Privacy Policy
Last updated: August 14, 2026
HyperLyft, LLC, doing business as ShopperClaw (“ShopperClaw,” “we,” “us”), operates shopperclaw.ai and related APIs (the “Service”). This Privacy Policy explains what personal data we collect, why, and what rights you have over it. It covers two kinds of people the Service touches: advertisers who create accounts to run campaigns, and end users of AI agents whose preferences and activity pass through the Service when their agent fetches or converts an ad. If you're an agent developer, you're also responsible for giving the end users of your agent appropriate notice about how their data flows through ShopperClaw — this policy describes our side of that, not yours.
1. Data we collect
From advertisers
- Account data: name, email address, and (if you use API-key auth) a hashed API key. We do not store your plaintext API key after it's issued — only a SHA-256 hash.
- Billing data: we do not store full card numbers. Your card is held by Stripe, our payment processor; we store your Stripe customer ID, a reference to your default payment method, and billing history.
- Campaign and offer data: everything you submit to create a campaign or offer (pricing, targeting, destination/booking URLs, descriptions).
- Masumi / Cardano data (optional): if you connect a Cardano wallet via Masumi, we store your decentralized identifier (DID), public key, and wallet address. We never have access to your private keys.
From end users of AI agents
Most people who benefit from ShopperClaw never create a ShopperClaw account directly — their AI agent talks to our API on their behalf. Depending on how the agent authenticates, we may receive:
- Consumer-agent (DID) sessions: preferences supplied inline by the agent for that request, and (for approval-gated flows) a consumer agent identifier. We do not require this end user's email in this flow.
- Legacy agent-key sessions: an email and name (used only to send an approval email when a human needs to approve an offer before the agent acts on it), and stored travel preferences.
- Activity data: which offers were shown to an agent (an “impression”), the match score behind that decision, and what happened next (viewed / clicked / booking initiated / purchased / declined) — a “conversion.”
Automatically, from anyone who visits shopperclaw.ai or the advertiser dashboard
- Session cookies: an advertiser-login cookie and admin auth cookies. These keep you signed in — we don't use them for cross-site tracking or ad targeting of our own.
- Error and performance monitoring via Sentry, including a masked session replay (all text is masked and all media is blocked before it leaves your browser) used only to debug issues, not to read your actual input.
- Aggregate analytics via Vercel Web Analytics and Speed Insights, not tied to your identity beyond what's needed to compute aggregate stats.
2. How we use data
- To match relevant offers to agent queries (we generate vector embeddings of preferences and offers via OpenAI to compute semantic similarity).
- To operate advertiser billing (creating Stripe customers/subscriptions, metering ad spend, sending invoices).
- To detect and prevent fraud, abuse, and prompt-injection attempts in submitted offer content.
- To send transactional email (approval requests, payment-failure notices, campaign-paused notices) via Resend.
- To operate our admin tools, restricted to a small allowlist of ShopperClaw team email addresses.
- To debug and improve the Service (error monitoring, aggregate analytics).
We do not use advertiser or end-user data to build user profiles for sale, and we do not sell personal data to third parties.
3. Who we share data with
We share data with the following categories of service providers, each processing data only to provide their service to us:
| Provider | What they receive | Purpose |
|---|---|---|
| Stripe | Advertiser name, email, payment method, billing amounts | Payment processing, invoicing |
| OpenAI | Text of preferences and offer descriptions | Generating embeddings for ad matching |
| Supabase | All data described in §1 | Database hosting |
| Vercel | Request metadata, aggregate analytics | Application hosting, performance monitoring |
| Sentry | Error stack traces, masked session replay | Error monitoring / debugging |
| Resend | Recipient email, message content | Transactional email delivery |
| Masumi | DID, public key, wallet address (advertisers who opt in) | Cardano-based identity/wallet features |
We may also disclose data if required by law, to enforce these policies or our Terms of Service, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required by law).
4. Data retention
We retain personal data only as long as necessary for the purposes described in this policy: advertiser account and billing records for 7 years after account closure, to satisfy tax and financial recordkeeping obligations; impression and conversion records for 3 years; and end-user preference data for 2 years from last use, after which it is deleted or anonymized. We may retain data longer where required by law or to resolve an active dispute.
5. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export the personal data we hold about you, or to object to or restrict certain processing. To exercise these rights, contact us at privacy@shopperclaw.ai. We'll verify your request and respond within 30 days.
If your data reached us because an AI agent queried ShopperClaw on your behalf, the fastest path to correcting or deleting your preferences is usually through that agent or its operator — but you can also contact us directly.
Advertisers can update or delete campaign/account data through the advertiser dashboard, or by contacting support@shopperclaw.ai.
If you're in the European Economic Area, UK, or Switzerland (GDPR)
Legal basis for processing. We process personal data under the following legal bases:
- Contract: advertiser account and billing data, to provide the Service you signed up for.
- Legitimate interests: ad matching/scoring, fraud and prompt-injection detection, error monitoring, and aggregate analytics — balanced against your rights; you can object to processing based on this ground.
- Consent: where you opt in to something specific, e.g. connecting a Masumi/Cardano wallet.
- Legal obligation: tax and financial record-keeping tied to billing.
Your GDPR rights include the right to: access a copy of your data; rectify inaccurate data; erase your data (“right to be forgotten”), subject to exceptions (e.g. billing records we're legally required to retain); restrict processing; receive your data in a portable format; object to processing based on legitimate interests or for direct marketing; and withdraw consent at any time where processing is based on consent, without affecting processing that occurred before withdrawal.
Automated decision-making. ShopperClaw's core matching function automatically scores and ranks advertiser offers against a user's preferences (semantic similarity, price proximity, recency, and advertiser reputation) without human review of each match. We don't believe this produces a legal or similarly significant effect on you — it decides which ad you see, not whether you can access a service, credit, or employment — but we're disclosing it for transparency. You can request more information about the logic involved by contacting us.
International transfers. Our infrastructure providers (Stripe, OpenAI, Supabase, Vercel, Sentry, Resend) process data in the United States. We rely on Standard Contractual Clauses approved by the European Commission, or an equivalent lawful transfer mechanism, with providers who process personal data outside the EEA/UK.
Supervisory authority. You have the right to lodge a complaint with your local data protection supervisory authority — for example, the Information Commissioner's Office (ICO) for UK users — in addition to contacting us directly.
We do not currently maintain an establishment in the EEA or UK and do not currently designate a representative under Art. 27 GDPR / UK GDPR. If our processing of EEA/UK residents' data reaches a scale that requires one, we will designate a representative and update this policy.
If you're a California resident (CCPA/CPRA)
Categories of personal information we collect, mapped to CCPA's categories: identifiers (name, email, IP address); commercial information (campaign, offer, and billing history); internet/network activity (impressions, conversions, session/cookie data); professional/business information (advertiser company details); and inferences (match scores, reputation signals). We do not knowingly collect sensitive personal information (e.g. government ID numbers, precise geolocation, health data) — payment card details are collected and stored by Stripe directly, not by us.
Sources. Directly from you (account/campaign forms), automatically (cookies, error/analytics tooling), and from AI agents making requests on behalf of their end users.
Disclosures to third parties. As described in §3 above, we disclose data to service providers for a business purpose. We do not sell personal information for money, and we do not believe our advertiser-matching function constitutes “sharing” for cross-context behavioral advertising — but we offer the opt-out below regardless, out of caution.
Your CCPA/CPRA rights include: the right to know what personal information we've collected, used, disclosed, and (if applicable) sold/shared about you; the right to delete it, subject to exceptions (e.g. completing a transaction, legal compliance, security); the right to correct inaccurate personal information; the right to opt out of sale/sharing; the right to limit use of sensitive personal information; the right to non-discrimination for exercising these rights; and the right to appeal a denied request.
How to exercise these rights, or opt out of sale/sharing. Email privacy@shopperclaw.ai with the subject line “CCPA Request” — we'll honor opt-out requests within 15 business days. You may designate an authorized agent to submit a request on your behalf; we may require proof of the agent's authorization and verification of your identity. We will not discriminate against you for exercising any of these rights.
Some CCPA/CPRA obligations (e.g. annual metrics reporting) apply only to businesses meeting certain revenue or data-volume thresholds. We'll comply with any such requirement as and when it applies to us.
6. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@shopperclaw.ai and we'll delete it.
7. Security
We use industry-standard measures to protect data in transit and at rest (including hashed API keys, HMAC-signed session tokens, and encrypted connections), but no system is 100% secure. If you believe your account or data has been compromised, contact support@shopperclaw.ai immediately.
8. International data transfers
Our infrastructure (Vercel, Supabase, and our other providers) may process and store data in the United States and other countries. See the GDPR subsection above for EEA/UK/Swiss-specific transfer mechanism details.
9. Changes to this policy
We'll update the “Last updated” date above when this policy changes, and post material changes prominently. Continued use of the Service after changes take effect constitutes acceptance.
10. Contact us
Questions or requests about this policy: privacy@shopperclaw.ai
HyperLyft, LLC, d/b/a ShopperClaw — a Delaware limited liability company. Business information available on request.