Privacy Policy

We take your privacy seriously. Here's exactly how we protect your information.
Last Updated: October 8, 2025

1. Introduction

Welcome to Vellix Assist ("we," "our," or "us"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension for Gorgias.

2. Information We Collect

We collect information that you provide directly to us when you:

  • Install and set up the Vellix Assist extension
  • Provide your OpenAI API key
  • Authorize OAuth access to your Gorgias account
  • Contact our support team

This information may include:

  • Gorgias account information (account ID, subdomain)
  • Usage analytics and performance data
  • Technical information (browser version, extension version)
  • Communication records with our support team

3. Automatically Collected Information

When you use Vellix Assist, we automatically collect certain information about your usage patterns. This includes:

  • Extension activation and feature usage events
  • Performance metrics (response times, error rates)
  • Browser and device information
  • Anonymized ticket IDs for usage tracking

Important: OpenAI API Keys

You provide your own OpenAI API key for AI functionality. We never store, access, or manage your OpenAI credentials. All AI processing happens directly between your browser and OpenAI's servers.

4. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Vellix Assist service
  • Process OAuth authentication with Gorgias
  • Improve service performance and user experience
  • Provide customer support and technical assistance
  • Monitor service usage and analyze trends
  • Comply with legal obligations and protect our rights

5. Sharing Your Information

We may share your information with:

  • Gorgias: For OAuth authentication and API access (only necessary account information)
  • OpenAI: For AI processing (you provide your own API key)
  • Service Providers: Hosting and infrastructure providers (Vercel)

We do NOT share your information with:

  • Other users or third parties
  • Advertising networks or data brokers
  • Social media platforms
  • Any external analytics or tracking services

6. Your Choices and Rights

You have several rights regarding your personal information:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Request removal of your data
  • Portability: Export your data in a portable format
  • Opt-out: Disable usage analytics collection

To exercise these rights, please contact us at privacy@vellixapp.com. We will respond within 30 days.

7. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: All data transmission uses HTTPS/TLS
  • Secure Storage: Sensitive data is encrypted at rest
  • Access Controls: Strict limitations on who can access your data
  • Regular Audits: Ongoing security reviews and updates

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain your information for the following periods:

  • Usage Analytics: 24 months for service improvement
  • Account Information: While you use the service
  • Error Logs: 30 days for debugging and support
  • Communication Records: 2 years for legal compliance

9. OAuth and Third-Party Access

Vellix Assist uses OAuth 2.0 for secure authentication with Gorgias. This provides:

  • Secure, token-based access to your Gorgias account
  • Limited permissions (only necessary for functionality)
  • Ability to revoke access at any time through Gorgias
  • No storage of your Gorgias credentials on our servers

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers, including:

  • Standard contractual clauses
  • Adequacy decisions where applicable
  • Compliance with applicable data protection laws

11. Children's Privacy

Our service is designed for business use by customer support teams and professionals. We do not knowingly collect personal information from individuals under 18 years of age.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will:

  • Post the updated policy on this page
  • Update the "Last Updated" date
  • Notify you of material changes via email or service notification

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Privacy Inquiries
privacy@vellixapp.com
General Support
hello@vellixapp.com
Back to Vellix