Privacy Policy
Last updated: 25.11.2025
This Privacy Policy explains how Inveon (“Inveon”, “we”, “us”, or “our”) collects, uses, and shares information when you use inveon.ai (inveon.ai website), our related dashboards, browser extensions, integrations, communication channels (such as email or messaging apps), and any other services we operate (collectively, the “Services”).
By accessing or using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. Your use of the Services is also subject to our Terms and Conditions.
Important: inveon.ai is designed for business use (e.g. e-commerce brands, retailers, agencies). It is not intended for children or for processing highly sensitive personal data such as health, financial, or government ID numbers.
1. Information We Collect
We collect information in three main ways: (a) information you provide directly, (b) information automatically collected when you use the Services, and (c) (c) information we receive from third parties, including Google APIs when you grant access. We access Google Analytics and Google Ads data only after you explicitly grant permission through the Google OAuth consent screen. This Privacy Policy applies to all permissions and data access requested through the Google OAuth consent screen.
1.1 Information You Provide
Account & Profile Information
When you create an account or are invited by your organization, we may collect:
Name and surname
Business email address
Role / job title
Company name and basic company info
Password or authentication information (or via SSO provider)
Workspace & Organization Information
If you onboard your company to inveon.ai, we may collect:Business contact details, billing contact, and team structure
E-commerce platform details (e.g., Shopify store URL, inCommerce instance, etc.)
Configuration parameters, preferences, user roles and permission settings
Prompts, Inputs and Content
When you interact with our AI agents, you may provide:
Text prompts, instructions, uploaded files, links, or snippets of your data
Feedback, comments, or examples used to refine outputs
This content may include non-personal business data such as:Product catalog and merchandising data
Campaign plans and performance metrics
Analytics exports or reports
You are responsible for ensuring you have the right to share such content with us.
Support & Communication
When you contact us (e.g. email, forms, chat, event registrations), we may collect:
Contact details
The content of your message and attachments
Any feedback or survey responses
Billing & Payment Information
For paid plans, we may collect or receive:
Billing contact name and details
Tax and invoicing information
Subscription details (plan type, billing period)
Payment card data is typically processed by our third-party payment provider and not stored by us directly (except limited metadata like last 4 digits, card type).
1.2 Information Collected Automatically
When you use the Services, we automatically collect certain information to operate, secure, and improve inveon.ai, such as:
Device & Log Information
IP address
Browser type and version
Operating system
Device identifiers
Date/time stamps of access
Pages viewed, features used, and referring/exit pages
Usage & Interaction Data
Which agents you interact with and how often
Clicks, navigation events, and feature usage
Performance metrics and error logs
We may use first-party cookies, local storage, and similar technologies to remember your settings, maintain sessions, and analyze usage. More details can be provided in a separate Cookie Notice.
1.3 Information from Third Parties and Integrations
To deliver the Services, inveon.ai may connect to third-party systems. When you authorize such connections, we may receive information from:
E-commerce & Marketing Platforms
(e.g. Shopify, inCommerce, Google Analytics, Google Ads, Meta Ads, email marketing tools, etc.), such as:
Order and transaction data
Product and inventory data
Campaigns and performance metrics
Web analytics and events
Authentication & Identity Providers
If you sign in with SSO or identity providers (e.g. Google, Microsoft, custom SSO), we may receive:
Your name, email, avatar, and organization metadata allowed by the provider.
Service Providers & Partners
We may receive limited business contact information or account information from:
CRM tools, marketing automation tools, or sales platforms
Strategic partners or referral partners (e.g. agencies, solution integrators)
Revocation
You can disconnect any integration at any time through the respective platform or by contacting us.
Google User Data
When you connect your Google Analytics or Google Ads account to inveon.ai, we receive data strictly within the permission scopes you authorize during OAuth.
These scopes are:
(A) /auth/analytics.readonly — Google Analytics (GA4)
Allows us to:
Read analytics reports
Access performance metrics
Access events, sessions, conversions
We do NOT:
Modify or change GA4 settings
Send instructions to GA4
Create or edit GA4 properties
Access personally identifiable visitor data
No Collection of Personally Identifiable Information (PII) from Google Analytics
inveon.ai does not receive, collect, or process any personally identifiable information (PII) from Google Analytics.
We only access aggregated and non-PII data such as events, sessions, conversions, traffic sources, and performance metrics.
We do not use or store:
Email addresses
Names
Phone numbers
Precise location
Financial or payment information
Government identifiers
Any user-level identifiers that could be tied to an individual person
We rely solely on non-PII analytics data, consistent with Google Analytics terms and Google’s API Services User Data Policy.
If a Google Analytics property is misconfigured to send PII, that data is not processed by Inveon and should be removed by the customer in accordance with Google Analytics policies.
This scope is read-only.
(B) /auth/adwords — Google Ads API
Allows us to:
Read Google Ads campaign performance
Read account structure and settings
Analyze keywords, budgets, bidding
Suggest optimization actions
Create or edit campaigns, ad groups, keywords
Only when you explicitly trigger an action inside inveon.ai
We never modify campaigns automatically without user approval.
Google Limited Use Compliance
Our access, storage, and use of Google user data complies with:
Google API Services User Data Policy
(including the Limited Use policy)
https://developers.google.com/terms/api-services-user-data-policy
We do NOT:
Sell Google user data
Transfer Google user data to third parties
Use Google data for advertising
Use Google data to build user profiles unrelated to your account
Use Google data to train external or internal AI models
Use Google data to build generalized datasets
Use Google data for any purpose not explicitly described here
Human Access to Google User Data
Inveon follows strict controls over access to Google Analytics and Google Ads data, consistent with the Google API Services User Data Policy.
No Routine Human Access
We do not allow employees, contractors, or support staff to access Google user data unless an allowed exception applies.
Google user data is not reviewed, examined, or manually processed in normal operations.
Allowed Exceptions
Human access may occur only in these limited situations:
With your explicit, informed consent
— For example, when you request troubleshooting or support that requires viewing specific data.For security or abuse investigations
— Only to detect, prevent, or respond to security issues, fraud, attacks, or service abuse.To comply with legal obligations
— When we are required by applicable law or legal process.Aggregated or de-identified data
— We may review anonymized or aggregated forms that do not contain identifiable Google user data.
Internal Controls
When an allowed exception applies:
Access is restricted to a minimal set of authorized personnel.
All access is logged and monitored.
Access is read-only unless required for the specific support request.
Access is revoked immediately after the issue is resolved.
No Other Human Access Permitted
We do not:
Allow human access for product development
Review raw Google user data for AI model training
Use human reviewers to annotate, classify, or label Google data
Share data with contractors unless strictly within the exceptions and under binding confidentiality terms
These restrictions apply to both personal and business Google data.
2. How We Use the Information We Collect
We use the information we collect for the following purposes:
Providing and Operating the Services
Creating and managing user accounts and workspaces
Enabling AI agents to analyze your authorized data and provide suggestions
Executing workflows and automations you approve (e.g. campaign adjustments)
Improving and Developing the Services
Understanding how the product is used to improve UX and reliability
Debugging, monitoring, and detecting incidents
Training internal models or rule systems on aggregated and/or de-identified usage patterns to improve suggestions and features
Personalizing the Experience
Tailoring recommendations based on your role (e.g. C-level vs specialist)
Surfacing relevant dashboards, alerts, or actions based on your context
Security, Fraud Prevention, and Compliance
Monitoring for suspicious or abusive behavior
Protecting the integrity of connections between inveon.ai and your systems
Complying with legal obligations and enforcing our Terms and policies
Communication & Support
Sending service-related notifications (e.g. onboarding, security alerts, feature updates)
Responding to support requests and feedback
Sending product updates, event invitations, or marketing communications (where permitted by law and your preferences)
Legal and Business Purposes
Protecting our rights, privacy, safety, and property, and that of our users or others
Supporting corporate transactions such as mergers, acquisitions, or restructuring
We rely on various legal bases to process your data, including contract performance, legitimate interest, compliance with legal obligations, and consent where applicable.
3. AI Providers and Data Processing
inveon.ai uses large language models and other AI infrastructure provided by third-party providers (for example, OpenAI or similar providers), as well as Inveon’s own AI systems.
We only send data to AI providers that is necessary to generate responses or enable the requested feature.
We aim to configure our AI providers so that your business data is not used to train their public models, to the extent such options are available and within our control.
We may use aggregated, de-identified usage data to improve our own models, features, and best-practice libraries.
Exact vendor list and data handling practices may be provided in an annex or updated from time to time.
4. How We Share Information
We do not sell your personal information. We may share information in the following situations:
Within Inveon Group
With our parent company, subsidiaries, and affiliates, where necessary to operate the Services and for internal administration, in line with this Policy.Service Providers (Processors)
With trusted third-party vendors helping us deliver the Services, such as:Cloud hosting and infrastructure providers
AI/ML service providers
Authentication and security services
Analytics and error-tracking tools
Payment processors and billing platforms
Email and communication tools
These providers are bound by contractual obligations to process data only as instructed by us and to protect it.
Your Organization and Authorized Users
If you use inveon.ai under a corporate or team account, your usage and content may be visible to your organization’s administrators or other authorized team members, according to the settings and governance rules of your workspace.
Business Transfers
In connection with any merger, acquisition, financing, sale of assets, or other similar transaction, your information may be transferred as part of the business assets, subject to appropriate confidentiality protections and continuity of protections.Legal and Safety Obligations
We may access, preserve, or disclose information if we believe it is reasonably necessary to:Comply with applicable laws or legal processes
Respond to lawful requests by authorities
Enforce our Terms and other agreements
Protect the rights, property, or safety of Inveon, our users, or others
With Your Consent
We may share information with third parties when you expressly direct or consent to such sharing (e.g. connecting a new integration, participating in a joint case study, etc.).
5. Your Choices and Rights
Depending on your location and applicable law (e.g. GDPR, UK GDPR, certain U.S. state laws), you may have the following rights:
Access – Request a copy of the personal data we hold about you.
Correction – Request that we correct inaccurate or incomplete data.
Deletion – Request deletion of your personal data, subject to legal and contractual obligations.
Restriction / Objection – Request we limit or stop certain processing.
Portability – Request a copy of your data in a structured, commonly used format.
Consent Management – Where processing is based on consent, you can withdraw consent at any time (this may affect your ability to use certain features)
You can exercise many of these controls by:
Updating your profile and settings within inveon.ai, and/or
Contacting us at [email protected]
We may need to verify your identity before fulfilling certain requests and may deny a request where we are legally or contractually required to retain data.
You may also have the right to contact or lodge a complaint with your local data protection authority.
6. Data Retention
We retain personal data for as long as necessary to:
Provide the Services and fulfill the purposes described above
Comply with legal and regulatory obligations
Resolve disputes and enforce our agreements
In-Product Privacy Notices
Inveon provides clear and prominent in-product privacy notices before you connect Google Analytics or Google Ads to the platform. These notices explain:
What specific Google data will be accessed
How the data will be used within the product
Which features rely on Google Analytics or Google Ads data
Any Google Ads actions that require explicit user confirmation
How you can disconnect the integration at any time
These notices appear directly in the integration flow, before access is granted, and are always available for review in the integration settings.
We do not request access to Google data without first presenting a transparent, user-facing explanation and obtaining your explicit permission.
Retention While Connected
We retain only the minimum Google Analytics and Google Ads data necessary to operate the features you actively use within inveon.ai.
Google user data is stored in encrypted form on secure servers.
We do not store full historical datasets unless you explicitly initiate an action (such as exporting data, saving reports, or pinning metrics to a dashboard).
We may process anonymized or aggregated data that no longer identifies you, and we may use such information for legitimate business purposes as described in this Policy.
If you revoke access or delete the connection:
All OAuth tokens and cached Google data are deleted within 30 days.
User-Initiated Deletion
You may revoke Inveon’s access to Google services at any time through:
https://myaccount.google.com/permissions
You may also request deletion of remaining data associated with your account by contacting us at [email protected].
7. International Data Transfers
Inveon is headquartered in İstanbul, Türkiye and we may process data in other countries where we or our providers operate. This may mean your data is transferred to countries that may not have the same data protection laws as your home jurisdiction.
Where required by law, we implement appropriate safeguards (such as standard contractual clauses) to protect your information in cross-border transfers.
8. Security
We use technical and organizational measures designed to protect your information, such as:
Encrypted communications (e.g. HTTPS/TLS)
Access controls and authentication
Regular monitoring, logging, and backups
Limiting access to personal data to authorized personnel and service providers
However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials.
9. Children’s Privacy
The Services are not intended for, and we do not knowingly collect personal information from, individuals under the age of 18. If you believe a child has provided us with personal information, please contact us at [email protected] and we will take appropriate steps to delete such information.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the Services, by email, or by other reasonable means. The “Last updated” date at the top of this page indicates when it was last revised.
Your continued use of the Services after any changes become effective will constitute your acceptance of the revised Policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can contact us at:
C/O Srm, 59, Terrington Hill, Marlow, Buckinghamshire, England, SL7 2RE
Email: [email protected]