How we handle merchant and shopper data.
This page is a plain-language summary of current practice and has not yet been reviewed by counsel. It must be replaced with a reviewed policy before launch.
For merchants: account details, catalog data you connect, and usage of your console.
For shoppers on a merchant's site: conversation content and interaction events, stored on that merchant's instance so the merchant can review their own sessions.
Personally identifying information appearing in transcripts — names, emails, phone numbers — is masked by default in the merchant console. Revealing it is a deliberate action and is recorded in an audit log.
HOLLOU's own platform console holds aggregate counts only: sessions, tokens, cost and instance health. It holds no message content, and raw transcripts are never visible across merchants.
Your data, and your shoppers' data, are never used to train external models.
Data is encrypted in transit and at rest. Our data handling is built to GDPR requirements. No card data reaches HOLLOU, so we sit outside PCI-DSS cardholder-data scope. We are working toward SOC 2 Type II and do not hold a report today.
Questions about data handling: contact@hollou.ai