Privacy Policy

Last updated: July 9, 2026

Last updated: July 9, 2026.

This Privacy Policy (Aviso de Privacidad Integral) explains how EvaAI ("EvaAI," "we," "us"), operated by Gustavo Zermeno P., operating commercially as EvaAI, with domicile in Leon, Guanajuato, Mexico, collects, uses, and protects information when businesses use our software to deploy AI chatbots, connect their messaging channels, and when administrators access our website or dashboard. This document constitutes the Aviso de Privacidad of EvaAI in accordance with Mexico's LFPDPPP.

For details on how we process data on behalf of business customers, see our Data Processing Agreement (available at /legal/dpa).

If you have questions, reach us at support@goeva.ai and we will respond promptly.

This Policy is available in English and Spanish. In case of conflict between language versions, the Spanish version shall prevail.

1) Scope

This Policy applies to the EvaAI website, admin dashboard, APIs, and the messaging integrations that we provide to our customers.

It does not govern how our customers handle information they export or store outside of EvaAI.

2) Roles

  • For end-user conversations handled by EvaAI on behalf of a business, the business is the controller and EvaAI is the processor/service provider.
  • For our website, billing, analytics, abuse prevention, and account administration, EvaAI is the controller.

3) Information We Process

Business account data such as company name, email, phone, messaging channel identifiers, configuration, and billing details.

Message and media data, including message content, attachments, templates, metadata, delivery status, and related conversation history.

Technical and security data like logs, IP addresses, device/browser information, diagnostic events, and fraud-prevention signals.

Support communications that you send to us.

4) How We Use Information

To provide, secure, and improve the EvaAI platform; deliver conversations; enable integrations; and troubleshoot issues.

To operate analytics, billing, compliance, monitoring, abuse prevention, and product development.

To respond to support requests and communicate updates about the service.

5) Sharing

We do not sell personal data.

  • Service providers (sub-processors) that host or help deliver our services — including infrastructure, storage, monitoring, email, analytics, payment processing, voice and SMS communications, and artificial-intelligence model providers — under confidentiality and security obligations. A current list of our sub-processors is available in our Data Processing Agreement (/legal/dpa).
  • Authorities or third parties when required by law, to enforce our terms, or to investigate abuse.

6) Data Transfers

We operate primarily in Mexico and the United States and may process data in other regions where our infrastructure or service providers are located.

When legally required, we use appropriate safeguards such as Standard Contractual Clauses.

7) Legal Bases

Our customers are responsible for any required notices or consents to their end-users.

  • Performance of a contract (providing the EvaAI service).
  • Legitimate interests (security, fraud prevention, product operation and improvement).
  • Legal obligations (record-keeping, compliance).
  • Compliance with Mexico's Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP) and its regulations.

8) Retention

We store conversations and configuration data while an account is active to enable features such as inbox history and analytics.

When a subscription is cancelled, we honor the paid period: the service and the AI agent keep running until the end of the period you already paid for. When the subscription terminally ends — at the end of that paid period, or after a failed payment once our automatic retries are exhausted — the account is paused.

While paused, most data is held in a reversible state so the account can be reactivated at any time before permanent deletion; reactivation restores the service. During this period the account owner keeps access to log in, manage billing, request a data export, and reactivate.

Certain resources are reclaimed on a staged schedule. A dedicated voice or telephone number, if the account has one, is released approximately 30 days after a voluntary cancellation, or approximately 60 days after a pause caused by non-payment; once released, a later reactivation is assigned a new number.

Approximately 150 days after the pause, if the account has not been reactivated, we permanently and irreversibly delete conversations, personal data, media, and knowledge-base content, and disconnect the messaging channels. Backups containing the deleted data are purged in the ordinary course of our backup rotation.

Fiscal and billing records, including electronic invoices (CFDI), are retained for the period required by Mexican tax law (approximately five years), even after the data above is deleted.

Before permanent deletion, we notify the account owner and offer the option to export the account's data or to reactivate.

9) Security

We use administrative, technical, and physical safeguards appropriate to the data we process, including encryption in transit (HTTPS), access controls, least-privilege practices, monitoring, and audit logging.

No method of transmission or storage is 100% secure; we continually improve our defenses.

10) Cookies and Similar Technologies

We use cookies and similar technologies on our website to provide essential functionality (session management, authentication, locale preferences), improve our services (analytics), and support third-party integrations (payment processing via Stripe, scheduling via Calendly).

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect site functionality.

Third-party services used on our site may set their own cookies subject to their own privacy policies.

For users in the European Economic Area (EEA), we provide additional cookie management options as required by applicable law.

11) Rights and Requests

Business administrators can access or update data through the dashboard or by emailing support@goeva.ai.

End-users of our customers should contact the business they messaged. We act as processor and will assist our customers as required by law.

Under Mexican data protection law (LFPDPPP), you have the right to Access, Rectify, Cancel, and Oppose the processing of your personal data (ARCO rights). To exercise these rights, contact privacy@goeva.ai.

We will respond to ARCO requests within 20 business days of receipt, as required by LFPDPPP Article 32.

12) Account Closure and Data Handling

An authorized account owner may request closure via the dashboard or by contacting support. Cancelling the subscription starts the lifecycle described in "Retention": the paid period is honored, then the account is paused, and data is deleted on the staged schedule set out there.

Login remains available throughout — closing or pausing an account never locks the owner out of billing, data export, or reactivation. Fiscal and billing records (CFDI) are retained as required by Mexican tax law even after other data is permanently deleted.

13) Children

Our services are intended for businesses and are not directed to children.

14) Sensitive Data

EvaAI does not intentionally collect sensitive personal data (datos personales sensibles) such as health information, racial or ethnic origin, religious or moral beliefs, union affiliation, political opinions, sexual preference, or biometric data.

Business customers are responsible for ensuring that sensitive personal data is handled appropriately when transmitted through the Services and for obtaining the express written consent required under LFPDPPP for the processing of such data.

15) Automated Decision-Making

The EvaAI platform uses artificial intelligence models to generate automated responses in conversations on behalf of our business customers. These AI agents may qualify leads, route inquiries, provide product information, and perform other automated actions based on their configuration.

Business customers using EvaAI are responsible for disclosing to their end-users that they may be interacting with AI-powered agents. End-users may request human intervention by contacting the business directly.

16) Data Breach Notification

In the event of a personal data breach that may significantly affect the economic or moral rights of data subjects, EvaAI will notify affected parties without undue delay in accordance with applicable law, including LFPDPPP Article 20.

The notification will include the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address and mitigate the breach.

17) Consent Withdrawal

You may withdraw your consent to the processing of your personal data at any time by contacting privacy@goeva.ai. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Please note that withdrawing consent for data processing that is essential to providing the Services may require the closure of your account, as we may not be able to continue delivering the Services without processing certain data.

18) Marketing Communications

We may send you service-related communications (account notifications, billing updates, security alerts) which are necessary for the operation of your account and are not optional.

If we send promotional or marketing communications, you may opt out at any time by following the unsubscribe link in the email or by contacting support@goeva.ai. Opting out of marketing does not affect service-related communications.

19) Third-Party Links

Our website and Services may contain links to third-party websites or services not operated by EvaAI. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access.

20) Updates

We may update this Policy as our product evolves. If changes are material we will provide at least 30 days advance notice via email or in-product alerts.

21) Shopify Integration Data

When a merchant connects their Shopify store to EvaAI, we receive specific data from the Shopify Admin API in order to power the AI agent's responses on the merchant's behalf. This section discloses what we receive, why, and how long we keep it.

  • Catalog data — product titles, descriptions, prices, variants, images, inventory levels, and store locations. Used to answer product, stock, and pricing questions.
  • Order data — order number, status, line items, fulfillment and tracking information, plus the email address used at checkout. Used only to answer order-status and tracking questions when the end-customer self-identifies by email or phone.
  • Customer data — name, email, phone number, default address (where granted by Shopify Protected Customer Data Access). Used only to recognize a returning customer in a conversation, after that customer self-identifies in chat. Never used for marketing, profiling, or sale to third parties.
  • Draft order data — drafts EvaAI creates when an end-customer asks for a custom order or invoice. Created on the merchant's behalf at the merchant's instruction.

Purpose Limitation

Shopify-derived data is processed only for the purpose of operating the merchant's AI customer-service agent within EvaAI. We do not use Shopify customer data for advertising, model training, profiling, automated decision-making with legal effects, or any purpose unrelated to answering the merchant's customers.

Retention

While the merchant remains connected, Shopify data is refreshed via webhooks and a nightly reconciliation job. We retain it for as long as the connection is active.

When the merchant disconnects their Shopify store from EvaAI, all Shopify-derived rows (products, customers, orders, draft orders, locations) are deleted within 90 calendar days. Backups containing the data are purged within an additional 60 days.

If a merchant or end-customer requests earlier deletion via the Shopify GDPR webhooks (`customers/data_request`, `customers/redact`, `shop/redact`), EvaAI honors that request within 30 days.

End-Customer Rights

End-customers of a merchant using EvaAI may exercise their rights (access, rectification, deletion, opt-out) by contacting the merchant directly. The merchant is the data controller. Upon receiving the merchant's instruction, EvaAI will execute the requested action on its systems within the response windows set out elsewhere in this Policy.

22) Contact Us

For privacy-related questions or to exercise your data rights:

  • General: support@goeva.ai
  • Privacy and data protection: privacy@goeva.ai
Message us on WhatsApp