Legal
Privacy Policy
The quick version: you own your data, and we don't sell it. We collect what we need to run the platform: your account, your catalog, and content from your own channels. Product text is sent to AI providers to power enrichment, never to train their models. Payments are handled by Stripe, so your card details never touch our servers. You can delete your account and everything with it, yourself, at any time.
Masira, Inc. ("Masira", "we", "us") provides a catalog-intelligence platform that helps e-commerce brands make their product data readable to AI shopping assistants. This policy explains what information we collect, why we collect it, and the choices you have. It applies to our websites and the Masira dashboard (together, the "Service").
Information we collect
Account information. When you create an account we collect your name and email address. Sign-in is passwordless: we email you a one-time code, so we never store a password for you.
Workspace and brand information. To run the Service we store the details you give us about your brand and workspace: brand name, website domain, and your plan.
Billing information. If you subscribe to a paid plan, payment is processed by Stripe. Your card details go directly to Stripe and are never stored on our servers; we keep your subscription status, plan, billing period, and a reference to your Stripe customer record, and we share your email address with Stripe to create that record.
Connected-store credentials. If you connect your storefront (for example Shopify or WooCommerce), we store the API credentials you provide, encrypted at rest. We use them only to read your catalog and, on plans that include it, to publish updates you have approved back to your own store.
Content you bring to the Service. Masira works on data about your products, so we store what you connect or upload:
- Product catalogs you import (for example CSV files) or that we read from your own storefront, including titles, descriptions, attributes, prices, and product imagery.
- Customer reviews of your products, fetched from your own store pages and the public review widgets your store already uses (for example Yotpo).
- Social content from your own brand accounts that you explicitly connect, accessed through the platform's official APIs (for example the Instagram Graph API). We never scrape third-party accounts.
Forms and correspondence. If you contact sales or request a strategy call, we collect the details you submit: name, email, company, and your message.
Usage information. We use Google Analytics to understand how our websites are used (pages visited, approximate location, device type), and we keep standard server logs for security and debugging.
How we use information
- To provide the Service: normalizing and enriching your catalog, generating target queries, analyzing reviews and social content, and running AI-visibility diagnostics, including periodic automatic re-measurement so your results stay current.
- To generate the agent-ready feeds you export or, on plans that include it, publish to your own channels.
- To manage billing for paid plans, through our payment processor, Stripe.
- To send transactional email: sign-in codes, email-change confirmations, and account-deletion confirmations, through our email provider, Resend.
- To respond to sales inquiries and strategy-call requests.
- To secure, maintain, and improve the Service.
We do not sell your personal information, and we do not use your catalog data for anything other than operating the Service for you.
AI processing
Enrichment, product-copy rewrites, semantic search, and visibility diagnostics are powered by third-party AI models. To provide these features we send relevant product text from your catalog (and related content such as review excerpts) to AI model providers: currently Microsoft Azure, which hosts the OpenAI and xAI (Grok) models we use, OpenAI directly as a fallback, and Google, Perplexity, and other model providers reached through OpenRouter. These providers process the data to return results and, under the API terms we use them on, do not use your data to train their models. Models hosted on Azure are operated by Microsoft, which does not share your data with OpenAI or xAI. When a measurement uses web search, the search queries the model writes are sent to Microsoft Bing. When you choose a measurement market in the dashboard (for example France, or the European Union), we include that market and language in measurement requests so the assistants answer as they would for a shopper there. Only the market label you chose is sent, never your own or your shoppers' locations.
Who we share information with
We share data only with the service providers (subprocessors) that run the platform:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Sentry | Error monitoring and alerting |
| Better Stack | Uptime monitoring and the public status page |
| Neon | Database hosting (PostgreSQL) |
| Resend | Transactional email delivery |
| Microsoft Azure | Hosting for the OpenAI and Grok models, Bing search |
| OpenAI, OpenRouter | AI model processing for enrichment and diagnostics |
| Google APIs | Merchant Center and Analytics access you grant |
| Google Analytics | Website usage analytics |
| Stripe | Payment processing for paid plans |
We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets; in which case this policy continues to apply to your data.
Cookies
We use a small number of cookies: a session cookie that keeps you signed in, preference cookies (such as remembering whether your sidebar is open), and Google Analytics cookies. You can block cookies in your browser, but the session cookie is required to stay signed in.
Data retention and deletion
We keep your data for as long as your account is active. You can delete your account yourself from the dashboard settings; deletion is confirmed by email and permanently removes your account together with your workspaces, catalogs, and all content derived from them. You can also change the email on your account at any time from settings. If you had a paid subscription, we may keep records of your payments after deletion where tax or accounting law requires it.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise most of these directly in the dashboard (edit your details, change your email, delete your account). For anything else, email us at support@masirahq.com and we will respond within a reasonable time.
Security
Data is encrypted in transit, credentials for connected stores are encrypted at rest, access to production systems is restricted, and sign-in codes expire quickly and can only be used once. No method of transmission or storage is completely secure, but we work to protect your information appropriately.
International transfers
Our infrastructure is hosted in the United States. The Service is available to brands in the United States, the United Kingdom, Canada, Australia and the European Union, and you can measure any of the markets listed in the dashboard from any of them. Wherever you are, your information is processed in the United States, and choosing a European market does not move it. If you are in the European Economic Area, the United Kingdom or Switzerland, this is a transfer of your information to a country that may not offer the same data-protection rules as yours. We protect it with the safeguards described in this policy. If your organization needs a data processing agreement, contact support@masirahq.com and we will discuss what we can put in place.
Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16.
Changes to this policy
We may update this policy as the Service evolves. If we make material changes we will update the date at the top of this page and, where appropriate, notify you by email or in the dashboard.
Contact
Questions about privacy? Email support@masirahq.com.