In short

  • ORVX is a commerce analytics product. You connect your store and your advertising accounts, and ORVX computes what you actually earned.
  • ORVX only ever reads from the platforms you connect. It does not create, edit, pause or delete anything in your Shopify store or your ad accounts.
  • No personal data about your shoppers is ever sent to an AI model. The AI features receive totals and business figures, never a name, phone number or email address.
  • The marketing site sets no advertising cookies and no advertising pixels. Google Analytics runs there only if you accept it, and is denied by default. Signed in, there is one cookie, and it is what keeps you signed in.
  • You can ask for a copy of your data or its deletion at any time by writing to support@orvx.ai.

Who this policy is from

ORVX operates the website at orvx.ai and the ORVX application. Where this policy says “we”, “us” or “ORVX”, it means the operator of that service.

For questions about this policy, about the data ORVX holds, or to make any request described under Your rights, write to support@orvx.ai. We answer to that address; it is not a queue that discards mail.

Two different kinds of data, and two different responsibilities

This distinction runs through the whole policy, so it is worth stating once, clearly.

Your account data — your email address, your store's name, your plan — is data ORVX decides what to do with. We are responsible for it.

Your store's data — your orders, your products, and the personal data of the people who buy from you — belongs to you and your business. You decide what happens to it; ORVX processes it on your instructions, in order to give you the analysis you asked for. We do not use it for our own purposes, we do not sell it, and we do not share it with other merchants.

Because your shoppers' data is yours, the obligations you owe those people stay with you. ORVX gives you the tools to answer a deletion or access request; it cannot answer one on your behalf, because we have no relationship with your shoppers and no way to verify who they are.

What ORVX collects about you

All of it comes from you, either when you create the account or as you use it.

WhatWhy it exists
Email addressSigning in, password resets, and service notices about your own account
PasswordStored only as a one-way bcrypt hash. ORVX cannot read your password, and nobody at ORVX can recover it — a forgotten password is reset, never retrieved
Store name, country, currencyFormatting your figures in your own currency, and defaults that depend on where you trade
Sign-in timeShowing you the last activity on the account
Plan, subscription status, trial end dateDeciding what the account has access to
Bank transfer details, if you pay that wayThe payer name, the transaction reference and the payment proof you upload, so a transfer can be matched to your account and confirmed
Team members you inviteTheir email address and the role you gave them, so the right people see the right screens
Support conversationsThe messages and any files you send us, so a question already answered does not have to be asked twice
Notification preferencesWhich categories you want to hear about, and by which channel
Web Push endpointOnly if you turn on push notifications yourself. It is the browser's address for your device, not an identifier we build
ORVX does not process card payments and stores no card numbers. If card payments are introduced, the processor handling them will be named in this policy before they are switched on.

What ORVX imports from the platforms you connect

Nothing is imported until you connect a platform yourself and approve the permissions on that platform's own screen. You can disconnect at any time from Integrations.

PlatformPermission requestedWhat is read
Shopifyread_products, read_orders, read_customersProducts and variants, collections, orders and their line items, refunds, and customer records
Meta AdsRead access to the ad account you selectCampaigns, ad sets and ads, with spend, impressions, clicks and conversions
Google AdsRead access to the ad account you selectCampaign performance and spend
TikTok AdsRead access to the ad account you selectCampaign performance and spend
Google Analytics 4analytics.readonlyAggregate session and traffic figures for the property you select
Every one of these connections is read-only. ORVX has no code that writes to a connected platform: it cannot change a budget, pause a campaign, edit an order or alter a product. When ORVX recommends stopping a campaign, it tells you — you make the change, in the platform, yourself.

Access tokens for these connections are held encrypted, and no screen, report, log line or error message in ORVX ever discloses one.

Your shoppers' personal data

Customer analytics — repeat purchase rate, acquisition cost, retention — cannot be computed without knowing which orders belong to the same person. So ORVX imports enough to answer that question, and stops there.

StoredNot stored
Name, as it appears on the orderShipping or billing addresses
Phone number and email address from the orderCard numbers or any payment credentials
The store's own customer identifier from ShopifyAnything from a platform you have not connected
Order counts and first and last order datesBrowsing behaviour or any tracking of individuals across sites

The phone number and email address are used to recognise a returning buyer whose orders would otherwise look like several different people. They are not used to contact anyone: ORVX sends no marketing of any kind to your shoppers, and has no feature that could.

This data is visible only inside your own account. Every query in ORVX is scoped to the account that owns the data, and no screen, export or API route accepts another account's identifier.

The AI features, and what they are given

ORVX AI explains your figures. It does not calculate them. Every number it discusses was produced beforehand by ORVX's own deterministic engine — the same one behind your reports — and the model's role is to interpret what those numbers mean for your business.

To do that, a summary of your business is sent to our AI provider, OpenAI. Here is what that summary does and does not contain.

SentNever sent
Period totals: revenue, cost of goods, margin, ad spend, profitAny shopper's name, phone number or email address
Your product, collection and campaign names, and their figuresAny per-customer row at all
Counts of identified and repeat customersPasswords, API keys or integration tokens
Data-quality warnings about your own figuresSession data, or anything belonging to another account
Customer information in that summary is aggregated to counts — how many customers were identified, how many bought more than once. There is no route in ORVX by which an individual shopper's identity can reach a language model.

If you would rather no business summary left our servers at all, do not use the AI features; every other part of ORVX works without them.

Cookies and what is kept in your browser

  • One session cookie. It keeps you signed in. It is httpOnly, so page scripts cannot read it, restricted to this site, sent only over HTTPS in production, and it ends when you close your browser. It is strictly necessary, and it is not something that can be switched off while you are using the application.
  • Google Analytics, only if you agree. The public orvx.ai site uses Google Analytics to understand which pages people read. It is off until you accept — see below.
  • No advertising cookies and no advertising pixels. Nothing here is used to target you, and no advertising platform receives anything about your visit.
  • A few interface preferences are kept in your browser's own storage — the date range you last looked at, which tab you had open, your expense category list, and your answer to the consent banner. They stay on your device and are never sent to us.

How the analytics consent actually works. Before Google's script is requested at all, ORVX declares every storage type denied using Google Consent Mode. Analytics therefore starts in cookieless mode: it writes nothing to your browser and sends no identifier. A banner then asks. Only if you press Accept is that denial lifted.

Declining changes nothing about how the site or the product works, and you will not be asked again. To change your mind later, clear this site's data in your browser and the banner will reappear.

What Google Analytics receivesWhat it does not
Which pages were viewed, and in what orderYour name, email address, or anything from your ORVX account
Approximate location from a truncated IP addressYour full IP address — it is truncated before it is stored
Browser, device type and referring siteAnything about your store, your orders or your customers
Analytics runs on the public marketing pages only. It is not present on any signed-in page of the application, so nothing you do inside ORVX with your own commerce data is measured by it.

Notifications

ORVX can tell you when something in your business needs attention — a product losing money, a campaign below break-even, stock about to run out. Those findings come from the same deterministic engine as your reports.

  • In the app — always available, on the bell.
  • By email — to your account address, if you leave it on. You choose the categories and whether it arrives as it happens or once a day.
  • Web Push — off unless you turn it on. Your browser will only ask for permission after you press the button in Settings yourself, never when a page loads. Turning it off in Settings deletes the stored endpoint.

Email is sent from our own server. No third-party email marketing platform is involved, and your address is not added to any list.

Who else is involved

The complete list of companies that process any of this data on our behalf:

WhoWhat they handleWhere
A2 Hosting, Inc.The servers and the database — all application data lives thereUnited States
OpenAIThe business summary described under the AI features, and nothing elseUnited States
Google (Analytics)Page views on the public marketing pages, and only after you accept. Never anything from inside the applicationUnited States

That is the whole list. The platforms you connect — Shopify, Meta, Google Ads, TikTok — are not on it, because data flows the other way: ORVX reads from them and sends them nothing about you. Google appears above in an entirely separate capacity, as the analytics provider for the public marketing pages, with no access to any account data.

ORVX does not sell personal data, and does not share it with anyone for advertising.

We may disclose data if a law that applies to us requires it. If that happens and we are permitted to tell you, we will.

Where your data is held

On servers in the United States. If you are somewhere else, your data is transferred there in order to provide the service you signed up for.

Where the law that applies to you requires a safeguard for that transfer, we will put the appropriate one in place and describe it here.

How long it is kept

  • While your account is open — your commerce history is the product. A profit trend needs the months behind it, so nothing is aged out while you are using ORVX.
  • If you disconnect a platform — the history already imported stays, so your past reports do not develop holes. Ask us and we will remove it.
  • If you close your account — write to support@orvx.ai and we will delete your data. Backups roll off on their own schedule, so a copy may persist there briefly after deletion from the live system.
  • Records we are required to keep — payment records may be held for as long as the applicable law requires, and no longer.

How it is protected

  • Passwords are stored as bcrypt hashes and are never readable, by us or by anyone who obtained the database.
  • Integration access tokens are encrypted before they are stored.
  • Traffic to orvx.ai is served over HTTPS.
  • Every database query is scoped to the account that owns the data, so one merchant's screen cannot return another merchant's rows.
  • Access to production systems is limited to those who need it to operate the service.

No system is beyond compromise. If a breach affects your data and the law requires you to be told, we will tell you.

Your rights

Depending on where you live, the law may give you some or all of the following. Where it does, ORVX will honour them; where it does not, we will still try to help.

  • Access — a copy of the personal data we hold about you.
  • Correction — anything inaccurate put right. Most of it you can edit yourself in your profile.
  • Deletion — your data removed.
  • Portability — your data in a machine-readable format.
  • Objection and restriction — to ask us to stop or limit a particular use.
  • Withdrawing consent — where something was based on consent, such as push notifications, withdrawn at any time without affecting what came before.

Write to support@orvx.ai. We will ask enough to confirm you are the account holder — that check protects you — and then act without charge. If you believe we have handled your data wrongly, you may also complain to the data protection authority where you live.

If you are a shopper who bought from a store that uses ORVX, we are not the right people to ask. Your relationship is with that merchant: they decide what happens to their customer data, and they can action your request. Contact the store you bought from.

Children

ORVX is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects how your data is handled, we will tell you in the app or by email before it takes effect rather than leaving you to notice.