This Privacy Policy explains how Heem Megacorp LLC ("HundredFold," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with our marketing website at gohundredfold.com and our application at app.gohundredfold.com (together, the "Services").
HundredFold is a multi-tenant business-intelligence and action platform for direct-to-consumer (DTC) ecommerce brands. Merchants connect their store, advertising, email, and inventory data sources to HundredFold, and we surface AI-prioritized insights and let them act on those insights inside the app.
We have written this policy to be specific and honest about exactly what data we handle. If anything here is unclear, contact us at admin@gohundredfold.com.
1. Scope
This policy applies to:
- gohundredfold.com — our public marketing website.
- app.gohundredfold.com — the authenticated HundredFold application used by merchant teams.
It covers two distinct categories of people:
- Account users — the individual members of a merchant's team who log in to HundredFold.
- End customers of a merchant — the people who place orders on a merchant's connected store, whose limited data flows into HundredFold so the merchant can analyze and act on it.
This policy does not govern the independent practices of the merchant-connected platforms (Shopify, Meta, Google, Amazon) or any third-party website that links to us. Those services are governed by their own terms and privacy policies.
2. Our Role: Controller and Processor
HundredFold plays two different legal roles depending on whose data is involved. This distinction matters and we keep it clear throughout this policy.
| Data category | Whose data it is | Our role | Controller |
|---|---|---|---|
| Account / user data | The merchant's team members who log in | Controller | HundredFold |
| End-customer data from connected stores | The merchant's customers (e.g. people who place Shopify orders) | Processor | The merchant |
In plain English:
- For account data — the email and role of the people who log in to HundredFold — we are the controller. We decide how that data is used to run the Services, and this policy governs it directly.
- For end-customer data — the minimal order data that flows in from a merchant's connected store — we are a processor acting on the merchant's instructions. The merchant is the controller of that data. We process it only to provide the Services to that merchant. If you are an end customer of a brand that uses HundredFold and you want to exercise privacy rights over your data, please contact that brand directly; we will support them in responding (see "Your Privacy Rights" below).
3. Information We Collect
3.1 Account / user data (we are the controller)
Access to HundredFold is invite-only. A merchant's owner adds team members to an allowlist; there is no public self-serve signup today. Authentication is passwordless — users sign in with a magic link sent to their work email, or with Google sign-in — handled through Supabase Auth.
For each account user we store:
- Email address (work email)
- Role — one of owner, admin, member, or viewer
- An internal Supabase user ID
We do not collect or store account-user passwords, phone numbers, postal addresses, or payment/card details.
3.2 End-customer personal data (we are the processor — minimal)
When a merchant connects their Shopify store, a minimal amount of end-customer personal data flows into HundredFold. For each order, we store only:
- The customer's email address
- The shipping city, state/province, and country
That is the only end-customer personal data we store. We do not collect or store:
- Customer names
- Street addresses
- Phone numbers
- Payment, card, or financial account data
- Customer profiles or any other identifiers
The stored email address is used for one purpose: to let the merchant export win-back audience lists to the merchant's own Klaviyo account.
3.3 Integration metrics (per connected provider)
When a merchant connects an advertising, analytics, email, or marketplace provider, we read aggregate business metrics to power insights. Except for the Shopify order data described in section 3.2, these integrations bring in no end-customer personal data — they are aggregate counts and rates. Section 4 lists each provider, the exact data and OAuth scopes, and the reason we use them.
3.4 Product images
To generate ad creative, HundredFold sends a merchant's product images (plus text prompts) to our AI creative-generation sub-processor. No customer or personal data is included in this flow.
3.5 Technical, usage, and cookie data
When you use the Services we collect standard technical and usage information such as IP address, browser/device type, pages viewed, and request logs, used to operate, secure, and debug the Services.
Cookies. The app sets a single, strictly-necessary authentication/session cookie (via Supabase) so you can stay logged in. We do not use advertising or analytics tracking cookies, and there is no cross-site tracking. Because the only cookie we set is strictly necessary, we do not currently display a cookie consent banner.
4. Connected Services, OAuth Scopes, and Why
Merchants explicitly authorize each integration. The tables below state the exact data we access, the exact OAuth scopes requested, and why. The vast majority of these connections are read-only; the two exceptions (Meta paused-draft creation and Klaviyo draft push) are noted explicitly.
Shopify — read-only
Why: To sync products, variants, inventory, orders, locations, and fulfillments so we can power inventory forecasting, replenishment planning, sales analytics, and win-back audiences.
| Scope | Purpose |
|---|---|
read_products | Product catalog for analytics and forecasting |
read_inventory | Inventory levels for daily snapshots and replenishment |
read_orders | Orders, including the customer email + ship city/state/country (see §3.2) |
read_all_orders | Historical order backfill for trend analysis |
read_locations | Inventory locations |
read_fulfillments | Fulfillment status for operations |
read_customers | New-vs-returning and repeat-customer health metrics |
read_discounts | Discount/promotion analysis |
read_price_rules | Pricing/promotion analysis |
read_returns | Refund and return-rate metrics |
read_marketing_events | Marketing-event context for attribution |
The only end-customer personal data we retain from Shopify is the email + ship city/state/country described in §3.2.
Meta (Facebook / Instagram ads) — read, plus optional paused-draft creation
Why: To read aggregate ad performance (spend, impressions, clicks, ROAS, placement breakdowns — no end-user PII), and, optionally, to create paused draft ads for the merchant to review. We never publish live ads.
| Scope | Purpose |
|---|---|
ads_read | Read campaign/ad/insight metrics (aggregate) |
ads_management | Write — create paused draft ads only; never publishes |
pages_show_list | List the merchant's Pages to attach creative |
pages_read_engagement | Page engagement context |
business_management | Access the merchant's Business Manager assets |
instagram_basic | Associate Instagram placements for creative |
Google — read-only
Why: To read organic search metrics, analytics, and ads performance as aggregates for cross-channel reporting. See section 5 for the Google Limited Use affirmation.
| Scope | Purpose |
|---|---|
https://www.googleapis.com/auth/webmasters.readonly | Search Console organic metrics (read-only) |
https://www.googleapis.com/auth/analytics.readonly | GA4 sessions/conversions/revenue by channel — aggregates (read-only; Google sensitive/restricted scope) |
https://www.googleapis.com/auth/adwords | Google Ads campaign/product performance — aggregates (read-only; Google sensitive/restricted scope) |
Because analytics.readonly and adwords are Google sensitive/restricted scopes, our use of data obtained through them is subject to the Google API Services User Data Policy, including the Limited Use requirements described in section 5.
Amazon Selling Partner API — read-only
Why: To read FBA inventory, a daily sales & traffic report (revenue and order counts only), and inbound-shipment operations. Amazon authentication uses Login with Amazon (LWA); there are no OAuth scope strings. No customer personal data is obtained from Amazon.
Klaviyo — read, plus draft push
Why: To read email campaign and flow metrics, and to push draft templates and draft campaigns that the merchant reviews and sends from Klaviyo. We also export customer emails (from connected-store orders) to build win-back lists in the merchant's Klaviyo. Klaviyo uses API-key authentication (no OAuth scopes).
Higgsfield (AI creative generation) — product images only
Why: To generate ad creative, we send the merchant's product images plus text prompts. No customer or personal data is sent. Higgsfield is operated at the platform level — a single HundredFold company account serves all tenants.
5. Google API Services — Limited Use Affirmation
HundredFold's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the user-facing features that are prominent in the HundredFold experience (organic-search, analytics, and ads reporting and the cross-channel insights built from them).
- We do not transfer or sell Google user data to third parties for advertising, data-brokering, or any unrelated purpose.
- We do not use Google user data for serving advertisements.
- We do not use Google user data to develop, improve, or train generalized or large-scale AI/ML models. (Google-derived metrics are aggregate business figures and are not sent to any third-party AI model; see section 7.)
- Humans do not read Google user data except as required for security, to comply with applicable law, or with the user's explicit consent, or in aggregated/anonymized form for operations.
6. How We Use Information
We use the information described above to:
- Authenticate users and operate the invite-only account/role model.
- Sync and store the connected data needed to power inventory forecasting, replenishment planning, advertising and email analytics, customer-health metrics, and cross-channel reporting.
- Generate AI-prioritized insights, daily briefings, and ad/email copy and creative (see section 7).
- Create paused draft ads (Meta) and draft email templates/campaigns (Klaviyo) for the merchant to review and act on.
- Export win-back audience lists (customer emails) to a merchant's Klaviyo at the merchant's instruction.
- Secure, monitor, debug, and improve the Services.
- Communicate with account users (e.g. transactional and service messages).
- Comply with legal obligations and enforce our terms.
We process end-customer data only to provide the Services to the merchant that controls it.
7. AI Processing Disclosure
HundredFold uses Anthropic's Claude models to power the AI analyst, daily briefing, and copy/creative generation. We are deliberate about what is and is not sent to the AI:
What is sent to Anthropic: business aggregates only — for example revenue/ROAS/AOV KPIs, inventory summaries, top-ad metrics, customer-health rates (such as repeat-purchase and refund percentages), email metrics, and replenishment plans — together with the merchant's own written business-context notes.
What is never sent to Anthropic:
- Customer names, emails, or addresses, or any other end-customer personal data.
- API keys, tokens, or any secrets.
Product images and prompts used for ad-creative generation are sent to our creative sub-processor (Higgsfield), not to Anthropic, and contain no personal data. Anthropic processes business aggregates only and does not receive end-customer PII.
8. How We Share Information
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share information only as described here:
- Sub-processors (our infrastructure). We use vetted service providers to run the Services. See our Sub-processors list for the current list. In summary:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Managed Postgres database + authentication | All app data, including user emails |
| Vercel | Application hosting + scheduled cron jobs | Application traffic and logs |
| Anthropic | AI analysis | Business aggregates only — no end-customer PII, no secrets |
| Higgsfield | AI image generation | Product images + prompts — no personal data |
| Resend | Transactional email (warehouse packing lists / FBA labels to a merchant-configured warehouse email) | No end-customer PII |
| Klaviyo | Email-marketing platform | Draft templates + customer emails for win-back lists |
Provider hosting region per sub-processor: United States (confirm regions per provider before publication).
- Merchant-connected platforms. When a merchant authorizes an integration, data flows to/from that platform (Shopify, Meta, Google, Amazon) as described in section 4. These platforms are data sources the merchant authorizes and are governed by their own terms — they are not HundredFold infrastructure sub-processors.
- Legal and protective disclosures. We may disclose information if required by law, legal process, or government request, or where necessary to protect the rights, safety, or property of HundredFold, our customers, or others, or in connection with a corporate transaction (e.g. merger or acquisition), subject to appropriate safeguards.
We do not sell personal data and do not "share" it for targeted advertising as those terms are defined under applicable U.S. state privacy laws.
9. International Data Transfers
HundredFold and our sub-processors may process information in countries other than the one in which you reside. Where we transfer personal data internationally — including, where applicable, from the EU/UK to the United States — we rely on appropriate safeguards such as the Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with the supplementary measures described in our Security page. Our sub-processors primarily host data in the United States.
10. Data Retention and Deletion
Retention. We retain account data for as long as an Organization's account is active, and we retain order-derived end-customer data and integration metrics for as long as needed to provide the Services to the merchant. Automated, age-based deletion is being implemented; until it is fully live, data is retained for the life of the account and deleted on account closure or on request as described below.
Deletion / erasure. We are implementing an automated process to delete end-customer data on request, including support for Shopify's mandatory privacy webhooks (customers/redact, shop/redact, and customers/data_request) and for GDPR/CCPA erasure requests. When a merchant disconnects a store or a deletion request is received, we will delete or de-identify the associated end-customer data within 30 days. Account data is deleted when an account is closed, subject to legal retention requirements. To make a request, see section 12, our Data Deletion page, or contact admin@gohundredfold.com.
11. Your Privacy Rights
The rights available to you depend on your location and on whether HundredFold is the controller or processor of the data in question.
If you are an end customer of a merchant that uses HundredFold, the merchant is the controller of your data. Please direct access, correction, or deletion requests to that merchant; we will assist them in fulfilling your request as their processor.
If you are an account user (and HundredFold is the controller), you may exercise the rights below.
EU / UK (GDPR), where applicable
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data.
- Restriction — request that we limit processing.
- Portability — receive your data in a portable format and, where feasible, have it transmitted to another controller. (Our self-serve data-export process is being built; in the meantime, contact admin@gohundredfold.com and we will fulfill portability requests manually.)
- Objection — object to certain processing.
- You may also lodge a complaint with your supervisory authority.
California (CCPA/CPRA) and similar U.S. state laws, where applicable
- Right to know what personal information we collect, use, and disclose.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — note that we do not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination for exercising your rights.
How to exercise your rights. Contact us at admin@gohundredfold.com. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.
12. Security
We design our security controls to align with the SOC 2 Trust Services Criteria. Key measures include:
- Multi-tenant isolation. Every record carries the owning organization's ID; every database read and write is scoped to the caller's organization in application code, with PostgreSQL Row-Level Security enforced as a backstop. One merchant cannot access another merchant's data.
- Token storage. Integration tokens are being migrated to Supabase Vault by reference — encrypted at rest, with application tables holding only an opaque secret ID and decryption locked to the server's service role via
SECURITY DEFINERfunctions (revoked from the anonymous and authenticated roles). Token resolution reads Vault-first, with a per-provider backfill. This is not yet the active path for every provider; some credentials currently live in server-side environment variables or, for some OAuth providers, in database columns. Wherever a credential sits, it is never exposed to the browser or the AI, and the database enforces Row-Level Security and per-organization scoping. - Passwordless authentication. Magic-link or Google SSO; invite-only owner allowlist; role-based access; no public signup.
- Encryption. TLS/HTTPS in transit; encryption at rest via our managed database provider.
- Infrastructure. Our core providers, Supabase and Vercel, both maintain SOC 2 Type II reports. Automated database backups and point-in-time recovery are in place.
- AI privacy. No end-customer PII is sent to the AI model.
- Secrets handling. Provider keys and app secrets live in server-side environment variables and are never exposed to the browser or to the AI.
About SOC 2: HundredFold does not currently hold its own SOC 2 report; a SOC 2 program is planned. It is accurate that our infrastructure providers (Supabase, Vercel) are SOC 2 Type II and that our controls are designed to align with the SOC 2 criteria.
For more detail, see our Security page.
Incident response. We maintain an incident- and breach-response plan and will notify affected parties and regulators as required by applicable law, with a target notification window of 72 hours from confirmation of a qualifying incident.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
The Services are a business tool and are not directed to, or intended for, children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" above and notify account users by email and/or an in-app notice before the changes take effect. Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy.
15. Contact Us
For privacy questions or to exercise your rights, contact:
- Contact: admin@gohundredfold.com
- Entity and mailing address: Heem Megacorp LLC, 8500 Blazyk Drive, Austin, Texas 78737
This policy is governed by the laws of the State of Texas, USA.