Privacy Policy
Published by: AvanceAI LLC
Version: 2026-07-26.1
Last updated: July 26, 2026
1. Who we are
This Privacy Policy describes how AvanceAI LLC, a limited liability company organized under the laws of the State of Utah, United States of America (the “Company,” “Avance,” “we,” or “us”), processes personal data in connection with:
- the marketing site avance.ai;
- the AVA application (presented as AVA by Avance) at app.avance.ai; and
- related services.
Registered business address: <PLACEHOLDER: Utah registered business address>
Privacy contact: privacy@avance.ai
Support: support@avance.ai
Security: security@avance.ai
AVA’s launch market is Colombia. The applicable Colombian personal-data regime is Law 1581 of 2012 and Decree 1377 of 2013, enforced by the Superintendencia de Industria y Comercio (SIC).
Our customers are businesses and also sole proprietors / independent professionals.
2. Controller and processor
2.1 Avance as controller
Avance acts as controller (responsable del tratamiento) for personal data we collect and process to operate our own commercial relationship with you, including:
- AVA account and authentication data;
- billing and commercial-relationship data related to your account (when it exists);
- support and security communications related to your account;
- marketing-site and application usage data needed to provide and secure the service for that same customer, as described in this policy.
2.2 Avance as processor
When a customer uses AVA to manage contacts, messages, appointments, advertising, or other CRM functions, Avance acts as processor (encargado del tratamiento) for the customer’s CRM content (including data of individuals who communicate with the customer’s business). In that case:
- the customer is generally the controller vis-Ă -vis those individuals;
- Avance processes that data solely to deliver the service to that same customer and according to the customer’s instructions and configured integrations;
- the customer is responsible for obtaining the authorizations (autorizaciones) and notices required by Colombian law for its own data subjects (titulares).
For deletion routes, see /en/data-deletion.
3. Categories of data we process
Depending on how the service is used, we may process:
Account data
name, email, password or other authentication identifiers, role, preferences.
CRM contacts
name, phone, email, tags, notes, interaction history.
Messaging and media
message bodies and media sent or received via WhatsApp, Facebook, and Instagram.
Appointments
scheduling data and appointment status.
Payments and billing
AVA billing records when they exist; and, when the customer enables charges to its own end customers, payment data processed through Stripe or PayPal according to the customer’s configuration. AVA is not the acquirer or party responsible for those end-customer charges.
Advertising and attribution
click identifiers (gclid, fbc / fbclid), conversion events, and related campaign metadata.
OAuth tokens and integration credentials
access tokens and metadata needed to maintain third-party connections.
Technical data
IP address, user agent, integration and connectivity event logs.
4. Purposes of processing
We process personal data to:
- provide, operate, and secure AVA and the site;
- authenticate users and administer accounts and locations;
- run integrations the customer enables;
- bill for the service under the applicable commercial terms;
- handle support, security, and incidents;
- meet legal obligations and respond to competent authorities;
- retain de-identified audit evidence where applicable (see retention and /en/data-deletion).
We do not use a customer’s CRM content for cross-customer AI training, and we do not use raw customer content for product improvement. Customer and contact content is used solely to deliver the service to that same customer. See Section 7.
5. Per-integration disclosure
AVA may connect the following integrations. Exact scope depends on what the customer enables and authorizes.
5.1 Available
Google Ads. Connection for measurement and offline conversion uploads keyed on gclid, subject to the customer’s Google authorizations.
Google Tag Manager. Connection to manage measurement tags configured by the customer.
Meta Ads. Connection to Meta ad accounts for operations and measurement tied to the customer’s account.
Facebook and Instagram messaging. Sending and receiving messages through Meta messaging APIs for Pages / accounts connected by the customer.
Meta Conversions API. Sending conversion events to Meta (details in Section 6).
WhatsApp. AVA supports two WhatsApp messaging paths, both enabled:
- the official Meta WhatsApp Cloud API; and
- a self-hosted WhatsApp server (WPPConnect / Baileys-style).
The customer chooses and configures the applicable path. Both may involve processing message bodies, session metadata and, depending on the path, connectivity credentials or tokens. WhatsApp is not part of the Facebook Login grant described below: WhatsApp access is not obtained through the Facebook Login OAuth scopes listed in this section.
Facebook Login scopes requested
When the customer connects Meta through Facebook Login, AVA requests exactly these OAuth scopes (and no others):
ads_management
Operate and manage Meta ad accounts and ad objects tied to the customer’s account.
ads_read
Read Meta campaign and ads measurement data needed for AVA’s advertising features.
instagram_basic
Identify the Instagram Business account linked to the connected Page and read basic metadata for that account.
instagram_manage_messages
Receive and send Instagram Direct messages through Meta messaging APIs for the connected account.
pages_manage_metadata
Manage Facebook Page metadata needed to maintain the messaging and linkage integration.
pages_messaging
Receive and send Messenger messages for the connected Facebook Page.
pages_show_list
List Facebook Pages the grantor can access so the grantor can choose which Page to connect.
public_profile
Identify the Facebook user who authorizes the connection (basic public profile of the grantor).
Google Ads and Tag Manager scopes requested
When the customer connects Google Ads and Google Tag Manager, AVA requests exactly these OAuth scopes:
https://www.googleapis.com/auth/adwords
Access the customer’s Google Ads account for measurement and offline conversion uploads keyed on click identifiers.
https://www.googleapis.com/auth/tagmanager.readonly
Read the customer’s Google Tag Manager container configuration.
https://www.googleapis.com/auth/tagmanager.edit.containers
Edit Google Tag Manager containers configured by the customer.
https://www.googleapis.com/auth/tagmanager.edit.containerversions
Create and edit Google Tag Manager container versions.
https://www.googleapis.com/auth/tagmanager.publish
Publish Google Tag Manager container versions authorized by the customer.
Google Calendar (when available) will request https://www.googleapis.com/auth/calendar. That scope is not requested today as part of the Google Ads / Tag Manager connection.
5.2 In development — not yet available
Google Calendar. Planned appointment sync. Not yet available.
Google Business Profile. Planned Google Business Profile integration. Not yet available.
When these integrations become available, this policy will be updated and processing will be limited to the scopes the customer then authorizes.
6. What we send to Meta and Google Ads
6.1 Meta Conversions API
When the customer enables this integration, AVA may transmit to Meta, among other fields:
- email, phone, name, and external id, SHA-256 hashed;
client_ip_addressandclient_user_agentunhashed;- click identifiers
fbc/fbclid.
6.2 Google Ads
When the customer enables offline conversions, AVA may upload conversions to Google Ads keyed on gclid.
6.3 Irrecoverability
Data already transmitted to Meta or Google cannot be recalled or “unsent” by AVA. No AVA deletion feature undoes those sends. The individual or the customer must use Meta’s and Google’s own controls and channels, as applicable.
7. Artificial intelligence and AI subprocessors
For AI-assisted features, Avance uses AI subprocessors, including:
- OpenAI — chat completion, Whisper transcription, and vision;
- Pinecone — embeddings and vector retrieval.
Avance acts as processor for customer content used in those features: that content is used only to deliver the service to that same customer. There is no cross-customer training and no product improvement on raw customer content.
The canonical subprocessor list is at /en/subprocessors.
8. Subprocessors (summary)
In addition to AI subprocessors, Avance uses infrastructure, messaging, advertising, and payment providers needed to operate AVA (for example, AWS, Stripe, and PayPal). The current canonical list is at /en/subprocessors. Do not treat any summary here as the source of truth—consult that page.
9. Hosting and international transfer
AVA and associated data are hosted on Amazon Web Services (AWS), region us-east-1 (United States).
This means an international transfer of personal data of Colombian data subjects (titulares) to the United States.
Transfer basis: processing and transfer are necessary to provide AVA from the infrastructure where the service is hosted, pursuant to the customer’s instructions (when Avance acts as processor) and the authorizations and legal bases applicable under Law 1581 of 2012 and Decree 1377 of 2013. Avance does not operate compute infrastructure in Colombia for this service and does not claim that traffic originates from Colombian IP addresses.
10. Retention
Without prejudice to /en/data-deletion, the following operational periods apply, among others:
Webhook payload archives
90 days.
Notifications
30 days (dismissed: 7 days).
WhatsApp connectivity events
90 days.
Integrations-health events
90 days.
Integration runtime events
730 days.
RDS backups
30 days.
Retention exceptions (may be kept longer when necessary): invoices and tax records; fraud and abuse evidence; legal hold; and aggregated de-identified analytics.
Audit exception: audits and contact_lifecycle_audits records may be retained in de-identified form as evidence that deletion occurred.
The forgotten control in AVA hides and minimizes a contact; it does not delete the contact.
11. Data-subject rights (Law 1581)
Data subjects (titulares) may exercise rights to know, update, rectify, and delete information, and to revoke authorization, under Law 1581 of 2012.
Channels and timelines (Articles 14 and 15):
- Inquiry (consulta): response within a maximum of ten (10) business days.
- Complaint (reclamo): handling within a maximum of fifteen (15) business days, subject to any legally permitted extensions.
How to exercise rights:
- If you are an AVA user or customer regarding account or billing data: email privacy@avance.ai.
- If you are an individual who contacted a business using AVA (and you have no AVA account): direct your request first to the business (controller). Avance, as processor, will carry out applicable erasure instructions and assist within the timelines above. Details: /en/data-deletion.
As of this version, AVA has no:
- self-service account-deletion button; and
- data export / portability feature (deferred).
Account or location deletion is handled by verified request to privacy@avance.ai. See /en/data-deletion.
12. Deletion and revocation
Routes for disconnecting integrations, removing the Facebook app, deleting an account or location, and individual data-subject requests are described at /en/data-deletion.
13. Children
AVA and the marketing site are not directed to individuals under eighteen (18). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@avance.ai so we can take appropriate steps.
14. Changes to this policy
We may update this Privacy Policy. We will post the current version on this page with the version number and last-updated date. For material changes, we may also notify you by email to the account address or by in-product notice, as appropriate. Continued use of the service after an updated version takes effect constitutes acceptance of that version to the extent permitted by applicable law.
15. Google API Services User Data Policy — Limited Use
Avance’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to Google user data obtained through Google Ads, Google Tag Manager, and, when available, Google Calendar, within the scopes the customer authorizes. Avance will not use that Google data for independent Avance advertising or to train generalized AI models, and will limit use to providing or improving user-facing features that are prominent and relevant to the authorized integration, in accordance with that policy.
16. Contact
Privacy inquiries: privacy@avance.ai.
General support: support@avance.ai.
Security reports: security@avance.ai.
Governing law and venue: State of Utah, United States, without prejudice to non-waivable rights Colombian law may grant data subjects before the SIC.