Legal

Privacy Policy

Effective date: June 20, 2026 Applies to: gohundredfold.com & app.gohundredfold.com

This Privacy Policy explains how Heem Megacorp LLC ("HundredFold," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with our marketing website at gohundredfold.com and our application at app.gohundredfold.com (together, the "Services").

HundredFold is a multi-tenant business-intelligence and action platform for direct-to-consumer (DTC) ecommerce brands. Merchants connect their store, advertising, email, and inventory data sources to HundredFold, and we surface AI-prioritized insights and let them act on those insights inside the app.

We have written this policy to be specific and honest about exactly what data we handle. If anything here is unclear, contact us at admin@gohundredfold.com.

1. Scope

This policy applies to:

It covers two distinct categories of people:

  1. Account users — the individual members of a merchant's team who log in to HundredFold.
  2. End customers of a merchant — the people who place orders on a merchant's connected store, whose limited data flows into HundredFold so the merchant can analyze and act on it.

This policy does not govern the independent practices of the merchant-connected platforms (Shopify, Meta, Google, Amazon) or any third-party website that links to us. Those services are governed by their own terms and privacy policies.

2. Our Role: Controller and Processor

HundredFold plays two different legal roles depending on whose data is involved. This distinction matters and we keep it clear throughout this policy.

Data categoryWhose data it isOur roleController
Account / user dataThe merchant's team members who log inControllerHundredFold
End-customer data from connected storesThe merchant's customers (e.g. people who place Shopify orders)ProcessorThe merchant

In plain English:

3. Information We Collect

3.1 Account / user data (we are the controller)

Access to HundredFold is invite-only. A merchant's owner adds team members to an allowlist; there is no public self-serve signup today. Authentication is passwordless — users sign in with a magic link sent to their work email, or with Google sign-in — handled through Supabase Auth.

For each account user we store:

We do not collect or store account-user passwords, phone numbers, postal addresses, or payment/card details.

3.2 End-customer personal data (we are the processor — minimal)

When a merchant connects their Shopify store, a minimal amount of end-customer personal data flows into HundredFold. For each order, we store only:

That is the only end-customer personal data we store. We do not collect or store:

The stored email address is used for one purpose: to let the merchant export win-back audience lists to the merchant's own Klaviyo account.

3.3 Integration metrics (per connected provider)

When a merchant connects an advertising, analytics, email, or marketplace provider, we read aggregate business metrics to power insights. Except for the Shopify order data described in section 3.2, these integrations bring in no end-customer personal data — they are aggregate counts and rates. Section 4 lists each provider, the exact data and OAuth scopes, and the reason we use them.

3.4 Product images

To generate ad creative, HundredFold sends a merchant's product images (plus text prompts) to our AI creative-generation sub-processor. No customer or personal data is included in this flow.

3.5 Technical, usage, and cookie data

When you use the Services we collect standard technical and usage information such as IP address, browser/device type, pages viewed, and request logs, used to operate, secure, and debug the Services.

Cookies. The app sets a single, strictly-necessary authentication/session cookie (via Supabase) so you can stay logged in. We do not use advertising or analytics tracking cookies, and there is no cross-site tracking. Because the only cookie we set is strictly necessary, we do not currently display a cookie consent banner.

4. Connected Services, OAuth Scopes, and Why

Merchants explicitly authorize each integration. The tables below state the exact data we access, the exact OAuth scopes requested, and why. The vast majority of these connections are read-only; the two exceptions (Meta paused-draft creation and Klaviyo draft push) are noted explicitly.

Shopify — read-only

Why: To sync products, variants, inventory, orders, locations, and fulfillments so we can power inventory forecasting, replenishment planning, sales analytics, and win-back audiences.

ScopePurpose
read_productsProduct catalog for analytics and forecasting
read_inventoryInventory levels for daily snapshots and replenishment
read_ordersOrders, including the customer email + ship city/state/country (see §3.2)
read_all_ordersHistorical order backfill for trend analysis
read_locationsInventory locations
read_fulfillmentsFulfillment status for operations
read_customersNew-vs-returning and repeat-customer health metrics
read_discountsDiscount/promotion analysis
read_price_rulesPricing/promotion analysis
read_returnsRefund and return-rate metrics
read_marketing_eventsMarketing-event context for attribution

The only end-customer personal data we retain from Shopify is the email + ship city/state/country described in §3.2.

Meta (Facebook / Instagram ads) — read, plus optional paused-draft creation

Why: To read aggregate ad performance (spend, impressions, clicks, ROAS, placement breakdowns — no end-user PII), and, optionally, to create paused draft ads for the merchant to review. We never publish live ads.

ScopePurpose
ads_readRead campaign/ad/insight metrics (aggregate)
ads_managementWrite — create paused draft ads only; never publishes
pages_show_listList the merchant's Pages to attach creative
pages_read_engagementPage engagement context
business_managementAccess the merchant's Business Manager assets
instagram_basicAssociate Instagram placements for creative

Google — read-only

Why: To read organic search metrics, analytics, and ads performance as aggregates for cross-channel reporting. See section 5 for the Google Limited Use affirmation.

ScopePurpose
https://www.googleapis.com/auth/webmasters.readonlySearch Console organic metrics (read-only)
https://www.googleapis.com/auth/analytics.readonlyGA4 sessions/conversions/revenue by channel — aggregates (read-only; Google sensitive/restricted scope)
https://www.googleapis.com/auth/adwordsGoogle Ads campaign/product performance — aggregates (read-only; Google sensitive/restricted scope)

Because analytics.readonly and adwords are Google sensitive/restricted scopes, our use of data obtained through them is subject to the Google API Services User Data Policy, including the Limited Use requirements described in section 5.

Amazon Selling Partner API — read-only

Why: To read FBA inventory, a daily sales & traffic report (revenue and order counts only), and inbound-shipment operations. Amazon authentication uses Login with Amazon (LWA); there are no OAuth scope strings. No customer personal data is obtained from Amazon.

Klaviyo — read, plus draft push

Why: To read email campaign and flow metrics, and to push draft templates and draft campaigns that the merchant reviews and sends from Klaviyo. We also export customer emails (from connected-store orders) to build win-back lists in the merchant's Klaviyo. Klaviyo uses API-key authentication (no OAuth scopes).

Higgsfield (AI creative generation) — product images only

Why: To generate ad creative, we send the merchant's product images plus text prompts. No customer or personal data is sent. Higgsfield is operated at the platform level — a single HundredFold company account serves all tenants.

5. Google API Services — Limited Use Affirmation

HundredFold's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

6. How We Use Information

We use the information described above to:

We process end-customer data only to provide the Services to the merchant that controls it.

7. AI Processing Disclosure

HundredFold uses Anthropic's Claude models to power the AI analyst, daily briefing, and copy/creative generation. We are deliberate about what is and is not sent to the AI:

What is sent to Anthropic: business aggregates only — for example revenue/ROAS/AOV KPIs, inventory summaries, top-ad metrics, customer-health rates (such as repeat-purchase and refund percentages), email metrics, and replenishment plans — together with the merchant's own written business-context notes.

What is never sent to Anthropic:

Product images and prompts used for ad-creative generation are sent to our creative sub-processor (Higgsfield), not to Anthropic, and contain no personal data. Anthropic processes business aggregates only and does not receive end-customer PII.

8. How We Share Information

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share information only as described here:

Sub-processorPurposeData involved
SupabaseManaged Postgres database + authenticationAll app data, including user emails
VercelApplication hosting + scheduled cron jobsApplication traffic and logs
AnthropicAI analysisBusiness aggregates only — no end-customer PII, no secrets
HiggsfieldAI image generationProduct images + prompts — no personal data
ResendTransactional email (warehouse packing lists / FBA labels to a merchant-configured warehouse email)No end-customer PII
KlaviyoEmail-marketing platformDraft templates + customer emails for win-back lists

Provider hosting region per sub-processor: United States (confirm regions per provider before publication).

We do not sell personal data and do not "share" it for targeted advertising as those terms are defined under applicable U.S. state privacy laws.

9. International Data Transfers

HundredFold and our sub-processors may process information in countries other than the one in which you reside. Where we transfer personal data internationally — including, where applicable, from the EU/UK to the United States — we rely on appropriate safeguards such as the Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with the supplementary measures described in our Security page. Our sub-processors primarily host data in the United States.

10. Data Retention and Deletion

Retention. We retain account data for as long as an Organization's account is active, and we retain order-derived end-customer data and integration metrics for as long as needed to provide the Services to the merchant. Automated, age-based deletion is being implemented; until it is fully live, data is retained for the life of the account and deleted on account closure or on request as described below.

Deletion / erasure. We are implementing an automated process to delete end-customer data on request, including support for Shopify's mandatory privacy webhooks (customers/redact, shop/redact, and customers/data_request) and for GDPR/CCPA erasure requests. When a merchant disconnects a store or a deletion request is received, we will delete or de-identify the associated end-customer data within 30 days. Account data is deleted when an account is closed, subject to legal retention requirements. To make a request, see section 12, our Data Deletion page, or contact admin@gohundredfold.com.

11. Your Privacy Rights

The rights available to you depend on your location and on whether HundredFold is the controller or processor of the data in question.

If you are an end customer of a merchant that uses HundredFold, the merchant is the controller of your data. Please direct access, correction, or deletion requests to that merchant; we will assist them in fulfilling your request as their processor.

If you are an account user (and HundredFold is the controller), you may exercise the rights below.

EU / UK (GDPR), where applicable

California (CCPA/CPRA) and similar U.S. state laws, where applicable

How to exercise your rights. Contact us at admin@gohundredfold.com. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.

12. Security

We design our security controls to align with the SOC 2 Trust Services Criteria. Key measures include:

About SOC 2: HundredFold does not currently hold its own SOC 2 report; a SOC 2 program is planned. It is accurate that our infrastructure providers (Supabase, Vercel) are SOC 2 Type II and that our controls are designed to align with the SOC 2 criteria.

For more detail, see our Security page.

Incident response. We maintain an incident- and breach-response plan and will notify affected parties and regulators as required by applicable law, with a target notification window of 72 hours from confirmation of a qualifying incident.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children's Privacy

The Services are a business tool and are not directed to, or intended for, children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" above and notify account users by email and/or an in-app notice before the changes take effect. Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy.

15. Contact Us

For privacy questions or to exercise your rights, contact:

This policy is governed by the laws of the State of Texas, USA.