In Plain English: We collect information to provide you with a better experience on Viva. We're committed to protecting your privacy and being transparent about how we use your data, including AI-assisted features. This policy explains what we collect, how we use it, and your rights regarding your information.
1. Introduction and Scope
Welcome to Viva. This Privacy Policy describes how Viva.ai ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our platform, including AI-powered features.
1a. Who We Are
Viva is an AI-powered platform that helps local businesses thrive through automation tools, community engagement, and collaborative purchasing. We serve multiple types of users:
- Businesses: Local companies using our AI staff tools, cost savings, and community features
- Chamber Partners: Chambers of commerce and business associations that provide Viva services to their members
- Community Organizations: Local associations that organize community experiences and events
- Consumers: Individuals participating in community experiences, events, and reward programs
- Service Providers: Vendors offering services to our business network
1b. Acceptance of Terms
By accessing or using Viva, you agree to this Privacy Policy. If you do not agree with any part of this policy, please do not use our Service.
2. Information We Collect
We collect information you provide directly, information from your use of our Service, information from third parties like QuickBooks and Google Calendar, and content processed by our AI features.
2a. Information You Provide Directly
When you create an account or use our Service, you may provide:
- Account Information: Name, email address, phone number, password
- Business Information: Business name, address, industry category, tax ID, employee count, description
- Chamber/Community Information: Organization name, city, contact details, service area, member roster
- Payment Information: Payment processor details (we do not store credit card numbers directly)
- Profile Information: Company logo, description, website, social media links
- Communications: Information you provide when contacting support or responding to surveys
2b. AI Staff Data
If you use our AI Staff features, we collect and process:
- Email Content: Incoming emails routed through our service for AI-assisted responses
- Calendar Data: Calendar events and availability when you connect Google Calendar or Outlook
- Lead Information: Customer inquiries, contact information, and communication history
- Business Context: Information you provide to customize AI responses (tone, services, FAQs)
- Corrections and Feedback: Edits you make to AI-generated drafts to improve accuracy
- Appointment Data: Booking details, customer information, and scheduling preferences
2c. Community Experience Data
When participating in community experiences (Game Passports, events, rewards):
- Participation Records: Check-ins, stamp collections, redemptions
- Location Data: Business locations you visit during experiences
- Prize/Reward Information: Prizes won, rewards earned, redemption history
- Survey Responses: Feedback provided during or after experiences
2d. Information We Collect Automatically
When you use Viva, we automatically collect:
- Usage Information: Pages viewed, features used, time spent on platform, click patterns
- Device Information: Device type, operating system, browser type and version, unique device identifiers
- Log Information: IP address, access times, referring/exit pages, error logs
- Location Information: Approximate geographic location based on IP address
- Cookies and Similar Technologies: See Section 9 for details
2e. Information from Third-Party Services
When you connect third-party services to Viva, we may receive:
- QuickBooks Integration: Vendor lists, expense categories, transaction history
- Google Calendar: Calendar events, free/busy information, attendee details
- Microsoft Outlook: Calendar events, availability, contact information
- Authentication Providers: Information from Google or other SSO providers if you use them to sign in
- Service Providers: Information from vendors you work with through our platform
3. AI Data Processing
Important: Our AI features process your data to provide automated assistance. This section explains how we handle AI-related data.
3a. How AI Processes Your Data
Our AI Staff features use your data in the following ways:
- Email Draft Generation: AI reads incoming emails and generates draft responses based on your business context
- Lead Qualification: AI analyzes inquiries to score and categorize leads
- Appointment Scheduling: AI checks your calendar availability and facilitates bookings
- Response Personalization: AI uses your corrections and feedback to improve future responses
3b. AI Model Provider
We use Anthropic's Claude API for AI processing. When processing your content:
- Your data is sent to Anthropic's API for processing
- Anthropic does not use your data to train their models
- Data is processed according to Anthropic's Privacy Policy
- We do not share your business-specific context with other customers
3c. Learning and Improvement
When you correct or edit AI-generated content:
- Corrections are stored to improve future responses for your business only
- We do not use your individual corrections to train models for other customers
- You can request deletion of correction history at any time
- Aggregated, anonymized patterns may be used to improve our service generally
3d. Human Review
AI-generated content may be reviewed by humans in the following circumstances:
- When you report an issue or request support
- To investigate potential abuse or misuse
- To improve AI accuracy (anonymized samples only)
- For quality assurance of new features
4. How We Use Your Information
We use your information to provide our Service, power AI features, analyze spending to identify savings, match you with vendors, support community experiences, and improve your experience.
4a. Provide and Improve Our Service
- Create and maintain your account
- Power AI Staff features (email drafts, lead management, scheduling)
- Analyze your spending patterns to identify cost-saving opportunities
- Match businesses with relevant service providers
- Calculate and display potential savings across expense categories
- Facilitate group purchasing and negotiated rates
- Support community experiences and event participation
- Provide customer support and respond to inquiries
- Improve and optimize our platform features and user experience
4b. Communications
- Send transactional emails (account verification, password resets, AI draft notifications)
- Send service announcements and updates
- Notify you of new savings opportunities and features (with your consent)
- Send newsletters and promotional content (you can opt out anytime)
- Request feedback and conduct surveys
4c. Analytics and Research
- Analyze usage patterns and trends
- Conduct research on cost-saving opportunities across industries
- Generate aggregated, anonymized insights about business spending
- Measure the effectiveness of our Service and AI features
- Improve AI accuracy through anonymized pattern analysis
4d. Security and Compliance
- Verify identity and prevent fraud
- Detect and prevent security incidents
- Monitor for suspicious activity or abuse
- Comply with legal obligations and enforce our Terms of Use
- Protect the rights and safety of our users
5. How We Share Your Information
We share limited information with service providers, vendors you choose to work with, chamber partners, and AI processors. We never sell your personal information.
5a. With Your Consent
- Vendor Connections: When you express interest in a vendor, we share relevant business information to facilitate the connection
- Chamber Partners: If you are a chamber member, your chamber may receive aggregated reports on member participation and savings (not individual transaction details)
- Community Organizations: Event organizers receive participation data for experiences you join
- Group Purchasing: When participating in group buying, other businesses may see aggregated participation numbers (not your specific details)
5b. Service Providers
We share information with third-party service providers who perform services on our behalf:
- AI Processing: Anthropic (Claude API for AI features)
- Hosting and Infrastructure: Cloudflare (website, API hosting, D1 database)
- Analytics: PostHog (product analytics and session recording)
- Email Services: Resend (transactional email delivery)
- Payment Processing: Stripe (subscription billing and payments)
- Communication: Support chat tools and email providers
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
5c. Chamber and Community Partners
When you participate through a chamber or community organization:
- The organization receives aggregated participation statistics
- They do not receive your individual email content, AI drafts, or lead details
- They may receive your basic business profile information
- Event participation is visible to event organizers
5d. Business Transfers
If Viva is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
5e. Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (subpoenas, court orders)
- Government requests
- Requests to protect our rights, property, or safety
- Requests to protect the rights, property, or safety of others
5f. Aggregated and Anonymized Data
We may share aggregated or anonymized information that cannot reasonably be used to identify you. For example, we might publish industry reports on average cost savings by category or AI response accuracy metrics.
We do not sell your personal information to third parties for their marketing purposes.
6. Data Security
We implement industry-standard security measures to protect your information, including encryption, access controls, and regular security assessments.
We take the security of your information seriously and implement appropriate technical and organizational measures:
- Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption
- Access Controls: Strict access controls limit who can view your information
- Authentication: Secure password hashing and session management
- Infrastructure Security: Hosted on secure, SOC 2 compliant infrastructure (Cloudflare)
- API Security: All API communications use HTTPS with proper authentication
- AI Data Isolation: Your AI context and corrections are isolated from other customers
- Regular Assessments: Ongoing security monitoring and vulnerability assessments
- Employee Training: Staff trained on data protection best practices
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
7. Data Retention
We keep your information for as long as your account is active or as needed to provide our Service. You can request deletion at any time.
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Active Accounts: Information is retained while your account is active
- AI Data: Email content and AI drafts are retained for 90 days after processing unless you request earlier deletion
- Corrections: AI correction history is retained to improve your responses; you can request deletion anytime
- Calendar Data: Calendar sync data is refreshed and not permanently stored beyond sync needs
- Closed Accounts: After account deletion, we delete or anonymize your personal information within 30 days
- Legal Requirements: Some information may be retained longer if required for legal, regulatory, or tax purposes
- Anonymized Data: We may retain anonymized, aggregated data indefinitely for research and analytics
- Backup Systems: Information may remain in backup systems for up to 90 days after deletion
8. Your Rights and Choices
You have control over your information. You can access, update, or delete your data, opt out of AI features, disconnect integrations, and control how we use your information.
8a. Access and Portability
- Access: You can access most of your information through your account dashboard
- Data Export: Request a copy of your data in machine-readable format by contacting [email protected]
8b. Correction and Updates
- Update your account information through your profile settings
- Contact us to correct inaccurate information
8c. Deletion
- Request account deletion through account settings or by contacting [email protected]
- Request deletion of AI correction history separately
- We will delete or anonymize your personal information within 30 days
- Some information may be retained as required by law
8d. AI Features
- Disable AI: You can disable AI Staff features at any time in your settings
- Delete AI History: Request deletion of your AI draft and correction history
- Manual Mode: Use the platform without AI assistance if preferred
8e. Marketing Communications
- Opt Out: Unsubscribe from promotional emails using the link in any email
- Preferences: Manage communication preferences in your account settings
- Transactional Emails: You cannot opt out of essential service communications
8f. Third-Party Connections
- Disconnect QuickBooks, Google Calendar, or other integrations through your account settings
- Revoke access permissions through the third-party service's settings
- Disconnecting does not delete data already synced; request separate deletion if needed
8g. Cookies and Tracking
- Manage cookie preferences through your browser settings
- Opt out of analytics tracking (see Section 9)
9. Cookies and Tracking Technologies
We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how you use our Service.
9a. What Are Cookies?
Cookies are small text files stored on your device that help us provide and improve our Service.
9b. Types of Cookies We Use
- Essential Cookies: Required for the Service to function (authentication, security)
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how you use the Service (PostHog)
- Session Cookies: Temporary cookies deleted when you close your browser
9c. Managing Cookies
You can control cookies through your browser settings. Note that disabling certain cookies may affect your ability to use some features of our Service.
- Browser Controls: Most browsers allow you to refuse or delete cookies
- Opt-Out: Opt out of PostHog analytics by setting "do not track" in your browser
10. Children's Privacy
Viva is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at [email protected], and we will take steps to delete such information.
11. International Data Transfers
Your information may be transferred to and processed in the United States. By using Viva, you consent to this transfer.
Viva is based in the United States. If you are accessing our Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate.
These countries may have different data protection laws than your country. By using our Service, you consent to the transfer of your information to the United States and other countries where we operate.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
12a. Right to Know
- Request disclosure of the personal information we collect, use, and share
- Request the specific pieces of personal information we have collected
12b. Right to Delete
- Request deletion of your personal information (subject to certain exceptions)
12c. Right to Opt-Out of Sale
- We do not sell personal information. We have not sold personal information in the past 12 months.
12d. Right to Non-Discrimination
- We will not discriminate against you for exercising your CCPA rights
12e. Exercising Your Rights
To exercise these rights, contact us at [email protected] or through your account settings. We will verify your identity before processing your request.
13. Other U.S. State Privacy Rights
Residents of Colorado, Connecticut, Utah, and Virginia have similar rights under their respective state privacy laws. Contact us at [email protected] to exercise these rights.
14. Changes to This Privacy Policy
We may update this policy from time to time. We'll notify you of material changes via email or through the Service.
We may update this Privacy Policy periodically to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you via email if you have an account
- Display a prominent notice on our Service
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Questions?
If you have any questions about this Privacy Policy or our data practices, please contact us:
We aim to respond to all inquiries within 48 hours