Legal
Privacy Policy
Effective date: June 26, 2026
1. Introduction
Vantro.ai (“Vantro”, “we”, “us”, or “our”) operates an AI agent platform for ecommerce businesses. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you access our website at vantro.ai and use our services.
This policy applies to all visitors, registered users, and customers of Vantro. By using our services you agree to the practices described here. If you do not agree, please discontinue use of the platform.
We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”).
2. Information We Collect
Account data
When you register, we collect your name, email address, and password (stored as a secure hash). If you connect a store or third-party integration, we collect the credentials or tokens required for that connection.
Usage data
We automatically collect information about how you interact with the platform: pages visited, agent tasks created, prompts submitted, credits consumed, timestamps, IP address, browser type, and device identifiers. This data is used to operate and improve the service.
Payment information
All payment processing is handled by Stripe, Inc. We do not store full card numbers or CVV codes on our servers. We receive and store non-sensitive billing metadata from Stripe, such as the last four digits of your card, card brand, billing address, subscription status, and transaction history.
Content you provide
We store the inputs you provide to AI agents (prompts, product data, brand guidelines) and the outputs generated on your behalf. This content is used solely to deliver the service to you.
Cookies and similar technologies
We use essential session cookies to keep you logged in and to protect against cross-site request forgery. We do not use advertising cookies, third-party tracking pixels, or behavioural analytics cookies. See Section 8 for details.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate your sessions.
- Deliver the AI agent platform, process your prompts, and return generated content.
- Process payments and manage your subscription through Stripe.
- Monitor credit usage and enforce plan limits.
- Detect and prevent fraud, abuse, and security incidents.
- Send transactional emails (account activation, billing receipts, agent task confirmations).
- Send optional product updates and announcements — you may opt out at any time.
- Analyse aggregate, anonymised usage patterns to improve platform performance and features.
- Comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
Contract performance (Art. 6(1)(b) GDPR)
Processing your account data, usage data, and payment metadata is necessary to provide the services you have contracted for. Without this processing we cannot operate your account.
Legitimate interests (Art. 6(1)(f) GDPR)
We process usage analytics and security logs on the basis of our legitimate interests in operating a secure, reliable platform and in understanding how the service is used. We have balanced these interests against your rights and concluded they do not override your fundamental interests.
Legal obligation (Art. 6(1)(c) GDPR)
We may process data where necessary to comply with a legal obligation, such as retaining billing records for tax purposes or responding to a lawful court order.
Consent (Art. 6(1)(a) GDPR)
Where we send optional marketing communications, we do so on the basis of your consent. You may withdraw consent at any time by clicking “Unsubscribe” in any such email or by contacting us at privacy@vantro.ai.
5. Your Rights
GDPR rights (EEA & UK residents)
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct inaccurate or incomplete data.
- Right to erasure: You may request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: You may request your data in a structured, machine-readable format.
- Right to restriction: You may ask us to restrict processing of your data in certain circumstances.
- Right to object: You may object to processing based on legitimate interests, including for direct marketing.
- Right to lodge a complaint: You have the right to file a complaint with your national data protection authority.
CCPA rights (California residents)
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to correct: You may request correction of inaccurate personal information.
- Right to opt out of sale: Vantro does not sell personal information. No opt-out is required, but you are entitled to this right.
- Right to non-discrimination: We will not discriminate against you for exercising any CCPA rights, including by denying services or charging different prices.
To exercise any of these rights, email privacy@vantro.ai. We will respond within 30 days (or 45 days where permitted by law).
6. Data Retention
We retain your account data, agent content, and usage logs for as long as your account is active. When you delete your account, we begin a 90-day retention window during which data is flagged for deletion but not yet purged. This window allows for recovery in the event of accidental deletion. After 90 days, personal data is permanently deleted from production systems and queued for deletion from backups on their regular rotation cycle.
Billing records and transaction logs are retained for a minimum of 7 years to comply with tax and financial reporting obligations, even after account deletion.
Anonymised and aggregated usage statistics that cannot be used to identify you may be retained indefinitely for product analytics.
7. Third-Party Services
We share data with the following third-party sub-processors where necessary to operate the platform. Each is bound by contractual data protection obligations.
Stripe, Inc.
Payment processingStripe processes payment card data on our behalf. Your card details are transmitted directly to Stripe and are never stored on Vantro servers. Stripe is PCI DSS Level 1 certified. Privacy policy: stripe.com/privacy.
Anthropic, PBC
AI model inferencePrompts and context you submit to AI agents are sent to Anthropic's Claude API to generate responses. Anthropic's API usage data practices are governed by their usage policy. We do not share identifying account information with Anthropic — only the content of agent requests.
Vercel, Inc.
Cloud hosting & edge deliveryOur frontend application is hosted on Vercel's infrastructure. Vercel may process request logs, including IP addresses, as part of its standard hosting operations. Vercel is SOC 2 Type II certified.
We do not sell personal data to any third party for advertising or marketing purposes.
8. Cookies
Vantro uses only essential cookies. Essential cookies are strictly necessary for the platform to function — they maintain your authenticated session and protect against security attacks such as CSRF. These cookies are set by vantro.ai and are not used for tracking.
We do not use third-party advertising cookies, social media tracking pixels, or behavioural analytics services that place cookies on your device. We do not use Google Analytics, Facebook Pixel, or similar tracking technologies.
Because we only use essential cookies, no cookie consent banner is required under ePrivacy Directive exemptions for strictly necessary cookies. If you block essential cookies via your browser settings, the platform will not function correctly.
9. California Residents
CCPA / CPRA Notice
We do not sell personal information. Vantro has not sold and does not sell personal information to third parties as defined under the CCPA. You therefore do not need to opt out of a sale.
We do not share personal information with third parties for cross-context behavioural advertising purposes.
In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address), commercial information (subscription and billing records), internet or other electronic network activity information (usage logs), and inferences drawn to create a profile about service usage patterns.
We collect this information for the business purposes described in Section 3. We disclose personal information only to the service providers listed in Section 7.
To submit a verifiable consumer request under the CCPA, or to designate an authorised agent to act on your behalf, contact us at privacy@vantro.ai. We will not discriminate against you for exercising your CCPA rights.
10. Contact
For all privacy-related enquiries, requests to exercise your rights, or concerns about this policy, please contact our privacy team:
Vantro.ai — Privacy
privacy@vantro.aiWe will acknowledge your request within 5 business days and aim to resolve it within 30 days. If we require more time, we will inform you of the reason and the expected completion date.
If you are an EEA resident and believe we have not handled your data correctly, you also have the right to lodge a complaint with your local supervisory authority.
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective date” at the top of this page. Material changes will be communicated to registered users by email at least 14 days before they take effect.