Last updated: April 13, 2026
1. Introduction
PVSN ("Price Variation Software Network", "we", "us", or "our") operates the pvsnapp.com platform and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our dynamic pricing platform, website, APIs, SDKs, and related services (collectively, the "Service"). It applies to merchants and authorized users of the Service. Where you use the Service to process data about your own end customers, you are the data controller and PVSN acts as your data processor; in those cases the Data Processing Addendum governs that relationship.
2. Information We Collect
Account Information
When you register for PVSN, we collect your name, email address, company name, and chosen currency preference. We also collect authentication credentials (stored only in hashed form using bcrypt), multi-factor authentication secrets where you enable MFA, and billing contact information if you subscribe to a paid plan.
Merchant Data
To provide our dynamic pricing services, we process the product catalogs, customer records, transaction events, pricing rules, and configuration that you upload or create through the Service ("Merchant Data"). This data remains yours and is processed solely to deliver the pricing engine functionality, generate predictions and offers, and produce analytics for your account.
Usage Data
We automatically collect information about how you interact with the Service, including API call logs, feature usage patterns, request and trace identifiers, IP addresses, browser type, operating system, and device information. This helps us maintain, secure, debug, and improve the platform, and is also used for rate limiting and abuse prevention.
Third-Party Data
Our pricing engine may incorporate publicly available contextual data such as weather conditions, local events, and market trends to calculate optimal prices. This data is sourced from third-party providers and relates to context (e.g., a city, a date), not to the identity of any individual end consumer.
3. How We Use Your Information
- Provide, operate, and maintain the dynamic pricing Service
- Calculate price variations using our 100+ variable pricing engine
- Generate predictions, analytics, and pricing recommendations
- Process transactions and manage your subscription and invoices
- Send transactional emails (account confirmations, password resets, billing notices)
- Deliver webhook notifications and API responses you request
- Monitor and improve Service performance, security, and reliability
- Detect fraud, abuse, and enforce our Terms of Service
- Respond to support requests and communicate about the Service
- Comply with legal, tax, and regulatory obligations
Legal bases for processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases to process personal data:
- Contract: to provide the Service you have signed up for and to administer your account and billing.
- Legitimate interests: to secure the platform, prevent abuse, debug issues, and improve our products, balanced against your rights.
- Legal obligation: to meet tax, accounting, and other statutory requirements.
- Consent: where you have given it, for example for optional product communications, which you may withdraw at any time.
4. Data Sharing and Disclosure
We do not sell your personal information or Merchant Data. We may share information with:
- Service providers (subprocessors): infrastructure hosting, payment processing, email and SMS delivery, and AI providers who assist in operating the Service. See the subprocessor table below.
- AI services: anonymized pricing inputs may be sent to our AI provider (Anthropic) to generate pricing recommendations and offer messaging, with no personally identifiable end-customer data included.
- Integration partners: when you connect third-party integrations (Shopify, WooCommerce, Slack, Zapier, SendGrid, Twilio), data flows to those platforms per your configuration.
- Legal requirements: when required by law, regulation, legal process, or a valid governmental request.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, with advance notice where required.
Subprocessors
We engage the following key subprocessors to deliver the Service. We maintain contractual data-protection commitments with each and will give notice of material changes to this list.
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing & billing | United States |
| Railway | Application & database hosting | United States |
| Vercel | Frontend / static asset hosting & CDN | Global edge network |
| Anthropic | AI pricing recommendations (anonymized inputs) | United States |
| Google Workspace | Transactional email (SMTP) | United States |
| Sentry | Error tracking & performance monitoring | United States |
| GitHub | Source control & CI/CD | United States |
5. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS), hashed passwords (bcrypt), HMAC-SHA256 signed webhooks, API key authentication with scoped permissions and rotation, role-based access control (RBAC), rate limiting, brute-force protection on login, audit logging, and security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options). Access to production systems is restricted on a least-privilege basis. While we strive to protect your data, no method of electronic storage or transmission is 100% secure.
6. Data Retention
We retain your account data for as long as your account is active. Merchant Data (products, customers, events, predictions, offers) is retained for the duration of your subscription. Upon account deletion, we anonymize or delete your data within 30 days, except where retention is required by law (for example, invoices retained for tax purposes). Audit logs and aggregated, anonymized analytics may be retained longer for security and compliance purposes.
7. Your Rights (GDPR and CCPA)
Depending on your jurisdiction, you may have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate personal data
- Erasure: request deletion of your personal data ("right to be forgotten")
- Portability: receive your data in a machine-readable format
- Restriction: limit how we process your data
- Objection: object to processing based on legitimate interests
- Withdraw consent: where processing is based on consent
- Lodge a complaint: with your local data protection authority
PVSN provides a self-service GDPR Center within the dashboard for data export and deletion requests. You can also exercise these rights by contacting us at support@pvsnapp.com. We respond to verifiable requests within the timeframes required by applicable law.
Your California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you the right to know what personal information we collect and how we use and disclose it, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the "sale" or "sharing" of personal information. PVSN does not sell or share personal information as those terms are defined under the CPRA, and we do not use sensitive personal information for purposes that require a right to limit. You will not be discriminated against for exercising any of these rights. To make a request, contact support@pvsnapp.com.
9. International Data Transfers
Your data may be processed in countries other than your own, including the United States. When we transfer personal data internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK transfer mechanisms, together with supplementary technical measures such as encryption in transit. By using the Service, you understand that your information may be transferred to and processed in these locations.
Automated decision-making
The Service uses automated models (the pricing and prediction engines) to recommend prices and offers. These outputs are recommendations and configuration that you control through guardrails (floor, ceiling, margin, and velocity limits) and approval settings — they are not decisions that produce legal or similarly significant effects on your end customers without your involvement. You remain responsible for the prices you publish. If you believe an automated output is incorrect, you can override it at any time and contact us for assistance.
Breach notification
We maintain an incident-response process. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected customers and, where required, the relevant supervisory authority without undue delay and in line with applicable law (for GDPR, generally within 72 hours of becoming aware of the breach). Our notice will describe the nature of the incident, likely consequences, and the measures taken or proposed.
Children's data
The Service is intended for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us immediately and we will take steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service dashboard at least 30 days before the changes take effect. The "last updated" date at the top of this page indicates when it was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries, data requests, or complaints, contact us at:
PVSN — Price Variation Software Network
Email: support@pvsnapp.com
Phone: 720-969-9858