Legal
Avoca, Inc. Privacy Policy
Effective Date: January 29, 2025
- Introduction. At Avoca, we value your privacy and are committed to protecting your personal data. This Privacy Policy outlines the types of information we collect, how we use it, who we share it with, and what choices you have regarding your data. By accessing or using our services, you acknowledge and agree to the terms of this Privacy Policy.
We may update this Privacy Policy from time to time, and we encourage you to review it regularly to stay informed about how we are protecting your information.
- Definitions
- Company. Refers to Avoca, Inc. Also referred to as “Avoca, ” “Company,” or “We.”
- Website. The Avoca website located at https://avoca.ai.
- Service. Refers to the Avoca website, platform, applications, and any related products or services provided by the Company.
- You. The individual accessing or using the Service or the legal entity on whose behalf such an individual is using the Service.
- Account. A unique account created for you to access our services.
- Device. Any hardware used to access our services, including but not limited to computers, smartphones, and tablets.
- Personal Data. Any information related to an identified or identifiable individual.
- Service Provider. Any third party that processes data on behalf of Avoca.
- Usage Data. Data collected automatically, including service interactions and activity logs.
- Cookies. Small files stored on your device that enhance user experience and track browsing activity.
- Affiliate. Any entity that controls, is controlled by, or is under common control with Avoca.
- What Data We Collect. We collect various types of personally identifiable information, including but not limited to:
- Name (First and Last)
- Email Address
- Phone Number
- Company Name and Job Title
- Mailing and Business Address
- Account Login Credentials (usernames and encrypted passwords)
- Billing Information, including payment details
- Bank Account Information for payment processing
- Government-Issued Identification (passport, driver’s license, or national ID) for verification
- Tax Identification Number (if applicable)
If you complete a financial transaction using our services, we may request additional verification, including:
- Date of Birth
- Proof of Address (utility bills, bank statements, or similar documents)
- Additional Identity Verification Documents as Required by Law
- Google Calendar Integration and OAuth Data
- What Calendar Data We Access. When you connect your Google Calendar to Avoca, we access and store:
- Your calendar list and calendar metadata
- Calendar events (title, description, date, time, attendees, location, reminders)
- Free/busy availability information
- Real-time calendar change notifications
- OAuth authorization tokens (stored encrypted in our systems)
- Why We Need Calendar Access. We request Google Calendar permissions (calendar.events scope) to enable automated service appointment management. Specifically, we use calendar access to:
- Read your team’s calendar availability to prevent double-booking technicians
- Automatically create calendar events when customers book appointments through Avoca’s AI conversation system
- Update or cancel calendar events when customers reschedule or cancel appointments
- Monitor calendar changes in real-time to keep your schedule synchronized
- Query free/busy windows to show accurate availability to customers
- How We Use Calendar Data.
- Calendar data is used exclusively to manage service appointments and maintain accurate scheduling for your team.
- We store encrypted OAuth tokens in our secure database to maintain your calendar connection.
- Calendar events are created, updated, and deleted automatically based on customer booking actions.
- We use Google’s Calendar API watch feature to receive notifications of calendar changes.
- Calendar data is encrypted both in transit (via HTTPS) and at rest in our databases.
- We do not share your calendar data with third parties for marketing or advertising purposes.
- Calendar information is only accessed when needed to check availability, create bookings, or sync changes.
- Automated AI Booking. Avoca uses AI-powered conversations to interact with your customers. When a customer books an appointment through our AI system:
- The AI checks your team’s calendar availability in real-time to offer available time slots.
- Upon confirmation, Avoca automatically creates a calendar event with appropriate details (customer name, service type, location, reminders).
- The calendar event includes the customer as an attendee and sends appropriate notifications.
- Any changes made by the customer are immediately reflected in your Google Calendar.
- Your Calendar Data Rights.
- You can revoke Avoca’s access to your Google Calendar at any time through your Google Account settings: https://myaccount.google.com/permissions.
- Revoking access will prevent Avoca from reading or creating calendar events and disable automated appointment management.
- You can request deletion of stored OAuth tokens and calendar data by contacting all@avoca.ai.
- Revoking calendar access does not delete your Avoca account, but automated scheduling features will no longer function.
- Data Retention.
- OAuth tokens are retained as long as your calendar integration remains active.
- Calendar event data is cached temporarily for scheduling purposes and synchronized with your Google Calendar.
- Upon disconnection or account deletion, we delete stored OAuth tokens and cached calendar data within 30 days.
- Compliance. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use calendar data for the purposes described above and do not use it for serving advertisements or building user profiles for non-service purposes.
- What Calendar Data We Access. When you connect your Google Calendar to Avoca, we access and store:
- How We Collect Data
- Directly from You. When you provide information via forms, account registration, or customer support interactions.
- Automatically. Through tracking technologies such as cookies, log files, and analytics tools.
- From Third Parties. Including service providers, business partners, and publicly available sources.
- Why We Process Your Data and How We Use It
- Providing and Maintaining Services. To operate and improve our services, including user authentication and personalization.
- Processing Payments and Transactions. To facilitate secure purchases and verify identity.
- Communication. To send updates, newsletters, service alerts, and customer support responses.
- Security and Fraud Prevention. To detect and prevent unauthorized access, fraud, or abuse.
- Legal Compliance. To meet legal obligations, including data protection regulations.
- Advertising and Marketing. To send promotional content and display targeted ads.
- Analytics and Research. To assess user trends, improve our services, and develop new features.
- Your Privacy Controls & Choices. You have control over your personal data, and depending on applicable laws, you may have the right to:
- Access Your Data: Request a copy of the personal data we hold.
- Correct Your Data: Update inaccurate or incomplete information.
- Delete Your Data: Request the removal of personal data under certain conditions.
- Restrict Processing: Limit how your data is used in specific circumstances.
- Object to Processing: Decline certain data processing, including direct marketing.
- Data Portability: Request a structured, machine-readable copy of your data.
- Withdraw Consent: If processing is based on consent, you may withdraw it at any time.
- Manage Cookies and Tracking Technologies: Adjust settings via your browser or opt-out mechanisms.
- File a Complaint: Lodge a complaint with a relevant data protection authority.
To exercise any of these rights, contact us at all@avoca.ai.
- How We Protect Your Data. We implement security measures such as:
- Data Encryption: Protecting data in transit and at rest.
- OAuth Token Encryption: Calendar authorization tokens are encrypted and stored securely to protect your calendar access credentials.
- Access Controls: Limiting access to authorized personnel only.
- Regular Security Audits: Assessing system vulnerabilities and ensuring compliance.
- How Long We Retain Your Data. We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy. Once data is no longer needed, we securely delete or anonymize it unless legal requirements mandate further retention.
- International Data Transfers. Your data may be processed outside your country of residence. We ensure compliance with applicable laws through:
- Standard Contractual Clauses (SCCs)
- Data Encryption and Pseudonymization
- Compliance with GDPR, CCPA, and other relevant regulations
- Children’s Privacy. Our services are not intended for individuals under 13. We do not knowingly collect personal data from children under 13. If we become aware of such collection, we will take immediate steps to remove the data. If your country requires parental consent for data collection under the age of 18, we may request additional verification.
- Governing Law and Dispute Resolution. This Privacy Policy is governed by the laws of the State of New York, United States. Disputes shall be resolved through:
- Negotiation. Attempting informal resolution before legal action.
- Mediation or Arbitration. Handling unresolved disputes through legally recognized mediation services.
- Litigation. Pursuing legal action in the courts of the State of New York, United States if necessary.
- Changes to This Privacy Policy. We may update this Privacy Policy periodically. We will notify users of significant changes via website updates or direct communication.
Contact: all@avoca.ai | 55 5th Ave Floor 17, New York, NY 10003