This Privacy Policy explains what personal data RENVAR INC ("Elai", "we") collects through the Elai Marketplace platform (the "Platform"), why, and what rights you have over it.
1. Data we collect
- Account data — email address and a hashed password (we never store your password in plain text) collected when you register as a Buyer or Developer.
- Usage / audit data — a record of key actions taken on your account (Agent installs, invocations, reviews left, payments, listing changes) is written to an append-only audit log. This exists for trust, safety, and dispute-resolution purposes, and is not shared for advertising.
- Content you upload — listing photos for your Agents or robot listings, stored on the Platform's servers and served back to anyone browsing the public catalog.
- Agent task input — when you invoke an installed Agent, the text you submit is sent to the underlying AI model provider (via the Platform's AI Gateway) to generate a response. See Section 3 on sharing.
- Locale/region — we read your browser's
Accept-Languageheader to auto-select a display language and a default warehouse region for physical-robot browsing. This is a convenience default, not a precise location lookup, and you can change both manually at any time. - Session token — after logging in, your session token is stored in your browser's
localStorage(not a tracking cookie) so you stay signed in. It is sent as an Authorization header on API requests you make. - Messages and chat — buyer/seller pre-purchase messages, dispute messages, and support tickets are stored and visible to the other party to that conversation (and to our staff, for moderation and support). Livestream chat messages are visible to every viewer of that stream, not just the seller.
- Saved delivery addresses — recipient name, phone number, and postal address you save to your address book for faster checkout, separate from the single delivery address on your account profile.
- Loyalty, coins, and referral activity — your loyalty-points and gamification-coin ledger (earned/spent), and, if you join our affiliate or referral programs, your tracking code and click/sale counts.
- Installment and rental payment schedule — if you use "Pay in 4" or rent equipment, which future charges are scheduled, and whether they succeeded, to run that payment schedule and contact you about it. See our Installment Credit Terms and Equipment Rental Terms.
- Error/diagnostic data — if error monitoring is enabled on a given deployment, crash reports (stack traces, request metadata) may be sent to our error-monitoring provider. This is inert and collects nothing unless the deployment operator has explicitly configured it.
2. Why we process it
- To operate your account and the marketplace (contract performance);
- To run the certification pipeline and maintain the audit trail (legitimate interest — trust & safety);
- To bill Buyers and pay out Developer/seller revenue (contract performance);
- To comply with legal obligations where applicable.
3. Who we share data with
- The Developer/seller you transact with — installing an Agent or submitting a robot inquiry shares the information needed to fulfill that transaction (e.g. your account identifier, your message on an inquiry).
- Other viewers of a livestream — chat messages you post in a livestream are visible to everyone watching that stream, not only the seller.
- AI model providers — the task text you submit to an installed Agent is sent to the model provider configured for that Agent, to generate the Agent's output. We do not send your account credentials or payment details to model providers.
- Payment processor — Stripe, and for transactions in Russian rubles, YooKassa, handle payment method details; Elai does not store full card numbers.
- Other service providers — SendGrid (transactional email delivery), Twilio (SMS notifications you've opted into), and Sentry (error/crash diagnostics, which may incidentally include your account identifier or email in a crash report). Each processes only the data needed to perform its function for us.
- We do not sell personal data to third parties for advertising.
4. Where data is stored
The Platform runs on a self-hosted server (VPS), and the specific hosting region depends on where the operator has deployed it at any given time. We do not currently commit to a specific data-residency guarantee (e.g. EU-only hosting); if you require one for regulatory reasons, contact us using the details in Section 8 before relying on the Platform for that use case.
5. Data retention
We retain account and audit-log data for as long as your account is active. When you delete your account:
- Deleted outright: your saved payment cards and your saved delivery address book. No retention obligation applies to these once the account is gone.
- Anonymized, not deleted: your account record itself — email, password, phone, and the single delivery address on your profile are cleared or replaced, and the account is deactivated.
- Retained as-is: your transaction, listing, and review records, buyer/seller messages, dispute messages, livestream chat messages, and loyalty/coin/affiliate ledger entries. These must survive for the other party's own transaction/conversation history and for our legal, tax, and accounting obligations — deleting them would also erase the other party's record of a conversation or purchase they are entitled to keep. Because the identifying fields on your account are anonymized as described above, these records no longer display your email or other contact details once your account is deleted — but the message/review content itself, and the fact that your (now-anonymized) account was a party to it, is not erased.
We have not yet set a fixed maximum retention period for anonymized historical records; if this matters for your use case, contact us using the details in Section 8.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details in Section 8. See also our Data Processing Agreement for details on our role as a processor for business/enterprise customers.
7. Children
The Platform is not directed at children and is not intended for use by anyone under 18.
8. Contact
Questions about this Privacy Policy or requests regarding your data: renvar.inc@gmail.com. We have not appointed a dedicated Data Protection Officer; the above address is the point of contact for privacy inquiries.
9. Changes to this Policy
We may update this Policy from time to time; material changes will be announced on the Platform.