Skip to content

Privacy policy

Effective 15 August 2026

This policy explains what AiRova Chat collects, why, and what you can ask us to do about it. AiRova Chat is operated by Varisoft. If anything here is unclear, write to privacy@airova.ai and we will answer.

Who this policy is for

AiRova Chat is used by businesses to answer their own customers. That gives two groups of people an interest in this policy: the business that signs up and its staff, and the customers who send messages to that business.

The business decides which channels to connect and what to do with the conversations. We process that content on the business's instructions in order to run the service.

Information we collect

  • Account information: name, email address, password (stored only as a cryptographic hash), and the workspace and role you belong to.
  • Channel connection details: the id and name of the Page, account or shop you connect, and the access tokens needed to receive and send messages. Tokens are encrypted before they are stored.
  • Conversation content: the messages exchanged between the business and its customers on connected channels, together with the sender name and profile picture supplied by the channel.
  • Commerce data: order details, where the connected channel is a marketplace that provides them.
  • Usage and technical data: sign-in times, actions recorded in the audit log, IP address and browser information in server logs, kept for security and troubleshooting.

How we use it

  • To show conversations in the shared inbox and deliver replies back to the channel the customer used.
  • To provide the features the business turns on: assignment, tags, saved replies, automation rules, reports and exports.
  • To keep the service secure: authentication, permission checks, rate limiting and audit logging.
  • To contact the business about the service, including billing and important changes.

Platform Data from Meta

When a business connects a Facebook Page or an Instagram account, Meta gives us access only to what the business selected during sign-in. We use it only to run the shared inbox for that business.

We do not use Platform Data for advertising, audience building or profiling. We do not sell it. We do not combine it across different businesses using our service.

A business can withdraw access at any time by disconnecting the channel in the app, or by removing the app under Facebook Settings and then Business Integrations. When access is withdrawn we stop receiving new messages and delete the stored data as described below.

AI features

Some optional features suggest a reply or answer a question about the workspace. When a member of the business asks for a suggestion, the relevant part of the conversation is sent to our AI provider to generate it. Internal notes are removed before the text is sent.

Suggestions are drafts. Nothing is sent to a customer until a person in the business chooses to send it. Our AI provider is contractually prevented from using this content to train its models.

Who we share it with

We do not sell personal data, and we do not share it with other businesses using the service. We use a small number of providers to operate it:

  • Google Cloud, for hosting, the database and file storage.
  • The messaging platforms themselves, to receive and deliver messages on the channels you connect.
  • Our payment provider, to process subscription payments. Card details are handled by the payment provider and never reach our servers.
  • Our email provider, to send account emails such as team invitations.
  • Our AI provider, for the optional features described above.

Where data is stored

The service runs on Google Cloud. Data is stored in a Google Cloud region and may be processed in other countries where our providers operate, under the contractual protections those providers offer.

How long we keep it

Conversation content is kept while the workspace is active, so the business can see the history of each customer. Audit log entries are kept for a limited retention period and then removed automatically.

When a channel is disconnected, its stored access tokens are removed immediately. When a workspace is closed, or when a business asks us to delete its data, we delete it within 30 days, except where we must keep records for legal or accounting reasons.

Security

  • Channel access tokens are encrypted before they are stored.
  • Passwords are stored only as cryptographic hashes and are never recoverable.
  • Every request is scoped to a single workspace, so one business cannot read another's data.
  • Access inside a workspace is limited by role, and sensitive actions are written to an audit log.
  • Traffic is served over HTTPS.

Your rights

Under Thailand's Personal Data Protection Act, and comparable laws elsewhere, you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, or object to how it is used. Write to privacy@airova.ai and we will respond within 30 days.

If you are a customer who messaged a business that uses AiRova Chat, that business decides what happens to your conversation. Contact them first. If you cannot reach them, write to us and we will help.

Cookies

We use cookies that the service needs in order to work: one that keeps you signed in, and one that remembers your language choice. We do not use advertising or cross-site tracking cookies.

Children

The service is for businesses. It is not directed at children, and we do not knowingly create accounts for anyone under 18.

Changes to this policy

If we change this policy in a way that affects you, we will update the date at the top and, for significant changes, tell account owners by email before the change takes effect.

Contact

Varisoft, operator of AiRova Chat. Privacy and data requests: privacy@airova.ai. General support: support@airova.ai.