Privacy Policy
Last updated: September 2, 2026
This is version 1 of our privacy policy, published so our legal pages have stable URLs. It is pending final owner and legal review; company entity details may be corrected in a future revision without changing the substance of our data practices.
Ziftr, Inc. ("Ziftr", "we", "us") provides Aimee, an AI Marketing & E-Commerce Engine, including the ziftr.ai website, the Aimee admin dashboard, APIs and SDKs, the Aimee assistant, and the Aimee MCP gateway (together, the "Services"). This policy explains what data we collect, how we use it, and the choices you have.
Data we collect
Account data
When you create an account we collect your name, email address, and authentication credentials. Authentication is managed through AWS Cognito; we never store plaintext passwords.
Merchant and store data
Merchants store business data on the platform: products, pricing, inventory, orders, customer records, store settings, and content. Merchants own this data; we process it to operate the Services on their behalf.
Payment data
Payments are processed by Stripe. Card numbers and full payment credentials are handled by Stripe and never stored on Ziftr systems. We retain payment metadata (amounts, status, last four digits) needed to display and reconcile transactions.
Communications
Transactional and notification emails are delivered through SendGrid. If you contact support we keep the correspondence.
Usage and log data
We collect standard technical logs (IP address, browser and device information, API request logs, timestamps) to operate, secure, and debug the Services.
AI assistant and MCP gateway
The Aimee assistant and the Aimee MCP gateway (mcp.ziftr.ai) let you and AI clients such as Claude interact with Aimee documentation and tooling. When you use these features:
- Your prompts, queries, and tool requests are processed to generate a response. Model inference is performed by Anthropic as a subprocessor under its commercial terms.
- The MCP gateway keeps an audit log of each tool call recording only the authenticated user identifier (Cognito subject), the tool name invoked, and a timestamp. Tool arguments and request content are not stored in audit logs.
- Gateway access is authenticated with OAuth 2.0; we do not sell or share assistant conversations for advertising purposes.
How we use data
- Provide, operate, and maintain the Services
- Authenticate users and secure accounts
- Process payments and prevent fraud or abuse
- Send transactional messages and respond to support requests
- Monitor, debug, and improve performance and reliability
- Comply with legal obligations
We do not sell personal data.
Sharing and subprocessors
We share data only with service providers that help us run the Services, under contracts that restrict their use of it:
- Amazon Web Services (AWS) -- cloud hosting, storage, and authentication (United States)
- Anthropic -- AI model inference for the assistant and MCP gateway
- Stripe -- payment processing
- SendGrid (Twilio) -- transactional email delivery
We may also disclose data where required by law or to protect the rights, safety, and security of Ziftr, our users, or others.
Data retention
We keep account and merchant data for as long as the account is active. When an account is closed, associated data is deleted or anonymized within a reasonable period, except where retention is required by law (for example, financial records). Technical logs and gateway audit logs are retained on a rolling basis and then deleted.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted, credentialed, and logged. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
International transfers
The Services are hosted in the United States. If you access them from elsewhere, your data is transferred to and processed in the United States.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise these rights, contact us at support@ziftr.com. If you are an end customer of a merchant using Aimee, contact that merchant first; we act as a processor of their store data.
Children
The Services are not directed to children under 16, and we do not knowingly collect personal data from them.
Changes to this policy
We may update this policy from time to time. We will post the revised version at this URL and update the "Last updated" date above. Material changes will be communicated to account holders.
Contact
Questions about this policy or our data practices: support@ziftr.com.