Privacy
Privacy policy
What Via collects, why, and what you can ask us to do with it.
Draft for Founder review. This page is a placeholder written from how Via is built. It is not final and it is not legal advice. Items marked OPEN are decisions still to be made before publication.
Who we are
Via is a commerce operating system operated by ODX (OPEN: legal entity name, registration and address). This policy covers three places where Via handles personal data: this website, the Via Admin application used by merchants and their staff, and the online stores that merchants run on Via.
This website (runonvia.com)
This site, runonvia.com, sets no cookies, runs no analytics and makes no request to any third party. The only data it collects is what you send through the Start with Via form: what you would like (Setup Mode, demo or contact), your name, work email, company or brand, phone number, what you sell and where you sell today (chosen from lists), how many stores you run, the tier you are interested in, and your consent to be contacted. There is no free-text field.
We use these details only to contact you about Via. To limit abuse, our server keeps a one-way hash of the sending network address for a short time (OPEN: retention window; the technical default is the rate-limit window). A request creates no account, no store and no charge.
Via Admin (merchants and staff)
Merchants and their staff sign in to Via Admin with their own accounts. Via stores the account email, display name, role and permissions, and an append-only audit log of the changes each person makes (who, what and when). Integration credentials that a merchant connects are held server-side, referred to by name, and never shown back in a browser.
Stores that run on Via
When you shop at a store that runs on Via, the merchant is responsible for your data and Via processes it on the merchant's behalf: your orders, delivery addresses, contact details, payment status and messages you exchange with the store. Each store's data is isolated from every other store at the database level.
- Payments. Card numbers and security codes are entered on the payment provider's hosted page. Via never receives or stores them. Via records the payment outcome and a masked reference.
- Marketing measurement. Where a merchant has connected Meta, Via sends conversion events to Meta only after the visitor's consent has been recorded, and records what was sent.
- Messaging. Where a merchant has connected WhatsApp or email, Via sends order and service messages on the merchant's behalf and records delivery state and the consent the merchant holds.
- Test data. Test orders are flagged at the source and excluded from reports.
For questions about a specific store's use of your data, contact that store first; the merchant decides what is collected and why.
Data from Facebook and Instagram
When a merchant connects a Meta business account, Via receives access tokens scoped to that merchant's assets and, where the merchant enables it, business data such as ad spend, catalog and page or Instagram content the merchant owns. Tokens are stored encrypted on the server. Disconnecting Meta in Via Admin deletes Via's copy of the tokens. See Data deletion for how to have the rest removed.
Retention
Order and financial records are kept for as long as the merchant and the law require (OPEN: statutory period and the merchant-facing default). Start-with-Via requests are kept until handled and then for OPEN months. Audit logs are append-only and kept for OPEN.
Your rights
You can ask to see, correct or delete the personal data Via holds about you. If the data belongs to a store's records, we will route the request to the merchant and help them answer it. How to ask is on the Data deletion page.
Children
Via and this website are not directed at children (OPEN: age threshold under the applicable law).
Changes and contact
We will post changes to this page with a date. Contact for privacy questions: OPEN (a monitored address, decided by the Founder). Last updated: OPEN.