Legal
Privacy Policy
Effective Date: August 6, 2026
DRAFT — FOR LEGAL COUNSEL REVIEW
1. Introduction
Ambivia, Inc. ("Ambivia," "we," "us," or "our") is a Delaware C-Corporation that operates a Software-as-a-Service platform connecting physical businesses with consumers through real-time atmosphere intelligence, accessibility compliance tools, and multi-modal transit routing.
This Privacy Policy describes how we collect, use, disclose, and protect personal information when you access or use our platform, including the Ambivia mobile application, the Ambivia business web portal, and all related services (collectively, the "Platform").
By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use the Platform.
2. Information We Collect
2.1 Information You Provide Directly
- ●Account registration information (name, email address, phone number, date of birth)
- ●Business information for business operators (business name, address, tax identification, beneficial ownership)
- ●Profile preferences (accessibility needs, atmosphere preferences, persona settings)
- ●Payment information (processed by Stripe; we do not store card numbers)
- ●Communications with us (support requests, feedback)
- ●Know Your Business (KYB) verification data submitted during onboarding
2.2 Information Collected Automatically
- ●Device information (device type, operating system, unique device identifiers)
- ●Location data (GPS coordinates, with user consent; rounded for analytics)
- ●Usage data (features accessed, interaction patterns, session duration)
- ●Log data (IP address, browser type, access times, referring URLs)
- ●Telemetry data (system performance metrics — anonymized before processing)
2.3 Information We Do Not Collect
- ●Biometric templates — passkey authentication (FaceID/TouchID) is processed entirely on-device; on the web via WebAuthn and on mobile via hardware-bound cryptographic keys stored in the Secure Enclave (iOS) or Trusted Execution Environment (Android). Biometric data never leaves your device — only a cryptographic signature is transmitted to our servers
- ●Payment card numbers — all payment processing is handled by Stripe (PCI DSS Level 1 certified)
- ●Health records or clinical data — our healthcare vertical manages spatial routing and queueing only
- ●Social Security numbers or government-issued ID numbers (except as required for KYB verification via our third-party provider)
2.4 Operator Location Broadcasting
When business operators activate live broadcasting (e.g., a food truck going live or a mobile service provider en route), their business location is shared in real time with nearby patrons on the discovery map. Operators have full control over when broadcasting is active and can disable it at any time. This location data represents the business operating location — not the operator's personal residence or private location.
3. How We Use Your Information
- ●Provide, maintain, and improve the Platform and its features
- ●Process transactions and send related information (receipts, confirmations)
- ●Calculate personalized business discovery results based on proximity, availability, and preferences
- ●Generate business analytics and business intelligence for subscribed operators
- ●Verify business identity and conduct KYB/AML compliance checks
- ●Send administrative communications (service updates, security alerts)
- ●Detect, prevent, and address fraud, abuse, and security incidents
- ●Comply with legal obligations and enforce our Terms of Service
- ●Conduct anonymized research and analytics to improve service quality
- ●Provide accessibility compliance tools and generate compliance reports for business operators
4. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data on the following legal bases:
- §Contractual Necessity — to provide the Platform services you have requested (route calculation, business discovery, subscription services)
- §Consent — for location tracking, marketing communications, and optional data sharing (you may withdraw consent at any time)
- §Legitimate Interest — for service improvement, fraud prevention, and security monitoring (balanced against your rights)
- §Legal Obligation — for tax reporting, AML/CFT compliance, and responding to lawful government requests
5. How We Share Your Information
We do not sell your personal information to third parties. We share information only in the following circumstances:
Service Providers
- ●Amazon Web Services (AWS) — cloud infrastructure and data hosting
- ●Stripe — payment processing, subscription billing, and business payouts
- ●Cobalt Intelligence — Business verification via Secretary of State API
- ●Amazon SES — transactional email delivery
- ●Mapbox — map rendering and multi-modal transit routing
- ●Sentry — application error monitoring and crash reporting
- ●Firebase Cloud Messaging — push notification delivery (mobile)
Other Disclosures
- ●Legal compliance — when required by law, subpoena, court order, or government request
- ●Safety and security — to protect the rights, property, or safety of Ambivia, our users, or the public
- ●Business transfers — in connection with a merger, acquisition, or sale of assets (you will be notified)
- ●With your consent — when you explicitly authorize a specific disclosure
6. Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Active user account data | Duration of account |
| Booking and appointment history | 12 months |
| Anonymized analytics | 12 months |
| Application logs | 30 days |
| Financial records | 7 years (legal requirement) |
| KYB verification records | 5 years post-relationship |
| Deleted account data | 30-day grace period, then permanent deletion |
| Inactive accounts | 3 years after last activity |
7. Your Rights
7.1 Rights Under GDPR (EEA/UK Users)
- §Right of Access — request a copy of your personal data
- §Right to Rectification — correct inaccurate or incomplete data
- §Right to Erasure — request deletion of your personal data ("Right to be Forgotten")
- §Right to Restrict Processing — limit how we use your data
- §Right to Data Portability — receive your data in a machine-readable format (JSON)
- §Right to Object — object to processing based on legitimate interest
- §Right to Withdraw Consent — withdraw consent at any time without affecting prior processing
- §Right to Lodge a Complaint — file a complaint with your local data protection authority
7.2 Rights Under CCPA/CPRA (California Residents)
- §Right to Know — what personal information we collect, use, and disclose
- §Right to Delete — request deletion of personal information
- §Right to Opt-Out of Sale — we do not sell personal information; this right is honored by default
- §Right to Non-Discrimination — equal service regardless of privacy choices exercised
- §Right to Correct — correct inaccurate personal information
- §Right to Limit Use of Sensitive Personal Information — restrict processing of sensitive data
7.3 Exercising Your Rights
To exercise any of these rights, contact us at privacy@ambivia.tech or use the account settings within the Platform. Account deletion is available directly in the mobile app under Profile settings. Data export (portability) requests can be submitted via email and will be fulfilled in JSON format. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). Identity verification may be required to process your request.
8. Data Security
We implement industry-standard technical and organizational measures to protect your personal information:
- ●Encryption at rest using AES-256 for all stored data
- ●Encryption in transit using TLS 1.2+ for all data transmission
- ●Zero-Trust authentication architecture
- ●Multi-factor authentication required for all administrative access
- ●Tenant isolation enforced on all authenticated API routes
- ●Regular security audits, automated vulnerability scanning, and code quality analysis
- ●SOC 2 Type II compliance program planned
- ●Automated threat detection and incident response procedures
- ●Data breach notification to affected users and authorities as required by applicable law
To report a security vulnerability or unauthorized access to your account, contact us at security@ambivia.tech.
9. International Data Transfers
Ambivia, Inc. is based in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers from the EEA/UK to the United States, we rely on:
- ●Standard Contractual Clauses (SCCs) approved by the European Commission
- ●Data Processing Agreements (DPAs) with all sub-processors
- ●AWS data residency options in EU regions for EU customers
- ●Supplementary technical measures (encryption, pseudonymization) as required
11. Children's Privacy
The Platform is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly in accordance with the Children's Online Privacy Protection Act (COPPA).
If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@ambivia.tech.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- ●Update the "Effective Date" at the top of this page
- ●Notify you via email or in-app notification for material changes
- ●Provide at least 30 days notice before changes take effect
- ●Obtain renewed consent where required by applicable law
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Inquiries: privacy@ambivia.tech
Legal Department: legal@ambivia.tech
General Support: support@ambivia.tech
Security: security@ambivia.tech
Ambivia, Inc.
A Delaware Corporation
10770 Columbia Pike, Suite 300 #1100
Silver Spring, Maryland 20901
United States
This Privacy Policy constitutes a binding agreement between you and Ambivia, Inc. regarding the collection and use of your personal information. This document is provided for legal counsel review and will be finalized prior to public launch.
© 2026 Ambivia, Inc. All rights reserved.