Legal
Privacy policy
Last updated: Draft
This is a pre-launch draft. It is published so you can see the shape of our terms while we finalise them with counsel, and it is not yet the agreement between us. If you need final documents before you can build — a DPA, a signed agreement, a security review — email hello@mapier.ai and we will get them to you directly.
Who controls what
Mapier has two different relationships with data and they carry different obligations. Keeping them apart is the most important thing in this document.
For this website, Mapier Labs Inc. is the controller. We decide what we collect from visitors and why.
For the messaging service, you are the controller and Mapier is your processor. The messages your agent sends and receives, and the phone numbers it sends them to, are your end users' data. We process it on your instructions to deliver the service, and for nothing else.
What we handle for you
To deliver messages and prove they arrived, the service handles:
- Message content and attachments your agent sends and receives
- Phone numbers and platform handles for the people your agent talks to
- Conversation and group metadata: participants, names, timestamps
- Delivery evidence: which channel carried a message and what happened to it
- Operational logs and audit records of the commands your keys issued
We do not train on your message content
Customer message content is not used to train models — ours or anyone else's. It is processed to deliver and prove delivery of the message, and that is all.
What we collect on this website
Separately from the service: if you email us we receive whatever you send, so we can reply. This website has no forms and writes nothing about a visitor to a database.
Sub-processors
We use a small number of vendors to run the service. The current list, with what each one processes and where, is available on request and will be published here before launch. Full-service agreements include notice of changes to it.
Retention and deletion
Events are kept for ninety days, webhook delivery records and test-environment messages for thirty, and the audit log is not purged. Live messages are kept for as long as the agreement runs; a full-service agreement may set other windows. Ask us and we will delete a conversation's stored content, and we delete customer data on termination.
Where data goes
The service runs across cloud infrastructure and a fleet of hosts, which may sit in different jurisdictions from you or from the people your agent messages. The regions in use and the transfer mechanism that covers them will be named here before launch, and are available on request now.
How we protect it
Traffic to the API and between our own services runs over TLS. Access to customer data is limited to the people who need it to operate or support the service, and what they do is logged.
Your API keys are the boundary of your account: they are scoped, revocable, and every command issued with one is recorded in an audit trail you can read. Treat them as credentials — see the acceptable use and key sections of the terms.
We hold no SOC 2, ISO 27001 or HIPAA attestation today, and we would rather say so than let a badge imply one. If your procurement needs a security review, a questionnaire or a penetration-test summary, email hello@mapier.ai and we will work through it with you directly.
If something goes wrong
If we become aware of a breach of security that affects your data, we will tell you without undue delay — what we know, which of your data is involved, what we have done about it, and what we recommend you do. As your processor we notify you rather than your end users: you are the controller, and the decision about what they are told is yours to make.
Suspected vulnerabilities in the service can be reported to hello@mapier.ai. We will not pursue good-faith security research that respects the privacy of our customers and their end users.
Your rights, and your end users'
If you are a visitor to this site, contact us to access, correct or delete what we hold about you. If you are one of your customers' end users, your relationship is with them — they are the controller, and we will route your request to them.
We do not sell or share personal information as those terms are used in the CCPA.
Children
Mapier is sold to companies, and this site and the service are meant for the people who build and run them. Neither is directed to children, and we do not knowingly collect their personal information through either. If you believe a child's data has reached us through this website, email hello@mapier.ai and we will delete it.
What your agent says to your own end users, and who those end users are, is governed by your agreement with them rather than by this policy.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how we handle data we process for you, we will tell customers before it takes effect rather than relying on you to notice.
Contact
Privacy questions go to hello@mapier.ai.
