Privacy Policy
Published by: AvanceAI LLC
Version: 2026-08-25.1
Last updated: August 25, 2026
1. Who we are
This Privacy Policy describes how AvanceAI LLC, a limited liability company organized under the laws of the State of Utah, United States of America (the “Company,” “Avance,” “we,” or “us”), processes personal data in connection with:
- the marketing site avance.ai;
- the Avance application at app.avance.ai; and
- related services.
Business mailing address: AvanceAI LLC, 3214 N University Ave PMB 214, Provo, UT 84604, United States
Privacy contact: privacy@avance.ai
Support: support@avance.ai
Security: security@avance.ai
Avance’s launch market is Colombia. The applicable Colombian personal-data regime is Law 1581 of 2012 and Decree 1377 of 2013, enforced by the Superintendencia de Industria y Comercio (SIC).
Our customers are businesses and also sole proprietors / independent professionals.
2. Controller and processor
2.1 Avance as controller
Avance acts as controller (responsable del tratamiento) for personal data we collect and process to operate our own commercial relationship with you, including:
- Avance account and authentication data;
- billing and commercial-relationship data related to your account (when it exists);
- support and security communications related to your account;
- marketing-site and application usage data needed to provide and secure the service for that same customer, as described in this policy.
2.2 Avance as processor
When a customer uses Avance to manage contacts, messages, appointments, advertising, or other CRM functions, Avance acts as processor (encargado del tratamiento) for the customer’s CRM content (including data of individuals who communicate with the customer’s business). In that case:
- the customer is generally the controller vis-Ă -vis those individuals;
- Avance processes that data solely to deliver the service to that same customer and according to the customer’s instructions and configured integrations;
- the customer is responsible for obtaining the authorizations (autorizaciones) and notices required by Colombian law for its own data subjects (titulares).
For deletion routes, see /en/data-deletion.
3. Categories of data we process
Depending on how the service is used, we may process:
Account data
name, email, password or other authentication identifiers, role, preferences.
CRM contacts
name, phone, email, tags, notes, interaction history.
Messaging and media
message bodies and media sent or received via WhatsApp, Facebook, and Instagram.
Appointments
scheduling data and appointment status.
Payments and billing
Avance billing records when they exist; and, when the customer enables charges to its own end customers, payment data processed through Stripe or PayPal according to the customer’s configuration. Avance is not the acquirer or party responsible for those end-customer charges.
Advertising and attribution
click identifiers (gclid, fbc / fbclid), conversion events, and related campaign metadata.
OAuth tokens and integration credentials
access tokens and metadata needed to maintain third-party connections.
Technical data
IP address, user agent, integration and connectivity event logs.
SMS marketing data and consent
When you choose to receive Avance marketing text messages, we process the mobile number you provide and evidence of your consent, such as the opt-in source, consent and revocation timestamps, the disclosure version presented to you, and your current opt-in or opt-out status. We use this information to administer the SMS marketing program, honor your communication preferences, and maintain compliance records.
All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.
4. Purposes of processing
We process personal data to:
- provide, operate, and secure Avance and the site;
- authenticate users and administer accounts and locations;
- run integrations the customer enables;
- bill for the service under the applicable commercial terms;
- handle support, security, and incidents;
- send recurring automated promotional text messages when you have affirmatively opted in, and process STOP and HELP requests;
- record, administer, and demonstrate your SMS marketing consent or revocation;
- meet legal obligations and respond to competent authorities;
- retain de-identified audit evidence where applicable (see retention and /en/data-deletion).
We do not use a customer’s CRM content for cross-customer AI training, and we do not use raw customer content for product improvement. Customer and contact content is used solely to deliver the service to that same customer. See Section 7.
5. Per-integration disclosure
Avance may connect the following integrations. Exact scope depends on what the customer enables and authorizes.
5.1 Available
Google Ads. Connection for measurement and offline conversion uploads keyed on gclid, subject to the customer’s Google authorizations.
Google Tag Manager. Connection to manage measurement tags configured by the customer.
Google Calendar. When a user connects Google Calendar, Avance accesses calendar-list metadata, event and appointment details, and availability information. Avance uses that data to let the user select calendars and to display, synchronize, create, update, and delete appointments through the Avance calendar features.
Meta Ads. Connection to Meta ad accounts for operations and measurement tied to the customer’s account.
Facebook and Instagram messaging. Sending and receiving messages through Meta messaging APIs for Pages / accounts connected by the customer.
Meta Conversions API. Sending conversion events to Meta (details in Section 6).
WhatsApp. Avance supports two WhatsApp messaging paths, both enabled:
- the official Meta WhatsApp Cloud API; and
- a self-hosted WhatsApp server (WPPConnect / Baileys-style).
The customer chooses and configures the applicable path. Both may involve processing message bodies, session metadata and, depending on the path, connectivity credentials or tokens. WhatsApp is not part of the Facebook Login grant described below: WhatsApp access is not obtained through the Facebook Login OAuth scopes listed in this section.
Facebook Login scopes requested
When the customer connects Meta through Facebook Login, Avance requests exactly these OAuth scopes (and no others):
ads_management
Operate and manage Meta ad accounts and ad objects tied to the customer’s account.
ads_read
Read Meta campaign and ads measurement data needed for Avance’s advertising features.
instagram_basic
Identify the Instagram Business account linked to the connected Page and read basic metadata for that account.
instagram_manage_messages
Receive and send Instagram Direct messages through Meta messaging APIs for the connected account.
pages_manage_metadata
Manage Facebook Page metadata needed to maintain the messaging and linkage integration.
pages_messaging
Receive and send Messenger messages for the connected Facebook Page.
pages_show_list
List Facebook Pages the grantor can access so the grantor can choose which Page to connect.
public_profile
Identify the Facebook user who authorizes the connection (basic public profile of the grantor).
5.2 In development — not yet available
Google Business Profile. Planned Google Business Profile integration. Not yet available.
When this integration becomes available, this policy will be updated and processing will be limited to the permissions the customer then authorizes.
6. What we send to Meta and Google Ads
6.1 Meta Conversions API
When the customer enables this integration, Avance may transmit to Meta, among other fields:
- email, phone, name, and external id, SHA-256 hashed;
client_ip_addressandclient_user_agentunhashed;- click identifiers
fbc/fbclid.
6.2 Google Ads
When the customer enables offline conversions, Avance may upload conversions to Google Ads keyed on gclid.
6.3 Irrecoverability
Data already transmitted to Meta or Google cannot be recalled or “unsent” by Avance. No Avance deletion feature undoes those sends. The individual or the customer must use Meta’s and Google’s own controls and channels, as applicable.
7. Artificial intelligence and AI subprocessors
For AI-assisted features, Avance uses AI subprocessors, including:
- OpenAI — chat completion, Whisper transcription, and vision;
- Pinecone — embeddings and vector retrieval.
Avance acts as processor for customer content used in those features: that content is used only to deliver the service to that same customer. There is no cross-customer training and no product improvement on raw customer content.
The canonical subprocessor list is at /en/subprocessors.
8. Subprocessors (summary)
In addition to AI subprocessors, Avance uses infrastructure, messaging, advertising, and payment providers needed to operate Avance (for example, AWS, Stripe, and PayPal). The current canonical list is at /en/subprocessors. Do not treat any summary here as the source of truth—consult that page.
9. Hosting and international transfer
Avance and associated data are hosted on Amazon Web Services (AWS), region us-east-1 (United States).
This means an international transfer of personal data of Colombian data subjects (titulares) to the United States.
Transfer basis: processing and transfer are necessary to provide Avance from the infrastructure where the service is hosted, pursuant to the customer’s instructions (when Avance acts as processor) and the authorizations and legal bases applicable under Law 1581 of 2012 and Decree 1377 of 2013. Avance does not operate compute infrastructure in Colombia for this service and does not claim that traffic originates from Colombian IP addresses.
10. Retention
Without prejudice to /en/data-deletion, the following operational periods apply, among others:
Webhook payload archives
90 days.
Notifications
30 days (dismissed: 7 days).
WhatsApp connectivity events
90 days.
Integrations-health events
90 days.
Integration runtime events
730 days.
RDS backups
30 days.
Retention exceptions (may be kept longer when necessary): invoices and tax records; fraud and abuse evidence; legal hold; and aggregated de-identified analytics.
Audit exception: audits and contact_lifecycle_audits records may be retained in de-identified form as evidence that deletion occurred.
The forgotten control in Avance hides and minimizes a contact; it does not delete the contact.
11. Data-subject rights (Law 1581)
Data subjects (titulares) may exercise rights to know, update, rectify, and delete information, and to revoke authorization, under Law 1581 of 2012.
Channels and timelines (Articles 14 and 15):
- Inquiry (consulta): response within a maximum of ten (10) business days.
- Complaint (reclamo): handling within a maximum of fifteen (15) business days, subject to any legally permitted extensions.
How to exercise rights:
- If you are an Avance user or customer regarding account or billing data: email privacy@avance.ai.
- If you are an individual who contacted a business using Avance (and you have no Avance account): direct your request first to the business (controller). Avance, as processor, will carry out applicable erasure instructions and assist within the timelines above. Details: /en/data-deletion.
As of this version, Avance has no:
- self-service account-deletion button; and
- data export / portability feature (deferred).
Account or location deletion is handled by verified request to privacy@avance.ai. See /en/data-deletion.
12. Deletion and revocation
Routes for disconnecting integrations, removing the Facebook app, deleting an account or location, and individual data-subject requests are described at /en/data-deletion.
13. Children
Avance and the marketing site are not directed to individuals under eighteen (18). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@avance.ai so we can take appropriate steps.
14. Changes to this policy
We may update this Privacy Policy. We will post the current version on this page with the version number and last-updated date. For material changes, we may also notify you by email to the account address or by in-product notice, as appropriate. Continued use of the service after an updated version takes effect constitutes acceptance of that version to the extent permitted by applicable law.
15. Google API user data
Avance’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing integration the customer authorizes.
Avance shares Google user data only with: users whom the customer authorizes to access the relevant Avance location, when synchronized event data is displayed through the CRM; Google, when Avance performs actions requested through the connected integration; Amazon Web Services (AWS), solely to host and operate Avance; authorized Avance personnel, only with the user’s affirmative agreement for support, when necessary to investigate abuse or a security incident, or to comply with law; and competent authorities when disclosure is legally required. Avance does not sell Google user data, send Google Calendar data to Meta or other advertising platforms, use it for advertising, or provide it to AI model providers for training generalized AI or machine-learning models.
Google user data and OAuth credentials are protected in transit and at rest with encryption. Disconnecting Google Calendar removes the stored OAuth connection and tokens, but events already synchronized into the CRM and Calendar sync logs remain subject to Avance’s normal retention and deletion process described on the Data deletion page. Additional safeguards are described on the Security page.
16. Contact
Privacy inquiries: privacy@avance.ai.
General support: support@avance.ai.
Security reports: security@avance.ai.
Governing law and venue: State of Utah, United States, without prejudice to non-waivable rights Colombian law may grant data subjects before the SIC.