Invo Plus AI connection privacy
This connection lets ChatGPT or Claude perform the business actions you approve. Sign-in uses Google through Firebase Authentication. The assistant receives separate, limited access tokens; it never receives your Google password or Google tokens.
Information shared
Depending on your permissions, tools return business names, products and prices, customer names, optional customer email addresses, order summaries (including customer names, totals and status), recorded business notifications (including messages and actors), website page content, and delivery-area names, boundaries and fees. Public place searches send the supplied place name to the configured geocoding provider and are cached for one day. Do not enter customer addresses in place search. The map loads Leaflet assets from unpkg.com and tiles from OpenStreetMap; these providers receive normal browser requests, including IP address and map tile coordinates, but no Invo Plus access token. Embedded HTML/CSS/JavaScript source is returned only when explicitly requested with custom-code permission. The AI provider processes returned information under its own privacy policy. Delivery addresses and phone numbers are shared only when explicitly requested with separate order delivery-details permission. Stock counts, customer-specific prices, fulfillment/tracking, delivery rules and assistant change history may also be shared with the corresponding permissions. Payment credentials and provider payloads, account balances, passwords and private authentication fields are not returned. Notifications may contain names or contact details already recorded in their message text; only approve activity access for information you want your assistant to read.
Public product and website content
Existing Invo Plus storefront storage allows public reads of catalog records and website pages, including hidden products and unpublished drafts. Hidden and draft flags control storefront display; they do not make that content confidential. Use these tools only for public product and website copy. Never put personal or confidential information in product descriptions or page content.
Stored information
We store your Google user identifier, verified email, approved businesses and permissions, connection records and hashed tokens in Firebase. Tokens expire and can be revoked. Authorization requests expire after 10 minutes, codes after one minute, access tokens after 15 minutes, and connections after 30 days. Expired records are unusable even before physical cleanup.
Mutation receipts and audit records identify the actor, business, operation and result so retries cannot duplicate changes. Private before-and-after change records support safe undo of supported assistant actions; newer edits prevent undo. These records are retained with the business until an authorized retention or deletion request is handled. We do not log raw tokens or Google passwords.
Your choices
Select individual businesses and permissions during consent. Use Manage connections to revoke access immediately. For access, correction, retention or deletion requests, contact yaacov@invo-plus.com.