Privacy Policy
Zoho Advisor AI — appvisor.ai

Effective Date: April 3, 2026
Last Updated:April 3, 2026

1. Introduction

Zoho Advisor AI (AppVisor, the “Service”), accessible at appvisor.ai, is an AI-powered consultation tool operated by United Parts of Chicago, LLC (“we,” “us,” “our”), an Advanced Zoho Partner based in Deerfield, Illinois. The Service recommends Zoho products based on a visitor’s business needs through a chat-based interface powered by Anthropic’s Claude AI.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have. By using the Service, you agree to the practices described in this policy.

2. Information We Collect

2.1 Information you provide directly

  • Conversation content: the messages you type during your consultation with the AI advisor.
  • Contact information: if you choose to submit the consultation form or request a PDF summary, we collect your name and email address.
  • Business information: details you share about your business during the conversation, such as industry, company size, challenges, and tools you currently use.

2.2 Information collected automatically

  • Geographic location: your country, city, and region, determined from Cloudflare network headers (CF-IPCountry, CF-IPCity, CF-Region). We do not use GPS or precise geolocation.
  • IP address: collected from the Cloudflare CF-Connecting-IP header. Used for rate limiting and geographic identification.
  • Browser and device information: user agent string transmitted by your browser.
  • Referral source: the URL parameter (?ref=) indicating which link or campaign brought you to the Service.
  • Session metadata: timestamps, message count, session duration.

2.3 Cookies and tracking technologies

The Service uses cookies and similar technologies through the following third-party services:

  • Google Analytics: sets cookies (including _ga, _gid, and _gat) to distinguish unique visitors, track session activity, and measure traffic sources. These cookies are used for aggregate analytics, not for advertising or user profiling.
  • Google Tag Manager: loads and manages analytics scripts on the page. GTM itself does not set cookies, but it loads Google Analytics which does.
  • Zoho PageSense: sets cookies to track visitor sessions, clicks, scrolling behavior, and page interactions. Used for heatmaps and session recordings to improve the user experience. Zoho PageSense does not use this data for advertising.
  • Session tokens: a session identifier is stored in your browser (cookie or localStorage) to maintain conversation continuity. This is a functional cookie, not a tracking cookie.

You can disable cookies through your browser settings. Disabling cookies will not prevent you from using the AI consultation, but may limit our ability to improve the service based on aggregate usage data.

2.4 Information we do NOT collect

  • We do not use cookies for advertising, retargeting, or cross-site tracking.
  • We do not collect financial information, payment details, or government identifiers through the chat.
  • We do not use GPS, Bluetooth, or Wi-Fi signals for location tracking.

3. How We Use Your Information

3.1 To provide the Service

  • Process your messages and generate AI-powered Zoho product recommendations.
  • Display your recommended product stack during and after the consultation.
  • Generate and email PDF recommendation summaries when you request them.
  • Create shareable recommendation links that you can send to colleagues.

3.2 To improve the Service

This is important and we want to be transparent about it:

We use anonymized insights from conversations to improve the AI advisor and to create publicly accessible recommendation pages. Specifically:

  • After your conversation ends, the AI generates a structured summary: your industry (generalized), the apps recommended, and the reasoning behind the recommendation.
  • This summary is processed through a multi-step anonymization system that removes all identifying details, including names, company names, specific locations, email addresses, phone numbers, and exact employee counts. The process combines automated checks with human review (see Section 8 for details).
  • An anonymized summary may be reviewed by our team and published as a recommendation case on our website. These pages show generalized business scenarios (e.g., “a small roofing contractor”) alongside the Zoho apps recommended and the AI’s reasoning.
  • A short excerpt from the conversation (typically one question and one answer) may be included on the published recommendation page, but only after it has been anonymized and reviewed by a human editor.
  • Published recommendation pages are indexed by search engines. They do not contain your name, email, company name, city, or any other personally identifying information.
  • Common questions from conversations are clustered and may be used to generate FAQ content on our main website. These FAQs contain generic questions and answers, not individual conversation data.

3.3 To generate leads for our consulting business

  • When you submit the contact form or provide your email for a PDF, we may create a Lead record in our Zoho CRM system containing your name, email, the anonymized conversation summary, and the recommended Zoho apps.
  • We may send notifications to our internal team (via Zoho Cliq) when a consultation is completed, including session metadata and the recommended apps. These notifications do not include your conversation transcript.

3.4 For analytics and operations

  • Aggregate analytics: session counts, conversion rates, geographic distribution, demand patterns by industry, cost tracking. These analytics operate on aggregate data, not individual conversations.
  • Rate limiting and abuse prevention: your IP address is used to enforce per-session message limits and per-IP request limits.
  • Service monitoring: response times, error rates, API usage.

4. Third-Party Services

The Service relies on the following third-party providers, each with their own privacy policies:

4.1 Anthropic (Claude AI)

Your conversation messages are sent to Anthropic’s API to generate AI responses. Anthropic processes these messages in accordance with their privacy policy and API terms of service. We use prompt caching, which means repeated elements of the system configuration are cached by Anthropic for performance. Your individual messages are not cached by Anthropic beyond request processing. Your messages are not used by Anthropic to train their models (per their API terms). Anthropic’s privacy policy.

4.2 Google Analytics and Google Tag Manager

We use Google Analytics 4 (GA4) to measure aggregate website traffic: page views, session duration, traffic sources, and general user behavior patterns. Google Analytics sets cookies on your browser to distinguish visitors and track sessions. We do not enable Google’s advertising features, cross-site tracking, or user-level profiling. Google Tag Manager is used to manage the loading of analytics scripts and does not independently collect personal data. Google’s privacy policy.

4.3 Zoho PageSense

We use Zoho PageSense for heatmaps, click tracking, and session recordings to understand how visitors interact with the Service. PageSense sets cookies to maintain session context. Session recordings may capture mouse movements, clicks, and scroll behavior but do not capture text typed into the AI chat input (the chat operates on a separate API channel). PageSense data is stored in Zoho’s infrastructure and is accessible only to our team. Zoho PageSense privacy.

4.4 Cloudflare

All traffic to appvisor.ai passes through Cloudflare’s network for DNS resolution, SSL encryption, DDoS protection, and bot detection. Cloudflare provides us with your approximate geographic location (country, city, region) via HTTP headers. Cloudflare’s privacy policy.

4.5 Zoho Corporation

We use Zoho products (CRM, Books, Desk, Flow, Mail) for our internal business operations. When you submit a contact form or provide your email, your information may be stored in Zoho CRM. Zoho’s privacy policy.

4.6 Zoho product and registration links

The Service contains links to Zoho product pages and free trial registration pages. These are partner registration links provided to us by Zoho Corporation as part of the Zoho Partner Program. When you click these links, you leave appvisor.ai and are subject to Zoho’s privacy policy. We do not control what information Zoho collects when you visit their pages or sign up for trials.

4.7 Partner commissions

As a Zoho Authorized Partner, we may or may not receive referral commissions from Zoho Corporation when visitors register for Zoho products through links on this Service. Whether a commission is paid, and the amount, is determined solely by Zoho Corporation under the terms of the Zoho Partner Program. This is a standard commercial arrangement between Zoho Corporation and its authorized partners worldwide. The presence of registration links and the possibility of commissions does not influence the AI’s recommendations — the advisor recommends products based on the visitor’s stated business needs, not on commission structures.

5. Data Storage and Security

  • Conversation data is stored in a PostgreSQL database hosted on a virtual private server located in [REGION — to be specified based on VPS provider].
  • All data is encrypted in transit via TLS (HTTPS enforced through Cloudflare).
  • Database access is restricted to authenticated application processes. There is no public database endpoint.
  • Administrative access to the Service’s backend is protected by Zoho OAuth authentication with an email whitelist. Only authorized team members can access conversation data or analytics.
  • API keys and credentials are stored as environment variables on the server, never in client-side code or public repositories.

6. Data Retention

  • Conversation transcripts and session data: retained indefinitely for service improvement and analytics. Conversations that are used to generate published recommendation cases retain only the anonymized summary and excerpt; however, the original transcript is retained internally.
  • Contact information (name, email): retained as long as the corresponding Lead record exists in our CRM, or until you request deletion.
  • Usage and cost data: aggregated daily and retained indefinitely. Individual request-level token counts are not retained after daily aggregation.
  • Rate limit logs: retained for 90 days, then automatically purged.
  • Published recommendation cases: retained on the website indefinitely unless unpublished by our team.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate personal information.
  • Deletion: request deletion of your personal information. If we have published an anonymized recommendation case derived from your conversation, deletion of the original transcript does not require removal of the anonymized case, since it contains no personally identifying information. However, if you believe an anonymized case is identifiable to you, contact us and we will review and remove it.
  • Objection: object to the processing of your data for specific purposes.
  • Data portability: request your conversation data in a machine-readable format.

To exercise any of these rights, contact us at hello@crmforyourbusiness.com. We will respond within 30 days.

8. How We Anonymize Your Data

Because anonymized conversation data may be used publicly, we want to explain how we protect your identity:

We use a multi-step anonymization process combining AI-based generalization with automated verification and manual review to ensure no personally identifying information appears in published content.

When a conversation ends, the system generates an anonymized summary that removes all identifying details: company names, personal names, city and state names, and specific employee counts. It generalizes to industry and size range (e.g., “a 15-person roofing company in Dallas” becomes “a small roofing contractor”). Additional automated checks verify the output before it reaches any human reviewer.

Human review: No anonymized case is published without a human editor reviewing it. The editor verifies that the summary and any conversation excerpt are genuinely anonymized before making them public.

Published recommendation pages show only: a generalized business description, the Zoho apps recommended with justifications, topic tags, the visitor’s country (not city), a partially masked session identifier, and the month and year of the conversation.

9. Published Recommendation Pages

Our website includes recommendation pages at URLs like appvisor.ai/zoho-crm/for/real-estate/. These pages contain anonymized cases derived from real consultations. Each published case shows:

  • An anonymized business scenario (industry and generalized need, no identifying details).
  • The Zoho apps recommended, with per-app justifications.
  • A short conversation excerpt (visitor question + AI response), anonymized and human-reviewed.
  • The visitor’s country (from Cloudflare geolocation), displayed as a country name only.
  • A partially masked session identifier (middle digits obscured).
  • The month and year the consultation occurred.

These pages are indexed by search engines. They are designed so that no individual visitor can be identified from the published content. If you believe a published case is identifiable to you, contact us immediately and we will review and remove it.

10. Children’s Privacy

The Service is designed for business owners and professionals. We do not knowingly collect personal information from anyone under the age of 16. If we learn that we have collected information from a child under 16, we will delete it promptly.

11. International Data Transfers

The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. Our third-party providers (Anthropic, Cloudflare, Zoho, Google) may process data in various countries in accordance with their own privacy policies.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights:

United Parts of Chicago, LLC
Email: privacy@crmforyourbusiness.com
Phone: (833) 880-2387

14. Supplemental Disclosures

14.1 Anthropic Claude AI — How your messages are processed

When you send a message in the consultation chat, the following happens: your message is sent from your browser to our server (encrypted via HTTPS). Our server adds system instructions and knowledge base context, then forwards the combined request to Anthropic’s Messages API. Anthropic’s AI processes the request and returns a response. Our server saves the message and response to our database, then sends the AI’s response back to your browser. At no point does your browser communicate directly with Anthropic. Your messages are not used by Anthropic to train their models (per their API terms).

14.2 Shareable recommendation links

When you click “Share this recommendation,” a unique URL is generated (e.g., appvisor.ai/r/abc123xyz). This page shows an anonymized summary of the AI’s recommendation. It does not show your conversation transcript, name, email, or any personally identifying information. The page is accessible to anyone with the link but is not indexed by search engines. You can share this link at your discretion; we cannot retract access once a link has been shared with a third party.

14.3 PDF email delivery

When you request a PDF summary, the email is sent via our Zoho Mail infrastructure. Your email address is stored in our database and CRM. The PDF contains the recommended Zoho stack, justifications, and a link to book a consultation. It does not contain your conversation transcript.