Legal

Privacy Policy

How we handle merchant and shopper data.

Draft

This page is a plain-language summary of current practice and has not yet been reviewed by counsel. It must be replaced with a reviewed policy before launch.

What we collect

For merchants: account details, catalog data you connect, and usage of your console.

For shoppers on a merchant's site: conversation content and interaction events, stored on that merchant's instance so the merchant can review their own sessions.

PII masking

Personally identifying information appearing in transcripts — names, emails, phone numbers — is masked by default in the merchant console. Revealing it is a deliberate action and is recorded in an audit log.

What the platform sees

HOLLOU's own platform console holds aggregate counts only: sessions, tokens, cost and instance health. It holds no message content, and raw transcripts are never visible across merchants.

Model training

Your data, and your shoppers' data, are never used to train external models.

Security and compliance

Data is encrypted in transit and at rest. Our data handling is built to GDPR requirements. No card data reaches HOLLOU, so we sit outside PCI-DSS cardholder-data scope. We are working toward SOC 2 Type II and do not hold a report today.

Contact

Questions about data handling: contact@hollou.ai