Legal
Privacy Policy
This policy explains what information Tuvi Solutions handles, why we handle it, and the choices available to you.
Last updated: 13 August 2026
1. Who we are and what this policy covers
Tuvi Solutions ("Tuvi", "we", "us", or "our") builds websites, applications, AI assistants, and business automation. This policy applies to our public website, consultation and callback services, voice assistant, business outreach, and Google-connected email functionality.
2. Information we collect
- Consultation information: your name, email address, phone number, selected appointment time, confirmation details, and communications about the appointment.
- Voice and callback information: your name and phone number, microphone audio while a voice session is active, conversation transcripts or interaction records, and details needed to complete a booking or callback.
- Business outreach information: business contact details, restaurant or company information, outreach status, delivery events, responses, and opt-out preferences. This information may come from public sources, service providers, or directly from the business contact.
- Venue Pulse verification information: the name, email address, and phone number you submit, the selected restaurant listing, verification-code request and attempt timestamps, and report-access status. We keep these details with the report request for verification, security, and support. Verifying an email is not marketing consent.
- Technical information: standard hosting and security logs may include an IP address, browser or device details, requested pages, timestamps, and error information.
We do not currently use advertising cookies on this website. Outreach emails may use time-limited open or link tracking and always provide an unsubscribe option where required.
3. Google API data and Gmail access
Our Google Workspace email application, tuvi, uses the Google Gmail API only after an authorized Google Workspace mailbox owner or administrator grants access. Sending mailboxes request the narrow Gmail send permission (gmail.send) so tuvi can send approved messages from that mailbox over Google's HTTPS API. One selected outreach mailbox may also grant gmail.readonly so tuvi can capture replies sent to unique outreach Reply-To addresses and use that same mailbox for administrator-written responses.
- We process the authorized mailbox address, recipient address, message subject and body, Google's delivery identifier, and OAuth credentials needed to perform the send.
- Other sending mailboxes do not receive permission to read inbox messages. The selected reply mailbox does not grant access to contacts, Google Drive files, or other Google account products.
- The selected mailbox is polled over a bounded recent-inbox window to capture outreach replies. Matched replies and administrator-written responses are stored for internal follow-up; the application does not provide a general mailbox browser.
- Refresh tokens are kept in protected server configuration. Short-lived access tokens are used only to call Google's token and Gmail endpoints and are cached in server memory for their valid lifetime.
- Google user data is not sold, used for advertising, or used to train generalized AI or machine-learning models.
Tuvi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
When you request a restaurant search or digital-footprint report, Tuvi may send the restaurant query, location, or Place identifier to Google Maps Platform and receive public Place information such as the business name, address, rating, review count, website, phone number, map links, photos, reviews, and contributor or third-party provider attributions. Those results are displayed with their supplied attribution and can change when a new live scan runs. Google Maps embeds and source links may also receive standard browser, device, and request information under Google's Privacy Policy. Use of that content is also subject to the Google Maps Platform Terms of Service.
4. How we use information
- Provide, operate, secure, and improve our website and services.
- Schedule consultations, place requested callbacks, and send confirmations.
- Generate restaurant digital-footprint reports, send requested verification codes, control access to detailed findings, and prevent report abuse.
- Prepare and send reviewed business communications and maintain suppression and unsubscribe records.
- Diagnose errors, prevent abuse, and protect our systems and users.
- Meet legal, accounting, compliance, and audit obligations.
5. When we share information
We share information only as needed to provide and protect the services, such as with hosting, database, communications, voice, and email providers acting for us. Google receives the data required to authenticate the authorized mailbox and send messages through Gmail. We may also disclose information when required by law, to protect rights or safety, or as part of a business transaction subject to appropriate safeguards.
We do not sell personal information or Google user data. Access by personnel is limited to people who need it to operate, support, secure, or comply with legal obligations for the service, or where the user has given permission.
6. Retention and deletion
We keep consultation, outreach, delivery, security, and opt-out records only for as long as reasonably needed for the purposes described in this policy, including providing the service, honoring suppression requests, resolving disputes, maintaining audit records, and meeting legal obligations. We then delete or de-identify the information where practicable.
OAuth credentials remain configured only while a mailbox integration is active. An authorized mailbox owner or administrator may revoke access in their Google Account and may ask us to disconnect the mailbox and remove the stored credential. Revocation prevents future Gmail API access, although limited delivery and audit records may be retained for the purposes above.
7. Your choices and rights
- Use the unsubscribe link in an outreach email to stop future marketing messages to that address.
- Revoke Tuvi's Google access from the security settings in your Google Account.
- Contact us to request access, correction, deletion, or restriction of personal information. Applicable law may provide additional rights.
8. Security
We use technical and organizational safeguards designed to protect information, including access controls, server-side credential storage, encrypted HTTPS connections, and restricted operational access. No system is completely secure, so we cannot guarantee absolute security.
9. International processing
Our service providers may process information in countries other than the one where you live. Where required, we use appropriate safeguards for those transfers and continue to protect the information as described here.
10. Children
Our services are intended for businesses and adults. We do not knowingly collect personal information from children under 13 through these services.
11. Changes to this policy
We may update this policy as our services or legal obligations change. We will post the revised version here and update the date above. Material changes will be communicated when required by law.