Legal

Privacy Policy

Last updated: May 2026

Draft. This policy is a working draft. Review with counsel before relying on it as your final published policy.

Overview

Mandate Technologies, Inc. (“Mandate”, “we”, “us”) provides a trust and policy enforcement layer for autonomous AI agent commerce. This policy explains what information we collect when you use our website, dashboard, API, SDK, and middleware, how we use it, and the choices you have.

Information we collect

  • Account information. Name, email address, and authentication credentials when you sign up.
  • Configuration data. Agents, mandates, sellers, API keys, and policy settings you create.
  • Transaction metadata. Policy evaluations, payment proofs, transaction amounts, merchant domains, timestamps, and audit log entries.
  • Operational logs. Request logs, error logs, and performance telemetry necessary to operate the service.

How we use information

We use the information above to operate, secure, and improve the service, to enforce policies and detect abuse, to communicate with you about your account, and to comply with legal obligations. We do not sell your personal information.

Sharing

We share information with service providers who help us run the platform (such as hosting and database providers), with your authorized integrations, and when required by law. We do not share customer transaction data across customers.

Data retention

We retain account, configuration, and transaction data for as long as your account is active and as needed to comply with legal, accounting, and audit requirements. You can request deletion of your account data at any time.

Security

We use industry-standard safeguards to protect your data, including encryption in transit, authentication-scoped access, and audit logging on sensitive operations. No method of transmission or storage is perfectly secure; we will notify affected users in the event of a material breach as required by applicable law.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing. To exercise these rights, contact us using the details below.

Contact

Questions about this policy? Email hello@mandate.dev.