Privacy Policy

Previously published version: July 2, 2026. Read the historical version.

Proposed revision: September 22, 2026. Owner legal and operational review is required before adoption; these revisions are not yet effective in production.

MailPanda is operated by Manifest Five Equity LLC (“MailPanda”, “we”, “us”). MailPanda is an AI email marketer for e-commerce brands: it studies your store, designs campaigns and flows, and either publishes them to your connected email platform or delivers them through MailPanda’s own sending infrastructure (“PandaSend”). This policy explains what we collect, why, and the choices you have. It covers mailpanda.ai, app.mailpanda.ai, and the MailPanda integrations (including our Klaviyo app). Questions any time: steven@mailpanda.ai.

Information we collect

Your customers’ data

To do its job, MailPanda may process data about your store’s customers — for example order events and the profile attributes that ride along with them (such as email address, name, and purchase history) synced from your connected platforms. MailPanda stores synced customer profiles, marketing consent states, order records, and storefront or engagement events in its workspace-scoped database; the available data depends on the connected integration, permissions, and features used. We process this data on your behalf and under your instructions, solely to segment audiences, configure flows, and measure performance for your brand. Your connected email platform may also retain its own audience records. We never sell customer data, never use it for advertising, and never use one brand’s data to benefit another.

How we use information

AI processing

MailPanda uses large language and image models to generate marketing content. Depending on the feature and configured provider, prompts, brand content, and reference images are sent through OpenRouter and its model providers, through fal and its model providers, or directly to Google’s Gemini API for image editing, solely to produce your results. We do not train our own models on your data, and we do not permit subprocessors to use your content for advertising.

The current application sends OpenRouter’s data-collection denial setting with its requests, while preserving any stricter zero-data-retention preference. Requests through the shared fal integration opt out of JSON request/response history and request a one-hour expiry for generated media. That expiry does not delete artwork saved separately in MailPanda. Direct Google requests are separate and are not covered by those OpenRouter or fal settings. These are request-level controls, not proof of zero retention, historical deletion, or provider-wide training restrictions. Actual provider accounts, applicable terms, and retention practices still require owner legal and operational verification before this draft is adopted.

Sharing & subprocessors

We share data only with the service providers that run MailPanda, including Vercel (hosting), Supabase (database & storage), Clerk (authentication), Shopify (Shopify app billing), Stripe (non-Shopify plan payments and existing Stripe subscriptions), PostHog (product analytics), Amazon Web Services (email delivery via SES when you send through PandaSend), OpenRouter and its model providers, fal and its model providers, and Google’s Gemini API (AI generation or editing, as described above). Connected platforms such as Klaviyo and Shopify process data for the integrations you use.

Optional design tools and support services process data only when their features are configured and used. Figma imports can read your connected account details and selected file metadata and designs; explicit exports send selected email designs and assets to Figma. Managed-service onboarding can send merchant contact details, brand names, and setup information to a private Slack channel when Slack provisioning is configured. This draft does not certify that all provider agreements or account settings have been verified.

We may also disclose information if required by law, or as part of a merger or acquisition (we’d notify you). We do not sell personal information.

Data retention & deletion

We keep your data while your account is active. Disconnecting an integration deletes its access tokens. “Start over” in Settings deletes your brand workspace — profile, flows, designs, and calendar. To delete your account and associated data entirely, email steven@mailpanda.ai and we’ll complete it within 30 days, except records we must keep for legal or accounting reasons.

Security

Data is encrypted in transit (TLS) and at rest by our database provider. Access to private workspace records is checked on the server using the applicable identity, role, and workspace scope. Private Shopify-embedded reads use verified session tokens and linked MailPanda membership. Public integration endpoints, such as storefront capture and webhooks, use route-specific checks rather than requiring a signed-in browser session. Integration access uses scoped, revocable OAuth tokens rather than master credentials wherever the platform supports it. No method is 100% secure, but we design for least privilege throughout.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Email steven@mailpanda.ai and we’ll honor verified requests. We never discriminate for exercising your rights.

International transfers

MailPanda is operated from the United States and our subprocessors may process data there and in other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses.

Children

MailPanda is a business tool and isn’t directed to anyone under 16. We don’t knowingly collect children’s data.

Changes to this policy

If we make material changes we’ll post the new policy here and update the effective date — and for significant changes, notify you by email or in the product.

Contact

MailPanda · steven@mailpanda.ai

Related policies