Cairry← Back to home

Privacy Policy

Last updated May 3, 2026

This Privacy Policy explains what information Cairry (“Cairry”, “we”, “us”) collects when you use our service, how we use it, and the choices you have. By using Cairry you agree to this policy.

1. Information you provide

  • Account: name, email, password (hashed), and authentication tokens from sign-in providers (e.g. Google).
  • Company info: company name, website, and any settings you enter.
  • Connected services: when you connect a storefront (e.g. Shopify) or social account (e.g. TikTok), we receive an OAuth token from that provider plus the scopes you granted.
  • Posts and assets: drafts, scheduled posts, generated copy and images.

2. Information we receive from connected platforms

When you connect a third-party account, we may receive only what you authorize:

  • TikTok: your basic profile (open ID, display name, avatar) and, if you grant publishing permission, the ability to upload and publish videos you have approved. We do not read your private messages, browsing history, or follower lists.
  • Shopify: product catalog, prices, and stock data needed to generate posts and affiliate links.

We never sell or share data we receive from any platform with third parties for advertising, analytics, or model training.

3. How we use your information

  • To provide the Service: generate, schedule, and publish posts on your behalf.
  • To show you your accounts, products, and post history in your dashboard.
  • To send service-related emails (billing, security, important changes).
  • To prevent abuse and improve reliability.

4. AI providers

Cairry uses third-party AI providers (such as Google Gemini and OpenAI) to generate post copy and images. We send only the minimum input required (e.g. product title, description, brand voice) and we configure these providers to not retain or train on your content where that option is available.

5. Storage and security

Data is stored in our cloud database (Supabase, hosted on AWS). Access tokens for connected platforms are encrypted at rest. Communications between your browser and Cairry use HTTPS. Access to production data is limited to authorized personnel.

6. Retention

We keep your data while your account is active. When you disconnect a platform we delete its access token. When you delete your account we remove your personal data within 30 days, except where we are required to retain it for legal or accounting reasons.

7. Your rights

  • Access, correct, or export the personal data we hold about you.
  • Disconnect any third-party platform at any time from your dashboard.
  • Delete your account at any time from settings.
  • If you are in the EEA, UK, or California, you have additional rights under GDPR/CCPA including the right to object, restrict processing, and lodge a complaint with a supervisory authority.

To exercise these rights, email privacy@cairry.com.

8. Cookies

We use a small number of essential cookies to keep you signed in and remember which company you are working in. We do not use advertising cookies.

9. Children

Cairry is not intended for anyone under 18 and we do not knowingly collect data from children.

10. International transfers

Cairry is operated from the United States. If you are outside the US, your data will be transferred to and processed in the US under appropriate safeguards.

11. Changes

We may update this policy. Material changes will be communicated by email or in-app notice before they take effect.

12. Contact

Questions or requests? Email privacy@cairry.com.