Privacy policy
Who we are
ProductChat IQ is a product created by OrangeFin, a technology and marketing studio based in Toronto, Canada, serving the Greater Toronto Area and beyond. This policy explains how we handle personal information. If you have questions, contact us at troy@orangefinagency.com.
Who this covers
This policy describes three situations, which are different:
- Visitors to this marketing site. People reading these pages.
- Account holders. Staff at a manufacturer or distributor who sign in to run assistants.
- End users of a website assistant. People who chat with an assistant on a customer's website. Here the customer decides what is collected and why; we handle that information on their behalf, as a processor. Their own privacy notice governs that use.
What we collect, and why
On this marketing site, we use Google Analytics to understand aggregate traffic, such as which pages are visited, approximate location, and device type. It runs only if you accept analytics cookies in the banner; if you decline, or before you choose, it is off and sets no analytics cookies. We do not set advertising cookies. If you email us or request a demo, we receive what you send, such as your name, email, and message, to reply and follow up.
Our own assistant runs on this site, in the corner of every page. It is the same product this site describes, so you can judge it directly. Questions you type into it, and the answers it gives, are stored against a short-lived, anonymous session so we can see which questions we answer badly and fix them. You do not need to tell it who you are, and we ask you not to put anything confidential into it. It becomes personal information only if you choose to open the contact form inside it and give us your details. Cloudflare Turnstile runs a bot check when a conversation starts.
For account holders, we collect the email address used to sign in, basic profile details, and the operational records needed to run the service, such as sign-in events and audit entries for privileged actions. Uploaded documents belong to the customer; we process them only to provide the service the customer configures.
For end users of an assistant, no account and no personal information are required to ask a question. Personal information is collected only if the visitor chooses to send a question to a person, and only the fields the customer has configured, which start from a minimal set, such as name, email, and the question. Consent is recorded at that point.
How the model uses content
Assistants answer from the documents a customer has published. Customer content is not used to train a shared model. It is used to provide the service, and nothing else.
Who we share information with
We do not sell personal information. We use a small number of service providers, listed below, to run the product. Each processes information only to provide its part of the service.
| Provider | What they do |
|---|---|
| Cloudflare | Hosting, content delivery, bot protection (Turnstile), and model inference (Workers AI). |
| Supabase | Database, authentication, and file storage for uploaded documents. |
| Resend | Delivery of escalation and demo-request emails. |
| Google Analytics | Aggregate marketing-site traffic analytics, only after cookie consent. |
We may also disclose information where required by law, or to protect the service and its users from abuse.
Cookies
This marketing site sets Google Analytics cookies only if you accept them in the cookie banner; until you choose, and if you decline, no analytics cookies are set. When you are signed in to the application, it also sets a small functional cookie that records only the fact that you are signed in — no name, email, or session token — so this site can offer a link to your dashboard instead of a sign-in prompt. You can change your mind, or remove either cookie, by clearing this site's cookies. The signed-in application uses a small number of strictly necessary cookies to keep you signed in and to remember which account you are working in. The website assistant uses short-lived session tokens rather than cookies.
How long we keep information
We keep information for as long as needed to provide the service, then delete or de-identify it. Conversation and escalation records follow retention windows that a customer can adjust. Copies held in encrypted backups age out on a documented schedule rather than being kept indefinitely.
Your choices and rights
Account holders can export their originals and structured data at any time, and can delete a document or the whole account. Deletion covers the primary data, the derived chunks and embeddings, and the stored files, with backup copies ageing out on the retention window.
Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you. For information collected through an assistant on a customer's site, contact that company first, since they decide how it is used. For anything we hold directly, email troy@orangefinagency.com.
Security
We protect information with the controls described on our security page, including private storage, separation between accounts, approved-domain controls on the assistant, and audit logging. No service can promise that data is impossible to compromise; we describe the controls so you can judge them.
Where information is held
The service runs on Cloudflare and Supabase infrastructure and may process and store information in data centres outside your country. We use providers that offer appropriate safeguards for that processing.
Children
The product is for business use and is not directed at children.
Changes
We will update this policy as the product changes, and will note the effective date when a reviewed version is published.
Contact
Questions about privacy: troy@orangefinagency.com.