Probat AI Inc. Privacy Policy

Effective Date: February 14, 2026

Last Updated: September 25, 2026

This Privacy Policy explains how Probat AI Inc. ("Probat AI," "we," "us," or "our") collects, uses, discloses, and otherwise processes information in connection with our website (probat.ai), our web application (probat.app), the pages we host and publish for our customers, our Shopify app, and related services (collectively, the "Services").

1. Company Information

Probat AI Inc.

1908 Thomes Avenue, STE 12612, Cheyenne, Wyoming 82001

Privacy contact: privacy@probat.ai

Support: support@probat.ai

2. Scope and Roles (Controller vs Processor)

2.1 When we act as a Controller

We act as a "controller" (or equivalent) for information we process for our own purposes, such as:

  • Account creation and administration
  • Billing and subscription management
  • Marketing and communications
  • Website analytics and product usage analytics for operating the Services
  • Security, fraud prevention, and compliance

2.2 When we act as a Processor / Service Provider

When Customers use the Services to publish pages, run tests, connect advertising platforms or a Shopify store, or send mailed campaigns, we process information about their end users on the Customer's behalf: visitors to the pages we host, shoppers on the Customer's Shopify store, and recipients of the Customer's mailed campaigns. In those cases we act as a "processor" or "service provider" (or equivalent), the Customer controls what data is collected and how it is used, and the Customer is responsible for providing notices and obtaining any required consents.

3. Information We Collect

We may collect the following categories of information:

3.1 Account and Contact Information

Name, email address, company name, role/title, login credentials (stored in hashed form when applicable), and account settings.

3.2 Billing and Transaction Information

Billing contact information, billing address, invoices, subscription status, and transaction records. Payment card data is typically processed by payment processors; we generally receive limited payment tokens and metadata.

3.3 Customer Data Submitted Through the Services

Customers may provide information to the Services such as:

  • Pages imported from the Customer's website (markup, styles, images, fonts, and brand assets) and the pages the Customer builds or edits from them
  • Advertising platform data when the Customer connects Meta, Google, TikTok, or Pinterest: ad account metadata, campaigns, ad sets, ads, ad creative (headlines, text, images, and video), destination URLs, audience and targeting settings, and performance data (impressions, clicks, spend)
  • Shopify store data when the Customer connects a store: the store's name, domains, currency, and settings; the product catalog (titles, descriptions, images, prices, variants, and availability); theme files we read or write when the Customer publishes a page into the store; and order information limited to the order id and number, totals, currency, line items, timestamps, status, and the attribution attributes our script adds. We do not request or store buyer names, email addresses, phone numbers, or addresses.
  • Mailing lists the Customer uploads for mailed campaigns (recipient names and mailing addresses) and the property information we attach to them: an estimated property value from a licensed property data provider and a street-level photograph of the property
  • Form definitions, consent text, tracking pixel identifiers, and other configuration
  • Prompts, instructions, and outputs generated through the Services' AI features
  • Logs or diagnostics submitted for troubleshooting

3.4 End User Data (Collected Through Customer Implementations)

Depending on Customer configuration, the Services may process the following about visitors to pages we host for a Customer, shoppers on a Customer's Shopify store, and recipients of a Customer's mailed campaigns:

  • Page views, clicks, and form submissions on hosted pages, together with the ad and page version involved
  • A random session identifier stored in a cookie on the hosted page and kept by us in hashed form
  • IP address, browser and device type, and the page URL
  • Advertising click identifiers that ad platforms add to the page URL (for example fbclid, gclid, ttclid, or epik) and Meta browser identifiers, used to report conversions back to the Customer's own ad platforms
  • Consent state, where the Customer's consent banner reports it
  • Information a visitor submits in a Customer's form, using the fields the Customer defines
  • Purchases on a Customer's Shopify store, limited to the order information listed in Section 3.3
  • Scans of the QR code on a mailed card and views of the page it opens

3.5 Usage and Device Data

Information about how the Services are accessed and used, such as:

  • IP address
  • Device type, OS, and browser type
  • Approximate location derived from IP
  • Feature usage, logs, timestamps, performance data, errors, and crash reports

3.6 Cookies and Similar Technologies

We use cookies, local storage, and similar technologies for:

  • Authentication
  • Preferences
  • Security
  • Basic usage analytics

On pages we host for Customers we set one session cookie, used only to measure the page and attribute conversions. It contains a random identifier and no personal details. You can control cookies through your browser settings. Some features may not function properly without them.

3.7 Information Collected When You Visit or Log In

When you visit or log into our website, we use cookies and similar technologies to collect certain information about your visit. This includes:

  • Usage Data: Information about how you use our site, such as pages visited, time spent on pages, and links clicked.
  • Device Information: Details about the device you use to access our site, including IP address, browser type, and operating system.
  • Personal Data: If you provide it, we may collect information such as your email address, phone number, or other contact details.

We may also combine this information collected automatically with other data we receive from third-party sources, such as data providers and marketing partners, to create a more complete profile of you. We then use this profile to communicate with you, including providing personalized advertising and promotional content based on your interests and browsing behavior. You may opt out of this at any time.

4. How We Use Information

We use information to:

4.1 Provide and Operate the Services

  • Create and manage Accounts and authenticate users
  • Import, edit, publish, and host pages for Customers, including publishing pages into a Customer's Shopify store
  • Personalize a hosted page or a Customer's store page to match the ad a visitor clicked
  • Measure page views, clicks, form submissions, and purchases, and report results to the Customer
  • Forward the Customer's conversions to the Customer's own advertising platforms when the Customer configures it
  • Print and mail cards for the Customer's mailed campaigns
  • Maintain and support platform operations

4.2 Improve and Develop the Services (Including AI Features)

We may use Customer Data such as imported pages, brand assets, ad creative, prompts, configurations, and generated outputs to:

  • Improve and develop the Services
  • Train, fine-tune, validate, and evaluate models and automation systems
  • Build new features and product capabilities
  • Troubleshoot, test, and debug systems

End User Data, Shopify order data, and the personal data of mailed-campaign recipients are excluded from this. We use them only to provide the Services to the Customer they belong to and to produce aggregated statistics that cannot identify a person. We do not use them to train models, for other Customers, or for any other purpose.

When Customers connect advertising platforms such as Meta, Google, TikTok, or Pinterest, we process ad account metadata, campaign and ad information, ad creative content (including headlines, primary text, images, and video), destination URLs, audience and targeting settings, and basic performance metrics (impressions, clicks, spend). We use this data to generate a landing page experience that matches each specific ad for that Customer, to update the ad's destination URL to point to that experience when the Customer asks us to, to measure results, and to surface this information back to the Customer in our dashboard. We use Customer ad-platform data only to provide the Services to the Customer it was collected from. We do not sell or share Customer ad-platform data with third parties, and we do not use it to build profiles of end users.

Data we receive from Pinterest through its API (ad accounts, campaigns, ads, Pin creative, destination URLs, and performance metrics) is handled the same way and in line with Pinterest's developer and advertising guidelines: we use it only to build and measure pages for the Customer whose account it came from, to update a Pin's destination when the Customer asks, and to report the Customer's conversions back to Pinterest when the Customer configures it. We do not combine it with data from other platforms to profile a person, we do not use it for our own advertising, and we delete it when the Customer disconnects Pinterest or Pinterest asks us to.

When Customers connect a Shopify store, we read the store's catalog and settings to build and personalize pages, we write pages into the store's theme when the Customer publishes, and we receive order information so the Customer can see which ads and pages led to purchases. We read order totals, line items, timestamps, status, and the attribution attributes our script adds; we do not request buyer names, email addresses, phone numbers, or addresses. Shopify store data is used only to provide the Services to the Customer whose store it is. It is never sold or shared, and it is not used to train models.

Pages may be personalized automatically: the Services choose which version of a page a visitor sees based on the ad the visitor clicked. This is the only automated decision the Services make about a visitor, and it has no legal or similarly significant effect on anyone. Visitors can opt out: a browser Global Privacy Control signal or a declined consent banner serves the Customer's standard page instead, and visitors may also contact the Customer.

The Services' AI features send page content, brand assets, ad creative, prompts, and, for mailed campaigns, property photographs to AI model providers acting as our subprocessors, which use them only to return the requested output.

For mailed campaigns, recipient names and mailing addresses come from the Customer. We attach an estimated property value from a licensed property data provider and a street-level photograph of the property, print a card addressed to the recipient through a print-and-mail vendor, and record when the card's QR code is scanned. Recipients can ask the Customer to be removed from future mailings.

We may create aggregated or de-identified data for analytics, benchmarking, research, and product improvement.

4.3 Security and Fraud Prevention

  • Protect accounts and prevent abuse
  • Monitor for suspicious activity
  • Maintain system integrity and safety

4.4 Billing and Account Management

  • Process payments
  • Manage subscriptions and plans
  • Send receipts, billing notices, and service communications

4.5 Communications

  • Respond to support requests
  • Send product updates and administrative messages
  • Send marketing messages where permitted by law (you can opt out)

4.6 Legal Compliance

  • Comply with legal obligations
  • Enforce our Terms
  • Resolve disputes
  • Protect rights and safety

5. How We Disclose Information

We may disclose information to:

5.1 Service Providers and Subprocessors

We use vendors to help operate the Services: hosting and databases (for example Railway and Supabase), content delivery and storage (Cloudflare), AI model providers (Anthropic, Google, and fal.ai), email delivery (Resend), product analytics (PostHog), property data (ATTOM), map imagery (Google), payments, customer support tools, and a print-and-mail vendor for mailed campaigns. These providers process information under contractual obligations consistent with this Privacy Policy. The current list is available on request at privacy@probat.ai.

5.2 Integrations You Enable

If you connect Meta, Google, TikTok, Pinterest, or Shopify, we exchange with that platform the information needed to run the integration, as directed by you: for example, we update an ad's destination URL, report a conversion to your ad platform, or write a page into your Shopify theme.

5.3 Legal and Safety Reasons

We may disclose information if we believe in good faith it is necessary to:

  • Comply with law or legal process
  • Protect our rights, property, and safety
  • Investigate fraud, security incidents, or misuse
  • Enforce our Terms or prevent harm

5.4 Business Transfers

We may disclose information in connection with a merger, acquisition, financing, reorganization, or sale of assets.

5.5 Aggregated / De-Identified Information

We may disclose aggregated or de-identified information that cannot reasonably be used to identify an individual.

5.6 No Sale of Personal Information

We do not sell personal information and do not share it for cross-context behavioral advertising. We honor opt-out signals such as Global Privacy Control.

6. Data Retention

We retain information for as long as necessary for the purposes described in this Policy, including:

  • While your Account is active
  • To provide the Services and comply with legal obligations
  • For security, fraud prevention, dispute resolution, auditing, and enforcing agreements
  • In backups and logs for limited periods consistent with business operations

In particular: End User Data is kept while the Customer's account is active. Integration credentials are deleted when the Customer disconnects the integration, including a Shopify store; the store's synced catalog stays until the Customer reconnects or deletes it. When the Customer uninstalls our Shopify app, or Shopify sends us an erasure request on a store's behalf, we also delete that store's catalog and any personal data. Mailing lists and lead records are deleted with the account or on the Customer's request. We may retain aggregated or de-identified data indefinitely.

7. Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, additional application-level encryption of integration credentials, access controls, and audit logging of changes made in the Services. No system is completely secure. You are responsible for maintaining the security of your credentials and integrations.

8. International Data Transfers

Information may be processed in the United States and other locations where we or our service providers operate. When required by law, we use appropriate safeguards for cross-border transfers.

9. Your Choices and Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete personal information
  • Object to or restrict certain processing
  • Opt out of marketing communications
  • Receive a copy of certain information

If we process End User Data on behalf of a Customer, requests should generally be directed to the Customer (the controller). We may assist Customers as required. Shoppers on a Customer's Shopify store exercise their rights through the merchant; we honor the customer data request and erasure requests Shopify sends us on a merchant's behalf. Visitors to a hosted page can opt out of personalization with a Global Privacy Control signal or by declining the Customer's consent banner.

To make a request, contact privacy@probat.ai.

10. Data Deletion

You can request deletion of your Probat AI account and all associated data at any time.

10.1 How to delete your data

  • In the app: open Settings → Account → Delete account in the Probat AI web app. This schedules your account and associated personal data for deletion immediately.
  • By email: send a request to support@probat.ai with the subject "Delete my data" from the email address registered to your account. We will confirm receipt and process the deletion.

10.2 What gets deleted

Your Probat AI account, profile information, pages and configurations, imported ad creatives, connected Shopify store data, mailing lists, integration credentials (including OAuth tokens for any connected advertising platform or Shopify store), and associated personal data are removed from our production systems.

10.3 Timeframe

We process deletion requests within 7 business days of receipt. Data is removed from production systems within that window. Residual copies may persist in encrypted backups for up to 30 days, after which they are automatically purged, except where retention is required for legal compliance, security, dispute resolution, or enforcing our agreements.

10.4 Disconnecting integrations

If you have connected Meta Ads, Google Ads, TikTok Ads, Pinterest Ads, a Shopify store, or any other third-party platform, you can revoke Probat AI's access at any time from Integrations in the web app. Disconnecting deletes the stored OAuth tokens and stops all further API calls on your behalf. You can also revoke our access directly from the third party (for example, your Meta Business Integrations page, your Google Account security page, the connected apps page in your Pinterest settings, or by uninstalling the app from your Shopify admin, which also removes the store's catalog from our systems).

10.5 End-user deletion requests

If you are an end user of a Probat AI Customer (for example, a visitor to a page we host, a shopper on a store that uses our Shopify app, or the recipient of a mailed card), please contact the Customer directly. They control what data is collected about you and how to fulfill deletion requests; we will assist the Customer as required.

11. Marketing Communications

You may opt out of marketing emails by using the unsubscribe link or by contacting privacy@probat.ai. You may still receive essential service and administrative communications.

12. Children

The Services are not intended for children, and we do not knowingly collect personal information from children under 13 (or under 16 in certain jurisdictions).

13. Third-Party Links and Services

The Services may contain links to third-party websites or services. This Policy does not apply to third-party practices. Your use of third-party services is governed by their terms and privacy policies.

14. Changes to This Privacy Policy

We may update this Policy from time to time. The "Last Updated" date reflects the most recent revision. Continued use of the Services after an update constitutes acceptance of the updated Policy.

15. Contact Us

If you have questions or requests, contact us:

Email: privacy@probat.ai

Mail: Probat AI Inc., 1908 Thomes Avenue, STE 12612, Cheyenne, Wyoming 82001