Back

Effective date: May 11, 2026

Privacy Policy

This Privacy Policy explains how AlwaysOnline collects, uses, stores, protects, and shares personal data when you visit our website, use our merchant workspace, connect third-party integrations, or use AI-powered business tools.

1. Who we are

AlwaysOnline provides a business SaaS platform for merchants, including AI phone reception, merchant workspace tools, AI Team automation, invoice management, and email integrations.

For privacy questions, you can contact us at [email protected]. For product support, contact [email protected].

2. Information we collect

We may collect account information such as your name, email address, authentication provider, preferred language, and basic profile information.

We may collect organization and workspace information such as organization names, stores, roles, permissions, team members, billing status, and product settings.

We may collect operational data generated when you use AlwaysOnline, such as contacts, bookings, call records, invoices, audit logs, usage records, and AI Team task activity.

3. Information you provide

You may provide business content such as store information, customer contact details, scripts, instructions, invoice files, email attachments, and configuration choices.

If you invite team members or configure roles, we process the information needed to create and manage those permissions within your organization.

4. Gmail and Outlook integrations

Connecting Gmail or Outlook is optional. Signing in to AlwaysOnline and connecting a business email account are separate actions.

AlwaysOnline only accesses Gmail or Outlook data after you explicitly connect your account. We use this data only to provide the features you request, such as invoice extraction, email archiving, email sending, and AI Team automation.

Depending on the feature you enable, we may process message metadata, sender and recipient information, subject lines, message content, attachments, invoice files, and delivery status. We do not access email data that is not needed for the feature you choose to use.

5. Google API data use and limited use

Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Gmail data, use it for advertising, or use it to train general-purpose AI models. We do not allow humans to read your Gmail content except when necessary to provide support you request, investigate abuse or security issues, comply with law, or when you have given explicit permission.

6. How we use information

We use data to provide, secure, maintain, and improve AlwaysOnline services; authenticate users; enforce organization and role permissions; process invoices; automate requested workflows; provide customer support; and comply with legal obligations.

We may use aggregated or de-identified information to understand service performance and improve product reliability, provided it does not identify you or your customers.

7. How we share information

We share information only when necessary to provide the service, comply with law, protect rights and security, or with your direction.

We may use trusted infrastructure providers for hosting, databases, authentication, email delivery, payment processing, logging, analytics, and AI processing. These providers are bound by confidentiality and security obligations appropriate to their role.

8. Data retention

We retain account, organization, and operational data for as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements.

Invoices, tax records, and financial files may be retained for legally required periods. When data is no longer needed, we delete or anonymize it according to our retention practices and technical backups schedule.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect data against unauthorized access, loss, misuse, alteration, or disclosure.

These safeguards include role-based permissions, organization isolation, server-side authorization checks, encryption in transit, audit logging, and least-privilege access controls.

10. International data transfers

AlwaysOnline may use service providers located in different countries. Where required, we use appropriate safeguards for international transfers, such as contractual protections and security controls.

11. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal data.

To exercise privacy rights, contact [email protected]. We may need to verify your identity before processing a request.

12. Revoking OAuth access

You can disconnect Gmail or Outlook from the AlwaysOnline integration center at any time. You can also revoke access from your Google or Microsoft account security settings.

After revocation, AlwaysOnline will stop new access to that mailbox. Data already processed may remain if needed to provide the service, keep audit records, comply with legal obligations, or preserve invoice and financial records for required retention periods.

13. Children’s privacy

AlwaysOnline is a business service and is not intended for children. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and provide notice when appropriate.

15. Contact us

For privacy requests, contact [email protected]. For general support, contact [email protected].