands, it lands in the document itself and this panel loses a row. A trust page that only lists what is finished is a brochure.
Bring the hard questions to the demo.
Book a 30-minute call with the founder and ask whatever this page did not answer. If you would rather send a security questionnaire first, it goes to [email protected] and comes back answered by a person.
Private rollout · one-click uninstall if it doesn’t earn its keep