Skip to content
OutcomeArc
FeaturesHow it worksWhy OutcomeArc
Sign inStart for free
FeaturesHow it worksWhy OutcomeArcSign inStart for free
Privacy at OutcomeArc

Privacy Policy

Last updated: March 2026

Our approach: we collect the information needed to provide, secure, support, and improve OutcomeArc. We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Content to train general-purpose artificial intelligence models.

1. Scope and controller

This Privacy Policy explains how Velora Studios, LLC (“Velora,” “OutcomeArc,” “we,” “us,” or “our”) handles personal data when you visit our websites, create an account, use the hosted Service or support widget, receive or send a support message through OutcomeArc, or communicate with us.

Velora is the controller of account, website, billing, and direct-customer relationship data. Privacy questions may be sent to [email protected], and formal legal matters to [email protected]. Our mailing address is Attn: Velora Studios, LLC, 16192 Coastal Highway, Lewes, Delaware 19958, United States.

When an OutcomeArc customer submits or connects personal data about its own customers, prospects, employees, or other individuals, that customer generally determines why and how the data is processed and acts as controller; Velora generally acts as its processor or service provider. Questions about a support conversation should first be directed to the organization whose support team handled it.

2. Information we collect

Information you provide

  • Account and workspace information: name, email address, avatar, authentication data, organization name, team membership, roles, preferences, goals, milestones, and service settings.
  • Customer Content: customer profiles, contact details, custom fields, notes, support conversations, email headers, message content, attachments, tags, knowledge sources, saved replies, AI instructions, widget submissions, surveys, imports, and related metadata.
  • Connection and integration information: inbox addresses, sender-domain settings, webhook endpoints, public widget configuration, import mappings, and credentials or tokens that you direct us to store. Sensitive credentials are restricted and encrypted where supported.
  • Billing information: plan, subscription status, transaction details, and payment-provider identifiers when paid services are offered. Full payment-card details are collected by the payment provider, not OutcomeArc.
  • Communications: messages and information you provide when requesting support, exercising rights, or otherwise contacting us.

Information collected when you use the Service

  • Conversation and operational metadata: message times, channel, status, assignment, inbox, delivery state, customer milestones, feedback, usage, survey state, and automation or import progress.
  • AI usage data: prompts assembled from authorized workspace context, model responses, token usage, estimated cost, prompt version, generation status, and teammate feedback.
  • Device and log data: IP address, browser and device type, operating system, referring pages, request times, diagnostic data, security events, and correlation identifiers recorded by us or infrastructure providers.
  • Widget data: configured customer identity, anonymous browser and session identifiers, message history, handoff contact details, availability, and abuse-prevention signals.

3. How we use information

We use personal data to:

  • create and authenticate accounts and manage workspaces, roles, and invitations;
  • receive, store, route, search, display, and deliver support conversations and attachments;
  • provide customer profiles, knowledge, goals, milestones, saved replies, reporting, imports, webhooks, and support-widget features;
  • generate requested AI drafts, responses, summaries, and next-action guidance using authorized workspace context;
  • process subscriptions and maintain plan entitlements when paid services are offered;
  • provide support and send service, security, billing, invitation, survey, report, and policy communications;
  • monitor reliability, troubleshoot problems, prevent abuse, enforce retention choices, and protect users and the Service;
  • understand and improve product performance using aggregated or de-identified information; and
  • comply with law, enforce agreements, and establish or defend legal claims.

4. Legal bases for EEA, UK, and Swiss users

Where data-protection law requires a legal basis, we rely on contract to provide requested features and support; legitimate interests to secure and improve the Service, prevent fraud and operate our business where those interests are not overridden by your rights; legal obligation to maintain required records and respond to lawful requests; and consent where we specifically request it. You may withdraw consent at any time without affecting earlier processing.

5. How we disclose information

  • To workspace users and people you communicate with. Authorized members can access workspace data according to available permissions. Customer-facing messages and widget responses are disclosed to their intended recipients.
  • To service providers. Vendors provide database, authentication, hosting, email delivery, AI processing, background jobs, and traffic-security services under contractual restrictions. See our Subprocessors page.
  • At a customer’s direction. We disclose data through configured inboxes, webhooks, imports, exports, and other integrations when a customer directs us to do so.
  • For legal and safety reasons. We may disclose information when reasonably necessary to comply with law or valid process, protect rights and safety, investigate abuse, or enforce agreements.
  • In a business transaction. Information may be transferred in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice where required.

We do not sell personal data or share it for cross-context behavioral advertising.

6. Cookies and local storage

OutcomeArc uses cookies, browser storage, and similar technologies needed to authenticate users, maintain sessions, remember preferences, restore widget sessions, secure public endpoints, and provide requested functionality. If we add non-essential analytics or advertising technologies, we will provide any notice and choice required by applicable law.

7. Artificial intelligence

When an authorized user requests an AI feature or a configured workflow invokes one, OutcomeArc may send relevant Customer Content and instructions to the AI provider identified on our Subprocessors page. Depending on the feature, context may include customer details, recent conversation history, workspace goals, milestones, knowledge excerpts, and AI behavior settings. We limit context to what is reasonably needed for the requested function and require provider terms that restrict processing. AI output is stored with relevant operational metadata so teammates can review it. We do not use Customer Content to train general-purpose AI models.

8. Retention

We retain account and Customer Content while the workspace is active and as reasonably needed to provide the Service, subject to customer-configured retention settings and deletion requests. Customers may export or erase individual customer records through available privacy tools. Some operational records have shorter or fixed retention periods to support security, delivery reconciliation, rate limiting, audits, or legal obligations.

After deletion, limited information may remain temporarily in encrypted backups, logs, fraud-prevention records, or records retained for tax, accounting, dispute, and legal-compliance purposes. Data delivered to email recipients, webhooks, integrations, exports, or customer-controlled systems is outside our control.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including encrypted network transport, access controls, private attachment storage, row-level database controls, restricted service credentials, signed webhook delivery, audit records, rate limits, and encryption for designated integration secrets. No system is completely secure, and we cannot guarantee against every incident. Customers should protect accounts and endpoints, configure least-privilege access, and avoid submitting data that is not needed for support.

10. International transfers

Velora is based in the United States, and providers may process data in the United States, European Economic Area, and other countries with different data-protection laws. Where required, we use recognized safeguards such as the European Commission’s Standard Contractual Clauses, the UK Addendum, adequacy decisions, or another lawful transfer mechanism.

11. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of personal data; object to or restrict processing; withdraw consent; appeal a denied request; or lodge a complaint with a data-protection authority. We do not discriminate against anyone for exercising privacy rights.

You can update some information within the Service. For another request, email [email protected] with “OutcomeArc Privacy Request” in the subject line or write to the address in Section 1. We may need to verify your identity and authority. Authorized agents may submit requests where permitted. If your request concerns Customer Content controlled by an OutcomeArc customer, we may direct you to that customer.

Residents of certain U.S. states may also request categories and specific pieces of personal information collected, correction, deletion, and information about disclosures. As stated above, we do not sell personal information or share it for cross-context behavioral advertising.

12. Children

The Service is not directed to children, and account holders must be at least 18. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, contact us. Customers must not submit children’s personal data unless they have all legally required authority, consent, and safeguards.

13. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, law, or our practices. We will post the updated version and revise the date above. If changes materially affect your rights, we will provide additional notice where required.

OutcomeArc

Customer support that moves people forward.

Product

FeaturesHow it worksSign in

Company

Why OutcomeArcContact

Legal

TermsPrivacySubprocessors
© 2026 Velora Studios, LLC. All rights reserved.The customer outcome platform.