Privacy Policy

Introduction

At Verve AI, your privacy and data security are fundamental to everything we do. This policy explains how we collect, use, and safeguard your information — and your rights under UK GDPR, EU GDPR, and related privacy regulations.

Verve AI provides inventory forecasting and planning tools for e-commerce merchants, including integrations with Shopify and WooCommerce.

Verve AI is built using secure, modern infrastructure:

  • Supabase (secure backend database and authentication)

  • OpenAI (AI engine for forecasting and analysis)

  • Shopify API (for Shopify store integrations)

  • WooCommerce REST API (for WooCommerce store integrations)

All providers are globally trusted and adhere to strict security and compliance standards.

What We Collect

Depending on the platform you connect (Shopify or WooCommerce), Verve AI may collect the following data:

Account & Access Data

  • Name and email address

  • Store name and store domain / URL

  • Platform identifier (Shopify or WooCommerce)

  • Subscription and billing status

Store & Inventory Data

  • Product and variant data (SKUs, titles, options)

  • Inventory quantities

  • Supplier lead-time inputs (if provided)

  • Historical order and sales data (line-item level)

App Usage Data

  • Forecast inputs and adjustments

  • Feature usage and interaction data

  • Error logs and performance metrics

  • Optional feedback (support requests, surveys)

What We Do Not Collect

Verve AI does not collect or store:

  • Customer personal data (customer names, emails, addresses)

  • Payment card or checkout data

  • Shopify or WooCommerce admin passwords

  • WordPress administrator credentials

  • Sensitive personal data (medical, legal, biometric, etc.)

Where order data is processed, it is used only in aggregated or anonymized form for forecasting purposes.

How We Use Your Data

We use your data only to:

  • Generate inventory and demand forecasts

  • Identify sales trends and stock risks

  • Improve forecasting accuracy and system reliability

  • Enhance product features and user experience

  • Provide customer support when requested

We may review aggregated or anonymized data internally to improve algorithms and system performance.

We do not:

  • Sell, rent, or monetize your data

  • Use your data for advertising or marketing

  • Train OpenAI’s public or shared models on your data

  • Share your data with third parties beyond required infrastructure providers

Platform-Specific Notes

Shopify

  • Data is accessed via the Shopify API using OAuth-based authorization

  • Verve AI follows Shopify’s API usage, data protection, and app-store requirements

  • Customer personal data is not stored

WooCommerce

  • Data is accessed via the WooCommerce REST API using API keys generated by the store owner

  • Verve AI only accesses the minimum scopes required for forecasting

  • WordPress admin credentials are never stored

  • API access can be revoked by the merchant at any time

Data Protection & Infrastructure

Verve AI enforces strong security controls, including:

  • GDPR-compliant infrastructure

  • TLS encryption for data in transit

  • AES-256 encryption for data at rest

  • Role-based access control

  • Logged and monitored system access

  • Least-privilege internal access policies

  • OpenAI API logging disabled where applicable to prevent data retention

Only authorized personnel can access production data, and only when required for support or maintenance.

AI Forecasting Limitations

Verve AI provides decision-support tools, not professional advice.

Please note:

  • Forecasts rely on historical data and assumptions

  • Accuracy may vary for new, seasonal, or low-volume products

  • You remain responsible for purchasing and financial decisions

Verve AI does not provide financial, accounting, or investment advice.

Your Rights Under UK & EU GDPR

You have the right to:

  • Access and export your data

  • Correct inaccurate information

  • Request deletion of your account and data

  • Withdraw from beta or paid versions

  • Restrict or object to certain processing

  • Lodge a complaint with the ICO or relevant EU authority

To exercise your rights, contact:
📧 hello@getverveai.com

Data Controller & Sub-Processors

Verve AI is the data controller for all data processed through the application.

We use the following GDPR-compliant subprocessors:

  • Supabase – secure data storage and authentication

  • OpenAI – AI-generated forecasting responses

  • Shopify – Shopify store data via API

  • WooCommerce – WooCommerce store data via API

In future white-label or embedded deployments, Verve AI may act solely as a technology provider and not retain merchant data.

Data Retention & Deletion

  • Data is retained only while your account is active

  • Beta data is deleted 30 days after beta exit or conclusion

  • Paid users may request deletion at any time

  • Upon deletion, all associated store data is permanently removed

  • API access tokens are revoked immediately on disconnect

Summary

At Verve AI, we are committed to:

  • Respecting merchant privacy by design

  • Collecting only what is necessary

  • Using data solely to deliver forecasting value

  • Providing transparency, control, and security

If you have any questions or concerns, contact us at:
📧 hello@getverveai.com