Skip to content
Avo Ops

Privacy policy


Last updated: 2026-08-14

1. Who is responsible

The controller of your personal data is:

Cesar Gabriel Gutierrez Medina
Rotenhofgasse 30/32
1100 Vienna
Austria
Email: privacy@avoops.com

Avo Marketing is part of AVO, an operations platform for restaurants ("the app", "we").

2. What this policy covers

This policy describes what personal data the Avo Marketing app collects, why, where it is stored, who processes it, and what your rights are. It applies to the mobile app, to the services behind it, and to the connection pages at conectar.avoops.com.

3. Our role: controller and processor

For your account data (name, email, sign-in) and for the operation of the platform, we act as controller. For the business content a restaurant stores in the app (its media, contacts of its team members, its metrics), the restaurant owner decides what is stored and why; in that respect we process the data on behalf of the restaurant. If you were invited to a restaurant's workspace by its owner, that owner is responsible for the decision to add you; we handle your data as described here.

4. Data we collect

Account data. When you create an account we store your name and email address. You can sign in with a one-time email code, with an email and password, or with Google Sign-In. Passwords are managed by our authentication provider (Supabase Auth) and are never stored in our own application tables. Google Sign-In is only an authentication method: it does not connect your Google Business Profile and does not give us access to any Google data beyond your basic profile (name, email).

Business data. The app stores the data of the restaurant you manage: organization and restaurant name, address, time zone, currency, and the roles of team members you invite.

Content you create. Photos, videos, captions, drafts, your brand voice and positioning, scheduled and published posts, and documents you upload (such as your menu) so that the assistant can write accurate content about your business.

Connected platform data. If you connect Instagram, Facebook or Google Business Profile, we store the access credentials needed to act on your behalf (stored encrypted, see section 8) and the performance data those platforms provide, such as views, clicks, calls and direction requests.

Technical data. The app does not include any third-party analytics, crash reporting or advertising trackers. Our infrastructure providers keep standard technical logs needed to operate and secure the service: Supabase (our backend) and Vercel (our websites) log requests including IP addresses; Expo's update service receives basic device and app-version information when the app checks for updates.

5. Why we process your data

  • To provide the service: managing your account, storing your content, publishing to the platforms you connected, and showing you your metrics. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • To generate content and insights with AI: drafts, captions and plain-language readings of your metrics. Legal basis: performance of a contract.
  • To send transactional emails such as sign-in codes, invitations and account notices. Legal basis: performance of a contract.
  • To secure the service and prevent abuse. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

We do not sell your data. We do not use your data for advertising.

6. Service providers (processors)

These providers process data on our behalf, under data processing agreements:

  • Supabase — database, authentication and file storage. Your data is hosted in the European Union.
  • Anthropic — AI processing. When the assistant writes a caption, the text you provide, your brand voice, your business knowledge and the photos involved are shared with Anthropic's Claude API; photos are retrieved by Anthropic through short-lived signed links to our storage. When you upload a menu for the assistant to learn from, the document itself is sent for processing and is not stored by us afterwards. When the assistant explains your metrics, only aggregated numbers are sent, without your business name. We do not send your email address or the names of individuals. Anthropic may retain API inputs and outputs for a limited period (by default, they are deleted within 30 days) and does not use them to train its models.
  • Resend — transactional email delivery (sign-in codes, invitations, account notices).
  • Vercel — hosting of avoops.com and of the connection pages at conectar.avoops.com.
  • Expo — delivery of application updates (EAS Update).

Transfers outside the EU. Some of these providers are based in the United States or may process data there. Where that happens, transfers are safeguarded by the European Commission's standard contractual clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.

7. Connected platforms (independent services)

Instagram, Facebook (Meta) and Google Business Profile are not our processors: when you connect them, they act under their own terms and privacy policies, based on the authorization you grant. Connections are optional and only happen when you explicitly authorize them. We only request the permissions needed to publish content you approved and to read your performance data. Nothing is ever published without the owner's explicit approval inside the app. You can disconnect any platform at any time from the app, which revokes our access.

During onboarding we also use Google's Places service to look up your restaurant's address; this is a server-side lookup and does not connect any account.

To establish the Facebook and Instagram connection, our connection page loads Meta's JavaScript SDK from Meta's servers, which is technically required to run the login. This only happens on that page and only when you use it.

8. Security

Access to your data is isolated per restaurant at the database level: row-level security rules deny access by default. Platform credentials (Instagram, Facebook, Google) are stored in an encrypted vault, separate from application tables. All communication between the app and our servers is encrypted in transit.

9. Retention

We keep your data for as long as your account exists. When you delete your account, your data is deleted as described in section 10. Technical logs kept by our infrastructure providers expire on their standard cycles. Some minimal records may be retained where the law requires it.

10. Deleting your account

You can delete your account directly in the app, under Settings. Deletion of your data in our application database is immediate: there is no grace period and no recovery, and the process ends by verifying against the database that your data is actually gone, not by assuming it.

When you delete your account:

  • Your profile, roles and memberships are deleted.
  • If you are the sole owner of a business, the business and all its data are deleted: content, media files, brand voice, campaigns, metrics and calendar.
  • If you belong to businesses you do not own, you are removed from them; the business and its data remain with their owner. Records needed for the integrity of that business's history are anonymized: your identity is removed and cannot be reconnected to you.
  • Connections to Instagram, Facebook and Google are revoked against those platforms first, and the stored credentials are then destroyed.
  • Posts already published on Instagram, Facebook or Google are not taken down: they live on those platforms and can be removed there. The app tells you this before you confirm.
  • If you sign up again later, you start as a new, unrecognized user.

Residual copies may persist for a limited time in encrypted infrastructure backups and server logs until they expire on our providers' standard cycles, and where retention is required by law.

11. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and object to the processing of your data, and the right to data portability. You can exercise these rights by emailing privacy@avoops.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).

12. Children

The app is a business tool and is not directed at children.

13. Changes

We will update this policy when the service changes. The current version is always available at avoops.com. Material changes will be communicated in the app.