Soulvaya OS
Legal

Privacy Policy

Effective date: July 22, 2026 · Operated by Soulvaya Labs, Inc., a Delaware corporation

⚠️ Attorney-review note: This document follows Soulvaya Labs, Inc.'s approved legal framework and is tailored to the Soulvaya OS platform. Confirm bracketed items and have counsel review before publication. It is not itself legal advice.

1. Scope — Two Audiences

This policy covers Clients (business owners who buy Soulvaya OS) and Clients' customers (end customers of our clients whose information flows through booking forms, inboxes, reviews, and reminders we operate on the client's behalf). For that second category, our client is the business responsible for the relationship; we act as their service provider/processor.

2. Information We Collect

From visitors/prospects: name, email, phone, business name, and answers submitted through our assessment, lead, checkout-request, and contact forms; basic technical data (IP, browser, pages viewed) from hosting logs.

From clients: onboarding brief content (business details, services, pricing, brand voice, hours, photos), account email, authentication data (PINs are stored only as salted cryptographic hashes — never in plain text), payment records (processed by Stripe — we never see or store full card numbers), support communications, and Command Center content.

From clients' customers (on the client's behalf): booking requests, appointment details, contact details, messages, review content, and communication consent/opt-out status.

From AI features: prompts and business context sent to AI providers to generate drafts, replies, media, and insights (Section 5).

3. How We Use Information

To deliver the Services (building/hosting sites, operating Command Centers, drafting content in the client's voice, sending approved communications, scoring assessments, support, billing); to operate the business (security, fraud prevention, debugging, improvement); and to communicate (transactional emails and limited service updates, with a cadence cap on non-essential email). We do not sell personal information and do not run third-party advertising trackers on the platform.

4. Cookies & Analytics

The marketing site and Command Center use only cookies/local storage necessary for operation (session state, preferences, demo mode, and consent choice). See the Cookie Notice for details and choices. [If any analytics tool is enabled, name it here and disclose what it collects.]

5. AI Processing

To provide AI features we send the minimum relevant business context (e.g., your services, pricing, recent activity, and the specific text being drafted or answered) to model providers — currently OpenAI and Anthropic — and media prompts to Higgsfield. We do not send your customers' payment details to AI providers. Under our provider agreements, API data is not used to train their public models [verify current provider API data-use terms at publication]. AI outputs are drafts requiring your approval before publication.

6. Subprocessors

Netlify (hosting, forms, functions), Supabase (database, auth), Stripe (payments), Resend (email), Twilio (SMS), Meta Platforms (social publishing), OpenAI / Anthropic (AI text), Higgsfield (AI media). Each receives only the data required for its function. Material changes will be reflected here.

7. Storage, Security & Retention

Data is stored in managed cloud infrastructure (Supabase/Postgres; media on hosted CDNs). Security measures include server-side-only API keys, project-scoped tenant isolation for hosted Command Centers, hashed PINs, brute-force lockouts, and least-privilege access. No system is perfectly secure; we will notify affected clients without undue delay after confirming a breach affecting their data [add statutory notice window if required by your state].

Retention: active client data is kept for the engagement. After cancellation we deliver exports on request within 14 days and delete or de-identify client project data within [90] days of wind-down, except records we must keep (billing/tax) and minimal logs. Prospect/lead data is retained up to [24] months from last contact.

8. Your Rights

All users may request access, correction, export, or deletion by emailing hello@soulvayalabs.com; we respond within 30 days. California (CCPA/CPRA): rights to know, delete, correct, and opt out of "sale/sharing" (we do neither), and non-discrimination. EU/UK (GDPR), if applicable: lawful bases are contract, legitimate interests, and consent; you may complain to your supervisory authority. [Confirm whether you serve EU/UK clients; if not, state the Services are directed to U.S. businesses.] Clients' customers should direct record-specific requests to the business they interacted with; we assist our client in fulfilling them.

9. Children

The Services are for businesses and are not directed to children under 13 (or 16 where applicable). We do not knowingly collect children's data.

10. Changes

We post updates here and email clients about material changes at least 14 days before they take effect.

11. Contact

Soulvaya Labs, Inc., a Delaware corporation · 131 Continental Drive, Suite 305, Newark, Delaware 19713 · hello@soulvayalabs.com