Privacy policy
Last updated October 1, 2026
3rd Hand(“we”) builds AI-powered operating platforms for businesses, starting with Ecom AI for ecommerce brands. This policy explains what we collect, why, where it is kept and how to have it deleted. We do not sell personal information, and we do not use the data we read from your accounts to advertise to anyone.
Who this covers
Visitors to our website, people who request access, and the brands (and their team members) who use 3rd Hand and connect their accounts to it.
What we collect
- When you request access:your name, work email, optional phone number and role; your brand name, website, revenue and ad-spend ranges, the software you use, and anything you write to us. We also keep a one-way hash of your IP address, used only to limit spam, and your browser's user agent.
- When you sign in: your email address. Sign-in uses one-time email links; we do not store passwords.
- From Shopify, when you connect it (read-only):order totals, dates, statuses, discounts, shipping, tax and refunds; products, variants, prices and the “Cost per item” you set. For each order we keep Shopify's anonymous customer ID to calculate repeat-purchase and lifetime value. We do not store customer names, email addresses, phone numbers or addresses.
- From Klaviyo, when you connect it (read-only):your account name and the performance of your campaigns and flows: recipients, unique opens and clicks, conversions, and the revenue Klaviyo attributes to them. We do not store your subscribers' profiles.
- From Meta, when you connect it (read-only): the names and IDs of the ad accounts you choose to share, and their ad performance: spend, impressions, clicks, and the purchases and purchase value Meta reports, by campaign and ad, per day. We do not read or store information about the people who saw your ads.
How we use it
Only to provide the service to the brand that connected it: dashboards, daily scorecards, profit and attribution reporting, and to review access requests and contact you about them. Data from one brand is never shown to another brand.
How it is protected
- The access tokens your accounts grant us are encrypted with AES-256-GCM before they are stored.
- Each brand's data is separated at the database level, so one account can never read another's.
- All traffic uses HTTPS (TLS 1.2 or higher). Access to Shopify, Klaviyo and Meta is read-only.
Where it is kept, and who processes it for us
- Supabase (database and sign-in), hosted in the United States.
- Vercel (website and application hosting), United States.
- Resend (sends staff notifications about new access requests).
These providers process data only on our instructions. If you are outside the United States, your information is transferred to and stored in the United States.
How long we keep it
Connected-account data is kept while the connection is active. When you disconnect an account in 3rd Hand, we delete the data pulled from it and its access token straight away. When you uninstall our Shopify app, Shopify notifies us and we delete that store's data. Access requests that do not become customers are deleted on request. Records of system activity are kept as long as needed to run and secure the service.
Your choices and rights
You can disconnect any account at any time from your 3rd Hand screen, and remove our access from Shopify, Klaviyo or Meta directly. You can ask us for a copy of your information, to correct it, or to delete it. See how to delete your data.
Contact
Questions or requests: syndicatefinancialsvs@gmail.com. We reply within 30 days.
Changes
If we change this policy we will update the date above, and tell active customers about material changes.