Privacy Policy
The short version
- Makerside is an AI office for founders who run product (D2C) and service businesses. To do that work, it uses your account details, what you tell your team, and data from the accounts you choose to connect.
- Connected accounts are read-only unless you approve an action. You can disconnect any of them at any time.
- Your AI team acts only through proposals you approve for anything consequential: spending, posting, sending, publishing or changing prices.
- We never sell your data. We never use your data or your customers' data to train general-purpose AI models.
- Marketplace data (for example from Amazon) is used only for that seller. It is never shared with or combined across other sellers.
- Your customers pay you directly through Stripe. Makerside never holds your money.
- You can ask us for a copy of your data, or ask us to delete it, at saif@getsauda.com.
1. Who we are
Makerside is operated by Saudaa Labs Pvt Ltd, 706, Bhaveshwar Arcade, LBS Marg, Mumbai, Maharashtra, 400086, India ("Makerside", "we", "us"). You can reach us about privacy at saif@getsauda.com.
For your account and your own business data, we are the controller: we decide how that data is used, as this policy describes. For the personal data of your customers, we act as your processor (see Your customers' data).
2. What this policy covers
This policy covers the Makerside web app (the office and the founder console), the Makerside connector that other AI assistants can use, and our email and WhatsApp channels. It also covers the pages Makerside publishes for your business, such as booking pages, surveys and your service website, to the extent we process your customers' data there.
It does not cover third-party services you connect, such as Shopify, Google or Instagram. Their own privacy policies apply to the data they hold.
3. Information we collect
Account and sign-in
Sign-in is handled by Clerk, with Google, Apple or an email link. When you sign in, we receive and keep:
- your name and profile photo, as your sign-in provider shares them;
- your verified email address and the sign-in account's identifier;
- your browser's time zone;
- the domain of your email address, if it is a verified work address (not a free-mail address such as Gmail).
We use these to run your account, pre-fill onboarding and schedule reminders in your time zone. They are only ever suggested to your founder profile; you decide whether to keep them. We do not look you up anywhere else.
If you link WhatsApp, we keep your verified phone number. We also keep the brands you belong to and your role in each.
What you give your team
Your chats with your AI team, your brand and founder profile, plans, decisions, approvals, and the files you upload (for example an orders export or a cost sheet).
Connected accounts
Data from the accounts you connect. See Connected accounts.
Your customers' data
Bookings, orders, mailing-list sign-ups, support messages, quote requests and survey responses. See Your customers' data.
Public information
When your team researches your market, it reads public web pages and public market data. If you ask it to, it also imports your own public profiles (for example LinkedIn) through a licensed data provider, to suggest updates to your founder profile.
Technical and usage data
Server logs, audit logs of actions and approvals, records of what each agent run did, and error reports. Error reports from your browser contain errors only: no session recordings, and web addresses lose their query strings and email addresses are masked before anything is sent.
4. Connected accounts
You choose which accounts to connect. Each connection goes through the provider's own permission screen (OAuth). We never see your password for that service. Sign-in tokens for accounts you connect are managed by Nango, our connection provider; Makerside's own database keeps only a reference to the connection, not the token. Any API key Makerside stores is encrypted (AES-256-GCM) before it is written, never kept in plain text. Tokens are never given to AI agents. Every use of a token is logged with its purpose.
| Service | What we read or do | Why |
|---|---|---|
| Shopify | Orders (with refunds), products, inventory and payouts, read-only. We import up to the last 12 months of orders when you connect, and then keep reading new orders, refunds and cancellations while the store is connected. | To understand your sales, stock, cash and margins. |
| Your professional account's profile (username, name, bio, follower counts), posts and reels with their captions and metrics, reel insights, and stories while they are live, read-only. | To learn your brand's voice and what works, and to draft a founder profile you review. | |
| TikTok and X | Your own profile and your posts or videos, read-only. | The same as Instagram. |
| Google Calendar and Google Meet | When you connect Google Calendar we see when you are busy, across the calendars you choose to count (your main calendar until you choose), and the names of your calendars so you can choose. We never read or store event titles, descriptions, guests or locations. If you choose "Let Mo add events", we create a calendar named Makerside and add only events you approve to it, and we never invite anyone. With your permission, events for confirmed bookings, with Google Meet links for online sessions. You can disconnect at any time, and your choices of calendars are deleted when you do. | To offer only times you are free, to check a proposed time against your calendar and suggest meeting times within your working hours, and to put approved events and bookings in your calendar. If your calendar cannot be read, Makerside tells you so and does not assume you are free. |
| YouTube | Live broadcasts on your channel, created only after you approve each one. | To run online classes and webinars. |
| Zoom | Meetings in your Zoom account for online sessions. | To give your customers a join link. |
| Coming later: Amazon (Selling Partner API) and TikTok Shop | Your orders, inventory, fees and settlements, read-only. | To understand sales and cash across your marketplaces. |
| Coming later: Meta Ads, Google Ads and Google Analytics 4 | Ad spend and performance, and site analytics, read-only. | To measure what your marketing earns. |
| Coming later: Klaviyo, QuickBooks and Xero | Email marketing results, and your accounts and reports, read-only. | To see your customers' engagement and your books in one place. |
- Read-only unless you approve. Connections read. Anything that changes something in a connected account (for example creating a calendar event, a meeting or a broadcast) happens only after you approve it, or after you turn on a feature that does it for you, such as creating the meeting for a confirmed online booking.
- Revoke at any time. Disconnect an account in your office, and we stop reading from it and delete its access token. You can also remove Makerside's access in the provider's own settings.
- Deletion. When you disconnect an Instagram, TikTok or X account under Connected accounts, we delete it and everything we imported from it. When you disconnect a store or marketplace, we stop reading from it; the orders and products already imported stay in your workspace until you ask us to delete them. We keep what the law requires, such as fee statements (see How long we keep data).
5. Google user data
Makerside's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data (your calendar free and busy times, and the events you approve us to create, your YouTube broadcasts, your Google Ads and Analytics data, and your Google sign-in profile) only to provide the features you use, as described above.
- We do not transfer it to anyone else, except as needed to provide those features, for security, to comply with the law, or as part of a merger or acquisition.
- We do not use it for advertising, and we do not sell it.
- No person at Makerside reads it unless you ask us to, it is needed for security or to investigate abuse, the law requires it, or it has been aggregated and made anonymous for our internal operations.
- We do not use it to develop, improve or train generalized AI or machine-learning models.
You can remove Makerside's access at any time in your Google account's permissions, or by disconnecting in your office.
6. Instagram, Meta and WhatsApp data
We use data from Instagram only to provide Makerside's features to the account owner who connected it: understanding the brand, suggesting ideas and drafting a founder profile the founder reviews. We do not sell it, use it for advertising, or share it with other Makerside customers.
- Disconnect in Makerside: under Connected accounts, we revoke access and delete the account and everything we imported from it.
- Remove Makerside in Instagram's settings: Meta tells us, and we disconnect, revoke the connection and stop reading. What we already read is kept until a deletion is requested, by you in Makerside or through Meta.
- Ask for deletion through Meta: Meta sends us your request, and we delete everything we imported from your account. You get a confirmation code and a link where you can check the status.
WhatsApp messages are sent and received through Meta's WhatsApp Business Platform (see Email and WhatsApp).
7. Marketplace data
Data from a marketplace such as Amazon (through the Selling Partner API) or TikTok Shop is used only to serve the seller who connected it, inside that seller's own workspace.
- It is never shared with, shown to or combined with data of other sellers or other Makerside customers.
- It is never aggregated across sellers, used for benchmarks, or used to train AI models.
- It is never sold or used for advertising.
- It is deleted when you ask us to, except records the law requires us to keep.
8. How AI processes your data
- Your AI team. Each brand's agents run separately from every other brand's. They reach AI model providers through an AI gateway, and receive only what a task needs. They never receive passwords, access tokens or payment details.
- Web research. A separate, quarantined reader reads public web pages. It never receives your business data: only a general question and a web address. What it finds is treated as untrusted and is never followed as an instruction.
- Approvals. Consequential actions (spending money, posting, sending messages, publishing, changing prices, submitting forms online, starting payments) become proposals. Nothing happens until you approve.
- Browser tasks. When a task needs a website, it runs in an isolated cloud browser. You type any login, one-time code or payment detail yourself; the agent never sees them. Each submit waits for your approval. Session recordings are kept for 90 days so you can review them.
- Code sandbox. When your team makes files such as spreadsheets or decks, the code runs in an isolated sandbox with no network access and none of our credentials. The sandbox is discarded after each run.
- No training on your data. We do not use your business data or your customers' data to train general-purpose AI models. Your team learns your preferences only inside your workspace, from corrections you approve. A reusable skill may be made available to other brands only after Makerside staff review it to check that it describes a method and contains none of your business's data.
- AI can be wrong. Check what your team tells you before relying on it.
9. Voice notes
You can send your AI team a voice note instead of typing. A speech provider turns the recording into text, and that text is treated as a message from you.
- Who turns it into text. OpenAI (United States) is Makerside's only speech provider.
- What is stored. The recording is stored in a folder for your brand and is marked to be deleted after 30 days by default. The text is saved in your chat as your message.
- Deleting recordings sooner. In your voice settings you can have each recording deleted as soon as it has been turned into text. A recording is deleted even when the provider could not transcribe it.
- Spoken replies. Your team can also answer with a spoken reply. The text of the reply is sent to OpenAI to be spoken, and the audio is stored the same way and marked to be deleted after 30 days, whatever you chose for recordings.
- First use. When you first send a voice note, we record your consent to the voice notice: who you are, when, and which version of the notice.
- Turning voice off. If you turn voice off in your voice settings, voice notes are not turned into text and no reply is spoken.
- No voice biometrics. Makerside does not build voiceprints or identify people by their voice. A voice note is only turned into text, and a reply only into speech.
- Mistakes. A transcript can contain errors, and your team is told so.
- Your customers' voice notes. A voice note from one of your customers is turned into text only if you have turned that on in your voice settings. It is off until you do. If you turn it on, you are responsible for telling your customers that their voice notes are turned into text by this provider.
- Deletion. Your voice settings and consent records are deleted with your brand. Every recording and spoken reply stored for your brand can be deleted in one step, because they are all kept in your brand's folder.
OpenAI receives the recording, or for a spoken reply its text, so it can do this.
10. Your customers' data
When your customers book with you, buy from you, join your mailing list, message your business, request a quote or answer your survey, Makerside processes their data on your behalf and on your instructions. For that data, you are the controller and we are your processor.
- This can include names, contact details, booking and order details, agreements they accepted, messages and survey answers.
- We use it only to provide Makerside to you. We do not use it for our own purposes, sell it, or share it with other Makerside customers.
- Marketing email goes only to people who confirmed their subscription, and every email has a one-click unsubscribe.
- Surveys ask respondents to confirm they are 18 or over.
- You are responsible for having a lawful basis to collect your customers' data, and for telling them how you use it.
If you are a customer of a business that uses Makerside, please contact that business about your data. We will help them respond.
11. Payments
- Your customers pay you directly through Stripe Connect. Card and bank details are entered on Stripe's own pages; Makerside never sees or stores them.
- We keep your Stripe account's identifier and status, the status and amount of each payment we created, and a ledger of the sales our fee applies to (amount, currency, the order's identifier, and any refunds).
- Makerside never holds your funds, never moves money for you, and never files taxes for you.
- Stripe's own privacy policy applies to the data Stripe collects.
How our fee works is in the Terms of Service.
12. Email and WhatsApp
- Email is sent and received through Amazon Simple Email Service (SES): your campaigns and flows to subscribers who opted in, your customers' support emails and your replies, and messages to other businesses that you approve (for example an enquiry about renting a space).
- WhatsApp goes through Meta's WhatsApp Business Platform: your conversations with your team, reminders you asked for, the code that verifies your number when you link it, and, if you connect a business number, your customers' support messages and your replies.
- Amazon and Meta process these messages to deliver them, under their own terms.
14. Where data is stored
Makerside is hosted on Amazon Web Services in the Asia Pacific (Mumbai) region, in India. Some of our service providers process data in other countries, including the United States.
15. Security
- Data is encrypted in transit (TLS) between your browser and Makerside, and between our servers and our database.
- Each brand's data is isolated from every other brand's: every request is checked against the brand it belongs to, every query our code runs is limited to that brand, and each brand's agents run separately.
- Sign-in tokens for connected accounts are managed by Nango, and any API key we store is encrypted (AES-256-GCM) before it is written. Neither is ever given to AI agents.
- Our services connect to the database with restricted roles, not an administrator login. Every credential use, consequential action, approval and staff access is written to an audit log.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
16. How long we keep data
- Your account and business data: while your account is active, and deleted when you ask us or close your account.
- Connected accounts: access tokens are deleted when you disconnect. Instagram, TikTok and X accounts disconnected under Connected accounts are deleted with everything imported from them; imports from a store or marketplace stay until you ask us to delete them (see Connected accounts).
- Raw data from a public-profile import: 30 days.
- Customer conversation transcripts: 12 months by default, after which the transcript is deleted and only its outcome is kept.
- Survey open-text answers: 12 months, after which only the totals remain.
- Browser session recordings: 90 days.
- Voice recordings and spoken replies: marked to be deleted after 30 days by default; a recording is deleted right after it is turned into text if you choose (see Voice notes).
- Uploaded files you did not confirm for import: 7 days.
- Payment and fee records: as long as tax and accounting law requires.
Deleted data can remain in backups for a period after it is deleted.
17. Your rights and choices
Depending on where you live (including under the GDPR, the UK GDPR, India's Digital Personal Data Protection Act and California's CCPA), you have the right to:
- know what personal data we hold about you and get a copy, including in a portable format (export);
- correct it;
- have it deleted;
- object to or restrict how we use it;
- withdraw consent, for example by disconnecting an account;
- opt out of the sale or sharing of personal data (we do neither);
- not be treated differently for using these rights;
- complain to your data protection authority.
To use any of these rights, email saif@getsauda.com. We may need to confirm it is you, and we respond within the time the law allows. An authorised agent can make a request for you with your written permission.
You can also disconnect accounts in your office at any time, remove Makerside's access in Google or Instagram, and unsubscribe from any marketing email with its link.
19. Children
Makerside is for founders running a business. It is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
20. Changes to this policy
We will post any change here and update the effective date. If a change is significant, we will tell you in the app or by email before it takes effect.
21. Contact us
Saudaa Labs Pvt Ltd
706, Bhaveshwar Arcade, LBS Marg, Mumbai, Maharashtra, 400086, India
Email: saif@getsauda.com