Legal
Privacy Policy
Mastiff Defense is operated by CapyBearHug LLC, a Wyoming limited liability company. This Privacy Policy explains how we collect, use, and protect information when you use the Mastiff Defense Shopify app and related services at mastiffdefense.com.
Mastiff is the name of our Shopify app, powered by the Mastiff Defense compliance engine. Both are products of CapyBearHug LLC and are governed by this Privacy Policy.
By installing or using Mastiff Defense, you agree to the practices described in this policy.
01 Information We Collect
When you install Mastiff Defense on your Shopify store, we collect:
- Your Shopify store domain and OAuth access token (required to communicate with Shopify's API)
- Your selected subscription plan and billing status
- The date your store was installed and any uninstall date
- API keys generated for your store (stored as SHA-256 hashes; the raw key is shown once and never stored)
When your chatbot sends requests through our compliance pipeline, we collect:
- The text of each request and response, processed in real time only. Message text is not written to our audit logs; only the compliance decision is logged
- Risk scores, compliance decisions, and a generalized reason for each request (the audit log stores this decision metadata, never the message content)
- IP addresses, used in two ways: recorded for failed authentication attempts (security logging), and processed in hashed form on successful requests as a per-source vote signal that helps us tune our compliance keyword rules. We do not store the raw IP as part of the policy-tuning signal; it is reduced to a one-way hash used only to prevent a single visitor from skewing a suggestion
- Timestamps of each request
We do not store conversation history between sessions. Each request is stateless by design. This is a deliberate GDPR-friendly architectural decision.
02 How We Use Your Information
We use collected information solely to:
- Provide the Mastiff Defense compliance screening service
- Authenticate API requests and resolve tenant policies
- Generate audit logs for your store's compliance activity
- Process billing and manage your subscription via Shopify
- Send transactional emails (installation confirmation, subscription changes)
- Monitor service health and diagnose technical issues
We do not use your data for advertising, marketing profiling, or any purpose beyond operating the service.
03 Cookies & Analytics
Mastiff Defense uses one strictly necessary cookie for merchant sessions, and, with your consent, Google Analytics on our public website pages. We do not use advertising cookies, and no analytics cookies are set unless you accept them.
- mastiff_store: an httpOnly, HMAC-signed session cookie set after a merchant authenticates through Shopify. It keeps a store owner signed in to the merchant settings and billing pages for up to 7 days. It is not readable by JavaScript, is not shared with any third party, and is not used for tracking
- Google Analytics (_ga, _ga_*): set by Google Analytics 4 on our public website pages (the marketing, documentation, and informational pages on mastiffdefense.com, including this one), and only after you choose Accept on our cookie banner. These cookies distinguish visitors and measure aggregate usage such as pages visited, referral source, approximate region, and device type. We use this only to understand how our website is used. Google Analytics 4 does not log or store visitor IP addresses. Google processes this data under Google's privacy policy. You can decline the banner, use the Google Analytics opt-out browser add-on, or block analytics cookies in your browser. Your Accept or Decline choice is stored in your browser's local storage, never leaves your device, and can be reset by clearing this site's data
Google Analytics runs only on those public website pages, and only if you have accepted. It is not present in the chat widget, on the merchant store settings page, or anywhere in the compliance pipeline. Chatbot messages, customer conversations, and merchant store data are never sent to Google.
The public chat widget your customers see does not set cookies of its own for identification or tracking.
Our informational pages, including this one, store a single theme preference (light or dark) in your browser's local storage. That value never leaves your device, is not a cookie, and is not sent to our servers.
04 Data Storage
Your data is stored in the following systems:
- PostgreSQL database on Amazon RDS (AWS us-west-1, North California)
- Audit logs stored in Amazon S3 (AWS us-west-1, server-side encrypted)
- All data is stored within the United States
AWS infrastructure is SOC 2 certified and encrypted at rest and in transit.
05 Data Sharing
We do not sell, rent, or share your data with third parties except with the service providers (subprocessors) we rely on to run the service:
- Shopify: required to process billing and validate app installation
- Anthropic: to generate chatbot replies and run semantic compliance evaluation, we send Anthropic's Claude API the customer's message content. When the bot answers a question that requires store data (for example, an order lookup or a product search), the order and catalog data our tools retrieve to build that reply is also sent to Claude as part of the request. Under Anthropic's commercial API terms, inputs sent through the API are not used to train Anthropic's models and are subject to limited retention. Anthropic's privacy policy applies to this processing
- Amazon Web Services: infrastructure provider for our database and audit log storage
- Cloudflare: our edge network and TLS provider. Traffic to mastiffdefense.com, including customer chat messages, transits Cloudflare in transit, where the encrypted connection is terminated before being re-encrypted to our servers. Cloudflare processes this data only to deliver and secure the connection
- Postmark: our transactional email processor. At installation, Postmark receives your store domain, the store owner's email address, and the one-time installation email containing your raw API key. Postmark retains sent message content for a limited period under its own retention policy
- Google (Google Analytics): receives usage data from visits to our public website pages, as described in the Cookies & Analytics section. Google does not receive chatbot message content, customer conversations, merchant store data, or anything from the compliance pipeline
- ntfy.sh: our operational alerting channel. We send it short push notifications for service health and for incoming Shopify data requests. These payloads are scrubbed of personal data: they carry the store domain, a one-way hashed prefix of any customer email, and record counts, never raw customer message content or a readable email address
- Legal requirements: if required by law, court order, or to protect our legal rights
We maintain a current list of the subprocessors we use and keep this policy in step with it. If we add or replace a subprocessor that materially handles personal data, we will notify installed merchants (by email where possible) and give a reasonable opportunity to object before the change takes effect for their store.
06 Our Role & Legal Basis
Our role under data protection law depends on whose data is being processed.
- End-customer chat data (processor): for the messages your storefront customers send and the store data used to answer them, the merchant is the data controller and CapyBearHug LLC acts as a processor on the merchant's behalf. We process this data only to provide the compliance screening and chatbot service under our agreement with the merchant, and only on the merchant's documented instructions
- Merchant account and billing data (controller): for the store owner's account details, subscription and billing status, contact email, and security logs, CapyBearHug LLC is the data controller
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract: to provide the service the merchant signed up for, including installation, screening, billing, and support
- Legitimate interests: to keep the service secure, prevent fraud and abuse, log authentication failures, and improve our compliance rules, balanced against the rights of the individuals concerned
- Legal obligation: to meet obligations such as responding to lawful data requests and honoring erasure webhooks
For end-customer data we process as a processor, the legal basis for the underlying collection is the merchant's responsibility as controller.
07 Shopify Merchant & Customer Data
Mastiff Defense processes customer messages that pass through your chatbot. These messages may contain personal information entered by your customers.
We handle this data as follows:
- Messages are processed in real time for compliance screening
- Each screening decision (status, risk score, generalized reason) is logged to your store's audit log; the message content itself is not stored in the log
- No customer personal data is stored beyond what appears in the audit log
- Conversation history is never stored server-side; it is stateless
In accordance with Shopify's Partner requirements, we respond to the following mandatory webhooks:
- App uninstall: deactivates your store and revokes all API keys
- Shop data erasure: permanently deletes all store data within 48 hours of request
- Customer data erasure: each request is acknowledged and durably recorded. Audit logs contain compliance decision metadata only — not customer message content — so no per-customer data is held in them to erase. Store-level data is deleted via the shop data erasure process above
- Customer data request: each request is durably recorded and reviewed, and we respond within the 30-day window. Because message processing is stateless and logs are metadata-only, there is typically no stored customer data to return
08 Automated Compliance Screening
Mastiff Defense works by automatically screening the messages that pass through a merchant's chatbot. For each message our pipeline makes an automated decision to allow it, block it, or redact sensitive content before a reply is generated. This screening runs in real time and combines keyword rules, tenant policy rules, and an AI intent evaluation.
This automated processing filters chatbot messages to protect the merchant's business information and to prevent misuse of the assistant. It does not make legal decisions or decisions that produce legal or similarly significant effects about any individual. It does not profile customers, set prices, approve or deny transactions, or determine access to any product, service, or benefit. If a message is blocked, the customer simply receives a safe fallback reply and can rephrase or contact the store's human support.
09 Your Rights
The rights available, and how they are exercised, depend on whether you are a merchant or a storefront customer.
Merchants. As the account holder, you may exercise the following rights directly with us regarding the data we control about your store:
- Access: request a copy of the data we hold about your store
- Correction: request correction of inaccurate data
- Deletion: request deletion of your store's data
- Portability: request your data in a machine-readable format
- Objection and restriction: object to, or ask us to restrict, certain types of processing
Storefront customers. When you chat with a store that uses Mastiff Defense, that merchant is the controller of your data and we act as their processor. Please direct data-subject requests (access, correction, deletion, and the rest) to the merchant you interacted with. We assist merchants in fulfilling these requests, including through Shopify's customer data-request and erasure webhooks. Because chat processing is stateless and our logs hold decision metadata only (never message content), there is typically no stored customer data for us to return or erase.
Everyone also has:
- The right to withdraw consent, where our processing relies on consent, without affecting processing already carried out
- The right to lodge a complaint with your local data protection or supervisory authority
To exercise a right, or to reach us as a processor on a merchant's behalf, contact [email protected]. We will respond within 30 days.
10 International Data Transfers
CapyBearHug LLC is based in the United States, and our infrastructure and data storage are located in the United States (AWS, North California). If you access the service from outside the United States, your data will be transferred to and processed in the United States.
Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as the transfer mechanism, together with appropriate safeguards. Our subprocessors, including Anthropic, Amazon Web Services, and Cloudflare, are likewise bound by Standard Contractual Clauses or their own data processing agreements covering these transfers. A copy of the relevant safeguards is available on request at [email protected].
11 California Privacy Rights
This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
In the past 12 months, depending on how you use the service, we may collect the following categories of personal information:
- Identifiers: such as a store domain, store owner email address, and API keys (stored hashed)
- Internet or other network activity: such as IP addresses (for security logging and, in hashed form, as a rule-tuning signal), request timestamps, and compliance decision metadata
- Inferences: such as the risk scores and generalized compliance reasons our screening produces
We collect this information to provide, secure, bill for, and improve the service, as described in this policy. Any personal information contained in a customer's chat message is processed transiently and is not written to our logs.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
Subject to verification and legal limits, California residents have the right to:
- Know what personal information we collect and how we use it
- Delete personal information we hold about you
- Correct inaccurate personal information
- Opt out of any sale or sharing (we do neither, so there is nothing to opt out of)
We will not discriminate against you for exercising any of these rights. To make a request, contact [email protected]. Storefront customers of a merchant should direct requests to that merchant, who is the business responsible for their data; we will assist as a service provider.
12 Data Retention
We keep personal data only as long as we need it for the purpose it was collected, then delete or aggregate it.
- Store and subscription data is retained while the app is installed. After uninstall, store data is deleted when Shopify sends its shop data erasure webhook (approximately 48 hours after uninstall). This erasure now also removes that store's audit logs, rather than leaving them to age out on the retention schedule below
- Audit logs contain compliance decision metadata only (no message text). We apply automated redaction to remove personal data from the decision rationale we store, though this reduction is best-effort rather than absolute. We retain these logs for up to 12 months for security, operational, and audit purposes, after which they are deleted or reduced to non-identifying aggregate statistics. We may retain a specific log entry longer only where needed to investigate a security incident, resolve a dispute, or meet a legal or contractual obligation, and only for as long as that need lasts
- Security logs of failed authentication attempts follow the same 12-month schedule
- API keys (hashed) are revoked immediately on uninstall
- You can request earlier deletion of your store's data at any time by contacting [email protected]; we respond within 30 days
13 Security
We take security seriously:
- All API keys are stored as SHA-256 hashes; raw keys are never stored in our systems. The one exception in transit: the raw key is delivered once in the installation email, which is processed by Postmark (see Data Sharing)
- All data in transit is encrypted via TLS
- All data at rest is encrypted via AWS SSE-S3
- Shopify webhook signatures are verified via HMAC before processing
- Admin access is protected by multi-user basic authentication
- Rate limiting is applied to public API endpoints and health checks
If you discover a security vulnerability, please report it to [email protected].
14 Breach Notification
If we become aware of a personal data breach affecting data we process, we will notify the affected merchants without undue delay after becoming aware of it, consistent with our obligations as a processor under GDPR Article 33 and applicable law. Our notice will describe, to the extent known, the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking to address it and to mitigate harm.
Where CapyBearHug LLC is the controller of the affected data, we will also notify the relevant supervisory authority and affected individuals where required by law. Merchants remain responsible, as controllers of their customers' data, for any onward notification to their customers or authorities.
15 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will notify installed stores via email where possible.
Continued use of Mastiff Defense after changes constitutes acceptance of the updated policy.
16 Contact Us
For privacy questions, data requests, or concerns:
CapyBearHug LLC
Operating as Mastiff Defense
Wyoming, USA
[email protected]
We aim to respond to all privacy inquiries within 30 days.