Legal
Privacy Policy — Enterprise Sovereign Data
Last updated: September 19, 2026
1. The Sovereign Data Contract
Merchants using CSM Engine retain 100% ownership of their catalog, customer records, and transaction histories. Whether you self-host the open-core engine or use the managed CSM Cloud Gateway, your data lives in a database you control. There is zero vendor lock-in: export or migrate your entire store at any time.
2. Information Collected on This Website
We only collect information you voluntarily submit through our forms:
- Early Access Waitlist: name, work email, company/venture fund, applicant role, and preferred frontend builder.
- Pitch Deck Request: fund or angel name and investor email address.
We do not collect payment information, precise location data, or special category data.
3. Zero Advertising Trackers
This website runs no third-party advertising trackers and sells no telemetry to ad networks. We use no tracking cookies. The only client-side storage is a local backup of your own form submission, held in your browser's local storage and clearable at any time.
4. Model Context Protocol Data Safety
Prompts and tool outputs streamed through the MCP endpoint are authenticated with Bearer token authentication and scoped by role-based access control. Your prompts and commerce data are used solely to execute the operations you request. We do not use merchant prompts, customer records, or transaction data to train public foundation models.
5. How We Use Your Information
- To reserve your place on the early access waitlist and contact you about onboarding.
- To send qualified investor requests the confidential pitch summary and data room link.
- To send occasional product and funding updates. Opt out at any time by replying to any email.
6. Processors
Form submissions on this site are delivered through Web3Forms (a form-to-email delivery service), which processes your submission solely to deliver it to our inbox. We do not sell, rent, or share your personal information with other third parties for marketing purposes.
7. Security & Compliance
Submissions are transmitted over HTTPS. Our full security architecture — cryptographic cart tokens, HMAC webhook verification, encryption at rest for API secrets, RBAC, and immutable audit logging — is documented in the Security Whitepaper. Data minimization applies throughout: we retain personal data only as long as needed for the stated purpose or as required by law.
8. GDPR & CCPA — Your Rights
Depending on your jurisdiction (including the EU/EEA under GDPR and California under
CCPA/CPRA), you may have the right to access, correct, delete, or port the personal data we
hold about you, and to object to or restrict its processing. Merchants on the platform can
additionally anonymize customer records and run audit purge routines
(audit_purge_run)
against their own sovereign databases. To exercise your rights, email us — we respond within
30 days.
9. Contact
Questions about this policy or your data? Email [email protected].