Vividstack LLC (“VividStack”, “we”, “our”, “us”) provides the VividHarbor AI Assistant WordPress plugin and the related hosted services required for it to function, including admin.vividstack.dev and widget.vividstack.dev. This policy explains what we collect, why, and what choices you have.
It applies to self-serve plugin users, trials, and subscriptions. It does not replace terms in a separately negotiated dedicated, municipal, or enterprise agreement.
Our two roles: controller and processor
This distinction determines who is responsible for what:
- We are the controller for account data about our customers — the person or business that signs up, configures a chatbot, and pays for a plan. This policy governs that data.
- We are a processor for Visitor Data — the messages typed by people using a chat widget on a customer’s website. We process that data on our customer’s instructions under our Data Processing Addendum. If you are a website visitor with a question about your chat messages, contact the operator of the website you were using; they control that data. We will support them in responding.
Information we collect
Customer account data (we are the controller)
- Account details: email address, authentication records, and portal role.
- Tenant and configuration data: tenant identifiers, site domain, widget settings, branding, allowlist state.
- Billing data: plan, subscription and billing status, and Stripe customer/subscription identifiers. Full payment card numbers are handled by Stripe and never stored by us.
- Legal acceptance records: which version of our Terms, Privacy Policy, and DPA you accepted, plus the timestamp, IP address, and browser user agent at the time of acceptance. We keep these as proof of agreement.
- Support communications you send us.
Customer Content (we are the processor)
- Uploaded knowledge documents and synced website pages used to ground chatbot responses.
Visitor Data (we are the processor)
- Questions and responses exchanged with the chatbot, along with timestamps.
- Technical and diagnostic metadata: detected language, session identifier, embedding origin domain, and rate-limit counters.
The widget does not require visitors to log in, and we do not ask visitors for their name, email, or other identifiers. Visitors may nonetheless type personal information into a chat message; customers are responsible for advising visitors not to submit sensitive information.
Operational data
- Security, error, and access logs used to operate and protect the Service.
Cookies and similar technologies
The admin portal uses strictly necessary cookies and browser local storage to keep you signed in and remember interface preferences. The chat widget uses browser storage only to maintain the state of an active conversation. We do not use advertising cookies, cross-site tracking, or third-party analytics pixels in the widget or the portal.
How we use information
- Operate, secure, and support the plugin-connected chatbot service.
- Authenticate users and manage tenant connection, allowlisting, and configuration.
- Generate chatbot responses and the analytics we surface to the customer who owns the chatbot.
- Process subscriptions, payments, and billing lifecycle events.
- Detect, prevent, and investigate abuse, fraud, and security incidents.
- Comply with legal obligations and enforce our Terms.
We do not sell or share personal information as those terms are defined under U.S. state privacy laws, and we do not use Customer Content or Visitor Data to train foundation models.
Legal bases (EEA/UK)
Where GDPR or UK GDPR applies to our processing as a controller, we rely on:
- Contract — to provide the Service you signed up for and to bill you.
- Legitimate interests — to secure the Service, prevent abuse, and improve reliability.
- Legal obligation — for tax, accounting, and lawful requests.
- Consent — where required, and which you may withdraw at any time.
Data sharing
We share data with the infrastructure, AI model, and payment providers needed to operate the Service. Our current providers are listed on the Subprocessors page. Each is engaged under terms requiring appropriate confidentiality and security, and our AI providers are contractually prohibited from training on data we send them.
We may also disclose information when legally required, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will notify affected customers.
International transfers
We operate primarily in the United States, and our providers may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.
Data retention
- Account and billing records — for the life of the account and up to 7 years afterward where required for tax and accounting.
- Legal acceptance records — for the life of the account plus 7 years, as evidence of agreement.
- Customer Content — until you delete it or close your account.
- Visitor Data and chat history — retained per the customer’s configuration and deleted within 30 days of account closure.
- Security and operational logs — typically up to 12 months.
Deleted data may persist briefly in routine encrypted backups before being overwritten.
Security
We use reasonable technical and organizational safeguards, including HTTPS in transit, encryption at rest with our infrastructure providers, tenant isolation, domain allowlisting for widget embedding, scoped access tokens, and role-based access control in the admin portal. No method of transmission or storage is completely secure. If we become aware of a breach affecting your data, we will notify you without undue delay and, where we act as processor, assist you with your own notification obligations.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. California residents may request disclosure of the categories of personal information collected and may exercise deletion and correction rights; we do not sell or share personal information and therefore offer no opt-out of sale. We will not discriminate against you for exercising any of these rights.
To make a request, email privacy@vividstack.dev. We will verify your identity and respond within the timeframe required by applicable law. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. Customers must not configure the chatbot to solicit information from children. If you believe a child has provided personal information, contact us and we will delete it.
Changes to this policy
We may update this policy. Each version is identified by the version number at the top of this page. For material changes we will notify customers by email or in the admin portal before the change takes effect.
Contact
Company: Vividstack LLC
Email: privacy@vividstack.dev