Legal

Privacy Policy

Effective August 16, 2026

This Privacy Policy explains how Arlo handles personal information in connection with its website, dashboard, embedded assistant, analytics, and related services. It does not replace the privacy notice of a business that installs Arlo on its own website.

1. Our role

When a business installs Arlo on its website, that business generally determines why and how visitor information is collected and used. In that setting, Arlo processes information to provide the Service on the business’s behalf. The business remains responsible for its website, its visitor-facing notices, its instructions to Arlo, and any consent or other legal basis required for its use. Arlo acts independently for information about its own website visitors, account holders, and business contacts.

2. Information we process

Depending on how the Service is used, we may process:

3. Sources

We receive information directly from account holders and website visitors; automatically from browsers, devices, and Service logs; from the business that configured Arlo; and from service providers that support authentication, billing, hosting, security, analytics, or model functionality.

4. How we use information

We use information to provide, maintain, secure, troubleshoot, and support the Service; authenticate users; configure and display the embedded assistant; respond to visitor requests; detect configured friction and goal signals; create dashboard analytics; process payments; prevent fraud, misuse, and security incidents; comply with law; enforce our Terms; and improve the Service. We do not sell personal information or use visitor conversations to build unrelated advertising profiles.

5. AI processing

To generate a response or perform a configured task, relevant conversation content, permitted website context, and business configuration may be transmitted to model providers and infrastructure providers that help operate the Service. AI outputs can be inaccurate or incomplete. Businesses should not configure Arlo to request or process sensitive information unless they have independently established an appropriate lawful basis, safeguards, notices, and controls.

6. Cookies and similar technologies

The Service may use cookies, local storage, session identifiers, pixels, logs, or similar technologies to keep a session working, remember settings, prevent abuse, measure performance, and associate visitor events within a site. A business that installs Arlo is responsible for the cookie banner, consent mechanism, and visitor disclosures required for its website and jurisdiction.

7. Disclosure

We may disclose information to the business operating the Arlo-enabled website; to service providers that host, secure, authenticate, process payments for, or otherwise operate the Service; to professional advisers; in connection with a corporate transaction; and to authorities or other parties when we reasonably believe disclosure is required by law, legal process, or to protect rights, safety, security, and the Service. We do not sell personal information for money or cross-context behavioral advertising.

8. International transfers

Information may be processed in countries other than the country in which it was collected. Those countries may have different data-protection laws. Where required, we use appropriate transfer mechanisms or safeguards for transfers of personal information.

9. Retention

We retain information only for as long as reasonably necessary to provide the Service, meet the purposes described here, maintain security and records, resolve disputes, enforce agreements, and comply with legal obligations. Retention can depend on the customer’s configuration, account status, the nature of the information, and applicable law. We may retain de-identified or aggregated information where permitted by law.

10. Security

We use reasonable technical and organizational measures intended to protect information, including access controls, authentication, monitoring, and safeguards appropriate to the Service. No system is perfectly secure. Do not submit highly sensitive information through the Service unless the business operating the site has clearly designed and authorized that use.

11. Your rights and choices

Privacy rights vary by location. You may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Visitors to an Arlo-enabled business site should direct requests to that business first because it controls the visitor relationship and underlying site data. Account holders should use available account controls or contact the support channel associated with their account. We will respond as required by applicable law and consistent with our role.

12. Children

The Service is not directed to children, and you must not use it to knowingly collect personal information from children except where you have independently implemented all legally required notices, permissions, safeguards, and controls.

13. Data minimization and customer responsibilities

Businesses should configure Arlo to collect only information needed for the requested visitor experience. They must not instruct Arlo to request passwords, payment-card details, government identifiers, health information, or other sensitive information unless they have independently determined that collection and processing are lawful and appropriately secured. Businesses remain responsible for their own retention, notices, and deletion practices.

14. Changes

We may update this Policy as the Service or applicable requirements change. The effective date identifies the most recent version. Continued use after the effective date is subject to the updated Policy to the extent permitted by law.