Skip to main content

Hivenue LLC · Legal

Privacy Policy

Last updated:

1. Introduction

Hivenue is a software platform for e-commerce businesses provided by Hivenue LLC, a Wyoming limited liability company in the United States. Hivenue LLC is the controller of account, billing, support and service-administration data. When we process a merchant’s customer, employee or contact data on its instructions, the merchant is the controller and Hivenue processes that data on its behalf under the applicable agreement. This notice covers the Hivenue platform.

2. Data we collect

To provide the service we collect and process the following categories of data:

  • Email address — used for authentication and service communications.
  • OAuth tokens — Google and Microsoft access and refresh tokens, encrypted AES-256-GCM at rest.
  • Email body content — when the Helpdesk module is active: subject, body (text and HTML), sender, recipients, headers.
  • Shopify customer matches — the association between an email sender and a Shopify customer (customer id, orders, address).
  • Attachments — files attached to emails, stored in Supabase Storage.
  • Workspace data — tasks, notes, module settings, and other user-generated content.
  • Store and advertising data — products, orders, inventory, customers, campaigns, audiences and performance data from the integrations and modules you enable.
  • Billing and usage data — business contact and billing details, subscription status, payment references, AI usage and technical logs. Card details are collected through Stripe.
  • AI data — prompts, selected workspace context and generated outputs, where the relevant feature is enabled.
  • Storefront chat — shopper messages, conversation history, contact or order details supplied or verified, and relevant page and cart context, where the chat feature is enabled.
  • Storefront analytics and session replay — browser and session identifiers, page structure and content, clicks, scrolls and other interaction events used to provide recordings and heatmaps, where the relevant feature is enabled. Masking settings affect the content included in recordings.

Purposes and legal bases

We use account and service data to provide requested services and perform our agreements; business contact and technical data to administer accounts, respond to requests and protect the service; and billing records to meet applicable accounting and tax obligations. Where the GDPR applies, these activities rely on performance of a contract, legitimate interests in running and securing the service, or legal obligations, as appropriate. For optional processing for our own purposes, we request consent where required and you may withdraw it.

Merchant-controlled data is processed on the merchant’s instructions. The merchant is responsible for its own lawful basis and notices, including any storefront tracking or customer communications it enables. It must assess and configure any required consent and tracking controls before activating those features on its storefront.

3. Google user data

When you connect Gmail, you authorize gmail.send and gmail.readonly, together with sign-in identifiers. Hivenue can read and synchronize messages, headers and attachments in the shared inbox, receive new messages and send replies on your behalf. The initial import normally covers 90 days of history, depending on the import settings and synchronization continues while the connection is active. Google data is used for the visible features you enable, is not sold, and is not used for advertising or training general-purpose AI models. Any AI features must comply with Google’s use restrictions and the user’s authorization.

Hivenue’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Microsoft Graph / Outlook user data

When you connect Microsoft or Outlook, Hivenue requests Mail.ReadWrite, Mail.Send and offline_access, together with sign-in identifiers and User.Read. These permissions allow message access, synchronization of email and attachments, creation of drafts used to send replies, and renewed access. You may also connect a mailbox through IMAP where available. This data is processed to provide the features enabled for the workspace, including support and, where enabled, the AI processing described below.

5. Data retention

We retain data according to its category, the features enabled, the merchant’s instructions, service needs and legal obligations. An email-import window is not an automatic deletion deadline. Disconnecting an integration, cancelling a subscription and requesting workspace deletion are separate actions. Contact support@hivenue.co to request deletion or export; records needed for tax, security or legal claims may be retained longer. Backups and data held by connected services may follow separate retention cycles.

6. Sub-processors

Depending on the features enabled, the platform uses the providers and connected services listed below. Some process data for Hivenue; others are services the merchant connects through its own account. They may process data outside your country. Contractual roles, processing locations and applicable safeguards depend on the service and actual configuration. Contact support@hivenue.co for information about the applicable processing arrangements and safeguards.

  • Supabase — database, authentication and file storage.
  • Vercel — hosting, technical analytics and performance monitoring.
  • Resend — transactional email and supported sending features.
  • Stripe — subscriptions, payments and billing records.
  • Anthropic and OpenAI — AI features, depending on the selected feature.
  • Google and Microsoft — connected email and identity services.
  • Shopify and Meta — connected store and advertising services.
  • Other payment, communication or business services you choose to connect.

AI features may send prompts and relevant workspace or customer context to the selected model provider to return a response. Some features use a merchant-provided API account; others use a Hivenue account. Using a merchant-provided key does not mean the data bypasses Hivenue’s servers.

7. User rights (GDPR Art. 15-22)

Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability and objection and, where relevant, withdrawal of consent. Contact our privacy team at support@hivenue.co to exercise these rights. For data handled on behalf of a merchant, direct your request to that merchant; Hivenue will assist it under the applicable agreement. You may complain to the relevant supervisory authority, including the Italian Data Protection Authority where applicable.

8. Changes to this policy

We update this notice when the processing described here changes. The date above identifies the latest revision. We will communicate material changes through the service or account contact details and request consent where required before new uses of data.

9. Contact

Hivenue LLC — Registered and mailing address: 33 N Gould St, Sheridan, WY 82801, United States.

For any privacy-related request or to exercise GDPR rights, contact:

support@hivenue.co