Last Updated: January 16, 2026
Your Data, Protected. Your Privacy, Respected.
All data hosted in secure US-based servers with enterprise-grade encryption and compliance standards.
All data hosted in secure US-based servers with enterprise-grade encryption and compliance standards.
All data hosted in secure US-based servers with enterprise-grade encryption and compliance standards.
All data hosted in secure US-based servers with enterprise-grade encryption and compliance standards.
Your information stays yours. We never sell, or monetize your personal data.
PRIVACY POLICY
Effective Date: 11/7/2025
Last Updated: 7/21/2026
Agentative, LLC
Agentative, LLC ("Agentative," "we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, store, and protect information in connection with our website, applications, and services (collectively, the "Services"). This policy is designed to meet applicable privacy laws and the transparency expectations of partner platforms, including TikTok Shop, Amazon, and Shopify.
INFORMATION WE COLLECT
We collect information only as necessary to provide and operate the Services.
a. Information You Provide Directly
Account registration information (such as name and email address)
Contact information
Authentication credentials and authorization tokens
Communications, support requests, and feedback
b. Service Usage and Operational Data
Interaction history with the Services
Logs, diagnostic data, and performance metrics
Store identifiers, order counts, product metadata, financial summaries, and configuration data, only as required to deliver automation, analytics, and accounting-related features
c. Third-Party Platform and Integration Data
Information obtained through integrations you explicitly authorize (for example, TikTok Shop, Shopify, Amazon, Xero, or QuickBooks)
OAuth tokens and integration metadata, stored securely and used solely to provide the requested functionality
d. Payment Information
Subscription payments are processed by our third-party payment processor, Stripe. Agentative does not store full credit card numbers or sensitive payment credentials on its systems.
HOW WE USE YOUR INFORMATION
We use personal data for the following purposes:
To provide, operate, and maintain the Services
To authenticate users and authorize access
To process transactions and manage subscriptions
To communicate service-related information and updates
To provide customer support
To monitor performance, troubleshoot issues, and improve features
To comply with legal and regulatory obligations
We do not sell personal data. We do not use personal data for unrelated marketing purposes unless you explicitly opt in.
LEGAL BASES FOR PROCESSING
Where applicable under data protection laws such as the EU General Data Protection Regulation (GDPR), we process personal data based on one or more of the following legal grounds:
Performance of a contract (providing the Services)
Legitimate interests (such as service security, fraud prevention, and product improvement)
Consent, where required by law
Compliance with legal obligations
COOKIES AND TRACKING TECHNOLOGIES
We may use cookies and similar technologies to maintain sessions, remember user preferences, and analyze site performance. You may control cookies through your browser settings.
THIRD-PARTY SERVICE PROVIDERS (SUBPROCESSORS)
We use third-party service providers ("Subprocessors") to support the operation of our Services. Each subprocessor below is identified by its legal entity name, registered address, and jurisdiction of incorporation or registration. These providers process data on our behalf only as necessary to deliver functionality requested by users.
5.1 CLOUD INFRASTRUCTURE & HOSTING
Amazon Web Services (AWS) - production backend and frontend container hosting in US regions.
Legal entity: Amazon Web Services, Inc. (a wholly-owned subsidiary of Amazon.com, Inc.) Registered address: 410 Terry Avenue North, Seattle, WA 98109-5210, USA Jurisdiction of incorporation: State of Delaware, USA (parent Amazon.com, Inc.)
DigitalOcean - used for CPU-based machine-learning training compute and ancillary workloads.
Legal entity: DigitalOcean Holdings, Inc. Registered address: 101 Avenue of the Americas, New York, NY 10013, USA Jurisdiction of incorporation: State of Delaware, USA
Microsoft Azure - used for GPU-based machine-learning training compute.
Legal entity: Microsoft Corporation Registered address: One Microsoft Way, Redmond, WA 98052-6399, USA Jurisdiction of incorporation: State of Washington, USA
5.2 EDGE & CDN
Cloudflare - public-facing edge for DDoS protection, WAF, TLS termination, and content delivery.
Legal entity: Cloudflare, Inc. Registered address: 101 Townsend Street, San Francisco, CA 94107, USA Jurisdiction of incorporation: State of Delaware, USA
5.3 PAYMENT PROCESSING
Stripe - processes subscription payments. Agentative does not store full credit card numbers.
Legal entity: Stripe, Inc. Registered address: 510 Townsend Street, San Francisco, CA 94103, USA Jurisdiction of incorporation: State of Delaware, USA
5.4 ACCOUNTING & FINANCIAL INTEGRATIONS (OPTIONAL)
These are only engaged when you explicitly connect the integration.
Xero
Legal entity: Xero Limited Registered address: Auckland, New Zealand Jurisdiction: New Zealand (NZX-listed)
QuickBooks
Legal entity: Intuit Inc. Registered address: 2700 Coast Avenue, Mountain View, CA 94043, USA Jurisdiction of incorporation: State of Delaware, USA
5.5 ARTIFICIAL INTELLIGENCE SERVICES
All AI / LLM inference is routed through OpenRouter (https://openrouter.ai), a single gateway that provides a unified API to multiple underlying model providers. OpenRouter is the only AI subprocessor we contract with directly; the underlying inference providers are accessed exclusively through OpenRouter under its terms.
OpenRouter, Inc.
Legal entity: OpenRouter, Inc. Registered address: 169 Madison Avenue, New York, NY 10016, USA Jurisdiction of incorporation: State of New York, USA
For any request that carries sensitive user data - including financial snapshots, PII, account context, business metrics, and OAuth-bearing content - the runtime restricts routing to Zero Data Retention (ZDR) provider endpoints only. On ZDR endpoints, no prompt or completion data is retained, logged, or used for training.
The ZDR hosting providers we route to for sensitive data, each accessed via OpenRouter under its terms, are:
Venice - Venice AI Inc., 160 Greentree Drive, Suite 101, Dover, Delaware 19904, USA (operational headquarters: Menlo Park, California). Used for ZDR-routed inference on sensitive chat, summary, and tool-orchestration requests.
Novita AI - headquartered in San Francisco, California, USA. SOC 2 Type II certified. Used for ZDR-routed inference on sensitive financial reasoning, tax, simulation, and reconciliation requests.
Phala - Hashforest Technology LLC, California, USA. Used for ZDR-routed inference on sensitive autopilot analysis requests.
Wafer - headquartered in San Francisco, California, USA (Y Combinator–backed inference provider; specific registered entity details not publicly disclosed). Used for ZDR-routed inference on sensitive autopilot analysis requests.
Non-sensitive workloads (live web search, public-data routing, classification over non-personal content) may use non-ZDR endpoints, since no customer data is exposed to those calls.
5.6 MACHINE-LEARNING TRAINING COMPUTE
DigitalOcean and Microsoft Azure (listed under §5.1) are also used as compute providers for machine-learning model training. Training data is anonymized or sourced from public data; no production customer data is uploaded to these providers for model training purposes. If you opt in to share specific business data for ML improvement, that data is handled under a separate consent flow.
5.7 MONITORING, OBSERVABILITY & SECURITY
Datadog - application performance monitoring, infrastructure metrics, distributed tracing, log management, real-user monitoring, and security signal collection across the production environment.
Legal entity: Datadog, Inc. Registered address: 620 8th Avenue, 45th Floor, New York, NY 10018, USA Jurisdiction of incorporation: State of Delaware, USA (NASDAQ: DDOG)
Datadog ingests operational telemetry (logs, metrics, traces, and security signals) from our production environment. Logs and traces that contain sensitive user data are scrubbed at the application layer before transmission; the platform does not ingest raw OAuth tokens, financial snapshots, PII, or other sensitive payloads through Datadog. Datadog is bound by its standard Data Processing Addendum.
We do not sell personal data and do not use customer data to train proprietary machine learning models outside of providing the Services.
5.8 ADVERTISING PLATFORMS
When you connect an advertising platform account, we collect and process data from that platform solely to power the analytics, automation, and reporting features you have explicitly requested. Agentative never modifies your advertising account or campaigns without your explicit action in the Agentative UI. Tokens issued by each platform are encrypted at rest using AES-256 and used only to authenticate API calls on your behalf.
5.8.1 Meta (Facebook) Marketing API
When you connect a Meta Ads account, we collect advertising performance data, including campaigns, ad sets, ads, impressions, clicks, spend, conversions, and ad-account metadata, plus OAuth tokens authorizing our read access (ads_read) and, when you opt in, write access (ads_management) to your Meta ad account.
Authorized data flows:
- Read campaigns, ad sets, ads, and ad-level insights for the Meta ad accounts you connect.
- Optional write actions such as campaign creation, bid adjustments, and budget changes, performed only when you explicitly trigger an automation in the Agentative UI. These actions require your confirmation and are recorded in an audit log.
We do not sell Meta-sourced data. We do not use Meta-sourced data to train proprietary machine learning models.
5.8.2 Google Ads API
When you connect a Google Ads account, we collect advertising performance data, including campaigns, ad groups, criteria, product ads, impressions, clicks, cost, conversions, and customer-account metadata, plus OAuth tokens (https://www.googleapis.com/auth/adwords) authorizing our access to your Google Ads account.
Authorized data flows:
- Read campaign structure, performance metrics, and search-term reports for the Google Ads accounts you connect.
- Optional write actions such as campaign creation, bid management, and budget changes, performed only when you explicitly trigger an automation in the Agentative UI. These actions require your confirmation and are recorded in an audit log.
We do not sell Google-sourced data. We do not use Google-sourced data to train proprietary machine learning models.
5.8.3 Amazon Ads API
When you connect an Amazon Ads account, we collect advertising performance data, including campaigns, ad groups, keywords, product ads, Sponsored Products, Sponsored Brands, and Sponsored Display metrics, impressions, clicks, spend, and sales-attribution data, plus Login with Amazon (LWA) refresh tokens authorizing our access to your Amazon Ads account.
Authorized data flows:
- Read campaign structure, performance metrics, and keyword reports for the Amazon Ads profiles you connect.
- Optional write actions such as campaign creation, bid adjustments, and budget changes, performed only when you explicitly trigger an automation in the Agentative UI. These actions require your confirmation and are recorded in an audit log.
We do not sell Amazon-sourced data. We do not use Amazon-sourced data to train proprietary machine learning models.
DATA RETENTION AND DELETION
We retain personal data only for as long as necessary to:
Provide the Services
Fulfill the purposes described in this Privacy Policy
Comply with legal and regulatory obligations
When a user disconnects an integration or revokes authorization, related data and access tokens are deleted or invalidated in a timely manner. Users may request deletion of their personal data as described below.
YOUR PRIVACY RIGHTS
Depending on your jurisdiction (including GDPR and CCPA / CPRA), you may have the right to:
Access your personal data
Correct inaccurate or incomplete data
Request deletion of your data
Restrict or object to certain processing
Receive a copy of your data
Requests may be submitted by contacting support@agentative.ai. We respond to requests in accordance with applicable law.
DATA SECURITY
We implement reasonable technical and organizational measures to protect personal data, including:
Encryption of data in transit using industry-standard protocols (such as TLS 1.2+)
Encryption of data at rest using infrastructure-provider mechanisms (AES-256)
Role-based access controls and authentication safeguards
Row-Level Security (RLS) on all user-scoped database tables
Monitoring and logging of system activity
For the full infrastructure, hosting, and encryption posture, see USA-Based Security.
While no system can be guaranteed to be completely secure, we take appropriate steps to protect data against unauthorized access, disclosure, or misuse.
INTERNATIONAL DATA TRANSFERS
Personal data is hosted in the United States. Where required by law, we implement appropriate safeguards for cross-border data transfers, including Standard Contractual Clauses (SCCs) for EU/EEA transfers.
CHILDREN'S PRIVACY
The Services are not intended for children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. The "Last Updated" date reflects the most recent changes. Continued use of the Services after updates constitutes acceptance of the revised policy.
CONTACT INFORMATION
For questions or requests related to this Privacy Policy or our data practices, please contact:
Email: support@agentative.ai