Privacy Policy
Effective date: 2026-08-19 · Last updated 2026-08-19 · Version 1.1
Contents
- 1. About This Policy
- 2. Our Two Roles: Controller and Processor
- 3. Information We Collect as a Controller
- 4. Store and Connected Account Data We Process for Merchants
- 5. Why We Process Data, and Our Legal Bases
- 6. Artificial Intelligence Processing
- 7. Outbound Messaging and Merchant Responsibility
- 8. Sharing and Subprocessors
- 9. Retention and Deletion
- 10. Security
- 11. International Data Transfers
- 12. Privacy Rights
- 13. Children
- 14. Changes to This Policy
- 15. How to Contact Us
1. About This Policy
Maison Forge, Inc. (“Maison Forge,” “we,” “us”) provides an AI-powered brand operations platform for merchants. The platform consists of specialized AI agents (the “Specialists”) that produce marketing content, plan and orchestrate campaigns, monitor trends and performance, and, where a merchant enables it, publish and send content through the merchant’s own third-party accounts.
This policy explains what data the platform touches, why we touch it, how long we keep it, who else sees it, and what rights individuals have. It applies to our website, our applications (including any application we list in a third-party app store), and the services we provide to merchants under our Subscription Services Agreement.
Who this policy is for. This policy is written primarily for the merchants who subscribe to Maison Forge and the individual users they invite. It also explains, in Section 12, how we handle personal information belonging to a merchant’s own customers, and where those individuals should direct their requests.
Terms used here. Capitalized terms not defined in this policy have the meaning given in the Subscription Services Agreement. “Personal information” and “personal data” are used interchangeably and mean information relating to an identified or identifiable individual.
2. Our Two Roles: Controller and Processor
Maison Forge handles data in two distinct capacities, and the rules differ for each. Reading the rest of this policy is much easier if you keep the distinction in mind.
- As a controller, we decide why and how data is used. This applies to merchant account information, billing records, support communications, product usage and security logs, and website visitor data. Sections 3, 5, and 9 through 12 govern this data.
- As a processor (a “service provider” under U.S. state privacy laws), we act only on the documented instructions of the merchant. This applies to everything we read from, generate for, or send through a merchant’s Connected Accounts, including any personal information about that merchant’s own customers. The merchant is the controller of that data and is responsible for having a lawful basis to collect it and to authorize our processing. Section 4 governs this data.
Where a merchant requires a data processing agreement, our Data Processing Addendum, available on request, governs our processor obligations and prevails over this policy in the event of a conflict.
3. Information We Collect as a Controller
3.1 Account and user information
When a merchant creates an account and invites users, we collect the name, business email address, and role of each user, together with a salted hash of any password (we never store passwords in plaintext). Where a user signs in through a third-party identity provider or an app store account, we receive the identifiers that provider returns to us rather than a password.
When a subscriber accepts the Subscription Services Agreement, we also record the brand or company name, the subscriber’s name and email address, an optional website, the terms version accepted, the time of acceptance, and the IP address the acceptance came from. This record exists to prove the agreement and to provision the account.
3.2 Connection credentials
When a merchant connects a store or service, we store the resulting access tokens or credentials and the public identifier of the connected property (for example a store’s myshopify.com hostname). Credentials are encrypted at rest using AES-256-GCM with keys held in Cloudflare’s encrypted secret store, and are decrypted only in memory at the moment a Specialist calls the relevant platform on the merchant’s behalf.
3.3 Billing information
Subscription payments are processed by our payment processor, Square. The card form on our checkout is Square’s own: card details go directly to Square, and we do not receive or store full payment card numbers. We receive and store the billing contact, billing address, plan, transaction history, the identifiers Square returns to us, and the last four digits and brand of the payment card.
3.4 Usage, device, and log information
We automatically record information about how the platform is used, including IP address, browser and device type, pages and features accessed, timestamps, actions taken by users and by Specialists, approval and publication events, API calls made to Connected Accounts, and error and diagnostic data. We use this information to operate and secure the service, to investigate incidents, to maintain an audit trail of what the Specialists did on a merchant’s behalf, and to improve the product.
3.5 Support and business communications
If a user contacts us for support, or corresponds with us about onboarding, sales, or an account matter, we retain that correspondence and any information contained in it.
3.6 Website visitors and cookies
We use PostHog for web analytics on our marketing website and the tenant dashboard, to understand page views, sessions, and aggregate usage. Our analytics run without cookies. PostHog is configured to keep its state in memory for the duration of a single page view only: it sets no analytics cookies, writes nothing to local or session storage, and places no persistent identifier on your device. A consequence we accept deliberately is that a returning visitor is counted as a new one. Because nothing is stored on or read from your device for analytics, no cookie consent banner is required, and there is nothing for you to opt out of storing.
The PostHog library is served from our own domain rather than a third-party content network, so no external script loads when you visit; only the analytics events themselves are sent, to PostHog’s United States cloud. Visitors to the marketing website remain anonymous — we never associate that browsing with a person. Within the authenticated dashboard, where you have already signed in, analytics events are associated with your user account so we can understand how the product is used. There are no advertising, retargeting, or cross-context behavioral tracking technologies on either surface, and we do not sell or share this data — see Section 12.2.
Within the authenticated application we use only cookies necessary to keep users signed in and to secure sessions. Those are strictly necessary and cannot be switched off without breaking sign-in.
3.7 Information we do not seek
We do not ask merchants to provide, and the platform is not designed to receive, special categories of personal data (such as health, biometric, precise geolocation, or government identifier data), payment card numbers, or information about children. Merchants should not upload such information to the platform.
4. Store and Connected Account Data We Process for Merchants
With a merchant’s authorization, the Specialists access the merchant’s Connected Accounts. Depending on the subscription tier and which Specialists the merchant enables, this can include commerce platforms such as Shopify, email and messaging platforms, and social and advertising accounts.
4.1 What we read
- Catalog and content data: products, variants, pricing, descriptions, images, collections, blog and page content, and site metadata.
- Commercial data: order and transaction records, line items, discounts, refunds, fulfillment status, and traffic and conversion metrics.
- Audience and engagement data: where a merchant enables a messaging or social Specialist, subscriber lists, segments, contact records, campaign and automation history, engagement events such as opens, clicks, and unsubscribes, and public social account metrics and comments.
- Brand materials: voice guidelines, prior campaigns, style references, and other materials a merchant supplies during onboarding.
4.2 What we do with it
We use Connected Account data solely to provide the service to the merchant that owns it: to produce analytics, content plans, and seasonal and inventory insights; to draft, schedule, and, where authorized, publish or send content; to segment audiences and personalize messages at the merchant’s direction; and to report on performance. We do not use one merchant’s data to serve another merchant, and we do not use it to train models for the benefit of any other customer.
4.3 Data minimization commitments
Our design intent is to hold as little end-customer personal information as the enabled functionality requires.
- Analytics and insight Specialists: where these Specialists read a merchant’s order history to compute trends, we request a limited set of fields from the store — order identifier, line items, order total, and order date. We do not request customer names, email addresses, or postal addresses on this path, so that information never reaches us in the first place. Where a Specialist displays live store activity in the dashboard, the response is reduced to a non-identifying summary and is not stored. The insights we retain are aggregates and do not identify individual customers.
- Diagnostic retention of AI requests: to debug and improve the platform, we record each AI request our systems make, including its full content, and retain that record for 7 days, after which an automated sweep deletes it. This record is internal: it is used for technical diagnostics and is not used to build profiles, is not shared with any other merchant, and is not sent to any third party beyond the model providers named in Section 8 who received the request in the first place. Where merchant or end-customer information forms part of a request, it is held for that 7-day window rather than discarded immediately, and we describe it here rather than claim otherwise.
- Messaging and outreach Specialists: our outbound Specialists today operate on business contact records — prospects a merchant is trying to reach — not on the merchant’s own end-customer lists. Where a merchant uses them, we store the business contact details, qualification notes, and campaign engagement history needed to run and report on that outreach in the merchant’s isolated database, and we pass the contacts to the sending platform the merchant has connected. We do not currently maintain a store of any merchant’s end-customer contact lists; where personalized customer messaging is operated through a merchant’s own connected platform, that platform remains the system of record.
- Tenant isolation: Connected Account data is stored in an encrypted, tenant-isolated environment dedicated to the merchant’s brand, consistent with the data sovereignty commitments in our Subscription Services Agreement.
5. Why We Process Data, and Our Legal Bases
For individuals in the European Economic Area, the United Kingdom, and Switzerland, the table below sets out the legal bases on which we rely as a controller. Where we act as a processor, the merchant determines the legal basis.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the platform and the Specialists to the merchant | Account, connection credentials, usage, Connected Account data | Performance of a contract |
| Authenticating users and securing accounts | Account, credential, device and log data | Performance of a contract; legitimate interests in securing the service |
| Billing, collections, and tax records | Billing and transaction data | Performance of a contract; legal obligation |
| Support, onboarding, and account communications | Account and correspondence data | Performance of a contract; legitimate interests |
| Detecting abuse, fraud, and security incidents | Usage, device, and log data | Legitimate interests in protecting the service and its users |
| Improving and troubleshooting the platform | Usage and diagnostic data, aggregated or pseudonymized where practicable | Legitimate interests in improving the service |
| Marketing our own services to business contacts | Business contact details | Legitimate interests; consent where required by local law |
| Complying with law and enforcing our agreements | Any of the above as relevant | Legal obligation; establishment or defense of legal claims |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by the rights of the individuals concerned. Where we rely on consent, it may be withdrawn at any time without affecting processing already carried out.
6. Artificial Intelligence Processing
The Specialists are built on large language models and related AI services, some of which are operated by third-party providers listed in Section 8. Content and data are sent to those providers only as needed to generate output for the merchant who owns the data.
- No training on your data. We do not use merchant data, Connected Account data, or Output to train, fine-tune, or otherwise improve models for the benefit of any other customer. Our AI providers’ terms prohibit them from using data submitted through our accounts to train their models. We do not, however, claim that our model providers discard every request on receipt: providers may retain requests for their own abuse monitoring and operational purposes under their published terms, and we have not contracted for zero-retention processing with them.
- Minimization before submission. We minimize the personal information that reaches a model provider. Where the platform can produce the same result without sending identifiable customer information, it is designed not to send it — primarily by not requesting those fields from a merchant’s store in the first place, so that they never enter the system. We keep this under review and continue to narrow what is sent as the platform develops.
- Human review. Our personnel may access merchant data where necessary to provide support, investigate an incident, or debug a defect. Access is limited to personnel who need it, is subject to confidentiality obligations, and is logged.
- No automated decisions with legal effect. The platform produces marketing content and recommendations. It does not make automated decisions that produce legal or similarly significant effects concerning individuals, and does not evaluate individuals for credit, employment, housing, insurance, or comparable purposes.
7. Outbound Messaging and Merchant Responsibility
Where a merchant enables Specialists that send email or messages, or that publish to social accounts, the merchant remains the sender of record and the controller of the underlying audience. The merchant is responsible for obtaining and maintaining any consent required to contact its recipients and for compliance with applicable marketing laws, including the CAN-SPAM Act, the Telephone Consumer Protection Act, Canada’s Anti-Spam Legislation, and the EU e-Privacy rules, as applicable.
We process suppression and unsubscribe signals as part of delivering the service and will not knowingly send to an address a merchant has suppressed. We do not use a merchant’s audience for our own marketing.
8. Sharing and Subprocessors
We do not sell data. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not disclose merchant data to any other merchant.
We disclose data only in the following circumstances:
- Subprocessors. Vendors that power the platform, acting on our documented instructions under written contracts that impose confidentiality and security obligations at least as protective as those in this policy.
- Connected Accounts. Content and data we transmit to a merchant’s own third-party platforms at the merchant’s direction. Those platforms handle the data under their own terms and privacy policies.
- Professional advisors. Auditors, accountants, insurers, and lawyers under duties of confidentiality.
- Legal and safety. Where we are legally compelled, or where disclosure is necessary to investigate suspected fraud, protect our rights, or protect the safety of any person. Where we receive a request for a merchant’s data, we will notify the merchant and direct the requester to the merchant unless we are legally prohibited from doing so.
- Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer honoring commitments materially equivalent to those in this policy. We will give merchants notice before their data becomes subject to a different privacy policy.
8.1 Current subprocessors
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Cloudflare | Application hosting, storage, databases, and content delivery; also AI conversion of uploaded brand documents and headless-browser reads of a brand’s own website | United States, with delivery through Cloudflare’s global network |
| Anthropic | AI content generation and analysis | United States |
| OpenAI | AI image generation | United States |
| AI image generation, and web font delivery to visitors’ browsers | United States | |
| Square | Subscription billing, and payment-form delivery to buyers’ browsers | United States |
| Resend | Transactional email delivery | United States |
| PostHog | Web analytics for the marketing site and tenant dashboard | United States |
| Apify | Social-media snapshot: retrieving a brand’s own published Instagram posts during onboarding | United States |
| Linear | Engineering issue tracking for automated service-failure reports | United States |
We will notify merchants by email at least 30 days before adding a subprocessor that processes personal data, during which a merchant may object on reasonable data protection grounds.
9. Retention and Deletion
We keep data only as long as needed for the purposes described in this policy, or as required by law.
| Category | Retention | Notes |
|---|---|---|
| Connection credentials | Deleted when the merchant disconnects the store or service, or on account termination | Deletion also revokes the token with the connected platform where that platform supports revocation |
| Connected Account data and generated Output | For the term of the subscription; deleted within 30 days of termination unless the merchant requests export first | Export in standard formats is available on request within 30 days of termination, per the Subscription Services Agreement |
| Aggregate insights | For the term of the subscription; deleted with the account | Do not identify individual end customers |
| Account and user records | For the term plus 12 months | Retained to support reactivation and dispute resolution |
| Billing and tax records | 7 years | Required for tax and accounting purposes |
| Security and audit logs | 12 months | Retained for incident investigation |
| Support correspondence | 24 months | |
| Backups | Deleted on the backup rotation schedule, currently 14 days | Deleted records persist in backups until the rotation completes, then are overwritten |
9.1 Merchant-initiated deletion
A merchant may disconnect any store or service at any time from the dashboard, which deletes the stored credentials for that connection. A merchant may request deletion of its account and associated data by contacting us as described in Section 15. We will complete verified deletion requests within 30 days, subject to the backup rotation described above and to records we are required to retain by law.
9.2 App store erasure obligations
Where we distribute an application through a third-party app store, we honor that store’s mandatory data erasure and data request notifications. For our Shopify application specifically:
- shop/redact. On receipt, we delete the merchant’s stored credentials, Connected Account data, and generated Output associated with that shop, retaining only the records described in the table above.
- customers/redact. On receipt, we log the request and confirm completion: because analytics processing is transient and stored insights are aggregates, there is no identifiable customer data retained for the shop to erase.
- customers/data_request. On receipt, we return any data we hold about the identified customer to the merchant so the merchant can respond to its customer, or confirm that we hold none.
We log every such notification and our response to it.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect data against unauthorized access, alteration, disclosure, and destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher and encryption at rest using AES-256.
- Tenant isolation, so that each merchant’s data is segregated from every other merchant’s data.
- Role-based access control, least-privilege provisioning, and mandatory multi-factor authentication for personnel with access to production systems.
- Audit logging of administrative and Specialist actions.
- Secrets management through Cloudflare’s encrypted secret store, with secrets accessible only to the running service.
- Confidentiality agreements for personnel with access to merchant data, together with security awareness training completed on joining and renewed annually by everyone with access to production systems or merchant data.
- Vulnerability management and dependency scanning.
- A documented incident response plan, covering containment, evidence preservation, severity assessment, merchant notification, and a written post-incident review, reviewed quarterly and after any significant incident.
No system is perfectly secure. Merchants are responsible for safeguarding their own account credentials and for promptly removing users who no longer require access.
10.1 Incident notification
If we become aware of a personal data breach affecting merchant data, we will notify the affected merchant without undue delay and in any event within 72 hours of becoming aware, describe what we know, and cooperate reasonably with the merchant’s own notification obligations. Where we act as a processor, notification to regulators and to affected individuals is the merchant’s responsibility as controller.
11. International Data Transfers
We are established in the United States and our infrastructure and subprocessors are located in the United States, with content delivered through Cloudflare’s global network. If a merchant or an individual is located outside the United States, data will be transferred to and processed in the United States and in any other country where our subprocessors operate.
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we apply supplementary measures including encryption in transit and at rest. We are not currently certified under the EU-U.S. Data Privacy Framework or its UK and Swiss extensions, and we do not rely on the Framework as a transfer mechanism; we may seek certification in the future and will update this policy if we do. Our Data Processing Addendum incorporates these clauses for merchants who require them.
12. Privacy Rights
12.1 If you are a merchant or a platform user
Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion, a portable copy, restriction of or objection to certain processing, and withdrawal of consent where we rely on it. To exercise these rights, contact us as described in Section 15. We will verify your identity before responding, will respond within the period required by applicable law (generally 30 days, extendable where permitted), and will not discriminate against you for exercising a right.
If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
12.2 If you are a resident of a U.S. state with a privacy law
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have rights to know, access, correct, delete, and obtain a portable copy of their personal information, to opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, and certain profiling, and to appeal a denial of a request.
Maison Forge does not sell personal information and does not share personal information for cross-context behavioral advertising, and has not done so in the preceding twelve months. We do not knowingly process the personal information of anyone under 16. Where we act as a service provider to a merchant, we process personal information only for the business purposes specified in our agreement with that merchant and are prohibited from retaining, using, or disclosing it for any other purpose.
The categories of personal information we collect as a controller, and the purposes for which we use them, are described in Sections 3 and 5. We disclose these categories to the subprocessors listed in Section 8 for business purposes.
You may designate an authorized agent to submit a request on your behalf; we will require proof of the agent’s authority.
12.3 If you are a customer of a merchant that uses Maison Forge
We process your personal information only on behalf of the merchant you did business with, and that merchant, not Maison Forge, controls it. Please direct requests to access, correct, or delete your information to that merchant. If you contact us directly, we will forward your request to the relevant merchant where we can identify them, and we will assist the merchant in responding, but we cannot act on your request without the merchant’s instruction.
13. Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have collected such information other than on a merchant’s instruction, we will delete it. Merchants are responsible for ensuring that audiences they process through the platform do not include individuals from whom parental consent would be required.
14. Changes to This Policy
We may update this policy as the platform evolves. We will revise the “Last Updated” date at the top and, where a change is material, notify merchants by email or through the dashboard at least 30 days before it takes effect. Continued use of the platform after a change takes effect constitutes acceptance of the updated policy. Prior versions are available on request.
15. How to Contact Us
Privacy questions, requests, and complaints:
| Contact | Details | Notes |
|---|---|---|
| Privacy inquiries | info@maisonforge.ai | Monitored mailbox, not an individual |
| Postal address | Maison Forge, Inc., 302 Bedford Ave # 89, Brooklyn, NY 11249 | |
| Merchant support | Your account representative or the support channel in your dashboard | For account and product questions |
| EU representative | Not appointed | We do not currently offer services to individuals in the EEA |
| UK representative | Not appointed | We do not currently offer services to individuals in the UK |
| Data protection officer | Not appointed | Not required of us under GDPR Article 37 on our current processing |
Maison Forge, Inc., a Delaware corporation, is the controller of the personal information described in Section 3.