Last updated: 20 August 2026. This Privacy Policy is effective as of 20 August 2026.
This Privacy Policy describes EnvisaSoft Live Chat at https://chat.envisasoft.com. It is based on what the product stores today. It is not a claim that EnvisaSoft is certified under any privacy or security standard.
Author Elixir Inc. is a Canadian corporation offering a commercial live-chat service. Federal or provincial privacy law may apply to some of this processing. This policy describes what EnvisaSoft Live Chat stores and which product tools exist. It is not a PIPEDA compliance statement and does not list every right a statute might provide.
Author Elixir Inc. (“EnvisaSoft,” “we”) provides the Service. Principal address: Suite 239, Scotia Place Tower 3, 10072 Jasper Avenue, Edmonton, AB T5J 1V8, Canada.
Chat messages are used to operate live chat, not for advertising analytics.
Relationship between EnvisaSoft and the Customer
The Service stores (1) EnvisaSoft account data for people who register, and (2) visitor chat and Site configuration for websites the Customer connects.
A website operator decides to place chat on their pages. EnvisaSoft provides the hosting and software that stores and transmits that chat. This policy does not assign the statutory labels “controller,” “processor,” “business,” or “service provider” for every jurisdiction.
If you need a processing contract, contact Author Elixir Inc. A data processing agreement for Customer Chat Data applies while you use the Service.
A. EnvisaSoft account / customer data
Collected: name, email, hashed password, role (customer, agent, or administrator), whether the account is active, email verification time, optional encrypted TOTP secret and recovery codes, deletion-request time.
Why: create and authenticate the account, send verification and password-reset email, enforce roles, and process deletion requests.
Stored: MySQL production database (chat_env1_app) on the Hostinger / Enhance host in the United States (Boston region). Passwords are hashed. TOTP secrets are encrypted with the application key.
Who can access: the account holder (profile). EnvisaSoft administrators can access customer account tools. Password hashes and TOTP secrets are not shown in website exports or the visitor widget.
Retention / deletion: Customer “Delete account” deactivates the login, invalidates sessions, purges owned conversations and visitors, and deactivates owned Sites. The customer user row remains. Agent accounts may be fully deleted from that flow. Administrators cannot delete themselves from Profile.
Export: Account fields are not included in the per-Site JSON export.
B. Website / Site configuration data
Collected: Site name, website URL, allowed origins, active flag, greeting, widget title/position/color, retention days, an email-notifications flag, owner, and creator. Public Site ID (ULID).
Why: load the widget only for allowed origins, show appearance, apply retention, and identify the Site.
Stored: sites table. The email-notifications flag is stored in the dashboard. The application does not currently send new-conversation email.
Who can access: Site owner, assigned agents, and EnvisaSoft administrators (all Sites).
Retention / deletion: Deactivate stops the widget. There is no customer control that removes the Site row. Account deletion deactivates owned Sites after chat data is purged.
Export: ulid, name, URL, active flag, retention days.
C. Visitor data
Collected if the visitor uses chat: optional name and email (if typed in the widget), user agent, IP address, hashed visitor session token, last-seen time. Columns named browser/device/os exist in the database but are not filled by the current session service.
Browser storage: the widget stores the plaintext session token, optional name/email, and conversation ULID in localStorage under a key prefixed livechat:{siteUlid}:. The widget does not set EnvisaSoft cookies on the Customer’s domain.
Why: keep the same visitor conversation after refresh, show name/email to operators, and operate rate limits and security.
Stored: visitors table. Token is hashed at rest.
Who can access: operators with access to that Site (Inbox shows name, email, user agent — not IP in the agent API resource). IP is stored and appears on security-event and login-session screens for signed-in EnvisaSoft users. Administrators see security events.
Retention / deletion: orphan visitors (no remaining conversations) can be pruned with Site retention. Deleting one conversation does not always delete the visitor. Account deletion deletes visitors on owned Sites.
Export: visitor ulid, name, email — not IP, not token hash, not user agent.
D. Conversations and messages
Collected: conversation status, page URL and title, unread flag, timestamps; message sender type, body, client message id.
Why: deliver live chat. Laravel Reverb (first-party software on the same host) may send the same message body and visitor name/email to authorized Inbox or widget subscribers over private channels. If WSS is unavailable, messages still send over HTTPS.
Who can access: operators with access to the Site; the visitor who holds the matching session token.
Retention / deletion: daily job deletes closed conversations older than the Site retention (30, 90, 180, or 365 days, after a grace window). Open conversations are not deleted by that job. Indefinite keeps closed threads until manual delete. Customers can delete a conversation with confirmation. Account deletion purges owned conversations.
Export: included (ulids, status, page URL/title, bodies, timestamps). Numeric database IDs, passwords, and visitor token_hash are omitted.
E. Technical, session, and security data
EnvisaSoft dashboard sessions (people signed in at chat.envisasoft.com): HTTP-only session cookie; session rows in the database include user id, IP address, and user agent. Production uses secure cookies.
CSRF tokens are used on EnvisaSoft forms.
Rate limits apply to chat APIs, registration, password reset, two-factor, and WordPress OAuth.
Why: keep you signed in, prevent abuse, and operate the Service.
F. WordPress OAuth / connection data
When a WordPress administrator uses Connect EnvisaSoft, EnvisaSoft may store: WordPress origin, admin callback URL, hashed connection token, connected/revoked times, PKCE challenge, hashed authorization code, and connection events.
WordPress itself stores Site ID, widget URL, appearance, and a connection token in WordPress options. EnvisaSoft passwords are not stored in WordPress. The plugin contains no EnvisaSoft client secret.
Disconnect revokes the EnvisaSoft token when present and clears local WordPress options. It does not delete the EnvisaSoft Site or conversations. Customer account deletion does not automatically revoke WordPress connection rows.
Export: not included in the Site JSON export.
Astro sites load the same widget using a Site ID you configure; they do not use this OAuth table.
G. Security / audit data
Collected: action, result, IP, user agent, user/site ULIDs, limited metadata (the auditor strips secret fields). Laravel and Reverb/Supervisor logs may exist on disk.
Who can access: EnvisaSoft administrators at /security-events.
Retention: not pruned by the chat retention job; not removed on customer account deletion.
Export: not in the customer Site export.
H. Backups
Operational MySQL dumps of the production database are kept on the application host. They can include hashes, IPs, and message bodies. In-app delete/export does not erase backups. A leftover SQLite file may exist on disk; it is not the live database.
A public backup-retention number and an off-server backup vendor are not published here. Internal backup practice is described in operations documentation, not as a customer contract.
Cookies, localStorage, and similar technologies
| Technology | Where | What |
|---|---|---|
| Session cookie | chat.envisasoft.com |
Signed-in EnvisaSoft users |
| CSRF / remember-me (Laravel) | chat.envisasoft.com |
Form security; optional remember-me if used |
localStorage |
Visitor’s browser on the Customer website | Visitor token, optional name/email, conversation ULID |
The visitor widget does not set EnvisaSoft cookies on the Customer domain.
EnvisaSoft HTML pages request a webfont from Bunny Fonts (fonts.bunny.net). That request is made by browsers that load EnvisaSoft pages, not by widget.js on Customer websites.
Why we use information (summary)
- Provide accounts, Inbox, widget, WordPress Connect, and email verification / password reset.
- Isolate Customers so they do not open another account’s Sites.
- Secure the Service (rate limits, audit events, two-factor for administrators).
- Apply the retention, export, and deletion tools in the product.
We do not sell chat contents for advertising. We do not use a product analytics SDK in this application.
Who we share with
Infrastructure used to host and operate the Service includes Hostinger / Enhance (United States, Boston region), Let’s Encrypt, Bunny Fonts for EnvisaSoft HTML pages, and Stripe for billing when you subscribe. EnvisaSoft administrators can access Sites for operations. We may disclose information if required by law. Unless legally prohibited, we will try to notify the affected Customer of a compelled disclosure of their Customer Chat Data.
International processing
Author Elixir Inc. is based in Edmonton, Alberta, Canada. The production application, database, and web stack run on Hostinger / Enhance hosting in the United States (Boston region). EnvisaSoft account data and visitor chat data for the production Service are stored and processed on that United States host. Mail is handed to sendmail on that host and to mail.chat.envisasoft.com on the same hosting platform. Let’s Encrypt issues TLS certificates. Bunny Fonts serves fonts to people who load EnvisaSoft HTML pages.
This policy discloses those locations. It does not describe a specific international-transfer contract tool (for example standard contractual clauses) and does not claim that any particular privacy statute is satisfied.
Security measures
Security controls include HTTPS, WSS when available, password hashing, tenant isolation, PKCE for WordPress Connect, administrator MFA, rate limiting, security headers, and hashed visitor tokens. These reduce risk; they are not a promise that incidents cannot occur.
Data exports and deletion
Site owners can export website data (JSON) and delete conversations or deactivate a Site. Site export includes visitor ulid, name, and email when stored — not IP, token hash, or user agent. Deleting one conversation may leave the visitor row if other conversations remain. Account deletion behaves as described in section A. Backups and audit logs are not wiped by those actions.
Privacy inquiries and data requests
Email info@envisasoft.com or write to Author Elixir Inc., Suite 239, Scotia Place Tower 3, 10072 Jasper Avenue, Edmonton, AB T5J 1V8, Canada (or the address on Contact).
If you are a visitor who chatted on a Customer website, start with that website operator. They can export Site JSON or delete a conversation for that Site. If they cannot finish the request in the dashboard, email info@envisasoft.com and Author Elixir Inc. can help using the same product tools. Site export includes visitor name and email when stored, not IP, user agent, or session secrets. Operational backups are not erased by in-app deletion.
This policy does not promise a statutory response deadline or a named list of access/erasure rights under a specific law. If applicable law requires Author Elixir Inc. to respond within a time that statute defines, that duty is not waived by the absence of a deadline here.
Children’s privacy
The Service is designed for website operators. EnvisaSoft does not knowingly create customer accounts for anyone under 18. Visitor chat on a Customer website is collected because that Customer embedded the widget; that website’s operator is responsible for that site. The Service is not directed at children.
Changes
We may update this policy by posting a new version here with a new “last updated” date. Posting on this URL is the official notice. We may also mention material changes by email to the account address. Continued use after the posted date means you accept the updated policy, except where applicable law requires a different method.
Contact
Author Elixir Inc.
Suite 239, Scotia Place Tower 3
10072 Jasper Avenue
Edmonton, AB T5J 1V8
Canada