Privacy Policy
Effective August 16, 2026
This Privacy Policy explains how Arlo handles personal information in connection with its website, dashboard, embedded assistant, analytics, and related services. It does not replace the privacy notice of a business that installs Arlo on its own website.
1. Our role
When a business installs Arlo on its website, that business generally determines why and how visitor information is collected and used. In that setting, Arlo processes information to provide the Service on the business’s behalf. The business remains responsible for its website, its visitor-facing notices, its instructions to Arlo, and any consent or other legal basis required for its use. Arlo acts independently for information about its own website visitors, account holders, and business contacts.
2. Information we process
Depending on how the Service is used, we may process:
- Account and business information: name, email address, authentication identifiers, profile details, organization details, and billing or subscription records.
- Service configuration: site domains, business context, approved flows, goals, style settings, instructions, limits, and embed identifiers.
- Visitor interaction information: conversation content, requests, pages viewed, page context, session identifiers, interaction events, configured goal events, and records of assistant suggestions or actions.
- Technical and security information: browser, device, IP-derived or network information, logs, timestamps, error records, request metadata, and information used to prevent abuse or maintain reliability.
- Communications: messages, requests, feedback, and support correspondence.
3. Sources
We receive information directly from account holders and website visitors; automatically from browsers, devices, and Service logs; from the business that configured Arlo; and from service providers that support authentication, billing, hosting, security, analytics, or model functionality.
4. How we use information
We use information to provide, maintain, secure, troubleshoot, and support the Service; authenticate users; configure and display the embedded assistant; respond to visitor requests; detect configured friction and goal signals; create dashboard analytics; process payments; prevent fraud, misuse, and security incidents; comply with law; enforce our Terms; and improve the Service. We do not sell personal information or use visitor conversations to build unrelated advertising profiles.
5. AI processing
To generate a response or perform a configured task, relevant conversation content, permitted website context, and business configuration may be transmitted to model providers and infrastructure providers that help operate the Service. AI outputs can be inaccurate or incomplete. Businesses should not configure Arlo to request or process sensitive information unless they have independently established an appropriate lawful basis, safeguards, notices, and controls.
6. Cookies and similar technologies
The Service may use cookies, local storage, session identifiers, pixels, logs, or similar technologies to keep a session working, remember settings, prevent abuse, measure performance, and associate visitor events within a site. A business that installs Arlo is responsible for the cookie banner, consent mechanism, and visitor disclosures required for its website and jurisdiction.
7. Disclosure
We may disclose information to the business operating the Arlo-enabled website; to service providers that host, secure, authenticate, process payments for, or otherwise operate the Service; to professional advisers; in connection with a corporate transaction; and to authorities or other parties when we reasonably believe disclosure is required by law, legal process, or to protect rights, safety, security, and the Service. We do not sell personal information for money or cross-context behavioral advertising.
8. International transfers
Information may be processed in countries other than the country in which it was collected. Those countries may have different data-protection laws. Where required, we use appropriate transfer mechanisms or safeguards for transfers of personal information.
9. Retention
We retain information only for as long as reasonably necessary to provide the Service, meet the purposes described here, maintain security and records, resolve disputes, enforce agreements, and comply with legal obligations. Retention can depend on the customer’s configuration, account status, the nature of the information, and applicable law. We may retain de-identified or aggregated information where permitted by law.
10. Security
We use reasonable technical and organizational measures intended to protect information, including access controls, authentication, monitoring, and safeguards appropriate to the Service. No system is perfectly secure. Do not submit highly sensitive information through the Service unless the business operating the site has clearly designed and authorized that use.
11. Your rights and choices
Privacy rights vary by location. You may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Visitors to an Arlo-enabled business site should direct requests to that business first because it controls the visitor relationship and underlying site data. Account holders should use available account controls or contact the support channel associated with their account. We will respond as required by applicable law and consistent with our role.
12. Children
The Service is not directed to children, and you must not use it to knowingly collect personal information from children except where you have independently implemented all legally required notices, permissions, safeguards, and controls.
13. Data minimization and customer responsibilities
Businesses should configure Arlo to collect only information needed for the requested visitor experience. They must not instruct Arlo to request passwords, payment-card details, government identifiers, health information, or other sensitive information unless they have independently determined that collection and processing are lawful and appropriately secured. Businesses remain responsible for their own retention, notices, and deletion practices.
14. Changes
We may update this Policy as the Service or applicable requirements change. The effective date identifies the most recent version. Continued use after the effective date is subject to the updated Policy to the extent permitted by law.