Privacy Policy
Previously published version: July 2, 2026. Read the historical version.
Proposed revision: September 22, 2026. Owner legal and operational review is required before adoption; these revisions are not yet effective in production.
MailPanda is operated by Manifest Five Equity LLC (“MailPanda”, “we”, “us”). MailPanda is an AI email marketer for e-commerce brands: it studies your store, designs campaigns and flows, and either publishes them to your connected email platform or delivers them through MailPanda’s own sending infrastructure (“PandaSend”). This policy explains what we collect, why, and the choices you have. It covers mailpanda.ai, app.mailpanda.ai, and the MailPanda integrations (including our Klaviyo app). Questions any time: steven@mailpanda.ai.
Information we collect
- Account information. Name, email address, and sign-in identifiers, managed by our authentication provider (Clerk). We never see or store your password.
- Store & brand content. When you connect your store, we analyze its public pages — products, images, copy, colors — to build your brand profile and design on-brand emails.
- Email platform data. When you connect Klaviyo via OAuth, you choose the permissions we receive. We access account details (such as your sender info and business address), lists and segments, flows, campaigns, templates, and engagement and order metrics to plan, build, and publish your email program. Access tokens are stored encrypted in transit and scoped to your workspace, and we access only what the connected features need.
- Content you create. Briefs, chat messages with the assistant, edits, and the emails and flows generated in your workspace.
- Billing information. Shopify app subscriptions are approved and billed through Shopify. Non-Shopify MailPanda plans are processed by Stripe. We store your plan, subscription status, and billing references — never card numbers. Existing Stripe subscriptions are not moved or canceled automatically when Shopify is connected.
- Usage data. Product analytics (pages viewed, features used, device and browser basics) via PostHog, used to improve MailPanda.
- Sending & deliverability data. When you send through PandaSend, we process the recipient addresses and message content needed to deliver each email via Amazon SES, and we record delivery events — sends, opens, clicks, bounces, spam complaints, and unsubscribes — to report performance, protect deliverability, and honor opt-outs.
Your customers’ data
To do its job, MailPanda may process data about your store’s customers — for example order events and the profile attributes that ride along with them (such as email address, name, and purchase history) synced from your connected platforms. MailPanda stores synced customer profiles, marketing consent states, order records, and storefront or engagement events in its workspace-scoped database; the available data depends on the connected integration, permissions, and features used. We process this data on your behalf and under your instructions, solely to segment audiences, configure flows, and measure performance for your brand. Your connected email platform may also retain its own audience records. We never sell customer data, never use it for advertising, and never use one brand’s data to benefit another.
How we use information
- Provide the service: analyze your brand, generate and publish emails, schedule campaigns, and sync with your email platform.
- Operate your account: authentication, billing, support, and important service notices.
- Improve the product: aggregate usage analytics and debugging.
- Keep things safe: fraud prevention, abuse detection, and legal compliance.
AI processing
MailPanda uses large language and image models to generate marketing content. Depending on the feature and configured provider, prompts, brand content, and reference images are sent through OpenRouter and its model providers, through fal and its model providers, or directly to Google’s Gemini API for image editing, solely to produce your results. We do not train our own models on your data, and we do not permit subprocessors to use your content for advertising.
The current application sends OpenRouter’s data-collection denial setting with its requests, while preserving any stricter zero-data-retention preference. Requests through the shared fal integration opt out of JSON request/response history and request a one-hour expiry for generated media. That expiry does not delete artwork saved separately in MailPanda. Direct Google requests are separate and are not covered by those OpenRouter or fal settings. These are request-level controls, not proof of zero retention, historical deletion, or provider-wide training restrictions. Actual provider accounts, applicable terms, and retention practices still require owner legal and operational verification before this draft is adopted.
Sharing & subprocessors
We share data only with the service providers that run MailPanda, including Vercel (hosting), Supabase (database & storage), Clerk (authentication), Shopify (Shopify app billing), Stripe (non-Shopify plan payments and existing Stripe subscriptions), PostHog (product analytics), Amazon Web Services (email delivery via SES when you send through PandaSend), OpenRouter and its model providers, fal and its model providers, and Google’s Gemini API (AI generation or editing, as described above). Connected platforms such as Klaviyo and Shopify process data for the integrations you use.
Optional design tools and support services process data only when their features are configured and used. Figma imports can read your connected account details and selected file metadata and designs; explicit exports send selected email designs and assets to Figma. Managed-service onboarding can send merchant contact details, brand names, and setup information to a private Slack channel when Slack provisioning is configured. This draft does not certify that all provider agreements or account settings have been verified.
We may also disclose information if required by law, or as part of a merger or acquisition (we’d notify you). We do not sell personal information.
Data retention & deletion
We keep your data while your account is active. Disconnecting an integration deletes its access tokens. “Start over” in Settings deletes your brand workspace — profile, flows, designs, and calendar. To delete your account and associated data entirely, email steven@mailpanda.ai and we’ll complete it within 30 days, except records we must keep for legal or accounting reasons.
Security
Data is encrypted in transit (TLS) and at rest by our database provider. Access to private workspace records is checked on the server using the applicable identity, role, and workspace scope. Private Shopify-embedded reads use verified session tokens and linked MailPanda membership. Public integration endpoints, such as storefront capture and webhooks, use route-specific checks rather than requiring a signed-in browser session. Integration access uses scoped, revocable OAuth tokens rather than master credentials wherever the platform supports it. No method is 100% secure, but we design for least privilege throughout.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Email steven@mailpanda.ai and we’ll honor verified requests. We never discriminate for exercising your rights.
International transfers
MailPanda is operated from the United States and our subprocessors may process data there and in other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses.
Children
MailPanda is a business tool and isn’t directed to anyone under 16. We don’t knowingly collect children’s data.
Changes to this policy
If we make material changes we’ll post the new policy here and update the effective date — and for significant changes, notify you by email or in the product.
Contact
MailPanda · steven@mailpanda.ai
Related policies
- Terms of Service — the agreement governing your use of MailPanda
- Acceptable Use Policy — anti-spam and prohibited sender rules
- Security Policy — our technical and organizational safeguards
