Privacy Policy
Effective 2026-09-14
This Privacy Policy describes how AlphaZero Studios LLC (“we”, “us”) collects, uses, discloses, and protects personal information when you use our website, admin, or storefronts powered by our platform.
1. Information we collect
From merchants
- Account info: name, email, business name, billing address, payment method.
- Identity / KYC: when you enable payments, Stripe collects legal name, address, date of birth, last four of SSN/EIN, bank account, and supporting documents. We don't store these directly — they live in your Stripe Connect account.
- Usage data: pages visited, features used, AI prompts, error logs, IP, browser.
We use Plaid Inc. (“Plaid”) to verify your bank account information for payouts. By connecting your account, you grant us and Plaid the right to access and use that information per this Privacy Policy and Plaid's End User Privacy Policy.
From shoppers (acting as a processor on behalf of merchants)
- Order info: name, shipping/billing address, email, phone, items purchased, totals.
- Payment info: handled by Stripe; we receive only a token, brand, and last four.
- Browsing data: session cookies, cart contents, pages viewed on the storefront.
From visitors entering the Virtual World (identity & biometric verification)
Entering our immersive “Virtual World” (the walkable 3D mall and avatar experience) is optional. If you choose to enter it, we ask you to verify your identity first, to confirm you are a real, unique person and to keep the space free of bots and duplicate accounts. Ordinary (non-immersive) shopping does not require this.
- What is collected, and by whom: our verification provider, Stripe Identity (Stripe, Inc.), collects a photo of your government ID and a selfie that includes a biometric facial scan used to match you to the ID. This collection and the biometric matching are performed and stored by Stripe as our service provider — see Stripe's Privacy Policy and Identity documentation.
- What AlphaZero Studios LLC receives and stores: we do not receive or store your ID images, selfie, facial geometry, full date of birth, or ID/document numbers. We store only: (a) a pass/fail verification result; (b) a coarse age-threshold flag (e.g. “over 18/21”); (c) your verified name and address, which you may edit; and (d) a one-way, non-reversible hashed token used solely to detect and prevent one person creating multiple accounts.
- Purpose: confirming you are a real, unique human for Virtual World access, and preventing duplicate or fraudulent accounts. We use it for nothing else.
- Consent: we obtain your informed consent before verification begins. You may decline — you simply won't enter the Virtual World, and can continue to shop normally.
- Retention & destruction: biometric identifiers and images are retained and destroyed by Stripe under its policies and our data-processing terms; AlphaZero Studios LLC never holds them. The verification result and hashed token are kept while your account is active and deleted within 90 days of account deletion, and in any case any biometric-derived data is permanently destroyed when the verification purpose is satisfied or within 3 years of your last interaction with us, whichever occurs first.
- No sale or profit: we do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, and we do not disclose them except to Stripe to perform the verification or where required by law.
2. How we use information
- To provide, operate, and improve the Service.
- To process payments and prevent fraud.
- To send transactional email (receipts, password resets, order updates).
- To send service announcements; marketing email only with your consent.
- To comply with legal obligations and enforce our Terms.
3. How we share information
- Service providers: Stripe (payments and identity verification), Plaid (bank verification for payouts), Amazon SES and Resend (email), Twilio (SMS and phone services), Cloudflare (CDN/edge), Hetzner (hosting), Anthropic, Google, OpenAI, Replicate, Deepgram, and ElevenLabs (tenant-enabled AI features). They process data on our behalf under contract; the current processor list is available in the privacy center.
- Merchants: shopper personal data is shared with the merchant operating the storefront — they're the controller for that data.
- Legal: when required by law, court order, or to protect rights/safety.
- Business transfers: as part of a merger, sale, or financing, subject to notice.
We don't sell personal data.
4. Cookies and similar tech
We use strictly necessary cookies (session, cart) and, with your consent where required, analytics cookies. You can disable cookies in your browser, but parts of the Service won't work without session cookies.
5. Data retention
We retain account data for the life of your account and for up to 7 years after termination for tax/audit purposes. Shopper data is retained per the merchant's instructions and applicable law. Backups are pruned within 90 days. Identity-verification data is retained and destroyed as described in the “identity & biometric verification” subsection of Section 1.
6. Security
We use industry-standard practices: TLS for data in transit, encryption at rest for sensitive fields, audit logging, least-privilege access, and regular vulnerability scanning. Card data is handled in SAQ-A scope — it never touches our servers.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to processing or withdraw consent. You can exercise these by emailing privacy@alphazerostudios.com. For data we hold as a processor on behalf of a merchant, contact the merchant directly.
8. International transfers
We may transfer data to the United States and other countries. For EEA/UK transfers we rely on Standard Contractual Clauses and equivalent safeguards.
9. Children
The Service is not directed to children under 16, and we don't knowingly collect their personal data.
10. Connected third-party accounts
Some AlphaZero Studios LLC products let you connect your own third-party accounts — social media accounts such as YouTube, TikTok, Instagram, Facebook, Threads, Pinterest, LinkedIn, Reddit, and X, and business listing accounts such as Google Business Profile — so you can publish content you create, see how it performs, respond to your audience, and manage your business presence from one place. Connecting an account is optional and is done through each platform's official OAuth sign-in. Each feature asks only for the permissions it needs, and you can see exactly what you are granting on the platform's own consent screen before you approve it.
What we access and store
- Authorization tokens: when you connect an account we receive the OAuth access and/or refresh tokens that let us act on your behalf for the permissions you grant. We store them encrypted at rest. We never receive or store your social-account password.
- Account details: basic profile and channel/page information the platform returns (such as account name, handle, id, and profile picture) so we can show you which account is connected and route your posts to it.
- Content you choose to publish: the videos, images, captions, titles, descriptions, tags, and publishing settings you submit, and the media files you upload to your library for that purpose.
- Performance metrics: audience and engagement numbers the platform reports for your account and for the posts you publish through us (for example follower counts, views, likes, and comment counts), so we can show you how your content is doing.
How we use it
- To publish or schedule the content you choose, to the connected accounts you choose, on your behalf.
- To show the connection status of your accounts and the status and performance of your posts.
- To show analytics dashboards for the accounts you connect, and to let you read and reply to comments where that feature is offered.
We use this access only to provide the features you request. We do not publish, reply, or change anything on a connected account on our own initiative. We do not sell information received from these platforms, use it for advertising or to build advertising profiles, use it to train generalised machine-learning models, or share it with anyone other than the service providers who help us run these features. When you publish, the content and metadata you provide are transmitted to the relevant platform through its API; your use of each platform is governed by that platform's own terms and privacy policy.
Google Business Profile
If you connect a Google Business Profile account, you grant us the Google https://www.googleapis.com/auth/business.manage scope. That connection is read-mostly and is used only to operate the Local Business features you asked for. Specifically, we:
- Read the business accounts and locations you manage — location name, address, phone number, website, categories, opening hours, and profile description — so you can pick which location this store represents and see it inside our admin.
- Read reviews left on that location (reviewer display name, star rating, review text, timestamp, and any existing reply) and the location's photos and performance metrics, so we can show them to you in one dashboard.
- Write only what you explicitly submit: replies you compose to reviews, and posts you choose to publish to the location. We do not post, reply, or edit your listing on our own initiative.
We store your OAuth refresh token encrypted at rest, plus the identifiers of the account and location you selected and the connected Google account email. Business Profile data we display is fetched for your session and cached only as long as needed to render it.
YouTube
AlphaZero Studios LLC uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy. There are three separate YouTube connections, each requested only when you use that feature:
- Publishing (
youtube.upload,youtube.readonly): we read your channel's id, name, and thumbnail so you can pick it as a destination; upload the videos you choose, with the title, description, and privacy settings you set; and read your channel's subscriber and view counts and the view, like, and comment counts of videos you published through us. - Analytics (
youtube.readonly,yt-analytics.readonly): read-only access to your channel's statistics (subscribers, total views, video count), YouTube Analytics reports for the period you select (such as views, watch time, and likes), and the titles and thumbnails of your top-performing videos. - Comment inbox (
youtube.readonly,youtube.force-ssl): we read comment threads on your videos (commenter display name, profile picture, comment text, and time) so you can see them in one inbox, and post the replies you write. We never post, edit, or delete comments on our own initiative.
Analytics reports are fetched live and held in memory for up to 15 minutes, and comment threads for about a minute; neither is written to our database. Publishing-related counts (subscribers, views, likes, comments) are refreshed from YouTube while your channel stays connected and are deleted when you disconnect it. Our website uses cookies as described in Section 4; we do not place cookies on your device on behalf of YouTube.
Meta: Facebook, Instagram, and Threads
- Facebook Pages publishing (
pages_show_list,pages_manage_posts,pages_read_engagement,business_management): we list the Pages you manage (id, name, and picture) so you can choose one, publish the text, photos, and videos you choose to it, and read its follower and fan counts. - Instagram publishing (
instagram_basic,instagram_content_publish,instagram_manage_insights,pages_show_list,business_management): we identify the Instagram professional account linked to your Page (id, username, and profile picture), publish the photos and videos you choose, and read your follower count and the like and comment counts of posts you published through us. - Instagram analytics (
instagram_basic,instagram_manage_insights,pages_show_list,pages_read_engagement,read_insights,business_management): read-only access to your follower and post counts, account insights (reach, impressions, and profile views), and your recent posts (caption, link, thumbnail, like and comment counts, and time). - Threads publishing (
threads_basic,threads_content_publish,threads_manage_insights): we read your Threads username and profile picture, publish the posts you choose, and read engagement on posts you published through us.
To publish photos and videos, Meta requires a link it can download the file from, so we give Meta an unguessable link to the media you chose. Meta issues long-lived access tokens rather than refresh tokens; we store them encrypted at rest. Analytics are held in memory for up to 15 minutes and are not written to our database.
Instagram comment-to-DM automations
Businesses using AlphaZero Studios LLC can connect an Instagram professional account through Instagram Login to automatically reply by direct message when someone comments a keyword they choose. This connection requests instagram_business_basic, instagram_business_manage_comments, and instagram_business_manage_messages, and subscribes to Instagram webhooks for comments and messages on that account.
- From the business: the Instagram account id, username, and profile picture; an encrypted access token; and the automations it sets up (keywords, which posts they apply to, message steps, and links).
- From people who comment or message that account: their Instagram-scoped user id and username, which keyword and post they commented on, a short preview of their comment or message (up to 240 characters), the time of each interaction, whether they clicked a link we sent, and — only if the automation asks for it and they reply with it — their email address. We do not store full webhook payloads.
- How it is used: only to send the private reply and follow-up messages that business configured, to stop when a conversation ends or after 7 days, and to show that business its own automation results and the leads who chose to share an email. It is never used to message anyone who did not first comment or message the business, and never shared with other businesses.
For this data the business is the controller and AlphaZero Studios LLC acts as its processor. If you commented on or messaged a business and want your information removed, you can ask that business, or email us at the address below and we will delete it. When a business disconnects Instagram, we immediately delete the access token and every contact, email address, conversation, and message preview received through that account; the automation settings themselves are kept, paused, so the business can reconnect.
TikTok
- Publishing (
user.info.basic,user.info.stats,video.list,video.upload,video.publish): we read your display name, avatar, and TikTok user id so you can pick the account; upload and publish the videos you choose with the caption and privacy settings you set; and read your follower and like counts and the view, like, and comment counts of videos you published through us. - Analytics (
user.info.basic,user.info.profile,user.info.stats,video.list): read-only access to your profile statistics and your 20 most recent videos (title, cover image, view, like, comment, and share counts, and posting time). Analytics are held in memory for up to 15 minutes and are not written to our database.
Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our access to and use of information received from Meta, TikTok, and the other platforms listed above complies with their developer and platform policies.
Disconnecting and deleting your data
- Disconnect in the product: you can disconnect any connected account at any time from Community & social → Social planner → Connected accounts (or from the relevant analytics, inbox, Automations, or Local Business page). Disconnecting immediately deletes the tokens we hold for that connection, along with the stored account details and performance metrics for it (for Google Business Profile, the account/location selection; for Instagram automations, all contacts, emails, conversations, and message previews). For YouTube and TikTok publishing connections we also ask the platform to revoke our access.
- Revoke at the platform: you can also remove our access directly from each platform — for Google and YouTube at myaccount.google.com/permissions; for Facebook and Instagram under Settings → Apps and websites; for TikTok under Settings and privacy → Security → Manage app permissions. Once access is revoked, our stored tokens stop working and we can no longer read or publish anything.
- Posts and media: drafts, scheduled posts, and media files you upload stay in your library until you delete them. Deleting a post removes it and its metrics from our systems; it does not delete anything already published on the platform, which you can remove there.
- Delete everything: deleting your AlphaZero Studios LLC account deletes all connected accounts, tokens, posts, media, and metrics described in this section. You can also email privacy@alphazerostudios.com from the address on your account to ask us to delete data we received from any connected platform; we confirm and complete the request within 30 days.
11. Changes
We'll update this policy and post the new effective date. Material changes will be flagged via email or in-product banner.
12. Contact
privacy@alphazerostudios.com
AlphaZero Studios LLC
6538 W 64th Pl, Chicago, IL 60638, USA

