Privacy Policy

Last updated: 25.11.2025

This Privacy Policy explains how Inveon (“Inveon”, “we”, “us”, or “our”) collects, uses, and shares information when you use inveon.ai (inveon.ai website),  our related dashboards, browser extensions, integrations, communication channels (such as email or messaging apps), and any other services we operate (collectively, the “Services”).

By accessing or using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. Your use of the Services is also subject to our Terms and Conditions.

Important: inveon.ai is designed for business use (e.g. e-commerce brands, retailers, agencies). It is not intended for children or for processing highly sensitive personal data such as health, financial, or government ID numbers.


1. Information We Collect

We collect information in three main ways: (a) information you provide directly, (b) information automatically collected when you use the Services, and (c) (c) information we receive from third parties, including Google APIs when you grant access. We access Google Analytics and Google Ads data only after you explicitly grant permission through the Google OAuth consent screen. This Privacy Policy applies to all permissions and data access requested through the Google OAuth consent screen.

1.1 Information You Provide


Account & Profile Information
When you create an account or are invited by your organization, we may collect:

  • Name and surname

  • Business email address

  • Role / job title

  • Company name and basic company info

  • Password or authentication information (or via SSO provider)

    Workspace & Organization Information
    If you onboard your company to inveon.ai, we may collect:

  • Business contact details, billing contact, and team structure

  • E-commerce platform details (e.g., Shopify store URL, inCommerce instance, etc.)

  • Configuration parameters, preferences, user roles and permission settings

Prompts, Inputs and Content
When you interact with our AI agents, you may provide:

  • Text prompts, instructions, uploaded files, links, or snippets of your data

  • Feedback, comments, or examples used to refine outputs
    This content may include non-personal business data such as:

  • Product catalog and merchandising data

  • Campaign plans and performance metrics

  • Analytics exports or reports
    You are responsible for ensuring you have the right to share such content with us.


Support & Communication
When you contact us (e.g. email, forms, chat, event registrations), we may collect:

  • Contact details

  • The content of your message and attachments

  • Any feedback or survey responses


Billing & Payment Information
For paid plans, we may collect or receive:

  • Billing contact name and details

  • Tax and invoicing information

  • Subscription details (plan type, billing period)
    Payment card data is typically processed by our third-party payment provider and not stored by us directly (except limited metadata like last 4 digits, card type).

1.2 Information Collected Automatically

When you use the Services, we automatically collect certain information to operate, secure, and improve inveon.ai, such as:

Device & Log Information

  • IP address

  • Browser type and version

  • Operating system

  • Device identifiers

  • Date/time stamps of access

  • Pages viewed, features used, and referring/exit pages


Usage & Interaction Data

  • Which agents you interact with and how often

  • Clicks, navigation events, and feature usage

  • Performance metrics and error logs

We may use first-party cookies, local storage, and similar technologies to remember your settings, maintain sessions, and analyze usage. More details can be provided in a separate Cookie Notice.

1.3 Information from Third Parties and Integrations

To deliver the Services, inveon.ai may connect to third-party systems. When you authorize such connections, we may receive information from:


E-commerce & Marketing Platforms
(e.g. Shopify, inCommerce, Google Analytics, Google Ads, Meta Ads, email marketing tools, etc.), such as:

  • Order and transaction data

  • Product and inventory data

  • Campaigns and performance metrics

  • Web analytics and events

Authentication & Identity Providers
If you sign in with SSO or identity providers (e.g. Google, Microsoft, custom SSO), we may receive:

  • Your name, email, avatar, and organization metadata allowed by the provider.


Service Providers & Partners
We may receive limited business contact information or account information from:

  • CRM tools, marketing automation tools, or sales platforms

  • Strategic partners or referral partners (e.g. agencies, solution integrators)

Revocation

You can disconnect any integration at any time through the respective platform or by contacting us.


Google User Data 

When you connect your Google Analytics or Google Ads account to inveon.ai, we receive data strictly within the permission scopes you authorize during OAuth.

These scopes are:

(A) /auth/analytics.readonly — Google Analytics (GA4)

Allows us to:

  • Read analytics reports

  • Access performance metrics

  • Access events, sessions, conversions


We do NOT:

  • Modify or change GA4 settings

  • Send instructions to GA4

  • Create or edit GA4 properties

  • Access personally identifiable visitor data


No Collection of Personally Identifiable Information (PII) from Google Analytics

inveon.ai does not receive, collect, or process any personally identifiable information (PII) from Google Analytics.
We only access aggregated and non-PII data such as events, sessions, conversions, traffic sources, and performance metrics.


We do not use or store:

  • Email addresses

  • Names

  • Phone numbers

  • Precise location

  • Financial or payment information

  • Government identifiers

  • Any user-level identifiers that could be tied to an individual person

We rely solely on non-PII analytics data, consistent with Google Analytics terms and Google’s API Services User Data Policy.

If a Google Analytics property is misconfigured to send PII, that data is not processed by Inveon and should be removed by the customer in accordance with Google Analytics policies.

This scope is read-only.

(B) /auth/adwords — Google Ads API


Allows us to:

  • Read Google Ads campaign performance

  • Read account structure and settings

  • Analyze keywords, budgets, bidding

  • Suggest optimization actions

  • Create or edit campaigns, ad groups, keywords

  • Only when you explicitly trigger an action inside inveon.ai

We never modify campaigns automatically without user approval.

Google Limited Use Compliance

Our access, storage, and use of Google user data complies with:

Google API Services User Data Policy
(including the Limited Use policy)
https://developers.google.com/terms/api-services-user-data-policy


We do NOT:

  • Sell Google user data

  • Transfer Google user data to third parties

  • Use Google data for advertising

  • Use Google data to build user profiles unrelated to your account

  • Use Google data to train external or internal AI models

  • Use Google data to build generalized datasets

  • Use Google data for any purpose not explicitly described here

Human Access to Google User Data

Inveon follows strict controls over access to Google Analytics and Google Ads data, consistent with the Google API Services User Data Policy.

No Routine Human Access

We do not allow employees, contractors, or support staff to access Google user data unless an allowed exception applies.
Google user data is not reviewed, examined, or manually processed in normal operations.


Allowed Exceptions

Human access may occur only in these limited situations:

  1. With your explicit, informed consent
    — For example, when you request troubleshooting or support that requires viewing specific data.

  2. For security or abuse investigations
    — Only to detect, prevent, or respond to security issues, fraud, attacks, or service abuse.

  3. To comply with legal obligations
    — When we are required by applicable law or legal process.

  4. Aggregated or de-identified data
    — We may review anonymized or aggregated forms that do not contain identifiable Google user data.

Internal Controls

When an allowed exception applies:

  • Access is restricted to a minimal set of authorized personnel.

  • All access is logged and monitored.

  • Access is read-only unless required for the specific support request.

  • Access is revoked immediately after the issue is resolved.

No Other Human Access Permitted

We do not:

  • Allow human access for product development

  • Review raw Google user data for AI model training

  • Use human reviewers to annotate, classify, or label Google data

  • Share data with contractors unless strictly within the exceptions and under binding confidentiality terms

These restrictions apply to both personal and business Google data.

2. How We Use the Information We Collect

We use the information we collect for the following purposes:

  1. Providing and Operating the Services

    • Creating and managing user accounts and workspaces

    • Enabling AI agents to analyze your authorized data and provide suggestions

    • Executing workflows and automations you approve (e.g. campaign adjustments)

  2. Improving and Developing the Services

    • Understanding how the product is used to improve UX and reliability

    • Debugging, monitoring, and detecting incidents

    • Training internal models or rule systems on aggregated and/or de-identified usage patterns to improve suggestions and features

  3. Personalizing the Experience

    • Tailoring recommendations based on your role (e.g. C-level vs specialist)

    • Surfacing relevant dashboards, alerts, or actions based on your context

  4. Security, Fraud Prevention, and Compliance

    • Monitoring for suspicious or abusive behavior

    • Protecting the integrity of connections between inveon.ai and your systems

    • Complying with legal obligations and enforcing our Terms and policies

  5. Communication & Support

    • Sending service-related notifications (e.g. onboarding, security alerts, feature updates)

    • Responding to support requests and feedback

    • Sending product updates, event invitations, or marketing communications (where permitted by law and your preferences)

  6. Legal and Business Purposes

    • Protecting our rights, privacy, safety, and property, and that of our users or others

    • Supporting corporate transactions such as mergers, acquisitions, or restructuring

We rely on various legal bases to process your data, including contract performance, legitimate interest, compliance with legal obligations, and consent where applicable.


3. AI Providers and Data Processing

inveon.ai uses large language models and other AI infrastructure provided by third-party providers (for example, OpenAI or similar providers), as well as Inveon’s own AI systems.

  • We only send data to AI providers that is necessary to generate responses or enable the requested feature.

  • We aim to configure our AI providers so that your business data is not used to train their public models, to the extent such options are available and within our control.

  • We may use aggregated, de-identified usage data to improve our own models, features, and best-practice libraries.

Exact vendor list and data handling practices may be provided in an annex or updated from time to time.


4. How We Share Information

We do not sell your personal information. We may share information in the following situations:

  1. Within Inveon Group
    With our parent company, subsidiaries, and affiliates, where necessary to operate the Services and for internal administration, in line with this Policy.

  2. Service Providers (Processors)
    With trusted third-party vendors helping us deliver the Services, such as:

    • Cloud hosting and infrastructure providers

    • AI/ML service providers

    • Authentication and security services

    • Analytics and error-tracking tools

    • Payment processors and billing platforms

    • Email and communication tools

  3. These providers are bound by contractual obligations to process data only as instructed by us and to protect it.

  4. Your Organization and Authorized Users

    • If you use inveon.ai under a corporate or team account, your usage and content may be visible to your organization’s administrators or other authorized team members, according to the settings and governance rules of your workspace.

  5. Business Transfers
    In connection with any merger, acquisition, financing, sale of assets, or other similar transaction, your information may be transferred as part of the business assets, subject to appropriate confidentiality protections and continuity of protections.

  6. Legal and Safety Obligations
    We may access, preserve, or disclose information if we believe it is reasonably necessary to:

    • Comply with applicable laws or legal processes

    • Respond to lawful requests by authorities

    • Enforce our Terms and other agreements

    • Protect the rights, property, or safety of Inveon, our users, or others

  7. With Your Consent
    We may share information with third parties when you expressly direct or consent to such sharing (e.g. connecting a new integration, participating in a joint case study, etc.).

5. Your Choices and Rights

Depending on your location and applicable law (e.g. GDPR, UK GDPR, certain U.S. state laws), you may have the following rights:

  • Access – Request a copy of the personal data we hold about you.

  • Correction – Request that we correct inaccurate or incomplete data.

  • Deletion – Request deletion of your personal data, subject to legal and contractual obligations.

  • Restriction / Objection – Request we limit or stop certain processing.

  • Portability – Request a copy of your data in a structured, commonly used format.

  • Consent Management – Where processing is based on consent, you can withdraw consent at any time (this may affect your ability to use certain features)

You can exercise many of these controls by:

  • Updating your profile and settings within inveon.ai, and/or

  • Contacting us at [email protected]

We may need to verify your identity before fulfilling certain requests and may deny a request where we are legally or contractually required to retain data.

You may also have the right to contact or lodge a complaint with your local data protection authority.

6. Data Retention

We retain personal data for as long as necessary to:

  • Provide the Services and fulfill the purposes described above

  • Comply with legal and regulatory obligations

  • Resolve disputes and enforce our agreements

In-Product Privacy Notices

Inveon provides clear and prominent in-product privacy notices before you connect Google Analytics or Google Ads to the platform. These notices explain:

  • What specific Google data will be accessed

  • How the data will be used within the product

  • Which features rely on Google Analytics or Google Ads data

  • Any Google Ads actions that require explicit user confirmation

  • How you can disconnect the integration at any time

These notices appear directly in the integration flow, before access is granted, and are always available for review in the integration settings.

We do not request access to Google data without first presenting a transparent, user-facing explanation and obtaining your explicit permission.


Retention While Connected

We retain only the minimum Google Analytics and Google Ads data necessary to operate the features you actively use within inveon.ai.

  • Google user data is stored in encrypted form on secure servers.

  • We do not store full historical datasets unless you explicitly initiate an action (such as exporting data, saving reports, or pinning metrics to a dashboard).

  • We may process anonymized or aggregated data that no longer identifies you, and we may use such information for legitimate business purposes as described in this Policy.

If you revoke access or delete the connection:

  • All OAuth tokens and cached Google data are deleted within 30 days.

User-Initiated Deletion

You may revoke Inveon’s access to Google services at any time through:
https://myaccount.google.com/permissions


You may also request deletion of remaining data associated with your account by contacting us at [email protected].

7. International Data Transfers

Inveon is headquartered in İstanbul, Türkiye and we may process data in other countries where we or our providers operate. This may mean your data is transferred to countries that may not have the same data protection laws as your home jurisdiction.

Where required by law, we implement appropriate safeguards (such as standard contractual clauses) to protect your information in cross-border transfers.


8. Security

We use technical and organizational measures designed to protect your information, such as:

  • Encrypted communications (e.g. HTTPS/TLS)

  • Access controls and authentication

  • Regular monitoring, logging, and backups

  • Limiting access to personal data to authorized personnel and service providers

However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials.

9. Children’s Privacy

The Services are not intended for, and we do not knowingly collect personal information from, individuals under the age of 18. If you believe a child has provided us with personal information, please contact us at [email protected] and we will take appropriate steps to delete such information.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the Services, by email, or by other reasonable means. The “Last updated” date at the top of this page indicates when it was last revised.

Your continued use of the Services after any changes become effective will constitute your acceptance of the revised Policy.


11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can contact us at:

C/O Srm, 59, Terrington Hill, Marlow, Buckinghamshire, England, SL7 2RE
Email: [email protected]