Legal
Privacy Policy
Effective June 15, 2026 · Last updated July 7, 2026 · Version 1.0
This Privacy Policy explains how Storefront AI, Inc. ("Storefront AI," "we," "us," or "our") collects, uses, shares, and protects personal data in connection with our website at storefront-ai.com (the "Site") and our answer engine optimization product and related services (collectively, the "Service").
We built this policy to be honest about a narrow reality: we are a business-to-business product, we collect a limited amount of personal data, and we do not collect sensitive personal data or the personal data of our customers' own end-customers. The sections below describe exactly what we do.
1. Summary
Who we serve. Storefront AI is a B2B service. Our customers are businesses, and the people who use the Service are those businesses' personnel.
What we collect. Account and contact details of the people who use the Service, billing information processed through our payment provider, technical and usage data from our Site and Service, and the content you submit to or generate through the Service (such as prompts and outputs, and content crawled from public web pages you direct us to).
What we do not collect. We do not collect special categories of sensitive data (such as health, biometric, or precise geolocation data), payment card numbers (these go directly to our payment provider), or the personal data of your customers' end-customers. Our service agreements prohibit submission of protected health information, payment card data, government identification numbers, biometric data, and data of individuals under the age of 16.
AI processing. We use third-party large language model ("LLM") providers to process prompts and generate outputs. We do not use paying customers' content to train AI models. If you participate in a beta test or evaluation program, your beta agreement may grant us broader rights to use your data for model training and improvement; in that case, the beta agreement governs.
We do not sell your data and we do not "share" it for cross-context behavioral (targeted) advertising, as those terms are defined under California and other US state privacy laws.
Your rights. Depending on where you live, you have rights to access, correct, delete, and port your personal data, and to object to or restrict certain processing.
This summary is for convenience only and does not replace the full policy below.
2. Who we are and how to contact us
Our role. For the account, billing, usage, and communications data described in this policy, Storefront AI, Inc. is the controller. When we process Customer Content on behalf of a business customer, meaning the prompts, inputs, configurations, and outputs submitted to or generated by the Service and content crawled from public web pages at the customer's direction, we act as a processor (or "service provider" under US state privacy laws), and the customer's agreement with us, including any data processing agreement, governs that processing.
Storefront AI, Inc. is a Delaware corporation. Our role with respect to each category of personal data is described below.
You can reach us about privacy at:
- Email: privacy@storefront-ai.com
- Mailing address: 153 Woodland Dr, Huntington, WV 25705, USA
If you are in the European Economic Area ("EEA") or the United Kingdom ("UK"), you also have the right to lodge a complaint with your local data protection supervisory authority (see Section 11).
3. The personal data we collect
We collect the following categories of personal data. "Personal data" (also called "personal information") means information that identifies or can reasonably be linked to an identifiable individual. Note that information about an individual acting in a business capacity (for example, a work email address) is still personal data.
| Category | Examples | Source |
|---|---|---|
| Account and contact data | Name, work email address, company name, job title, username, and password (stored in hashed form) | You, when you sign up or contact us |
| Billing and transaction data | Billing name, billing contact, billing address, subscription plan, and transaction records. Full payment card numbers are collected and processed directly by our payment provider and are not stored by us. | You and our payment provider |
| Service content | Prompts, configurations, and other inputs you submit to the Service; outputs generated for you; and content we crawl from public web pages that you identify or direct us to (which may incidentally include personal data appearing on those pages) | You, and public web pages |
| Usage and technical data | IP address, device and browser type, pages viewed, referring URLs, timestamps, and similar log and analytics data | Automatically, when you use the Site or Service |
| Communications data | The content of messages you send us and our correspondence with you, including support and sales communications | You |
We do not intentionally collect special categories of sensitive personal data (such as data revealing racial or ethnic origin, health, religious beliefs, precise geolocation, or biometric data). Please do not submit sensitive personal data through the Service, as it is not required to use it. The applicable service agreement (such as our Beta Test License Agreement, Terms of Service, or Master Subscription Agreement) may define additional categories of prohibited data, including protected health information, payment card data, government-issued identification numbers, biometric data, and data of individuals under the age of 16.
4. How we use personal data and our legal bases
We use personal data for the purposes below. For individuals in the EEA and UK, the General Data Protection Regulation ("GDPR") requires us to have a legal basis for each use; those bases are noted in the right-hand column.
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide and operate the Service | Create and manage accounts, authenticate users, deliver Service functionality, and process the content you submit | Performance of a contract |
| Billing and payments | Process subscriptions, charge fees, prevent payment fraud, and maintain financial records | Performance of a contract; compliance with legal obligations |
| Operate and improve the Site and Service | Monitor performance and reliability, debug and secure our systems, and analyze usage to improve features, and, for beta program participants where authorized by their beta agreement, use submitted content to train and improve our machine learning models | Legitimate interests (running and improving our business) |
| Communicate with you | Send service and administrative messages, respond to support requests, and (where permitted) send marketing about our products | Legitimate interests; consent where required for marketing |
| Security and abuse prevention | Detect, investigate, and prevent fraud, abuse, and security incidents | Legitimate interests; compliance with legal obligations |
| Legal and compliance | Comply with applicable laws, respond to lawful requests, and enforce our agreements | Compliance with legal obligations; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded the processing is proportionate. You can object to such processing as described in Section 11. Where we rely on consent (for example, certain marketing or non-essential cookies), you can withdraw it at any time without affecting prior processing.
Providing your account and billing data is necessary to enter into and perform our agreement with you; if you do not provide it, we cannot make the Service available. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
5. How we use AI and large language models
The Service uses third-party large language model ("LLM") providers to process the prompts and inputs you submit and to generate outputs. Our current LLM providers are Anthropic, OpenAI, Google, and Perplexity. Which of these providers processes your content depends on your account configuration: the Service routes your prompts and inputs only to the provider or providers enabled for your account.
The content of your prompts and the resulting outputs is transmitted to these providers solely to deliver the Service to you.
For customers under our Terms of Service or Master Subscription Agreement, we do not use your prompts, inputs, outputs, or other Service content to train, fine-tune, or develop AI or machine learning models, whether our own or third parties'. For participants in our beta test or evaluation programs, the applicable beta agreement may grant us the right to use content submitted during the beta period for model training and improvement. In all cases, we do not permit our third-party LLM providers to use your content to train their models.
Our agreements with these providers do not permit them to use your content to train their models, and limit their retention of that content to what is needed to provide their service to us.
Because prompts and inputs are processed by these providers, please avoid submitting sensitive personal data or any information you are not authorized to share.
Our current third-party LLM providers are listed in Section 6 below. Your use of the Service constitutes acknowledgment that your inputs and outputs are processed by these providers in accordance with our agreements with them.
6. How we share personal data
We do not sell your personal data. We share personal data only as described here.
Service providers (sub-processors). We use trusted vendors to operate our business and Service. They may process personal data only on our instructions and for the purposes we specify. Our current key sub-processors are:
| Vendor | Purpose | What they process |
|---|---|---|
| Supabase | Database and backend hosting | Account, Service content, and usage data |
| Vercel | Application and website hosting | Usage and technical data; data in transit |
| PostHog (PostHog Cloud) | Product and website analytics | Usage and technical data |
| Stripe | Payment processing | Billing and transaction data, including payment card data submitted directly to Stripe |
| Notion | Customer relationship management | Account and contact data; communications |
| Anthropic; OpenAI; Google; Perplexity | AI inference (processing prompts and generating outputs) | Prompts, inputs, and outputs, as described in Section 5 |
Which LLM providers process a particular customer's Service content depends on that customer's configuration, as described in Section 5.
We may engage new or replacement sub-processors as our business evolves. When we do, we will update this policy, and where required by law or contract we will provide advance notice so you can review the change.
Legal, safety, and corporate transactions. We may disclose personal data when we reasonably believe it is necessary to comply with law or a lawful request, to enforce our agreements, to protect the rights, safety, or property of Storefront AI or others, or in connection with a merger, acquisition, financing, or sale of assets (in which case we will require the recipient to honor this policy or notify you of any material change).
We do not disclose personal data to third parties for their own independent marketing.
7. International data transfers
We are based in the United States, and our sub-processors may process data in the United States and other countries. If you are in the EEA or UK, transferring your personal data to the United States means it may be processed in a country that the European Commission or UK authorities have not deemed to provide an equivalent level of data protection.
Where we transfer EEA or UK personal data to the United States or other countries, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum). You may request more information about these safeguards using the contact details in Section 2.
8. Data retention
We retain personal data only as long as necessary for the purposes described in this policy, after which we delete or anonymize it. In general:
- Account and contact data: for the life of your account, and for a reasonable period afterward to handle wind-down, disputes, and legal obligations.
- Billing and transaction data: as required by tax, accounting, and other legal obligations (typically several years).
- Service content (including prompts and outputs): for as long as needed to provide the Service to you, and then deleted or anonymized in line with our retention practices.
- Usage and technical data: for a limited period for security, analytics, and reliability purposes.
- Beta program data: deleted within thirty (30) days of the end of the beta period, with residual copies in backup systems deleted within ninety (90) days, unless otherwise specified in the applicable beta agreement. Model improvements and trained parameters derived from beta data during the beta period may be retained.
Retention periods may vary where a longer period is required by law or to resolve disputes.
9. How we protect personal data
We maintain administrative, technical, and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls limiting access to authorized personnel, and use of reputable infrastructure providers. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to respond appropriately to any incident.
10. Cookies and similar technologies
We use cookies and similar technologies on the Site to operate it, keep it secure, remember your preferences, and understand how it is used. We distinguish between:
- Strictly necessary cookies, which are required for the Site and Service to function; and
- Analytics and preference cookies, which help us understand and improve usage.
Where required by law, we will obtain your consent before setting non-essential cookies and will honor recognized opt-out preference signals (such as Global Privacy Control) where applicable. You can also control cookies through your browser settings.
We do not currently use advertising or marketing cookies, and we do not use cookies to share personal data for cross-context behavioral advertising. If we adopt advertising services in the future, we will update this section, implement any required consent mechanism, and describe your right to opt out before we begin.
Some browsers offer a "Do Not Track" (DNT) signal. Because there is no common industry standard for interpreting DNT, we do not currently respond to DNT signals. We do honor recognized opt-out preference signals, such as Global Privacy Control, as described above.
11. Your privacy rights
Depending on where you live, you have some or all of the following rights regarding your personal data:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Delete your personal data.
- Port your personal data to another provider, where applicable.
- Object to or restrict certain processing, including processing based on legitimate interests.
- Withdraw consent where we rely on it, at any time.
- Opt out of the sale of personal data or "sharing" for targeted advertising. We do not sell or share personal data in this way, so there is nothing to opt out of, but you retain this right.
Non-discrimination: we will not deny you service, charge a different price, or provide a different quality of service because you exercised your privacy rights.
To exercise any of these rights, email privacy@storefront-ai.com. We will verify your request (for example, by confirming control of the relevant account or email address) and respond within the time required by applicable law. You may use an authorized agent where the law permits.
For EEA and UK residents (GDPR): the legal bases for our processing are set out in Section 4. You may lodge a complaint with your local data protection supervisory authority, though we encourage you to contact us first so we can try to resolve your concern.
For California residents (CCPA/CPRA) and residents of other US states with comprehensive privacy laws (including, among others, Colorado, Connecticut, Texas, and Virginia): the categories of personal data we collect, our purposes, and our sharing practices are described in Sections 3, 4, and 6. We do not sell personal data or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal data for purposes that would trigger a right to limit such use.
12. Children's privacy
The Service is intended for businesses and their personnel, and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
13. Third-party links and services
The Site and Service may link to or integrate with third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy practices.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the "Last updated" date above and, where required, provide additional notice (such as by email or an in-product notice). Your continued use of the Site or Service after an update means you accept the revised policy.
Your use of the Service is governed by the applicable service agreement between you and Storefront AI, which may include our Beta Test License Agreement, Terms of Service, or Master Subscription Agreement. In the event of a conflict between this Privacy Policy and the applicable service agreement, the service agreement (including any data processing agreement) will control with respect to the processing of Customer Content, and this Privacy Policy will control with respect to personal data for which we are the controller.
15. How to contact us
Questions, requests, or complaints about this policy or your personal data:
Storefront AI, Inc. Email: privacy@storefront-ai.com Mailing address: 153 Woodland Dr, Huntington, WV 25705, USA