Skip to content
In private rollout: onboarded personally, usually live within 24 hours.
Trust centre

Where your data lives, and what we have not finished.

Everything below is reproduced from the documents that bind us, our Data Processing Agreement and our Privacy Policy, plus our Terms where an item is still open. Nothing here is new. It is the same posture, laid out so you can read it in one pass, with the source named under every section.

“If we cannot measure it, we will not claim it.

The mission statement of our claims registry. Every number this site states about the shipped product carries the date we measured it and a one line method you can follow to reach the same number. Where a number appears on this page, its receipt is printed underneath it.

01 · Where it lives

EU hosting, and what happens when data leaves.

  • Production

    Our production application and database are hosted in the European Union, currently the Netherlands.

  • Commitment

    We will keep production hosting within the EU/EEA. If we ever change the specific country, we will keep it within the EU/EEA or update the Privacy Policy.

  • Host

    Railway, for application and database hosting in production, in the European Union (Netherlands).

  • Transfers out

    Some sub-processors sit outside the EU/EEA, notably in the United States. Where personal data is transferred to them we rely on the European Commission’s Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, with additional safeguards. We are finalizing the formal transfer documentation with legal counsel and will make the relevant clauses available on request.

Source: Privacy Policy, sections 3 and 9, and the DPA, sections 4 and 5

02 · Who touches it

Every sub-processor, with purpose and processing location.

We engage the 7 sub-processors below. This list reflects production today.

The 7 sub-processors Cervito engages, with the purpose of each and where it processes data.
Sub-processorPurposeProcessing location
Railway

Application and database hosting (production).

European Union (Netherlands)
Anthropic

LLM inference for the associate’s replies.

Visitor-typed first names may be included in the conversation text sent for inference. Email, phone and card numbers are removed first.

United States
OpenAI

Text-embedding generation for catalog and product search.

Your catalog text, not visitor identifiers.

United States
Resend

Transactional email: verification links, data-export deliveries and notifications.

Receives visitor email addresses and exported personal-data files.

United States
Cloudflare

DNS, edge delivery, network security, and privacy-preserving (cookieless) analytics for our marketing website.

The analytics is Cloudflare Web Analytics: no cookies, nothing stored on your device, no fingerprinting, no cross-site tracking.

Global edge network
Google

Business email (Google Workspace; e.g. [email protected]); the appointment scheduler embedded on our marketing site’s /book page; and Google Meet for the 30-minute demo video call a prospect books, together receiving the booking and meeting details they choose to submit.

United States / EU
Shopify

Your connected store platform: catalog, orders and customer data for stores you connect.

Per Shopify’s terms

The Google appointment-scheduler and Google Meet entries cover demo bookings on our marketing site, where we (The Growth Locker FZC) are the controller of the prospect’s own data. They are listed for transparency, not as processing carried out on a merchant’s behalf.

We will give at least 30 days’ notice before a new sub-processor begins processing your visitors’ personal data. You may object on reasonable data-protection grounds within that period at [email protected]; if we cannot address the objection, you may terminate the affected service for the unused portion of any prepaid term.

Source: Data Processing Agreement, section 4

03 · Before inference

What we strip out, and what we do not.

The associate is an artificial-intelligence assistant, not a human. To answer a shopper, the text of the conversation is sent to Anthropic in the United States and, for catalog search, catalog text is sent to OpenAI in the United States.

Removed automatically

  • Email addresses
  • Phone numbers
  • Payment-card numbers

Not removed

  • Names
  • Any other detail a shopper chooses to type into the chat box

Which is why we ask shoppers not to enter sensitive personal information in the chat, rather than implying the redaction catches everything.

We are an AI shopping assistant, not an advertising network. We do not sell your data or your visitors’ data, and we do not use it to train shared or third-party AI models.

Source: Privacy Policy, sections 4 and 5

04 · Encryption and isolation

The technical and organizational measures, named.

We apply measures appropriate to the risk. These are the ones our DPA commits us to, in its own words.

Security measures
  • Platform credentials

    Encrypted at rest with AES-256-GCM.

  • Tenant separation

    Tenant isolation at the database layer.

  • Sessions

    Sealed, rotating session binding.

  • Administrative actions

    Audit logging.

  • Conversation text

    Email, phone and card numbers removed before AI inference.

We require our sub-processors to maintain appropriate measures.

Source: Data Processing Agreement, section 12

05 · How long we keep it

A daily job deletes on these fixed schedules.

These windows are not currently merchant-configurable.

Retention windows by data type, deleted by a daily automated job.
DataRetention
Anonymous visitor chat sessions90 days
Chat sessions linked to an identified contact365 days
On-store interaction events365 days
Attribution touches365 days
AI conversation analyses365 days
Dormant anonymous visitor profiles (no linked contact)deleted after 730 days inactive
Security event logs180 days
Administrative audit logs365 days
API cost and usage logs90 days
In-app notifications90 days

Aggregated, de-identified metrics that no longer identify any individual may be retained longer.

Two of these windows are in our claims registry, read from the prune job itself:

90 days

Measured 2026-08-10. The anonymous-session window in the retention prune job that runs daily against production. Check the retention table in our privacy policy

365 days

Measured 2026-08-10. The identified-session window in the retention prune job that runs daily against production. Check the retention table in our privacy policy

Source: Privacy Policy, section 7

06 · Widget footprint

What the associate costs your storefront.

One script, loaded once. This is the file your shoppers actually download, measured with the same method our build gate uses to enforce the ceiling it sits under.

110.76 KB gzipped, against a budget of 116 KB we enforce at build time

Measured 2026-08-10. Run gzip at level 6 over the shipped file, the same method our build gate uses. Check the file we measured

08 · Questionnaires

Send the questionnaire. A person answers it.

We make available the information reasonably necessary to demonstrate compliance, including, on request, a description of our technical and organizational measures and responses to a reasonable security questionnaire, no more than once per 12 months.

Where a documented review is insufficient and an on-site or third-party audit is genuinely required, it will be on at least 30 days’ written notice, during business hours, under a confidentiality agreement, limited to systems relevant to your data, conducted so as not to disrupt our operations or compromise other customers’ confidentiality, and at your cost.

A counter-signed copy of the DPA for your records is available on request.

Security questionnaires: [email protected]
DPA and data-protection matters: [email protected]

Source: Data Processing Agreement, sections 1, 9 and 13

09 · Open items

The legal work we have not finished.

Open items · 2

Our EU Article 27 representative is not yet appointed and the governing-law clause in our Terms is not yet final. Both are with counsel. We publish this here so you find it from us rather than in a diligence memo.

  • EU Article 27 representative

    Target: with counsel

    Not yet appointed. We are confirming the obligation with legal counsel and will name the representative and their EU address in the Privacy Policy once appointed.

    Privacy Policy, section 12

  • Governing law and dispute forum

    Target: with counsel

    Not final. The governing law, the dispute forum and any arbitration seat are being finalized with legal counsel and will be published in the Terms of Service.

    Terms of Service, section 14

When one of these lands, it lands in the document itself and this panel loses a row. A trust page that only lists what is finished is a brochure.

Still checking

Bring the hard questions to the demo.

Book a 30-minute call with the founder and ask whatever this page did not answer. If you would rather send a security questionnaire first, it goes to [email protected] and comes back answered by a person.

Private rollout · one-click uninstall if it doesn’t earn its keep