In short
- ORVX is a commerce analytics product. You connect your store and your advertising accounts, and ORVX computes what you actually earned.
- ORVX only ever reads from the platforms you connect. It does not create, edit, pause or delete anything in your Shopify store or your ad accounts.
- No personal data about your shoppers is ever sent to an AI model. The AI features receive totals and business figures, never a name, phone number or email address.
- The marketing site sets no advertising cookies and no advertising pixels. Google Analytics runs there only if you accept it, and is denied by default. Signed in, there is one cookie, and it is what keeps you signed in.
- You can ask for a copy of your data or its deletion at any time by writing to support@orvx.ai.
Who this policy is from
ORVX operates the website at orvx.ai and the ORVX application. Where this policy says “we”, “us” or “ORVX”, it means the operator of that service.
For questions about this policy, about the data ORVX holds, or to make any request described under Your rights, write to support@orvx.ai. We answer to that address; it is not a queue that discards mail.
Two different kinds of data, and two different responsibilities
This distinction runs through the whole policy, so it is worth stating once, clearly.
Your account data — your email address, your store's name, your plan — is data ORVX decides what to do with. We are responsible for it.
Your store's data — your orders, your products, and the personal data of the people who buy from you — belongs to you and your business. You decide what happens to it; ORVX processes it on your instructions, in order to give you the analysis you asked for. We do not use it for our own purposes, we do not sell it, and we do not share it with other merchants.
What ORVX collects about you
All of it comes from you, either when you create the account or as you use it.
| What | Why it exists |
|---|---|
| Email address | Signing in, password resets, and service notices about your own account |
| Password | Stored only as a one-way bcrypt hash. ORVX cannot read your password, and nobody at ORVX can recover it — a forgotten password is reset, never retrieved |
| Store name, country, currency | Formatting your figures in your own currency, and defaults that depend on where you trade |
| Sign-in time | Showing you the last activity on the account |
| Plan, subscription status, trial end date | Deciding what the account has access to |
| Bank transfer details, if you pay that way | The payer name, the transaction reference and the payment proof you upload, so a transfer can be matched to your account and confirmed |
| Team members you invite | Their email address and the role you gave them, so the right people see the right screens |
| Support conversations | The messages and any files you send us, so a question already answered does not have to be asked twice |
| Notification preferences | Which categories you want to hear about, and by which channel |
| Web Push endpoint | Only if you turn on push notifications yourself. It is the browser's address for your device, not an identifier we build |
What ORVX imports from the platforms you connect
Nothing is imported until you connect a platform yourself and approve the permissions on that platform's own screen. You can disconnect at any time from Integrations.
| Platform | Permission requested | What is read |
|---|---|---|
| Shopify | read_products, read_orders, read_customers | Products and variants, collections, orders and their line items, refunds, and customer records |
| Meta Ads | Read access to the ad account you select | Campaigns, ad sets and ads, with spend, impressions, clicks and conversions |
| Google Ads | Read access to the ad account you select | Campaign performance and spend |
| TikTok Ads | Read access to the ad account you select | Campaign performance and spend |
| Google Analytics 4 | analytics.readonly | Aggregate session and traffic figures for the property you select |
Access tokens for these connections are held encrypted, and no screen, report, log line or error message in ORVX ever discloses one.
Your shoppers' personal data
Customer analytics — repeat purchase rate, acquisition cost, retention — cannot be computed without knowing which orders belong to the same person. So ORVX imports enough to answer that question, and stops there.
| Stored | Not stored |
|---|---|
| Name, as it appears on the order | Shipping or billing addresses |
| Phone number and email address from the order | Card numbers or any payment credentials |
| The store's own customer identifier from Shopify | Anything from a platform you have not connected |
| Order counts and first and last order dates | Browsing behaviour or any tracking of individuals across sites |
The phone number and email address are used to recognise a returning buyer whose orders would otherwise look like several different people. They are not used to contact anyone: ORVX sends no marketing of any kind to your shoppers, and has no feature that could.
This data is visible only inside your own account. Every query in ORVX is scoped to the account that owns the data, and no screen, export or API route accepts another account's identifier.
The AI features, and what they are given
ORVX AI explains your figures. It does not calculate them. Every number it discusses was produced beforehand by ORVX's own deterministic engine — the same one behind your reports — and the model's role is to interpret what those numbers mean for your business.
To do that, a summary of your business is sent to our AI provider, OpenAI. Here is what that summary does and does not contain.
| Sent | Never sent |
|---|---|
| Period totals: revenue, cost of goods, margin, ad spend, profit | Any shopper's name, phone number or email address |
| Your product, collection and campaign names, and their figures | Any per-customer row at all |
| Counts of identified and repeat customers | Passwords, API keys or integration tokens |
| Data-quality warnings about your own figures | Session data, or anything belonging to another account |
If you would rather no business summary left our servers at all, do not use the AI features; every other part of ORVX works without them.
Cookies and what is kept in your browser
- One session cookie. It keeps you signed in. It is
httpOnly, so page scripts cannot read it, restricted to this site, sent only over HTTPS in production, and it ends when you close your browser. It is strictly necessary, and it is not something that can be switched off while you are using the application. - Google Analytics, only if you agree. The public orvx.ai site uses Google Analytics to understand which pages people read. It is off until you accept — see below.
- No advertising cookies and no advertising pixels. Nothing here is used to target you, and no advertising platform receives anything about your visit.
- A few interface preferences are kept in your browser's own storage — the date range you last looked at, which tab you had open, your expense category list, and your answer to the consent banner. They stay on your device and are never sent to us.
How the analytics consent actually works. Before Google's script is requested at all, ORVX declares every storage type denied using Google Consent Mode. Analytics therefore starts in cookieless mode: it writes nothing to your browser and sends no identifier. A banner then asks. Only if you press Accept is that denial lifted.
Declining changes nothing about how the site or the product works, and you will not be asked again. To change your mind later, clear this site's data in your browser and the banner will reappear.
| What Google Analytics receives | What it does not |
|---|---|
| Which pages were viewed, and in what order | Your name, email address, or anything from your ORVX account |
| Approximate location from a truncated IP address | Your full IP address — it is truncated before it is stored |
| Browser, device type and referring site | Anything about your store, your orders or your customers |
Notifications
ORVX can tell you when something in your business needs attention — a product losing money, a campaign below break-even, stock about to run out. Those findings come from the same deterministic engine as your reports.
- In the app — always available, on the bell.
- By email — to your account address, if you leave it on. You choose the categories and whether it arrives as it happens or once a day.
- Web Push — off unless you turn it on. Your browser will only ask for permission after you press the button in Settings yourself, never when a page loads. Turning it off in Settings deletes the stored endpoint.
Email is sent from our own server. No third-party email marketing platform is involved, and your address is not added to any list.
Who else is involved
The complete list of companies that process any of this data on our behalf:
| Who | What they handle | Where |
|---|---|---|
| A2 Hosting, Inc. | The servers and the database — all application data lives there | United States |
| OpenAI | The business summary described under the AI features, and nothing else | United States |
| Google (Analytics) | Page views on the public marketing pages, and only after you accept. Never anything from inside the application | United States |
That is the whole list. The platforms you connect — Shopify, Meta, Google Ads, TikTok — are not on it, because data flows the other way: ORVX reads from them and sends them nothing about you. Google appears above in an entirely separate capacity, as the analytics provider for the public marketing pages, with no access to any account data.
ORVX does not sell personal data, and does not share it with anyone for advertising.
We may disclose data if a law that applies to us requires it. If that happens and we are permitted to tell you, we will.
Where your data is held
On servers in the United States. If you are somewhere else, your data is transferred there in order to provide the service you signed up for.
Where the law that applies to you requires a safeguard for that transfer, we will put the appropriate one in place and describe it here.
How long it is kept
- While your account is open — your commerce history is the product. A profit trend needs the months behind it, so nothing is aged out while you are using ORVX.
- If you disconnect a platform — the history already imported stays, so your past reports do not develop holes. Ask us and we will remove it.
- If you close your account — write to support@orvx.ai and we will delete your data. Backups roll off on their own schedule, so a copy may persist there briefly after deletion from the live system.
- Records we are required to keep — payment records may be held for as long as the applicable law requires, and no longer.
How it is protected
- Passwords are stored as bcrypt hashes and are never readable, by us or by anyone who obtained the database.
- Integration access tokens are encrypted before they are stored.
- Traffic to orvx.ai is served over HTTPS.
- Every database query is scoped to the account that owns the data, so one merchant's screen cannot return another merchant's rows.
- Access to production systems is limited to those who need it to operate the service.
No system is beyond compromise. If a breach affects your data and the law requires you to be told, we will tell you.
Your rights
Depending on where you live, the law may give you some or all of the following. Where it does, ORVX will honour them; where it does not, we will still try to help.
- Access — a copy of the personal data we hold about you.
- Correction — anything inaccurate put right. Most of it you can edit yourself in your profile.
- Deletion — your data removed.
- Portability — your data in a machine-readable format.
- Objection and restriction — to ask us to stop or limit a particular use.
- Withdrawing consent — where something was based on consent, such as push notifications, withdrawn at any time without affecting what came before.
Write to support@orvx.ai. We will ask enough to confirm you are the account holder — that check protects you — and then act without charge. If you believe we have handled your data wrongly, you may also complain to the data protection authority where you live.
Children
ORVX is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, write to us and we will remove it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects how your data is handled, we will tell you in the app or by email before it takes effect rather than leaving you to notice.