Privacy Policy
Last updated: July 19, 2026
This Privacy Policy explains how Allyvia, Inc. (“Allyvia,” “we,” “us” or “our”) collects, uses, discloses and protects personal information through our websites, point-of-sale and business management platform, and related services (the “Service”). It also sets out the privacy rights California residents have under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, “CCPA/CPRA”).
Our two roles
We handle personal information in two ways. For visitors to our websites, prospective customers and the staff of our business customers, we act as a business (controller). When merchants use the Service to process information about their customers and staff, we act as a service provider (processor), handling it for the merchant and on their instructions. If you shop at or work for a business that uses Allyvia, please send privacy requests to that business, and we will help them as required.
1. Information we collect
We collect these kinds of personal information:
- Account and contact details: your name, business name, work email, phone number, role and login credentials.
- Demo requests and enquiries: what you enter in the demo form, such as your name, company, work email, phone and availability.
- Billing details: your plan, billing contact and transaction history. Card details are collected and kept by our payment processors, not by Allyvia.
- Merchant business data: the sales, inventory, staff schedules and other records our customers run through the Service. This can include personal information about a merchant's own customers or staff, which we handle as a service provider.
- Usage and device data: logs, IP address, device and browser type, pages viewed and how you use the Service, collected automatically.
- Support messages: anything you tell us when you get in touch.
2. How we use information
We use personal information to:
- run, secure and maintain the Service, including offline sync and reconciliation;
- set up accounts, manage subscriptions and handle billing;
- answer demo requests, questions and support tickets;
- produce forecasts, staffing suggestions, reorder recommendations and anomaly alerts for the merchant concerned;
- monitor, fix and improve performance, reliability and security;
- detect and prevent fraud, abuse and unauthorised access;
- send service messages and, where allowed, marketing (you can opt out of marketing at any time);
- meet our legal obligations and enforce our agreements.
4. Payments and card data
Payments taken through the Service are processed by third parties, including Stripe and Square. Card numbers are tokenised and go straight to the processor, and Allyvia never stores full card numbers. The processors handle card data as independent controllers, under their own privacy policies and PCI DSS obligations.
5. AI and model improvement
Our predictive features are trained and tuned on a merchant's own data to make recommendations for that merchant. We may also use aggregated, de-identified data, from which people and, where relevant, individual businesses cannot reasonably be identified, to build, test and improve our models and the Service. We never use one merchant's identifiable business data to make recommendations for another merchant. Recommendations are for information only and are not professional advice.
7. Data retention
We keep personal information as long as we need it to provide the Service, meet legal, tax and accounting duties, resolve disputes and enforce our agreements. Merchant business data is kept for as long as the account is open. After an account closes, we keep the data available to export for a limited time, then delete or de-identify it unless the law requires us to keep it. Aggregated, de-identified data may be kept indefinitely.
8. Security
We protect personal information with technical and organisational measures, including encryption in transit and at rest, role-based access, tenant isolation, authentication safeguards and monitoring. No way of sending or storing data is perfectly secure, so we cannot guarantee absolute security. You are responsible for keeping your login details safe and setting access appropriately.
9. Your California privacy rights (CCPA/CPRA)
If you live in California, you have these rights over personal information we hold about you as a business, subject to verification and legal exceptions:
- Know and access: the categories and specific pieces of personal information we have collected, where it came from, why we use it, and who we disclose it to.
- Delete: ask us to delete personal information we collected from you.
- Correct: ask us to fix inaccurate personal information.
- Opt out of sale or sharing: we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. If that ever changes, we will add a “Do Not Sell or Share My Personal Information” option.
- Limit use of sensitive personal information: we do not use sensitive personal information in ways that require this option.
- Non-discrimination: we will not treat you differently for using your rights.
To use these rights, email info@allyvia.si. We will verify the request against your account details. An authorised agent can submit a request for you with proof of authorisation. If you shop at or work for a business that uses Allyvia, send your request to that business, and we will support them as their service provider.
Categories collected, disclosed, sold or shared in the last 12 months:
| Category | Collected | Disclosed for a business purpose | Sold / shared |
|---|---|---|---|
| Identifiers (name, email, phone, IP) | Yes | Service providers, integrations you enable | No |
| Commercial information (transactions, subscriptions) | Yes | Payment and accounting providers | No |
| Internet or network activity (usage, logs) | Yes | Hosting and analytics providers | No |
| Professional information (business, role) | Yes | Service providers | No |
10. Children's privacy
The Service is for businesses and is not aimed at children under 16. We do not knowingly collect personal information from children. If you think a child has given us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy. We will post the new version with a new “Last updated” date and, for material changes, also tell you by email or in the product. Continuing to use the Service after a change takes effect means you accept it.
12. Contact us
For privacy questions, or to use your rights, contact Allyvia, Inc. at info@allyvia.si.