Privacy policy
Last updated: 2026-08-29
This is a plain-language description of how Orvia handles data. It is not legal advice. We wrote it to be accurate and to match what the software actually does — if you ever find something here that does not match your experience, tell us.
What data Orvia stores
Orvia stores the data your business enters: products, stock levels, clients, orders, invoices, payments, supplier catalogs, and the workspace's member accounts (name, email, password hash). We also keep an audit log of important actions inside your workspace so your team can see who did what.
How we use your data
- To run the service you asked us to run: storing your records, sending account emails, and keeping the product secure and available.
- We do not sell or rent your data to anyone, ever.
- We do not use your business data to advertise to you or to anyone else.
- We do not access your business data as part of normal operations. Limited access may occur for support you request, security incidents, or legal obligations — and is only ever used for that purpose.
Tenant isolation
Every business workspace is isolated. Queries are bound to the verified session's workspace — one business can never read another business's data. Client-supplied identifiers are re-verified as owned by the workspace in the same operation.
Supplier catalog PDFs
When you upload a supplier PDF catalog, the raw file is kept only long enough to review and commit the extracted data (a short TTL, then purged automatically). The committed structured catalog data is retained as part of your workspace. Imports never modify your inventory — you review and decide on every change.
Retention, backups, and deletion
- We keep encrypted-in-transit automated backups of the database so your data survives failures.
- Passwords are stored only as hashes, never in plain text.
- If you stop using Orvia and want your workspace and its data deleted, contact us and we will delete it (subject to any legal retention obligation).
Providers that help run the service
Orvia runs on infrastructure providers that process data on our behalf: Vercel (hosting), Supabase (database), automated error monitoring, and email delivery. Each receives only the data needed for its function. We also collect privacy-friendly, cookie-free page-view counts to understand how the product is used.
Email and communications
We send email only for account activity: verification, invitations, and password resets. Your email address is used for your account and those messages — nothing else.
Security
Passwords are stored as hashes, sessions expire, and a logout or password reset invalidates existing sessions. All traffic is encrypted in transit. Production deployments follow a fixed release gate including a security audit before merge.
Changes to this policy
If this policy changes, the date above is updated. Material changes are announced through the product.
Contact
Questions about this policy or your data? Contact us.