Privacy Policy
Last updated: 22 July 2026
This policy explains what data Vergio collects, how we use it, and the choices you have. It applies to our website and the Vergio application.
Information we collect
- Account & agency data:your name, email, and the agency profile you provide or we infer from your website (company, services, target market).
- Free-check submissions:the store URL and the email you enter to run a public store check.
- Usage & product data:the accounts you save, notes, and reports you generate.
- Payment data:handled by our payment processor (Stripe). We do not store full card numbers.
- Technical data:basic logs and error reports needed to operate and secure the Service.
- Store signals:publicly available information about Shopify stores we analyse (catalog, theme, apps, reviews, page speed). This is public storefront data, not private merchant data.
- Prospect & contact data:business contact details (such as a name and work email) for merchants and agencies, gathered from public sources and checked for deliverability, used to power account records and Outreach Studio.
How we use it
To provide the Service (build your list, generate reports, process payments), to communicate with you (product notifications, support, and your weekly digest where relevant), to keep the Service secure and reliable, and to improve it. We do not sell your personal data.
Service providers
We share data with vendors who process it on our behalf, under contract. Each processes data only to provide its service to us:
- Infrastructure: Supabase (database, authentication, storage), Vercel (application hosting), Trigger.dev (background jobs), Stripe (payments), Resend (transactional email), Sentry (error monitoring), and PostHog (product analytics, EU-hosted).
- AI analysis: Anthropic and OpenAI (the AI models that power diagnoses and reports), and Google PageSpeed (real-world performance data). These AI providers do not receive raw or derived Google Workspace API user data.
- Store discovery & enrichment: providers we use to find and analyse public Shopify storefronts and to compile and verify business contact details, including Apify, Bright Data, urlscan.io, SerpAPI, and MillionVerifier. These process publicly available store and business-contact data, not private merchant data.
- Google (Gmail API) where you connect a mailbox to Outreach Studio (see the Google user data section below).
Cookies
We use a small number of cookies and local storage: an authentication session so you stay signed in, your theme preference (light/dark), and your cookie-consent choice. We use limited error monitoring to keep the app reliable. We do not run third-party advertising trackers.
Product analytics
We use product analytics to understand how Vergio is used so we can improve it. Anonymous, cookieless usage analytics run for everyone: no cookies, nothing stored on your device, and no persistent identifier. Only if you choose Accept all do we store an analytics cookie and record a session replay of your visit, and replays mask what you type. We identify signed-in users by internal id only, never by name, and analytics never records the content of your reports. This data is hosted in the EU (PostHog).
Google user data (Gmail)
If you connect Gmail to Outreach Studio, we request gmail.send to send the permission-based cadences you create from your connected address, and gmail.metadata to query only metadata for threads Vergio started and delivery-status notices. Vergio can see message headers and short previews to detect replies, never message contents. We use that metadata to detect any inbound reply, out-of-office or automated response, unsubscribe request, or hard bounce so we can stop, delay, or suppress further sends. We do not scan unrelated mailbox content.
Data accessed and stored. Raw Google data accessed may include your connected account address and display name, OAuth credential, outgoing message content, message and thread identifiers, delivery-status notices, and headers, subject, and snippet for an inbound message in a Vergio-started thread. We store the sealed OAuth credential, connected account details, outgoing subject and body, message/thread identifiers, send status, and the resulting reply/bounce label. Inbound subject, snippet, and headers are processed transiently and are not stored or logged. Aggregated data is limited to workspace-level operational counts such as sends, replies, bounces, and reply rate; we do not create cross-customer advertising or data-broker profiles.
Data use, transfer, and AI. Google user data is used only to provide and improve the user-facing Gmail sending, threading, reply detection, suppression, security, and reliability features described above. Raw or derived Gmail data is not sold, used for advertising, lending, or surveillance, or transferred to data brokers. We do not send raw or derived Gmail data to OpenAI, Anthropic, or any other third-party AI/ML service, and do not use it to develop, improve, or train generalized, foundation, or shared AI/ML models. Reply detection runs within Vergio using deterministic rules; uncertain messages are treated as human replies and stop sending. Necessary infrastructure processors may process this data only to host and operate Vergio under contract, and disclosure may occur where required by law or with your explicit consent.
Protection, retention, and deletion. OAuth credentials are encrypted before storage, access is restricted to the server-side jobs that need it, tenant-scoped identifiers are enforced on application access, and Gmail content is excluded from application and error logs. Stored Google-derived data is kept while your mailbox/workspace remains active and as needed for the cadence record. Disconnecting immediately destroys the stored credential and stops new access. Account deletion removes stored Google-derived identifiers and outgoing message copies, subject to limited legal or security retention obligations described below.
Limited Use. Vergio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Humans do not read your Gmail data except with your explicit consent to resolve a support issue, where required for security, or where required by law. You can disconnect a mailbox at any time in Outreach Studio, and you can revoke access from your Google Account permissions.
Data retention and deletion
We keep your account and product data for as long as your account is active and as needed to provide the Service. You can request deletion of your account and all associated data at any time by emailing [email protected] with the subject "Data deletion request" from the email address on your account; we act on deletion requests promptly, except where we must retain specific records to meet legal obligations. Deletion removes your workspace and everything attached to it, including connected-mailbox credentials, sent-message copies, and Gmail-derived message identifiers. Disconnecting a Gmail mailbox immediately revokes Vergio's access with Google and destroys the stored credential, as described above, without deleting the rest of your account.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these, contact us and we'll respond as required by applicable law.
International transfers & security
Your data may be processed in countries other than your own. We use reputable providers and reasonable technical and organisational measures to protect it; no method of transmission or storage is perfectly secure.
Children
The Service is for businesses and is not directed to children under 16.
Changes
We may update this policy; we'll revise the date above and, for material changes, provide notice.
Contact
Questions or requests? Reach us via the contact page. The data controller is Ricky Wolff, trading as Vergio, registered with the Dutch Chamber of Commerce (KvK) under number 42111844, Duinmeer 92, the Netherlands.