CSM Engine Logo CSM Engine ← Back to Site

Legal

Privacy Policy — Enterprise Sovereign Data

Last updated: September 19, 2026

1. The Sovereign Data Contract

Merchants using CSM Engine retain 100% ownership of their catalog, customer records, and transaction histories. Whether you self-host the open-core engine or use the managed CSM Cloud Gateway, your data lives in a database you control. There is zero vendor lock-in: export or migrate your entire store at any time.

2. Information Collected on This Website

We only collect information you voluntarily submit through our forms:

  • Early Access Waitlist: name, work email, company/venture fund, applicant role, and preferred frontend builder.
  • Pitch Deck Request: fund or angel name and investor email address.

We do not collect payment information, precise location data, or special category data.

3. Zero Advertising Trackers

This website runs no third-party advertising trackers and sells no telemetry to ad networks. We use no tracking cookies. The only client-side storage is a local backup of your own form submission, held in your browser's local storage and clearable at any time.

4. Model Context Protocol Data Safety

Prompts and tool outputs streamed through the MCP endpoint are authenticated with Bearer token authentication and scoped by role-based access control. Your prompts and commerce data are used solely to execute the operations you request. We do not use merchant prompts, customer records, or transaction data to train public foundation models.

5. How We Use Your Information

  • To reserve your place on the early access waitlist and contact you about onboarding.
  • To send qualified investor requests the confidential pitch summary and data room link.
  • To send occasional product and funding updates. Opt out at any time by replying to any email.

6. Processors

Form submissions on this site are delivered through Web3Forms (a form-to-email delivery service), which processes your submission solely to deliver it to our inbox. We do not sell, rent, or share your personal information with other third parties for marketing purposes.

7. Security & Compliance

Submissions are transmitted over HTTPS. Our full security architecture — cryptographic cart tokens, HMAC webhook verification, encryption at rest for API secrets, RBAC, and immutable audit logging — is documented in the Security Whitepaper. Data minimization applies throughout: we retain personal data only as long as needed for the stated purpose or as required by law.

8. GDPR & CCPA — Your Rights

Depending on your jurisdiction (including the EU/EEA under GDPR and California under CCPA/CPRA), you may have the right to access, correct, delete, or port the personal data we hold about you, and to object to or restrict its processing. Merchants on the platform can additionally anonymize customer records and run audit purge routines (audit_purge_run) against their own sovereign databases. To exercise your rights, email us — we respond within 30 days.

9. Contact

Questions about this policy or your data? Email [email protected].