Privacy Policy

Last updated: March 20, 2026

1. Introduction

This policy describes how Everywave ("we", "us", or "our") collects, aggregates, stores, safeguards, and uses the data and information provided by users through our website, everywave.com (the "Site"), our data analytics platform, and any related applications (collectively, the "Service"), as well as information collected by us through other means, including by email, over the phone, or in offline communications.

2. Information We Collect

We collect information in three primary ways:

A. Information You Provide to Us
  • Account Data: When you sign up, we collect your name, email address, and a password of your choice.
  • Billing Information: Billing address and payment details are processed by our payment processor. Everywave does not store full card numbers.
  • Support & Communications: Information you provide when interacting with our customer support or sales teams.
B. Information Collected via Third-Party Integrations (Connected Platforms)

To provide our AI analytics, you may choose to grant Everywave read-access to your third-party e-commerce, marketing, and advertising platforms (e.g., Shopify, Klaviyo, Meta Ads, TikTok Ads, Google Analytics).

  • Authentication Data: We securely store API keys and OAuth tokens to maintain your connections.
  • Platform Data: We ingest metrics, aggregated reporting data, inventory levels, and campaign performance data as authorized by you.
C. Information Automatically Collected
  • Usage Data: We automatically log how you interact with our platform, including IP addresses, browser types, session durations, and the AI queries you submit.
  • Cookies & Tracking: We use cookies to maintain your session, analyze site traffic, and improve performance.
D. Data we do not collect

We do not intentionally collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or data about criminal convictions.

3. How We Use Your Data

We use your data strictly to operate and improve our business, including to:

  • Provide the Service: Connect your data sources, aggregate metrics, and generate reports and dashboards.
  • Maintain Security: Detect unauthorized access, abuse, or anomalous behavior, and maintain integrity of the Service.
  • Communication: Send administrative notices, product updates, and billing alerts.
  • Service Improvement: Analyze aggregate usage patterns to improve features, fix bugs, and develop new functionality.

4. How We Share Your Information

We do not sell your personal data. We only share information under the following circumstances:

  • Service Providers: We engage trusted third-party vendors to help operate the Service, including: cloud infrastructure and hosting providers, payment processors, customer communication tools, analytics and product monitoring tools, and LLM providers. All service providers are bound by Data Processing Agreements that restrict them from using your data for any purpose other than performing services on our behalf.
  • Legal Compliance: We may disclose data when required by law, court order, or governmental authority, or when necessary to protect the rights, property, or safety of Everywave, our users, or the public — including for fraud detection and prevention.
  • Business Transfers: In the event of a merger, acquisition, asset sale, or similar corporate transaction, your data may be transferred as part of that transaction. We will provide notice before personal data is transferred and becomes subject to a different privacy policy.

5. Third-Party Integrations

Our Service relies on connecting to third-party platforms. When you connect a platform, the data practices are also governed by that third party's respective privacy policy.

API Compliance & Limited Use Requirements

To provide our Service securely, Everywave complies with the specific developer policies and API requirements of our connected platform partners. Where required, we apply strict limitations on how we access, use, and transfer your connected data.

Google API Services Disclosure:

Specifically, to ensure compliance with Google's Limited Use requirements:

  • We request only the minimum OAuth scopes necessary to provide the features you use. You can review and revoke Everywave's permissions at any time via your Google Account permissions page.
  • When you connect Google Analytics, Everywave may access — with your explicit OAuth authorization and depending on the permissions granted — data such as traffic metrics, event data, session data, and reporting metadata.
  • We do not use Google user data for any purpose other than providing and improving the Everywave service as requested by the user.
  • We do not transfer Google user data to any party for advertising, data brokerage, or any purpose other than directly providing the Service.
  • We do not allow human access to Google user data unless explicitly authorized by you, required for security purposes, or mandated by law.
  • We do not use Google user data to create, train, or improve a machine learning or artificial intelligence model, including foundational models.
  • Google user data is retained only as long as necessary to provide the Service. When you disconnect a Google integration or close your account, we delete the associated Google user data from our active systems within a reasonable timeframe in accordance with our retention schedule, and from backups within 90 days.
  • Google user data is protected with the same enterprise-grade security measures applied to all data on our platform, including encryption in transit (TLS 1.2+) and at rest (AES-256).

6. International Data Transfers

Everywave operates primarily from within the European Economic Area and may process and store data on infrastructure located in the EU and the United States. If you are located in the EEA, UK, or Switzerland, your personal data may be transferred to countries that do not offer the same level of data protection as your home country.

Where we transfer personal data outside the EEA/UK, we rely on one or more of the following safeguards:

  • EU Standard Contractual Clauses (SCCs) — adopted under Commission Decision (EU) 2021/914, incorporated into our DPAs with subprocessors.
  • EU-US Data Privacy Framework (DPF) — for transfers to US-based subprocessors that are DPF-certified.
  • UK International Data Transfer Agreements (IDTA) — for transfers from the UK.
  • Adequacy decisions — where the destination country has received a formal adequacy decision from the European Commission.

You may request a copy of the transfer safeguards we rely on by contacting us at support@everywave.com.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law. Our general retention guidelines:

  • Account Data: Retained for the lifetime of your active account.
  • Integration Data: Cached data synced from third parties is retained only while the integration is active. If you revoke access or delete your Everywave account, the associated data and authentication tokens are automatically purged from our active systems within 30 days.

8. Your Privacy Rights

Depending on your location (e.g., EEA, UK, California), you have rights regarding your personal data, including:

  • Right to Access & Portability: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct inaccurate data.
  • Right to Erasure: Request the deletion of your personal data ("Right to be Forgotten").
  • Right to Restrict or Object: Limit or object to our processing of your data.
  • Withdraw Consent: If we process data based on consent, you may withdraw it at any time.

To exercise these rights, please email support@everywave.com. We will respond to your request within the timeframe required by applicable law.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, alteration, or disclosure. Our measures include:

  • Encryption in transit: TLS 1.2 or higher for all data transmitted between your browser/app and our servers.
  • Encryption at rest: AES-256 encryption for data stored in our databases and backups.
  • Access controls: Role-based access controls (RBAC) limiting data access to authorized personnel on a strict need-to-know basis. Multi-factor authentication (MFA) required for all internal systems.
  • Vulnerability management: Regular security assessments, penetration testing, and dependency audits.
  • Incident response: A documented incident response plan. In the event of a personal data breach affecting your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by applicable law.
  • Privacy by design: Data protection principles are integrated into our product development lifecycle.

No security system is impenetrable. We cannot guarantee the absolute security of data transmitted over the internet, but we commit to treating any security incident promptly and transparently.

10. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. If we make material changes, we will:

  • Update "Last Updated" date at the top of this policy.
  • Notify registered users via email and/or in-app notification at least 30 days before the change takes effect (for material changes).
  • For changes affecting your rights, seek fresh consent where required by law.

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the updated terms, to the extent permitted by applicable law. Previous versions of this policy are available upon request.

11. Contact

For any questions, concerns, or requests relating to this Privacy Policy, please contact us at support@everywave.com.

12. Data Controller

For the purposes of data protection laws, the Data Controller responsible for your personal information is:

Morad Boukhari
morad@everywave.com