إشعار الخصوصية
خصوصيتك مهمة. تعرف على كيفية جمع معلوماتك الشخصية واستخدامها وحمايتها.
Effective date: October 3, 2026 · Last updated: October 3, 2026
This Privacy Policy explains how Salesvex Labs ("Salesvex", "we", "us"), based in Istanbul, Turkey, collects, uses, shares and protects personal data across all of our websites, applications and services (together, the "Services"). It is the single privacy policy for every Salesvex product and is referenced by our app store listings and by the third-party platforms our products integrate with.
Contact: [email protected]
Products covered
| Product | Where | Section |
|---|---|---|
| Salesvex website | salesvex.com | B1 |
| Salesvex AI Assistant (web app, API and website chat widget) | agent.salesvex.com, api-agent.salesvex.com | B2 |
| Salesvex Inbox mobile app | Apple App Store, Google Play | B3 |
Third-party platform integrations (Google, Meta, Apple, Slack, Discord, Telegram, e-commerce and CRM platforms) are described in Part C. How to delete your data is described in Part D.
Part A: General Privacy Practices (all products)
A1. Our role
- For data about people who visit our website or sign up for our products (account, billing, security and usage data), Salesvex is the data controller.
- Our business customers use our products to communicate with their own customers ("end customers"). For that data (conversations, leads, orders, data from accounts they connect), the business customer is the data controller and Salesvex acts as a data processor on its instructions. End customers should send privacy requests to the business they contacted first; we will help that business respond.
A2. Categories of data we process
- Identity and contact data: name, email address, phone number, company name, job title, profile photo.
- Account data: login credentials (passwords are stored only as salted scrypt hashes), sign-in provider identifiers (Google, Apple), workspace, role, preferences.
- Billing data: plan, invoices and payment status. Payments are processed by our payment provider; we never receive full card numbers.
- Customer content: messages, attachments, knowledge documents, product catalogs and other content our customers bring into the Services.
- Data from connected platforms: described per platform in Part C.
- Technical data: IP address, browser and device type, operating system, logs and security events.
- Usage data: pages visited and features used, collected on our website as described in B1.
A3. Purposes and legal bases
| Purpose | Legal basis (GDPR / KVKK) |
|---|---|
| Providing the Services you request, including integrations you connect | Performance of a contract |
| Account security, fraud and abuse prevention, debugging | Legitimate interests |
| Transactional emails (verification, password reset, invitations, billing) | Performance of a contract |
| Push notifications, voice chat and other optional features | Consent |
| Website analytics | Consent |
| Responding to sales, demo and support requests | Legitimate interests / steps prior to a contract |
| Billing, tax and accounting records; responding to lawful requests | Legal obligation |
We do not sell personal data, do not share it for cross-context behavioral advertising, and do not use customer content or data from connected platforms for advertising.
A4. Artificial intelligence
Some products use AI language models to generate replies. The relevant part of a conversation, the assistant's instructions and the most relevant passages from the customer's knowledge sources are sent to an AI model provider through its API, only at request time and only to produce that reply. Knowledge-search embeddings are produced by self-hosted models on our own infrastructure.
We do not use customer content, end customer data, or any data received from third-party platform APIs (including Google, Meta, Slack and commerce platforms) to train, fine-tune or improve generalized or non-personalized AI or machine learning models.
A5. Sub-processors
We share personal data only with the service providers below, only as needed to provide the Services, and under terms that require them to protect it:
| Category | Providers |
|---|---|
| Hosting and infrastructure | Hetzner Online (servers, Germany/EU); Cloudflare (CDN, network security, web hosting, R2 object storage) |
| AI language models | Groq, OpenRouter, Mistral AI, Google (Gemini), NVIDIA, Hetzner. One provider per request; others are fallbacks |
| Search reranking | Cohere |
| Speech-to-text / text-to-speech (only when voice is enabled) | Groq (Whisper), Deepgram, AssemblyAI, Google Cloud, Microsoft Azure Speech, ElevenLabs |
| Email delivery | Resend |
| Payments | Polar (merchant of record) |
| Push notifications | Expo push service, Apple Push Notification service, Firebase Cloud Messaging |
| Website analytics | Google Analytics 4 |
We may also disclose data when required by law or valid legal process, to protect the rights, property or safety of our users or the public, or as part of a merger, acquisition or asset sale, in which case the recipient remains bound by this policy.
A6. International transfers
Our primary infrastructure is in the European Union (Germany). Some sub-processors may process data in the United States or other countries. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and, for transfers from Turkey, the safeguards required under the Turkish Personal Data Protection Law (KVKK).
A7. Retention
- Account and workspace data: kept while the account or workspace is active.
- Customer content (conversations, leads, knowledge, catalogs): kept until the customer deletes it, deletes the workspace or deletes the account.
- Raw IP addresses of chat widget visitors: automatically erased after 30 days.
- Voice audio: not stored; processed transiently to produce a transcript.
- Credentials of connected platforms: deleted when the integration is disconnected or the account/workspace is deleted.
- Sales and support correspondence: kept for up to 3 years after the last contact.
- Billing records: kept as long as tax and accounting law requires.
- Deletion records: when an account is deleted, we keep a minimal record (email address, date and type of request) as evidence that the deletion was carried out.
A8. Security
- TLS encryption for all data in transit.
- OAuth tokens, API keys and channel credentials encrypted at rest with AES-256-GCM, with key rotation support.
- Passwords hashed with scrypt; httpOnly session cookies with CSRF protection; revocable sessions.
- Webhook signature verification for connected platforms.
- Strict workspace isolation, enforced on every request.
- Access to production systems is limited to personnel who need it.
If a personal data breach affects you, we will notify you and the relevant authorities as required by law (under GDPR, within 72 hours of becoming aware, where required).
A9. Your rights
Depending on where you live, laws such as the GDPR / UK GDPR, KVKK (Law No. 6698), CCPA/CPRA (California) and LGPD (Brazil) give you the right to:
- access your personal data and receive a copy;
- correct inaccurate data;
- delete your data (see Part D);
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- not be discriminated against for exercising your rights;
- lodge a complaint with a data protection authority (in Turkey, the Personal Data Protection Authority, KVKK).
To exercise these rights, email [email protected]. We respond within 30 days. California residents: we do not sell or share personal information as these terms are defined in the CCPA/CPRA, and we do not use sensitive personal information to infer characteristics about you.
A10. Children
Our Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.
A11. Changes
We will notify customers by email or in the product before material changes take effect. The "Last updated" date shows the current version.
Part B: Product-Specific Disclosures
B1. Salesvex website
- Forms: when you request a demo, contact sales, sign up for updates or apply for a job, we collect what you enter (such as name, email, phone, company, role and message) to respond to you.
- Analytics: we use Google Analytics 4 to understand how visitors use the site (pages viewed, approximate location, device and browser type). Analytics cookies are used only according to your choices in the cookie banner, and you can change them at any time through the cookie settings.
- Cookies: strictly necessary cookies (for example, theme, language and cookie consent choice) and, with your consent, analytics cookies. We do not use advertising cookies.
B2. Salesvex AI Assistant
Salesvex AI Assistant lets businesses build AI assistants that answer their customers on the website chat widget, email, Instagram, Facebook Messenger, WhatsApp, Telegram, Slack and Discord, using their own knowledge sources, product catalogs and connected tools.
- Account data: name, email, optional avatar, workspace and role. Sign-in with email and password, Google (
openid,email,profile) or Apple (name and email, which may be a private relay address). - Conversation data: messages, attachments, timestamps, channel and sender identifiers, and end customer profile data provided by the channel (display name, username, profile photo, email, phone).
- Chat widget visitors: messages; data entered in the optional pre-chat form (name, email, phone); IP address, browser user agent and approximate country and city derived locally from the IP address (no external geolocation service). Raw IP addresses are erased after 30 days. Visitors are shown a notice before chatting that conversations are recorded and processed by service providers.
- Leads and customers: records created from conversations (name, email, phone, city, country, notes).
- Knowledge data: documents, web pages, files you select from Google Drive, public Google Sheets and product catalogs. Content is split into passages, embedded by self-hosted models and stored in a search index dedicated to your workspace.
- Voice (optional): when voice chat is enabled, microphone audio is sent to a speech-to-text provider; replies may be converted to speech. Audio is not stored; only the text transcript is saved.
- AI meeting feature (optional): the participant's webcam video is analyzed in the participant's browser to estimate engagement signals (facial expression estimates, eye movement, liveness score). Raw video is not uploaded or stored; only the derived scores are stored with the meeting record. These signals may be considered biometric or sensitive data in some jurisdictions. The business running the meeting must inform participants and obtain any required explicit consent, and participants may keep their camera off.
- Cookies and browser storage: only strictly necessary items: authentication cookies (
accessToken,refreshToken, session cookie; httpOnly), a CSRF token, preferences (workspace, language, display mode, cookie consent), and on the chat widget, a session identifier and the visitor's consent choice. No advertising cookies, tracking pixels or third-party analytics.
B3. Salesvex Inbox mobile app (iOS and Android)
- Purpose: lets a business's team read and answer conversations from Salesvex AI Assistant, manage assistants and knowledge, and receive new-message notifications.
- Sign-in: email and password, or browser-based sign-in with a Salesvex account (OAuth 2.0 with PKCE).
- Permissions (all optional):
- Photo library: only to pick an avatar image for an assistant.
- Files: only to upload documents you pick as knowledge sources.
- Notifications: to alert you about new messages. You can turn them off in the app or in device settings.
- The app does not access the camera, microphone, location, contacts or biometric data.
- Stored on the device in encrypted secure storage: sign-in tokens, selected workspace, language, push token and display settings. They are removed when you sign out or uninstall the app.
- Push tokens: your device's push token and device name are sent to our servers to deliver notifications and are deleted when you sign out or delete your account.
- No tracking: the app does not track you across other companies' apps or websites, contains no advertising or third-party analytics SDKs, and does not request App Tracking Transparency permission.
- Data collected (App Store / Google Play disclosures): name, email address, user ID, device ID (push token), photos you choose as avatars, and user content (messages, knowledge files). All of it is linked to your account, used only for app functionality, and not shared with third parties for their own purposes. Data is encrypted in transit.
- Account deletion: in the app under Settings → Delete account, or on the web (see Part D).
Part C: Third-Party Platform Integrations
We access a third-party platform only after a customer explicitly connects it, only within the permissions listed below, and only to provide the feature the customer enabled. Customers can disconnect any integration at any time, which stops access and deletes the stored credentials.
C1. Google
Limited Use disclosure: Salesvex's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
| Google API / scope | What we use it for |
|---|---|
Google Sign-In (openid, email, profile) | Creating your account, signing you in, and showing which Google account is connected. |
Gmail (https://www.googleapis.com/auth/gmail.modify) | Receiving new emails in the connected mailbox through Gmail push notifications, reading them so the AI assistant can answer customer emails, and sending the assistant's replies from the connected mailbox in the same thread. Conversations are shown in the product's Inbox. |
Google Calendar (https://www.googleapis.com/auth/calendar.events) | Checking availability and creating (with a Google Meet link and the customer as attendee), rescheduling or cancelling appointments that customers book through the assistant. |
Google Drive (https://www.googleapis.com/auth/drive.file) | Accessing only the files you explicitly select, to use them as knowledge sources. We cannot see any other files in your Drive. |
| Google Sheets (public links) | Reading public spreadsheets you add by link, with an API key. No access to private files. |
How we treat Google user data:
- It is used only to provide or improve user-facing features that are prominent in the product's interface.
- It is not used for serving advertisements, including retargeting, personalized or interest-based ads.
- It is not sold, and not transferred to third parties except as necessary to provide or improve user-facing features (for example, sending an email's content to an AI model API to generate the reply you configured), to comply with applicable law, for security purposes, or as part of a merger or acquisition with notice to users.
- Humans do not read it unless (a) you give explicit consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required by law, or (d) it has been aggregated and anonymized for internal operations.
- It is not used, raw or derived, to develop, improve or train generalized or non-personalized AI/ML models.
- It is not used to determine creditworthiness or for lending.
You can revoke access at any time from the product or at myaccount.google.com/permissions.
C2. Meta (Facebook Messenger, Instagram, WhatsApp)
| Product | Permissions |
|---|---|
| Messenger / Facebook Pages | pages_messaging, pages_manage_metadata, pages_read_engagement, pages_show_list, public_profile, business_management |
instagram_business_basic, instagram_business_manage_messages (Instagram Login) or instagram_basic, instagram_manage_messages (Facebook Login) | |
whatsapp_business_management, whatsapp_business_messaging |
We use these permissions to list the Pages and accounts you choose to connect, subscribe them to message webhooks, receive incoming messages, send replies from the assistant and your team, and show the sender's public name and profile photo in the Inbox. We do not post to your Page or feed, do not access your personal profile beyond basic identity, and do not use Meta Platform Data for advertising, profiling or model training. We comply with the Meta Platform Terms, the Meta Developer Policies and the WhatsApp Business messaging policies.
Deauthorization and data deletion: if you remove our app in your Facebook or Instagram settings, Meta notifies us and we disable the connection and erase the stored credentials. You can also request deletion of data received through Meta (see Part D).
C3. Apple
If you use Sign in with Apple, we receive only your name and email address (or Apple's private relay email) to create and sign in to your account. We do not use Apple-provided data for any other purpose.
C4. Slack and Discord
- Slack (
channels:history,channels:read,groups:history,groups:read,im:history,im:read,im:write,chat:write,users:read,app_mentions:read): to receive messages in channels and direct messages where the assistant is added or mentioned, reply to them, and show the sender's name. - Discord (
bot,applications.commands): to receive messages and commands sent to the assistant's bot in the servers where it is installed, and reply to them.
C5. Telegram
You connect a Telegram bot by providing its bot token. We receive messages sent to that bot, send the assistant's replies, and may show the sender's public name and profile photo.
C6. E-commerce platforms (Shopify, ikas, WooCommerce)
| Platform | Permissions |
|---|---|
| Shopify | read_products, read_orders, write_draft_orders, read_customers, write_customers, read_inventory, read_fulfillments, read_discounts, write_discounts, read_checkouts, write_checkouts, read_shipping, read_returns, write_returns |
| ikas | read_products, read_orders, write_orders, read_customers, read_inventories, write_inventories |
| WooCommerce | REST API key provided by the merchant |
We use this data so the assistant can recommend products, answer stock and price questions, look up an order's status for the customer who placed it, and, if the merchant enables it, create draft orders, discount codes, checkout links or return requests. Catalog sync stays off until the merchant enables it. Store customer data is processed only on the merchant's behalf, is never used for advertising or sold, and is deleted when the merchant uninstalls the app or deletes the workspace.
C7. CRM and scheduling (HubSpot, Calendly)
- HubSpot: contacts (read/write), companies (read), deals (read/write), tickets, owners and, optionally, leads. Used to create or update records from conversations and to look up existing records so the assistant can personalize replies.
- Calendly: used to read your event types and availability and show booking options to customers.
C8. Other tool connectors (MCP)
Customers can connect additional tools (for example web search, documentation, form or helpdesk services) through the Model Context Protocol. When the assistant uses such a tool, the query and any data it needs are sent to that provider under the customer's agreement with that provider.
Part D: How to Delete Your Data
- Delete your account on the web: Salesvex AI Assistant → Settings → Profile → Delete account.
- Delete your account in the mobile app: Salesvex Inbox → Settings → Delete account.
Deleting your account permanently deletes:
- your profile, sessions, push devices, consents and notifications;
- workspaces you solely own, together with their conversations, leads, knowledge, catalog data and connected integrations, including stored tokens.
It also cancels any active subscription and transfers shared workspaces to another member. Deletion from backups completes within 30 days.
- Disconnect an integration: in the product's Channels, Extensions or Integrations page. We stop accessing the platform immediately and delete the stored credentials. You can also revoke access from the platform itself (Google Account permissions, Facebook/Instagram "Apps and websites", Shopify admin → Apps).
- Meta data deletion: remove "Salesvex" in Facebook or Instagram settings under "Apps and websites", or email [email protected]. You will receive a confirmation code to check the status of your request.
- Export your data: Settings → Profile → Export my data, or email [email protected].
- End customers (people who chatted with a business's assistant): contact that business, or email [email protected] with the channel you used and your identifier (email, phone number or username). We will forward the request to the business and help with the deletion.
- Website and sales contacts: email [email protected] to have your form submissions and correspondence deleted.
تواصل مع فريق الخصوصية
إذا كانت لديك أسئلة حول إشعار الخصوصية هذا أو ممارسات البيانات لدينا، يرجى التواصل مع فريق الخصوصية.
تواصل مع فريق الخصوصية →