Privacy Policy

Privacy Policy

TrustPixel runs an exchange where AI agents buy on behalf of people. To do that safely we have to know who the person is, what they authorized, who the merchant is, and what actually happened. This policy explains what we collect to make that work, what we do with it, and the choices you have. We currently serve customers in the United States.

01Who we are and what this covers

1.1 Controller. TPixel, Inc. (d/b/a TrustPixel), a Delaware corporation with offices at 1808 Wedemeyer St., San Francisco, CA 94129, is the controller (or "business," under U.S. state law) of the personal data described here, except where Section 1.3 says otherwise.

1.2 Scope. This policy covers personal data we process when you use the TrustPixel exchange, SDK, MCP server, APIs, dashboards, and websites, whether you are a consumer whose agent transacts, a merchant, an agent developer, a distribution partner, or a visitor. It does not cover the practices of merchants, agent developers, wallets, or other parties who have their own relationship with you; their notices govern what they do.

1.3 When we act for someone else. Where a merchant or distribution partner supplies us personal data to perform a service for them — for example, a catalog that includes a contact person's details, or a partner's user record passed to us for attribution — we process that data as their processor or service provider under our agreement with them, and their notice applies. Once a transaction is placed, we process the transaction data as controller in our own right, because we are the merchant of record.

1.4 Where we operate. The exchange is currently offered to customers in the United States. We do not knowingly sell to, ship to, or verify people located elsewhere. If we expand, we will update this policy before doing so.

1.5 Data Protection Officer. Our Data Protection Officer is Chris Ashley, reachable at support@trustpixel.ai, +1 (415) 853-4659, or the address in Section 18.

02At a glance

QuestionShort answer
Do you sell my data?No. We do not sell personal data and do not share it for cross-context behavioral advertising.
Do you put my data on a blockchain?No. We anchor a cryptographic hash and pseudonymous identifiers. Nothing that directly identifies you goes on-chain. See Section 7.
Do you verify my identity?Yes, for some activities, through verification vendors. See Sections 3 and 8.
Do you make automated decisions about me?Yes — mandate checks, fraud screening, and merchant trust scores. Section 6 explains what they are and how to contest them.
Can I get my data or have it deleted?Yes, subject to legal retention. Section 12.
Where is it stored?In the United States. Section 9.

03Data we collect

What we collect depends on your role. The table below lists the categories; the sections after it explain the purposes.

CategoryExamplesTypically from
Account and contactName, email, phone, password hash, role, organization, preferencesAll roles
Identity verification (KYC)Government ID images and extracted fields, date of birth, address, selfie or liveness data where the vendor uses it, verification result and risk signalsConsumers, merchant principals
Business verification (KYB)Legal entity details, registration numbers, beneficial owners' names and identifiers, sanctions and adverse-media screening results, bank details for payoutsMerchants, partners
Agent verification (KYA)Agent identifiers, operator identity, declared capabilities, signing keys, request patternsAgent developers
Mandate and intentThe instruction you gave your agent: product or SKU, attributes, price ceiling, delivery constraints, confirmation eventsConsumers via their agents
Transaction and paymentItems ordered, amounts, taxes, delivery address, payment method type and last four digits, tokenized credential, order status, refund and dispute historyConsumers, merchants
Receipt dataSigned receipt contents, hashes, pseudonymous transaction identifiers, ledger referencesGenerated by us
Agent telemetryAPI calls, mandate-check inputs and scores, error and latency data, blocked-action reasonsAgents, automatically
Device and usageIP address, device and browser type, approximate location from IP, pages and dashboard actions, log timestampsAutomatically
CommunicationsSupport tickets, emails, dispute submissions, survey responsesYou
Partner-supplied signalsProduct-data compliance flags, brand-standards signals, attribution identifiersPIM and distribution partners

Sensitive data. Identity verification may involve government identifiers and, depending on the vendor's method, biometric-derived data used for liveness or face matching. We collect these only for verification and fraud prevention, only with the consent the applicable law requires, and we do not use them for any other purpose. We do not intentionally collect data about health, religion, political opinions, sexual orientation, or similar categories, and you should not send it to us; if a purchase incidentally reveals such information, we process it only as part of the transaction record.

04Where it comes from

05How and why we use it

PurposeWhat it involves
Run the exchangeAccounts, catalog discovery, mandate capture, mandate checks, order placement, receipts, payouts
Act as merchant of recordCharging you, collecting tax, issuing invoices and refunds, handling chargebacks, keeping financial records
Verify participantsKYC, KYA, KYB, sanctions screening, re-verification — with your consent where the law requires it for biometric-derived data
Prevent fraud and abuseRisk scoring, anomaly detection, blocking mandate circumvention, investigating disputes
Score merchantsTrust scores derived from verification, fulfillment, dispute, and partner compliance signals
Support youAnswering tickets, resolving refunds and disputes
Improve and secure the serviceDebugging, performance, security monitoring, product analytics on de-identified or aggregated data
CommunicateTransactional notices always; marketing only where the law allows, with opt-out
Comply with lawTax, anti-money-laundering, sanctions, consumer-protection, record-keeping, responding to lawful requests
Protect rightsEnforcing our terms, defending claims, protecting people's safety

No training on your data. We do not use your personal data, your mandates, or your transaction history to train generative AI models. Agent developers are prohibited from doing so under our Terms.

06Automated decisions

The exchange makes some decisions without a human in the moment. Several U.S. state privacy laws give you rights around automated decisions that produce legal or similarly significant effects, and we apply those rights to everyone. Here is what we do:

  1. Mandate checks. Before an agent transacts, we score the proposed action against your mandate and block, hold, or allow it. This protects you from your own agent overstepping and is a necessary part of the service you asked for.
  2. Fraud and risk screening. We may automatically decline, hold, or require additional verification for a transaction or account that presents fraud, sanctions, or abuse indicators.
  3. Merchant trust scores. We compute a score for each merchant and show it to agents at discovery time. Where the merchant is a sole trader, this is a decision about a person.

Your rights. If an automated decision significantly affects you — an account declined, a transaction blocked, a trust score that materially reduces your visibility — you may ask for human review, express your point of view, and contest the decision by writing to support@trustpixel.ai. We will have a person who was not involved in the original decision look at it and respond within the timeframes in Section 12.

07On-chain records

What goes on the ledger

Every completed order produces a signed receipt. We anchor a cryptographic hash of that receipt, together with pseudonymous identifiers, to a public blockchain so that the receipt can later be proven authentic and unaltered.

We do not write your name, contact details, address, payment details, the items you bought, or anything else that directly identifies you to any public ledger.

7.1 Why a hash. A hash is a fixed-length fingerprint. It lets anyone holding the original receipt prove it matches what was anchored, but it cannot be reversed to reveal the receipt's contents.

7.2 Permanence. Data written to a public blockchain cannot be modified or removed by us or by anyone. That is the point of anchoring, and it is why we keep identifying data off-chain. When you exercise a right to erasure, we delete or de-identify the off-chain receipt and the links between the on-chain identifiers and you. What remains on-chain is a fingerprint and identifiers that no longer resolve to any person in our systems.

7.3 Pseudonymous identifiers. The identifiers we anchor are generated by us and are not your wallet address, email, or any identifier used elsewhere.

7.4 Which ledger. The ledger we anchor to is documented in our developer documentation and may change; the commitments described in this section apply whichever ledger is used.

08Who we share it with

We share personal data only as described here, and we never sell it.

RecipientWhat and why
MerchantsDelivery name and address, order contents, and what they need to fulfill and support the order. Not your payment details.
Your agent and its developerWhat your agent needs to act for you: mandate status, order confirmation, receipt. Developers see telemetry about their agent's calls.
Distribution partnersThe wallet or app that brought you to the exchange receives attribution data and order status for that transaction, and whatever else you have agreed with them.
Payment processors and financial partnersWhat is needed to charge you, settle to merchants, handle disputes, and meet their compliance obligations. Card data goes to them, not to merchants or agents.
Verification vendorsIdentity, business, and agent verification data, so they can return a result. Their own notices apply to their processing. A current list of verification vendors is available on request.
Product-information partnersGenerally no personal data; occasionally a merchant contact's details for catalog operations.
Service providersHosting, email delivery, analytics, customer support tooling, security monitoring, and professional advisers — bound by contract to use data only for us.
Fraud-prevention networksSignals shared with consortium services to detect fraud across the ecosystem, where the law permits.
Authorities and courtsWhen required by law, subpoena, or lawful request; to protect rights and safety; or to investigate fraud.
SuccessorsIn a merger, acquisition, financing, or asset sale, with notice where the law requires it.

09Where we store it

Our systems are hosted in the United States, and that is where your data is stored and processed. Some of our service providers operate globally and may process data in other countries under contracts that require them to protect it to the standard described here.

10How long we keep it

We keep personal data for as long as we need it for the purpose we collected it and for any period the law requires, then delete or de-identify it. The main periods:

DataRetentionReason
Account dataLife of the account plus 90 daysService; allow reactivation
Transaction and financial records7 years from the transactionTax, accounting, and chargeback rules as merchant of record
Identity and business verification records5 years after the relationship endsAnti-money-laundering and sanctions record-keeping
Biometric-derived verification dataDeleted by the vendor promptly after verification, typically within 30 days; we retain only the resultData minimization
Mandate and receipt data (off-chain)Aligned with transaction recordsDispute evidence
Agent telemetry and logs13 monthsSecurity, debugging, abuse investigation
Support communications3 yearsQuality and dispute history
Marketing preferencesUntil you change them, then a suppression record indefinitelyHonor opt-outs

11Security

We protect personal data with encryption in transit and at rest, access controls and least privilege, key management for receipt signing, logging and monitoring, vendor due diligence, and periodic testing. Payment card data is handled in PCI DSS–compliant environments and is never exposed to agents or merchants. No system is perfectly secure; if a breach affects you, we will notify you and the relevant authority as the law requires.

12Your rights and how to use them

Depending on where you live, you may have the right to:

How to ask. Email support@trustpixel.ai, use the privacy controls in your account, or write to us at the address in Section 18. Tell us which right you are exercising and, where relevant, which account or transaction. We will verify your identity in a way proportionate to the request — usually by confirming control of the email on the account — and we may ask an authorized agent for proof of authority.

How fast. We respond within 45 days, extendable once by a further 45 days where a request is complex, and we will tell you if we need longer. There is no fee unless a request is manifestly unfounded or excessive.

Agent-made requests. A request made by an AI agent on your behalf is honored only if the agent can prove it is acting for you with authority for that purpose; otherwise we will ask you directly.

13California and other U.S. states

13.1 Categories collected. In the past twelve months we have collected the categories listed in Section 3, which map to the CCPA categories of identifiers; personal information under Cal. Civ. Code §1798.80; commercial information; internet or network activity; geolocation (approximate, from IP); professional information (for merchants and developers); inferences (trust and risk scores); and sensitive personal information (government identifiers, account credentials, and, where used for verification, biometric information).

13.2 No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the past twelve months. We do not knowingly sell or share the personal information of anyone under 16.

13.3 Sensitive personal information. We use sensitive personal information only for the purposes permitted under CCPA regulations §7027(m) — performing the service, preventing fraud, ensuring security, and verifying identity — and therefore do not offer a separate "limit use" control.

13.4 Your rights. California residents may exercise the rights in Section 12 and may designate an authorized agent. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including the right to appeal a refused request by replying to our response; we will explain how to contact your state attorney general if the appeal is denied.

13.5 Global Privacy Control. Because we do not sell or share personal information, an opt-out preference signal does not change how we process it, but we recognize such signals for any future practice that would require it.

13.6 Shine the Light. We do not disclose personal information to third parties for their own direct marketing.

14Outside the United States

The exchange is built for customers in the United States, and we do not currently offer it elsewhere. If you access our websites or documentation from outside the U.S., any data you provide is transferred to and processed in the United States. Should we begin serving other countries, we will update this policy first and add the disclosures, representatives, and transfer safeguards those places require.

15Cookies and tracking

Our websites and dashboards use strictly necessary cookies for sign-in, security, and preferences, and — with your consent where required — analytics cookies to understand how the product is used. We do not use advertising cookies or tracking pixels for behavioral advertising. You can manage non-essential cookies through the banner or your browser. Our APIs and MCP server do not set cookies; agents authenticate with credentials.

16Children

The exchange is for adults. We do not knowingly collect personal data from anyone under 18, and we do not knowingly allow an agent to act for a minor. If you believe a child has provided us data, contact us and we will delete it.

17Changes to this policy

We will post updates here with a new effective date. For material changes we will give notice by email or in-product at least 30 days before they take effect, and where a change requires your consent, we will ask for it.

18Contact

TPixel, Inc., doing business as TrustPixel
Attn: Privacy / Data Protection Officer (Chris Ashley)
1808 Wedemeyer St., San Francisco, CA 94129
support@trustpixel.ai · +1 (415) 853-4659

TrustPixel policies

Version 1.0 · effective 16 September 2026 · TPixel, Inc. (d/b/a TrustPixel), a Delaware corporation, 1808 Wedemeyer St., San Francisco, CA 94129.