Privacy Policy
TrustPixel runs an exchange where AI agents buy on behalf of people. To do that safely we have to know who the person is, what they authorized, who the merchant is, and what actually happened. This policy explains what we collect to make that work, what we do with it, and the choices you have. We currently serve customers in the United States.
01Who we are and what this covers
1.1 Controller. TPixel, Inc. (d/b/a TrustPixel), a Delaware corporation with offices at 1808 Wedemeyer St., San Francisco, CA 94129, is the controller (or "business," under U.S. state law) of the personal data described here, except where Section 1.3 says otherwise.
1.2 Scope. This policy covers personal data we process when you use the TrustPixel exchange, SDK, MCP server, APIs, dashboards, and websites, whether you are a consumer whose agent transacts, a merchant, an agent developer, a distribution partner, or a visitor. It does not cover the practices of merchants, agent developers, wallets, or other parties who have their own relationship with you; their notices govern what they do.
1.3 When we act for someone else. Where a merchant or distribution partner supplies us personal data to perform a service for them — for example, a catalog that includes a contact person's details, or a partner's user record passed to us for attribution — we process that data as their processor or service provider under our agreement with them, and their notice applies. Once a transaction is placed, we process the transaction data as controller in our own right, because we are the merchant of record.
1.4 Where we operate. The exchange is currently offered to customers in the United States. We do not knowingly sell to, ship to, or verify people located elsewhere. If we expand, we will update this policy before doing so.
1.5 Data Protection Officer. Our Data Protection Officer is Chris Ashley, reachable at support@trustpixel.ai, +1 (415) 853-4659, or the address in Section 18.
02At a glance
| Question | Short answer |
|---|---|
| Do you sell my data? | No. We do not sell personal data and do not share it for cross-context behavioral advertising. |
| Do you put my data on a blockchain? | No. We anchor a cryptographic hash and pseudonymous identifiers. Nothing that directly identifies you goes on-chain. See Section 7. |
| Do you verify my identity? | Yes, for some activities, through verification vendors. See Sections 3 and 8. |
| Do you make automated decisions about me? | Yes — mandate checks, fraud screening, and merchant trust scores. Section 6 explains what they are and how to contest them. |
| Can I get my data or have it deleted? | Yes, subject to legal retention. Section 12. |
| Where is it stored? | In the United States. Section 9. |
03Data we collect
What we collect depends on your role. The table below lists the categories; the sections after it explain the purposes.
| Category | Examples | Typically from |
|---|---|---|
| Account and contact | Name, email, phone, password hash, role, organization, preferences | All roles |
| Identity verification (KYC) | Government ID images and extracted fields, date of birth, address, selfie or liveness data where the vendor uses it, verification result and risk signals | Consumers, merchant principals |
| Business verification (KYB) | Legal entity details, registration numbers, beneficial owners' names and identifiers, sanctions and adverse-media screening results, bank details for payouts | Merchants, partners |
| Agent verification (KYA) | Agent identifiers, operator identity, declared capabilities, signing keys, request patterns | Agent developers |
| Mandate and intent | The instruction you gave your agent: product or SKU, attributes, price ceiling, delivery constraints, confirmation events | Consumers via their agents |
| Transaction and payment | Items ordered, amounts, taxes, delivery address, payment method type and last four digits, tokenized credential, order status, refund and dispute history | Consumers, merchants |
| Receipt data | Signed receipt contents, hashes, pseudonymous transaction identifiers, ledger references | Generated by us |
| Agent telemetry | API calls, mandate-check inputs and scores, error and latency data, blocked-action reasons | Agents, automatically |
| Device and usage | IP address, device and browser type, approximate location from IP, pages and dashboard actions, log timestamps | Automatically |
| Communications | Support tickets, emails, dispute submissions, survey responses | You |
| Partner-supplied signals | Product-data compliance flags, brand-standards signals, attribution identifiers | PIM and distribution partners |
Sensitive data. Identity verification may involve government identifiers and, depending on the vendor's method, biometric-derived data used for liveness or face matching. We collect these only for verification and fraud prevention, only with the consent the applicable law requires, and we do not use them for any other purpose. We do not intentionally collect data about health, religion, political opinions, sexual orientation, or similar categories, and you should not send it to us; if a purchase incidentally reveals such information, we process it only as part of the transaction record.
04Where it comes from
- You, when you create an account, set a mandate, place an order, or contact us.
- Your agent, which passes us your instructions and transacts on your behalf.
- Distribution partners such as wallets and apps, which may pass us an identifier, verification status, or attribution data when they route you to the exchange.
- Merchants, who supply fulfillment status and tracking.
- Verification and fraud-prevention vendors, who return results and risk signals.
- Product-information partners, who supply catalog attributes and compliance flags — not typically personal data, but sometimes a contact's details.
- Public and commercial sources for sanctions screening, business registries, and fraud consortium data.
- Automatically, from your device and from the operation of the exchange.
05How and why we use it
| Purpose | What it involves |
|---|---|
| Run the exchange | Accounts, catalog discovery, mandate capture, mandate checks, order placement, receipts, payouts |
| Act as merchant of record | Charging you, collecting tax, issuing invoices and refunds, handling chargebacks, keeping financial records |
| Verify participants | KYC, KYA, KYB, sanctions screening, re-verification — with your consent where the law requires it for biometric-derived data |
| Prevent fraud and abuse | Risk scoring, anomaly detection, blocking mandate circumvention, investigating disputes |
| Score merchants | Trust scores derived from verification, fulfillment, dispute, and partner compliance signals |
| Support you | Answering tickets, resolving refunds and disputes |
| Improve and secure the service | Debugging, performance, security monitoring, product analytics on de-identified or aggregated data |
| Communicate | Transactional notices always; marketing only where the law allows, with opt-out |
| Comply with law | Tax, anti-money-laundering, sanctions, consumer-protection, record-keeping, responding to lawful requests |
| Protect rights | Enforcing our terms, defending claims, protecting people's safety |
No training on your data. We do not use your personal data, your mandates, or your transaction history to train generative AI models. Agent developers are prohibited from doing so under our Terms.
06Automated decisions
The exchange makes some decisions without a human in the moment. Several U.S. state privacy laws give you rights around automated decisions that produce legal or similarly significant effects, and we apply those rights to everyone. Here is what we do:
- Mandate checks. Before an agent transacts, we score the proposed action against your mandate and block, hold, or allow it. This protects you from your own agent overstepping and is a necessary part of the service you asked for.
- Fraud and risk screening. We may automatically decline, hold, or require additional verification for a transaction or account that presents fraud, sanctions, or abuse indicators.
- Merchant trust scores. We compute a score for each merchant and show it to agents at discovery time. Where the merchant is a sole trader, this is a decision about a person.
Your rights. If an automated decision significantly affects you — an account declined, a transaction blocked, a trust score that materially reduces your visibility — you may ask for human review, express your point of view, and contest the decision by writing to support@trustpixel.ai. We will have a person who was not involved in the original decision look at it and respond within the timeframes in Section 12.
07On-chain records
Every completed order produces a signed receipt. We anchor a cryptographic hash of that receipt, together with pseudonymous identifiers, to a public blockchain so that the receipt can later be proven authentic and unaltered.
We do not write your name, contact details, address, payment details, the items you bought, or anything else that directly identifies you to any public ledger.
7.1 Why a hash. A hash is a fixed-length fingerprint. It lets anyone holding the original receipt prove it matches what was anchored, but it cannot be reversed to reveal the receipt's contents.
7.2 Permanence. Data written to a public blockchain cannot be modified or removed by us or by anyone. That is the point of anchoring, and it is why we keep identifying data off-chain. When you exercise a right to erasure, we delete or de-identify the off-chain receipt and the links between the on-chain identifiers and you. What remains on-chain is a fingerprint and identifiers that no longer resolve to any person in our systems.
7.3 Pseudonymous identifiers. The identifiers we anchor are generated by us and are not your wallet address, email, or any identifier used elsewhere.
7.4 Which ledger. The ledger we anchor to is documented in our developer documentation and may change; the commitments described in this section apply whichever ledger is used.
08Who we share it with
We share personal data only as described here, and we never sell it.
| Recipient | What and why |
|---|---|
| Merchants | Delivery name and address, order contents, and what they need to fulfill and support the order. Not your payment details. |
| Your agent and its developer | What your agent needs to act for you: mandate status, order confirmation, receipt. Developers see telemetry about their agent's calls. |
| Distribution partners | The wallet or app that brought you to the exchange receives attribution data and order status for that transaction, and whatever else you have agreed with them. |
| Payment processors and financial partners | What is needed to charge you, settle to merchants, handle disputes, and meet their compliance obligations. Card data goes to them, not to merchants or agents. |
| Verification vendors | Identity, business, and agent verification data, so they can return a result. Their own notices apply to their processing. A current list of verification vendors is available on request. |
| Product-information partners | Generally no personal data; occasionally a merchant contact's details for catalog operations. |
| Service providers | Hosting, email delivery, analytics, customer support tooling, security monitoring, and professional advisers — bound by contract to use data only for us. |
| Fraud-prevention networks | Signals shared with consortium services to detect fraud across the ecosystem, where the law permits. |
| Authorities and courts | When required by law, subpoena, or lawful request; to protect rights and safety; or to investigate fraud. |
| Successors | In a merger, acquisition, financing, or asset sale, with notice where the law requires it. |
09Where we store it
Our systems are hosted in the United States, and that is where your data is stored and processed. Some of our service providers operate globally and may process data in other countries under contracts that require them to protect it to the standard described here.
10How long we keep it
We keep personal data for as long as we need it for the purpose we collected it and for any period the law requires, then delete or de-identify it. The main periods:
| Data | Retention | Reason |
|---|---|---|
| Account data | Life of the account plus 90 days | Service; allow reactivation |
| Transaction and financial records | 7 years from the transaction | Tax, accounting, and chargeback rules as merchant of record |
| Identity and business verification records | 5 years after the relationship ends | Anti-money-laundering and sanctions record-keeping |
| Biometric-derived verification data | Deleted by the vendor promptly after verification, typically within 30 days; we retain only the result | Data minimization |
| Mandate and receipt data (off-chain) | Aligned with transaction records | Dispute evidence |
| Agent telemetry and logs | 13 months | Security, debugging, abuse investigation |
| Support communications | 3 years | Quality and dispute history |
| Marketing preferences | Until you change them, then a suppression record indefinitely | Honor opt-outs |
11Security
We protect personal data with encryption in transit and at rest, access controls and least privilege, key management for receipt signing, logging and monitoring, vendor due diligence, and periodic testing. Payment card data is handled in PCI DSS–compliant environments and is never exposed to agents or merchants. No system is perfectly secure; if a breach affects you, we will notify you and the relevant authority as the law requires.
12Your rights and how to use them
Depending on where you live, you may have the right to:
- Know what personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Delete your data, subject to the retention obligations in Section 10 and the on-chain limits in Section 7.
- Port data you provided to us in a machine-readable format.
- Restrict or object to processing based on legitimate interests, including profiling.
- Withdraw consent where processing is based on it, without affecting what was done before.
- Opt out of marketing at any time.
- Contest automated decisions as described in Section 6.
- Complain to a supervisory authority or regulator.
- Not be discriminated against for exercising any of these rights.
How to ask. Email support@trustpixel.ai, use the privacy controls in your account, or write to us at the address in Section 18. Tell us which right you are exercising and, where relevant, which account or transaction. We will verify your identity in a way proportionate to the request — usually by confirming control of the email on the account — and we may ask an authorized agent for proof of authority.
How fast. We respond within 45 days, extendable once by a further 45 days where a request is complex, and we will tell you if we need longer. There is no fee unless a request is manifestly unfounded or excessive.
Agent-made requests. A request made by an AI agent on your behalf is honored only if the agent can prove it is acting for you with authority for that purpose; otherwise we will ask you directly.
13California and other U.S. states
13.1 Categories collected. In the past twelve months we have collected the categories listed in Section 3, which map to the CCPA categories of identifiers; personal information under Cal. Civ. Code §1798.80; commercial information; internet or network activity; geolocation (approximate, from IP); professional information (for merchants and developers); inferences (trust and risk scores); and sensitive personal information (government identifiers, account credentials, and, where used for verification, biometric information).
13.2 No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the past twelve months. We do not knowingly sell or share the personal information of anyone under 16.
13.3 Sensitive personal information. We use sensitive personal information only for the purposes permitted under CCPA regulations §7027(m) — performing the service, preventing fraud, ensuring security, and verifying identity — and therefore do not offer a separate "limit use" control.
13.4 Your rights. California residents may exercise the rights in Section 12 and may designate an authorized agent. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including the right to appeal a refused request by replying to our response; we will explain how to contact your state attorney general if the appeal is denied.
13.5 Global Privacy Control. Because we do not sell or share personal information, an opt-out preference signal does not change how we process it, but we recognize such signals for any future practice that would require it.
13.6 Shine the Light. We do not disclose personal information to third parties for their own direct marketing.
14Outside the United States
The exchange is built for customers in the United States, and we do not currently offer it elsewhere. If you access our websites or documentation from outside the U.S., any data you provide is transferred to and processed in the United States. Should we begin serving other countries, we will update this policy first and add the disclosures, representatives, and transfer safeguards those places require.
15Cookies and tracking
Our websites and dashboards use strictly necessary cookies for sign-in, security, and preferences, and — with your consent where required — analytics cookies to understand how the product is used. We do not use advertising cookies or tracking pixels for behavioral advertising. You can manage non-essential cookies through the banner or your browser. Our APIs and MCP server do not set cookies; agents authenticate with credentials.
16Children
The exchange is for adults. We do not knowingly collect personal data from anyone under 18, and we do not knowingly allow an agent to act for a minor. If you believe a child has provided us data, contact us and we will delete it.
17Changes to this policy
We will post updates here with a new effective date. For material changes we will give notice by email or in-product at least 30 days before they take effect, and where a change requires your consent, we will ask for it.
18Contact
TPixel, Inc., doing business as TrustPixel
Attn: Privacy / Data Protection Officer (Chris Ashley)
1808 Wedemeyer St., San Francisco, CA 94129
support@trustpixel.ai · +1 (415) 853-4659
TrustPixel policies
Version 1.0 · effective 16 September 2026 · TPixel, Inc. (d/b/a TrustPixel), a Delaware corporation, 1808 Wedemeyer St., San Francisco, CA 94129.