SharePop Studio Privacy Policy
Last updated: August 20, 2026
Sharepop Studio Inc., operating as SharePop Studio ("SharePop Studio," "we," "our," or "us"), provides SharePop Studio, an online education and business resource center for small business operators and their advisors (the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, how we protect it, and the rights you have over it.
This Policy applies to information we collect through the SharePop Studio web experience at app.sharepopstudio.com, our marketing pages, and related communications. It does not apply to third-party websites, services, financial institutions, or AI agents that you connect to or interact with through the Service, each of which has its own privacy practices.
By using the Service you confirm that you have read this Policy. If you do not agree, do not use the Service. If you are a resident of California, Quebec, or another jurisdiction with specific privacy rights, see the "Your privacy rights" section for the rights that apply to you.
1. Plain-language summary
We collect what is needed to run the checks and analyses you ask for. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. To read your uploaded financial statements and to power the Light assistant, we send document contents and your questions to our AI processor (Google, through its Gemini models) under commercial API terms that provide that your data is not used to train general-purpose models. If you connect a bank through Plaid, we use that data only to run your analyses, never to train models. Payments are handled by Stripe; full card numbers never touch our servers. You can disconnect a linked account, revoke third-party agent access, and request deletion of your account at any time.
2. Personal information we collect
We collect the following categories of personal information. Not every category applies to every user; what we hold depends on how you use the Service.
a. Identifiers
- Your name, business name, business address, business email, and business phone.
- Account credentials managed through our identity provider (Stack Auth), including your sign-in email and an opaque user identifier. Passwords are handled by the identity provider and are never stored by us.
- IP address and approximate location derived from IP at the time of a request.
b. Business and financial information
- Information you provide directly during onboarding and intake: industry, location, ownership, revenue, costs, add-backs, goals, and the answers you give to questions asked by Light or by individual tools.
- Financial statements and other documents you upload (for example profit-and-loss statements, balance sheets, and tax documents). Uploaded files are stored using Vercel Blob and are processed as described in the "How we use AI to process your data" section.
- If you choose to link a financial account through Plaid: bank and account names, account types and masks (the last few digits of an account number), current and available balances, transaction history, and certain identity fields associated with the account holder. See the "Plaid and connected financial accounts" section for detail.
- Long-lived Plaid access tokens that allow us to refresh data for accounts you have connected. These tokens are encrypted at rest and are never returned to your browser or to any third party.
c. Commercial information
- Records of the tools you run, the scores, valuations, and cashflow views you generate, the goals and decisions you record, and other content you submit.
- Payment and subscription information. Payments are processed by Stripe, Inc.; we receive and store your subscription plan, billing status, billing currency, and limited card metadata (such as card brand and last four digits). Full payment-card numbers are handled by Stripe and never touch our servers.
d. Internet and network activity
- Pages visited, tools used, timestamps, and similar interaction events used to operate and improve the Service.
- Device and browser information such as browser type, operating system, screen size, and language.
- Diagnostic logs, error reports, and audit-log entries that record privileged operations (for example, connecting or disconnecting a bank, or a tool run made through the MCP endpoint).
e. Geolocation information
- Approximate location inferred from IP address. We do not collect precise device geolocation.
f. Communications
- Email and support messages you send us, including their content and attachments.
g. Sensitive personal information
Certain categories above are treated as "sensitive personal information" under California law and as "sensitive information" under several other state and provincial laws. For SharePop Studio this is limited to: account log-in credentials handled by our identity provider, and financial-account information you upload or that is returned by Plaid (account numbers in masked form, balances, and transactions). We use sensitive personal information only for the purposes described in the "How we use personal information" section and we do not use or disclose it for purposes that require an opt-out under California Civil Code section 1798.121.
3. Sources of personal information
We collect personal information from the following sources:
- Directly from you, when you create an account, complete onboarding, upload documents, or use the Service.
- From Plaid, when you choose to link a financial account through Plaid Link.
- From your devices and browsers, through cookies, local storage, and standard log fields when you interact with the Service.
- From an advisor, if a SharePop Studio advisor has been engaged to work with your business and provisions or is granted access to your business workspace.
- From service providers that help us operate the Service, such as our hosting, identity, database, AI-processing, payment, email, and storage providers.
- From public sources, where advisor tools assemble publicly available information about businesses (for example listings and published contact details) for lead discovery.
4. How we use personal information
We use personal information for the following business and commercial purposes, each tied to operating the Service you have asked us to provide:
- To create and maintain your account, authenticate you, and keep your session secure.
- To deliver the core Service features: reading and normalizing your uploaded statements, running the analysis tools (including Local Market Scan, Unit Economics, Market Structure, Price Position, Whitespace Opportunity, Location Quality, CAC, Risk Profile, and Business Score), computing valuations and cashflow views, and storing the goals and decisions you record.
- To power the Light conversational assistant, which uses AI to interpret your questions and present your results.
- To connect and refresh data from your financial accounts through Plaid, where you choose to link an account.
- To process payments, manage subscriptions, and administer billing through our payment processor, Stripe.
- To communicate with you about your account, including security notifications, billing notices, important changes to the Service, and responses to your support requests. Transactional email is delivered through Resend.
- To detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service or applicable law, and to keep audit logs of privileged operations.
- To meet our legal, regulatory, tax, and accounting obligations.
- To improve the Service in aggregate ways, for example by reviewing anonymized usage patterns and error rates. We do not use your uploaded documents, Plaid-connected data, or the contents of your tool results to train general-purpose AI or machine-learning models, and our AI processor is contractually prohibited from doing so.
If we ever intend to use personal information for a materially different purpose, we will obtain your consent or update this Policy in advance, as required by applicable law.
5. How we use AI to process your data
The Service relies on artificial intelligence in several places, and in each we transmit some of your data to our AI processor, Google LLC ("Google"), through its Gemini models, to return a result to you:
- Document extraction and classification. When you upload a financial statement or similar document, we send its contents to Google's Gemini models so they can classify the document and extract structured financial figures (for example revenue, expense, and balance-sheet line items). The extracted figures are returned to us and used to run your analyses.
- The Light assistant. When you interact with Light, we send your questions and the relevant context to Google to generate a response.
- Advisor tools. Certain advisor features, such as lead analysis and drafted outreach, also generate their results through Google's Gemini models.
We send Google only what is needed to perform these tasks. Google processes this data as our service provider under its paid Gemini API terms, which provide that Google does not use your prompts or responses to train its models. We do not use AI to make decisions that produce legal or similarly significant effects about you; see "Automated decisions and profiling."
6. How we share personal information
We share personal information only as described below. We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising.
a. Service providers and processors
We share personal information with vendors that process it on our behalf under written contracts that limit their use of the information to providing services to us. These currently include:
- Google LLC: AI processing (Gemini models) for document extraction, the Light assistant, and advisor tools.
- Plaid Inc.: financial-account connectivity and data, where you choose to link an account.
- Stripe, Inc.: payment processing and subscription billing.
- Stack Auth (Stack Frame, Inc.): authentication and identity.
- Neon Inc.: managed PostgreSQL database hosting.
- Vercel Inc.: web hosting, serverless functions, and Blob storage for your uploaded documents.
- Resend, Inc.: transactional email delivery.
b. At your direction
When you direct us to link a financial account, connect a third-party AI agent through our MCP endpoint, or otherwise share information with another party, we share the personal information needed to fulfill that request. See the "Third-party AI agents and MCP access" section for what this means when you connect an agent.
c. With your advisor
If a SharePop Studio advisor is engaged to work with your business and you or your business grant that advisor access to your workspace, we share your business and financial information with that advisor so they can perform the engagement. Advisor access is subject to the same confidentiality and security commitments described in this Policy.
d. Legal and safety
We may disclose personal information when we believe in good faith that disclosure is necessary to comply with a subpoena, court order, or other legal process; to enforce our Terms of Service; to protect the rights, property, or safety of SharePop Studio, our users, or others; or to investigate fraud or security incidents. Where permitted, we will notify you of any such legal request.
e. Business transfers
If SharePop Studio is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will notify you, and where required obtain your consent, before personal information becomes subject to a materially different privacy policy.
f. With your consent
We will share personal information with other parties when you give us specific consent to do so.
CCPA / CPRA disclosure. In the past twelve months we have disclosed the categories of personal information listed in the "Personal information we collect" section to the service-provider categories listed in this section, for the operational purposes listed in the "How we use personal information" section. We have not sold or shared personal information as those terms are defined under California Civil Code sections 1798.140(ad) and 1798.140(ah).
7. Third-party AI agents and MCP access
SharePop Studio exposes its analysis tools through a Model Context Protocol (MCP) endpoint so that you can run your tools from an authorized third-party AI agent or client (for example an AI assistant you use elsewhere) rather than only from the SharePop Studio web app.
- Access is opt-in and scoped. MCP access works only with a token issued for your account. That token carries scopes that limit which tools an agent may run, and every tool call is checked against the same multi-tenant authorization used by the web app, so an agent can only reach the business data you are authorized for. We never expose your data to an agent you have not connected.
- What is transmitted. When you (or an agent acting under your authorization) run a tool over MCP, the tool's inputs and its results ~ which may include your business and financial data ~ are transmitted to the connected agent or client and to any AI provider that agent relies on. Those parties process the data under their own terms and privacy policies, which we do not control.
- Your responsibility. You are responsible for the agents and clients you connect, for keeping any MCP token confidential, and for the downstream handling of data you direct us to send to them. If you believe a token has been exposed, contact us so we can revoke it. You can disconnect MCP access at any time.
- Logging. Tool runs made through MCP are recorded in our audit logs (tagged as MCP-originated) for security and accountability, the same as runs made in the app.
8. Cookies and similar technologies (Cookie Notice)
This section is a standalone Cookie Notice describing the cookies, local-storage entries, and similar technologies the Service sets in your browser.
SharePop Studio uses only strictly necessary and functional first-party technologies. We do not use third-party advertising cookies, cross-site tracking pixels, browser fingerprinting, or any technology that builds a profile of your activity across other websites or services.
a. Strictly necessary
- Authentication and session, set by our identity provider (Stack Auth) to keep you signed in across requests. These are required to operate the Service and cannot be disabled without breaking sign-in.
- Cross-site request forgery (CSRF) protection: short-lived nonces created during sensitive flows (sign-in, financial-account linking) to bind your browser session to the request that started it.
b. Functional (first-party local storage)
- Interface preferences you set.
- Onboarding and intake drafts: interim form values cached so you do not lose progress if you refresh the page.
- In-app data cache: query results held in browser storage for the duration of the session to keep the app responsive between navigations. Cleared on sign-out.
c. Diagnostic
- Server-side error logs and audit-log entries written when you take privileged actions such as linking or disconnecting a financial account or running a tool over MCP. These are written on our server, not in your browser.
d. What we do not use
- No third-party advertising cookies or pixels.
- No cross-context behavioral advertising trackers.
- No browser-fingerprinting, device-graph, or session-replay tooling.
- No social-media share or "like" buttons that report your visit back to a third party.
e. Consent and controls
Because the Service uses only strictly necessary and functional technologies, applicable laws in the European Economic Area, the United Kingdom, Canada (including Quebec under Law 25), and California do not require us to display a consent banner before setting them. Our marketing pages use Vercel Web Analytics, a cookieless, privacy-preserving usage-measurement service that counts page views and aggregate interaction without setting cookies and without storing any cross-site or cross-session identifier that could profile you across other websites. If we ever introduce cookie-based analytics or any other non-essential cookie, we will update this Notice, present a consent control, and respect any Global Privacy Control signal your browser sends before activating them.
You can also block or delete cookies and clear local storage using your browser settings. Doing so may sign you out and reset your interface preferences, but it will not delete data we hold on our servers; to delete server-side data, use the "How to exercise your rights" section.
9. Data retention
We retain personal information only as long as it is needed for the purposes described in this Policy, including to provide the Service, to meet our legal, accounting, audit, and tax obligations, and to defend or resolve legal claims. Specifically:
- Account profile information is retained while your account is active and for up to twenty-four (24) months after closure, after which it is deleted or anonymized.
- Uploaded documents and the financial figures extracted from them are retained while your account is active and deleted within a reasonable period (typically within thirty (30) days) after you delete them or close your account.
- Plaid access tokens, account identifiers, and cached financial-account data are deleted promptly when you disconnect an account, and within a reasonable period (typically within thirty (30) days) when you close your account.
- Audit-log entries that record privileged operations, including MCP tool runs, are retained for up to twenty-four (24) months for security and accountability.
- Backups containing personal information may persist for a limited period after the underlying data is deleted, after which they are overwritten on a rolling basis.
- Information retained to comply with a legal obligation, defend a legal claim, or resolve a security incident is retained for as long as needed for that purpose.
10. How we protect personal information
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and loss. These include:
- Transport security: HTTPS with modern TLS for traffic between your device, our servers, our database, and our service providers.
- Encryption at rest of sensitive access credentials, such as Plaid access tokens, with encryption keys stored separately from the database.
- Access controls: production data is accessible only to authorized personnel with multi-factor authentication and least-privilege scopes; MCP tokens are scope-limited and multi-tenant guarded.
- Audit logging of privileged operations such as bank connection, disconnection, account deletion, and MCP tool execution.
- Vendor due-diligence and written data-processing terms with our service providers.
- A documented incident-response process, including prompt notification to Plaid where Plaid-derived data is implicated.
No method of transmission or storage is one-hundred-percent secure, and we cannot and do not guarantee absolute security. By using the Service you acknowledge and accept this risk. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulators as required by applicable law, including California breach-notification law and Quebec Law 25. Any claim relating to a security incident is subject to the assumption of risk, release, and limitation-of-liability provisions of our Terms of Service, which apply to the fullest extent permitted by applicable law.
11. Children's privacy
The Service is intended for business operators and is not directed to children under sixteen (16). We do not knowingly collect personal information from anyone under sixteen. If you believe a child has provided personal information to us, contact us at privacy@sharepopstudio.com and we will take appropriate steps to delete it.
12. International data transfers
SharePop Studio operates the Service through service providers located primarily in the United States and Canada. Where personal information is transferred between jurisdictions, we rely on appropriate safeguards such as contractual protections and recognized transfer mechanisms.
If you are a resident of Quebec or another Canadian province, you acknowledge that your personal information may be communicated outside of your province, including to the United States, and may be accessible to government authorities under the laws of those jurisdictions. Before transferring personal information outside of Quebec, we conduct a privacy impact assessment as required by section 17 of Quebec Law 25.
13. Automated decisions and profiling
The Service uses automated processing, including AI, to read your documents and to compute scores, valuations, cashflow projections, and similar insights from the information you provide. These outputs are decision-support tools intended to inform your judgment; they are not used to make decisions that produce legal effects on you, that affect your eligibility for credit, insurance, employment, or housing, or that otherwise produce significant effects on you.
If you reside in Quebec or another jurisdiction that grants rights regarding decisions based exclusively on automated processing, you may contact us to learn what personal information was used, the principal factors that led to a result, and to request human review of any individual result. We will respond as required by applicable law.
14. Your privacy rights
Subject to applicable law, you have the following rights over your personal information. We honor these rights for every user, and we offer additional rights to residents of specific jurisdictions as described below.
a. Rights we offer to every user
- Access: ask us what personal information we hold about you.
- Correction: ask us to correct personal information that is inaccurate or incomplete.
- Deletion: ask us to delete personal information we hold about you, subject to limited exceptions allowed by law.
- Portability: ask us to provide personal information you have given us in a structured, commonly used, machine-readable format.
- Withdrawal of consent: where we rely on consent, withdraw it.
- Disconnect: revoke our access to a linked financial account, and revoke a connected third-party AI agent's MCP access, at any time.
- Account closure: ask us to close your account and delete the associated personal information.
b. California residents (CCPA / CPRA)
In addition to the universal rights above, California residents have the right to:
- Know the categories and specific pieces of personal information we have collected, the categories of sources, the purposes for collecting it, and the categories of third parties to whom we disclose it.
- Delete personal information we have collected from you, subject to the exceptions in California Civil Code section 1798.105(d).
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law, and we honor any Global Privacy Control signal your browser sends.
- Limit the use and disclosure of sensitive personal information. We use it only for purposes permitted by California Civil Code section 1798.121(a).
- Non-discrimination: we will not deny you the Service, charge a different price, or provide a different level of quality because you exercised a privacy right.
- Designate an authorized agent to submit requests on your behalf.
c. Other U.S. state residents
If you reside in a state with a comprehensive privacy law (for example Colorado, Connecticut, Delaware, Indiana, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia), you have rights of access, correction, deletion, portability, and, where applicable, the right to opt out of targeted advertising, sale of personal data, and certain profiling. You also have the right to appeal a denial of your request by emailing privacy@sharepopstudio.com with the subject line "Privacy appeal." We do not engage in targeted advertising, do not sell personal data, and do not engage in profiling that produces legal or similarly significant effects.
d. Canadian residents (PIPEDA and provincial laws)
If you reside in Canada, you have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial law (including Alberta's PIPA, British Columbia's PIPA, and Quebec's Law 25): access to and correction of your personal information, the right to withdraw consent subject to legal or contractual restrictions, and the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or your provincial regulator.
e. Quebec residents (Law 25)
In addition to the rights above, residents of Quebec have the right to:
- Contact our person in charge of personal-information protection (privacy officer) at the address in the "Contact us" section.
- Be informed of, and request correction of, decisions based exclusively on automated processing, as described in "Automated decisions and profiling."
- Receive the personal information you have provided in a structured, commonly used technological format, and request that we transmit it to another organization where technically feasible (section 27 of Law 25).
- Request that we cease disseminating your personal information or de-index hyperlinks attached to your name where the conditions of sections 28 and 28.1 of Law 25 are met.
- Be informed before personal information is transferred outside Quebec, and know the results of the related privacy impact assessment.
- Lodge a complaint with the Commission d'acces a l'information du Quebec.
f. EEA, UK, and Swiss residents
The Service is not currently directed to residents of the European Economic Area, the United Kingdom, or Switzerland. If you are a resident of one of those jurisdictions and choose to use the Service, you have the rights granted by the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection, including the right to lodge a complaint with your supervisory authority.
15. How to exercise your rights
You can exercise any of the rights above by emailing privacy@sharepopstudio.com with the subject line "Privacy request" and a description of what you would like us to do.
To protect your information, we will take reasonable steps to verify your identity before responding. The information we ask for will be limited to what is necessary to verify your identity, used only for that purpose, and destroyed once verification is complete.
We will respond to verifiable requests within the timelines set by applicable law (within forty-five (45) days for California requests, and within thirty (30) days for Quebec requests, with one extension where allowed). There is no charge unless a request is manifestly unfounded, excessive, or repetitive.
16. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will give you reasonable advance notice by email, in-product notification, or by posting a prominent notice on the Service. The "Last updated" date at the top indicates when it was last revised.
17. Contact us
If you have questions about this Policy, want to exercise a privacy right, or want to lodge a privacy complaint, please contact our person in charge of personal-information protection (privacy officer):
Sharepop Studio Inc., operating as SharePop Studio, Attention: Privacy Officer Email: privacy@sharepopstudio.com General support: support@sharepopstudio.com
If you are not satisfied with our response, you may contact your local privacy regulator. Quebec residents may contact the Commission d'acces a l'information du Quebec at https://www.cai.gouv.qc.ca. Canadian residents outside Quebec may contact the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca. California residents may contact the California Privacy Protection Agency at https://cppa.ca.gov.
