Privacy Policy
Last updated: August 2, 2026 Owner: VialAPI Privacy
1. Overview
VialAPI (“VialAPI,” “we,” “us,” or “our”) operates a private, business-to-business order and fulfillment platform that lets approved partner businesses submit orders, manage catalogs and pricing, coordinate shipping, and reconcile partnership accounting. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have.
The VialAPI operating platform is provided to approved businesses and their authorized staff. An approved business may also operate a customer-facing Store powered by VialAPI. In that setting, the Store operator controls the customer relationship and VialAPI processes checkout, order, account, and fulfillment data for that operator.
2. Our two data roles
We handle personal information in two distinct capacities, and your rights depend on which applies:
- As a controller — for the accounts and authentication data of the operators, partners, brokers, and staff who sign in to VialAPI. We decide how this data is used.
- As a processor— for the order and end-customer data that partner businesses submit to us so we can route and fulfill their orders (for example, a recipient’s name and shipping address). We process this data on the partner’s behalf and under their instructions. If you are an end customer of one of our partners, please direct privacy requests to that partner; we will assist them as needed.
3. Information we collect
Account and authentication data. When an account is created for you, we collect your name and email address, your role and partnership memberships, and either a securely hashed password or, if you use Google Sign-In, the identity information described below. We never store your password in plain text.
Google Sign-In data.If you choose “Continue with Google,” Google shares a limited profile with us based on the scopes you approve — your name, email address, email-verification status, and a Google account identifier (the OpenID Connect openid, email, and profile scopes). We use it solely to verify your identity and sign you in to an account that already exists in VialAPI. We do not receive or store your Google password, and we request no access to your Gmail, Drive, contacts, or other Google services.
Order and customer data (processed for partners). To fulfill orders, we process the details partners submit, which may include end-customer names, email addresses, phone numbers, shipping addresses, order line items, and order metadata.
AI assistant conversations.An authorized business user may choose to use the VialAPI assistant after accepting its in-product data notice. VialAPI keeps the conversation in that business workspace, minimizes the recent context sent to the configured AI provider, and redacts common email, phone, postal, and delivery-address patterns before transmission. Order-recipient and shipping details are handled by VialAPI’s deterministic order-draft path and are not needed by the provider. Users should not enter payment-card data, medical information, or unrelated sensitive information into the assistant.
Remote AI connectors (ChatGPT and Claude). An authorized business owner may separately connect a VialAPI workspace to ChatGPT from OpenAI or Claude from Anthropic using OAuth. VialAPI receives only the tool commands the connector sends and does not request or reconstruct the full chat history. A command may include or return catalog, customer, order, recipient-contact, and shipping-address data when the authorized user asks the connector to perform that task. Do not send payment-card data, medical information, government identifiers, passwords, API keys, or other unrelated sensitive information through a connector.
Store buyer and checkout data. A VialAPI-powered Store may collect your name, email, phone number, delivery address, cart, order, policy acceptance, and optional consent to create a Store-specific passwordless account. A hosted payment provider collects payment-card data; VialAPI receives provider identifiers, payment status, amount, tax, refund, and dispute information, but does not host the card-entry form or store full card numbers.
Business and partnership data. We store partner and party records, catalog and pricing configurations, profit-split agreements, ledger balances, invoices, and settlement records.
Technical and usage data. We collect IP addresses, browser/user-agent strings, session identifiers, request timestamps, and audit logs of privileged actions, which we use for security, troubleshooting, and abuse prevention.
Cookies and Store measurement. We use strictly necessary, first-party cookies to keep authorized users signed in, preserve a Store cart, protect buyer sessions, and prevent request forgery. Stores may record first-party events such as Store views, product views, cart actions, checkout starts, and purchases using a pseudonymous Store-scoped session. We do not use advertising or cross-site tracking cookies.
4. How we use information
- Authenticate users and maintain secure sessions.
- Provide the platform: route and fulfill orders, sync catalogs, quote shipping, and calculate pricing.
- Perform partnership accounting — profit splits, balances, settlements, and reporting.
- Secure the service, prevent fraud and abuse, and enforce rate limits.
- Provide support and send service-related communications.
- Generate an AI-assisted answer or review-only order draft for an authorized business user after the user enables that feature. The provider has no order-submission authority.
- Respond to a scoped catalog, customer, or order tool command from ChatGPT or Claude after a business owner authorizes the connector and its requested permissions.
- Operate Store carts, hosted checkout, payment reconciliation, receipts, optional buyer accounts, and order history.
- Comply with legal, tax, and regulatory obligations.
We do not sell or rent personal information, we do not use it for advertising, and we do not use it to build advertising profiles.
5. Google user data and Limited Use
VialAPI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, the Google account information we receive is used only to provide and improve the sign-in feature that you request. It is not transferred to others except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition; it is not used or transferred for advertising; and it is not used by humans to read your data or to train generalized artificial-intelligence or machine-learning models.
6. How we share information
- Fulfillment suppliers. To fulfill an order, we transmit the order and shipping details to the supplier responsible for fulfilling it.
- Service providers. We use vetted infrastructure vendors — including cloud hosting and managed database providers — that process data on our behalf under contractual confidentiality and security obligations.
- AI processing provider. When an authorized user enables the assistant, Anthropic processes the minimized recent message context and bounded tool results needed to produce that response. Anthropic does not receive a VialAPI password, API key, full payment-card data, or authority to submit an order. Its processing is governed by our applicable service and data protection terms with the provider.
- Remote AI connector providers.If a business owner connects VialAPI to ChatGPT or Claude, OpenAI or Anthropic processes the tool command and result as part of the user’s conversation. Those providers handle that information under the user’s provider account, settings, terms, and privacy policy. VialAPI limits each OAuth connection to the permissions approved by the owner and does not provide passwords, API keys, or full payment-card data.
- Payment providers. A Store may use a hosted payment provider to collect payment, calculate tax, process refunds, and handle disputes. The provider processes payment data under its own terms and privacy notice; VialAPI exchanges only the identifiers and transaction information needed to reconcile the order.
- Store operators. If you buy through a VialAPI-powered Store, the Store operator receives and controls the customer, order, support, and fulfillment information needed to serve you. Direct privacy requests to that Store first; VialAPI will assist the operator.
- Within a partnership. Members of a partnership can see the orders, balances, and records belonging to that partnership, scoped to their role. Partnerships are isolated from one another.
- Legal and safety. We may disclose information to comply with law, enforce our agreements, or protect the rights, property, or safety of VialAPI, our users, or others.
- Business transfers. Information may be transferred as part of a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. Data retention
We retain account information for as long as your account is active and as needed to provide the service. Store carts and access links expire on bounded schedules; Store buyer sessions can be revoked. Order, policy-acceptance, payment, and financial records are retained for the periods required for customer service, accounting, tax, disputes, and legal obligations. Diagnostic, API, and first-party Store measurement records are kept on limited retention schedules and then deleted or de-identified.
VialAPI assistant conversation records are retained for no more than 30 days and are then deleted by a scheduled cleanup process. An authorized user can clear the workspace’s assistant history sooner; that action removes the server records and the current browser’s session copy. Order records created later through a separate, explicit approval are business records and follow the order-retention rules above rather than the assistant-conversation schedule.
VialAPI does not store the full ChatGPT or Claude conversation for a remote connector. OpenAI or Anthropic may retain conversation content and VialAPI tool commands or results under the user’s provider account settings and their own retention policies. A business owner can disconnect VialAPI in the provider’s connector controls or revoke the OAuth connection; revocation prevents future VialAPI access but does not delete copies already retained by the provider.
8. Security
We protect information with encryption in transit (HTTPS/TLS), hashed passwords and API keys, role-based access controls, audit logging of privileged actions, rate limiting, and least-privilege data access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your rights and choices
Depending on your location, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at privacy@vialapi.com.
You can revoke VialAPI’s access to your Google account at any time from your Google Account permissions. If you are an end customer whose data was submitted by one of our partners, please direct your request to that partner, who acts as the controller of that data.
10. International data transfers
We operate and store data primarily in the United States. If you access VialAPI from outside the United States, you understand your information may be processed in the United States and other countries, and we take steps to ensure it receives an appropriate level of protection.
11. Children's privacy
VialAPI is a business tool intended for use by adults acting on behalf of a business. It is not directed to children, and we do not knowingly collect personal information from children.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide a more prominent notice. Your continued use of VialAPI after an update means you accept the revised Policy.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at privacy@vialapi.com.