01Scope and our roles
In shortThis policy covers information Parlox decides how to use. If you visited a store that uses Parlox, that store’s privacy policy applies.
Parlox (“Parlox”, “we”, “us”) builds conversion infrastructure for AI commerce: software that shows online stores how AI shopping agents use their sites, where those agents fail, and helps them complete purchases. Depending on the data, we play one of two roles under privacy law:
- Controller. We decide how information is used for visitors to parlox.io, people who request an audit, and our customers’ business contacts. This policy covers that information.
- Processor (or “service provider”). When a merchant installs Parlox on their store, we process that store’s data on the merchant’s behalf and follow their instructions (see section 3). If you visited such a store, its privacy policy applies, and requests about that data should go to the store.
02Information we collect
In shortWhat you give us when you ask for an audit or become a customer, plus the technical data every website receives.
Information you give us
- Audit requests: the web address of the store you want audited, and your work email.
- Customers: business contact details such as your name, work email, role and company, details about your stores and how you’ve set up Parlox, and billing details for paid plans.
- Communications: anything you tell us when you email us or we follow up with you.
Information collected automatically
- Standard technical data processed by our hosting provider when you visit parlox.io: IP address, user agent, pages requested, referring page, timestamps and security signals used to block abuse.
- For audit requests, where on our site you made the request, and your IP address for rate limiting and abuse prevention.
Information from other sources
To prepare an audit, we send automated agents to the publicly available pages of the store you name, the same way an AI shopping agent would. We don’t log in, bypass access controls or place real orders, and we don’t intentionally collect personal information from those pages.
We don’t collect sensitive personal information, such as health or financial account data, through the website or the audit.
03Information we process for merchants
In shortOn a merchant’s store, Parlox looks at incoming visits to tell AI agents from people. We use that data only for that merchant, never to profile anyone.
When a merchant installs Parlox, we process the following on the merchant’s behalf (“Service Data”), depending on how they’ve set it up:
- Request data from visits to the store, such as IP address, user agent and other request headers, pages or endpoints requested, referrer and timestamps.
- Signals used to classify traffic, for example whether a visit comes from an AI crawler, a browser agent or a person.
- Journey data: the steps an agent takes on the store, and where it succeeds or fails.
- Commerce data the merchant provides or connects, such as products, availability, prices, shipping and delivery options, warranties and offer rules.
- Order and attribution data, such as order identifiers, amounts, timestamps and whether an order is linked to an agent journey.
Telling agents and people apart means looking at incoming requests, so Parlox may process request data from human visitors too. We use it only to classify traffic and provide the Service to that merchant, never to identify or profile individual people.
We use Service Data only to provide, secure and support the Service for the merchant it belongs to, under our data processing terms. We may create aggregated, de-identified statistics that don’t identify any merchant or person, and use them to improve Parlox and describe industry trends.
04How we use information, and why
In shortTo deliver audits, run the Service, keep things secure and improve Parlox. Never to sell, and never for advertising.
As a controller, we use personal information for these purposes. The last column shows our legal basis if you’re in the EEA or UK.
| Purpose | Information used | Legal basis (EEA/UK) |
|---|---|---|
| Prepare and deliver the audits you request, and follow up | Store address, work email, request details | Steps you asked us to take; legitimate interests for follow-up |
| Provide and support the Service for customers | Business contact details, store and setup details, communications | Contract |
| Secure the website and Service, and prevent spam and abuse | IP address, user agent, request and security data | Legitimate interests |
| Understand and improve the website and Service | Technical and usage data, mostly aggregated | Legitimate interests |
| Send updates about Parlox (you can unsubscribe at any time) | Work email, name | Consent where the law requires it; otherwise legitimate interests |
| Meet legal obligations and enforce our terms | Whatever is relevant to the obligation or claim | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance them against your rights, and you can object (see section 11). We don’t sell personal information, share it for cross-context behavioral advertising, or make decisions about you with legal or similarly significant effects based solely on automated processing.
06Service providers
In shortThe companies that process personal information for us. We update this list before adding one.
These providers (sub-processors) process personal information for us. We’ll update this list, and notify customers, before adding a new one.
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery and serverless functions (including receiving audit requests) | United States; global edge network |
08International transfers
In shortYour information may be processed outside your country, with legal safeguards in place.
Our providers operate in many countries, so information may be processed outside the country where you live. When we transfer personal information from the EEA, UK or Switzerland, we rely on recognized safeguards such as the European Commission’s Standard Contractual Clauses, or an adequacy framework our provider takes part in.
09How long we keep it
In shortOnly as long as we need it, with fixed limits for each kind of information.
- Audit requests and results: while we deliver the audit and follow up, then deleted or anonymized within 24 months of your last contact with us, unless you become a customer.
- Customer account information: for as long as you’re a customer, then as long as needed for legal, tax or accounting reasons.
- Security and technical logs: generally no more than 30 days, unless needed to investigate abuse.
- Service Data: for as long as the merchant uses Parlox, then deleted within 30 days after they stop or ask us to. Backups expire on their normal cycle within a further 30 days. Aggregated, de-identified statistics may be kept.
10Security
In shortWe protect information with encryption and strict access controls, and tell people promptly if something goes wrong.
We use technical and organizational measures to protect personal information, including encryption in transit, access limited to people who need it, and protection against abuse. No method of transmission or storage is completely secure. If a breach affects your information, we’ll notify affected customers, individuals and authorities as the law requires.
11Your rights and choices
In shortYou can ask to see, fix, delete or export your information by emailing us. For data from a store, ask the store.
Depending on where you live, you may have the right to:
- access the personal information we hold about you, and get a copy;
- correct information that’s inaccurate;
- delete your information;
- object to or restrict certain processing, including direct marketing;
- receive your information in a portable format;
- withdraw consent where we rely on it, without affecting processing that already happened.
To make a request, email legal@parlox.io. We may need to verify your identity, and we’ll respond within the time the law requires, usually within one month. You can unsubscribe from our emails at any time using the link in each email. If you’re in the EEA or UK, you can also complain to your local data protection authority.
For Service Data, the merchant is responsible for responding to your request, so contact the store directly. If you contact us, we’ll pass your request to the merchant and help them respond.
12US state privacy notice
In shortIf you live in California or another US state with a privacy law, you have extra rights. We don’t sell or share your information.
In the past 12 months, as a controller, we collected these categories of personal information. We used them for the purposes in section 4 and disclosed them only to the service providers in section 6.
| Category | Examples | Source |
|---|---|---|
| Identifiers | Work email, name, IP address | You; your device |
| Internet or network activity | Pages requested, referrer, user agent, timestamps | Your device |
| Professional information | Company and role | You |
You may have the right to know what we collect and how we use and disclose it, and to request access, correction and deletion. We don’t sell personal information or share it for cross-context behavioral advertising, and we don’t use or disclose sensitive personal information. We treat Global Privacy Control signals as a valid opt-out request. We won’t discriminate against you for exercising your rights. You may use an authorized agent to make a request. If we decline a request, you can appeal by replying to our decision, and we’ll explain the outcome.
13Requests made by AI agents
In shortAn AI agent can request an audit for you. We treat what it sends as coming from you.
Our audit form is designed so AI agents can use it on someone’s behalf. If an agent submits information for you, we treat it as information you provided, and you’re responsible for having authorized the agent. We may contact the email address given to confirm the request.
14Children
In shortParlox is for businesses, not children.
Parlox isn’t directed at children, and we don’t knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we’ll delete it.
15Changes to this policy
In shortWe’ll update this policy as Parlox grows, and tell customers about significant changes.
We’ll update this policy as Parlox grows, including when we add service providers. We’ll change the date at the top and, for significant changes, notify customers by email or in the Service before they take effect.
16Contact
Questions or requests about privacy: legal@parlox.io.