Legal

Privacy policy

How Shopcue handles business contacts, accounts, public research evidence, Agent Memory, optional generation, and privacy requests.

Effective version: 2026-07-30· Service operator: Shopcue

1. Scope

This policy applies to Shopcue's website, private-beta request forms, authenticated Workspaces, research Agents, public-content research, optional media generation, support, and legal requests. Shopcue is a business SaaS product and is not directed to consumers or children.

2. Information Shopcue collects

  • Business contact and qualification data such as name, work email, company, role, website, company type, product and weekly-video bands, current tools, research job, and request context.
  • Account, authentication, Workspace membership, invitation, role, consent-version, security, and access records.
  • Public Shopify product-page data supplied through a URL, including product title, description, brand, category, public price, images, variants, product when public, and source URL.
  • User-confirmed Product Fingerprints and Research Lenses, including approved facts, forbidden claims, target problems, outcomes, use cases, audiences, keywords, exclusions, markets, platforms, and cadence.
  • Normalized public TikTok, Instagram Reels, and YouTube Shorts evidence when a provider is configured, including canonical URLs, public creator identifiers, captions or transcript-derived fields, publication and observation times, public metrics, Pattern membership, and score inputs.
  • Agent runs, provider coverage and failures, user saves, rejections, creator tracking, competitor product seeds, evidence-linked questions and frozen cited answers, explicitly requested Ask actions, Creator Briefs, Recreate prompts and versions, QA outcomes, generation lineage, and append-only Memory events.

3. Information the MVP does not require

Shopcue's creative research MVP does not require Shopify Admin access, TikTok Shop orders, ad-account data, customer email, postal address, phone number, payment credentials, private creator contact details, or manual CSV uploads. Customers must not submit those fields in public forms, product URLs, Research Lenses, support messages, or generation prompts.

4. How information is used

Shopcue uses information to qualify private-beta requests, authenticate users, maintain tenant boundaries, parse public product pages, schedule public research, normalize and score evidence, answer supported Agent questions with frozen source citations, preserve Agent Memory, prepare explicitly requested briefs or original drafts, enforce capacity, support customers, prevent abuse, meet legal obligations, and test whether the product solves the stated workflow.

5. Data minimization and provider boundary

Provider credentials and provider operation identifiers stay server-side. Shopcue stores normalized fields required by the product rather than retaining raw public-content provider payloads. Public source content remains controlled by its platform and rights holder; Shopcue stores source links and analysis evidence rather than claiming ownership of the underlying asset. Evidence Ask stores the user's question, visible answer, frozen citations, evidence cutoff, and any user-triggered safe-action lineage; it does not require private creator contact details or hidden reasoning. Optional generated media may be retained with its prompt, model, cost, QA, rights status, and source lineage.

6. Service providers

Shopcue may use Supabase for database and authentication, Vercel for application hosting and request execution, and Mailgun for operational email when configured. Public-content research may use Scrape Creators or a disclosed replacement adapter. Optional video generation may use Google Gemini/Veo. A provider is used only when configured; its availability, terms, geographic processing, and retention practices are governed by its own commitments.

7. Legal bases and customer responsibility

Depending on the context, processing is based on providing the requested service, steps requested before a contract, consent, legitimate business and security interests, or legal obligations. Customers are responsible for having the right to submit product media, claims, prompts, competitor URLs, and other inputs, and for reviewing outputs before commercial use.

8. Retention

Shopcue retains account and Workspace data while needed to operate the service and preserves research Agent evidence, Evidence Ask exchanges, action lineage, and Memory so research remains useful and auditable over time. A failed run or disconnected provider does not rewrite historical evidence. Shopcue does not currently promise an automatic fixed retention period for normalized Agent data. Users may archive Agents, disconnect providers, export their Agent evidence, or request deletion. Minimized consent, security, suppression, dispute, and legal evidence may remain when necessary.

9. Security

Shopcue uses Workspace-level database access controls, service-role-only ingestion, server-side secrets, limited public-data contracts, request validation, safe public-URL fetching, expiring or hash-only access tokens where applicable, and no-store boundaries for authenticated pages. See the current Security & data handling pagefor factual controls and limitations.

10. Choices and rights

People may request access, correction, deletion, restriction, or objection where applicable, unsubscribe from commercial outreach, and ask Shopcue to disconnect an integration. Some records may be retained for security, suppression, disputes, or legal obligations. Use the data deletion process for a verified request.

11. International processing, changes, and contact

Shopcue and its providers may process information in the United States and other locations where they operate. Material policy changes use a new effective version and apply prospectively. Questions may be submitted through the contact page or the legal request channel.