Trust & Privacy Center

This page is maintained by VOKYBE to answer common security, privacy, and data handling questions about the VOKYBE AI Concierge.

Service Context & Shared Responsibility

The VOKYBE AI Concierge runs on top of Lovable platform services and modern infrastructure. While our database, server functions, and AI integrations benefit from the robust, isolation-gated hosting practices of our platform provider, these platform descriptions are for informational transparency and do not represent a legal certification or independent audit of the custom application logic itself. Privacy is a shared responsibility between platform security foundations and VOKYBE's operational practices.

Anonymous Visitor Data Handling

When you initiate a session with the VOKYBE AI Concierge, we prioritize your privacy by minimizing data collection and keeping you anonymous until you explicitly request a service quote or human handover:

  • LocalStorage Session Keys: We generate a secure, random session token stored locally in your browser (`vokybe.leadToken`). This allows you to close the chat, return later from the same device, and resume your exact thread. No personal accounts or credentials are required.
  • Private AI Broker: All messages are brokered securely via server-side endpoints. Anonymous visitors are blocked from querying the database directly. Every chat action is validated through an intermediary API token verification loop to protect transaction histories.
  • Lead Quantification: If you input qualifying details (such as your name, travel dates, or rental needs), these are securely associated with your unique session token. They are only promoted to the VOKYBE operations team when the conversation meets qualification thresholds for a formal quote or handover.

Access Control & Authentication

Our application enforces a strict separation between public guest interactions and administrative operations:

  • Staff Authorization: Back-office dashboards, lead managers, quote generators, and service configurations are completely hidden behind password-based staff authentication and verified row-level role gates.
  • Row-Level Security (RLS): Our database employs Row-Level Security policies that prevent unauthenticated users and anonymous visitors from executing direct reads, updates, or deletes on underlying data tables.
  • Secure Public Endpoints: Anonymous actions are completely restricted to isolated public REST endpoints that only permit the addition of messages to your specific thread ID, and only when validated with your unique browser token.

Cookies, Tracking & Analytics

VOKYBE believes in transparent, privacy-first web visits:

  • No Invasive Ad Tracking: We do not deploy third-party advertising trackers, cross-site pixel tracking, or behavior behavioral retargeting campaigns.
  • Functional Session Storage: Our only tracking is functional session local storage key-value pairs designed to keep your ongoing chat conversation continuous and prevent you from losing your quotes.

Subprocessors & Integrations

To provide multilingual capabilities and handover pathways, we route data through select, secure integrations:

  • AI Gateway & Language Models: Client chats are processed using modern, privacy-compliant language models to interpret questions and draft quotes. Your messages are sent strictly to interpret context and are not used to train public foundational models.
  • WhatsApp Handover Integrations: If you opt-in to WhatsApp communication, conversation summaries are structured and formatted to launch outbound WhatsApp dialogs or prepare WhatsApp Meta Cloud templates to notify VOKYBE operators.

Retention, Deletion & Privacy Requests

You retain ultimate ownership of your communication history:

  • Data Retention Limits: Conversations that remain inactive without being promoted to qualified leads or formal quotes are eventually purged in accordance with our system cleanup parameters.
  • Privacy Rights: If you wish to delete your browser-stored thread or clear your chat records on our system, clearing your browser's local storage will remove your association key. For full database-side deletions, you can reach out directly.
  • Incident Reporting: If you suspect any vulnerability, have security queries, or would like to request file/data deletion, you can reach our team at security@vokybe.com.

Have questions about an upcoming tour or rental in Taolagnaro?