Legal

Privacy Policy

Effective date: July 27, 2026 · Contact: privacy@storepilothq.com

This template reflects how StorePilot is designed to handle data. Have it reviewed by counsel before relying on it with paying customers, and fill in the bracketed details.

This Privacy Policy explains how Zipf LLC ("Zipf," "we," "us"), operator of StorePilot (the "Service"), collects, uses, and protects information. By using the Service you agree to this Policy.

1. Our two roles

For information about you, our customer (account and billing data), we act as a data controller. For the store data we access on your behalf through your connected marketplace accounts, we act as a data processor, processing it only on your instructions under our Terms and Data Processing Agreement.

2. Information we collect

3. How we use information

4. Legal bases (EEA/UK)

Where GDPR applies, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve it), consent (where required), and legal obligations.

5. Sharing & sub-processors

We share data only with vetted sub-processors under data-processing agreements — including Anthropic (the Claude model that powers the agent), our cloud host, and our encrypted secrets provider. A current list is on our Security page. We may disclose information if required by law.

6. Data retention

We retain account data for as long as your account is active and as needed for legal and operational purposes. Operational store data is retained only as needed to provide the Service; buyer PII is not retained at rest. When you disconnect a store or close your account, we revoke access and delete or anonymize associated data within a commercially reasonable period.

7. Security

We encrypt data in transit and at rest, store credentials in an encrypted vault, apply least-privilege access, and gate every write behind your approval. See our Security page.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. Under the CCPA/CPRA, California residents may request access and deletion and may opt out of "sale" or "sharing" of personal information — we do not sell or share personal information as those terms are defined. To exercise any right, email privacy@storepilothq.com. For data we process on a customer's behalf, we will refer requests to that customer (the controller) and assist them.

9. International transfers

We operate in the United States. Where data is transferred internationally, we use appropriate safeguards such as Standard Contractual Clauses.

10. Children

The Service is for businesses and is not directed to children under 16.

11. Changes

We may update this Policy; we will post the new effective date and, for material changes, notify you.

12. Contact

Zipf LLC, 344 Maple Ave W, PMB 221, Vienna, VA 22180 — privacy@storepilothq.com.