Privacy Policy
Effective July 23, 2026
1. Scope and roles
This policy covers Arlo’s website, dashboard, and embedded website assistant. When a business installs Arlo on its website, that business controls the site and its relationship with its visitors. Arlo processes information on the business’s behalf to provide the Service. The business is responsible for providing any visitor notices and obtaining any permissions or consents required for its use of Arlo.
2. Information we process
We may process the following categories of information:
- Account information: authentication and profile details supplied through the sign-in provider, and business/workspace information configured in the dashboard.
- Service configuration: site domains, business context, goals, approved website flows, agent settings, and embed identifiers.
- Visitor interaction information: conversations with Arlo, pages and page context, session identifiers, interaction events, and outcome or goal events generated while using an Arlo-enabled website.
- Technical information: browser, device, and network information typically required to render the widget, secure requests, troubleshoot, and measure service performance.
3. How we use information
We use information to operate the embedded assistant; provide dashboard analytics and site configuration; respond to visitor requests; detect friction and configured goals; secure, debug, and support the Service; and comply with applicable legal obligations. We do not use visitor conversations to build unrelated advertising profiles.
4. AI and service providers
To produce an AI response, relevant conversation, configured business context, and permitted page or task context may be sent to the model providers configured for the Service. Arlo also uses hosted infrastructure and authentication/database providers to operate the Service. Those providers process information under their applicable terms and service arrangements.
5. Disclosure
We may disclose information to the business that operates the Arlo-enabled site, service providers that help us run the Service, and authorities or other parties when required by law or necessary to protect rights, safety, and the Service. We do not sell personal information.
6. Retention
We retain information for as long as reasonably needed to provide the Service, maintain security and records, resolve disputes, and meet legal obligations. Retention can also depend on the business customer’s configuration and account status. We do not promise a fixed retention period in the product today.
7. Security
We use reasonable technical and organizational measures intended to protect information. No internet-based system is perfectly secure, so please do not provide highly sensitive information unless the business operating the site has explicitly designed its Arlo flow to receive it safely.
8. Your choices and requests
If you are a visitor to an Arlo-enabled business website, contact that business first for access, correction, deletion, or opt-out requests because it controls the site relationship. If you are an Arlo account holder, contact your account administrator or the Arlo business contact through which you received access. We will handle requests consistent with applicable law and our role in the processing.
9. Changes to this policy
We may update this policy as the Service changes. The effective date above identifies the most recent version.