LEGAL · PRIVACYRETAILREASON.COM/PRIVACY

Privacy Policy

Revision: launch-privacy-v5
Controller: Startup Success Lab LLC, a Missouri limited liability company and the owner and operator of Retail Reason
Effective date: the date this revision is published on this page.

This Privacy Policy explains how Startup Success Lab LLC, through its Retail Reason product, collects, uses, discloses, and retains personal information through retailreason.com, the Retail Reason account application and MCP service, support and transactional communications, and related business contacts (collectively, the “Services”). It does not govern a customer-selected AI client, Walmart system, or other third-party service acting under its own terms. A customer-selected AI client or platform independently processes the conversation, tool request, request content, Retail Reason’s returned Output, and related metadata under Customer’s separate agreement with that provider; it is not a Retail Reason subprocessor for that independent handling.

Retail Reason is a business service for customer entities formed and principally located in the Launch Territory, as defined in the Terms of Service, and for Authorized Users physically located there. The account and billing information described below is handled by Retail Reason for its own business purposes. A business customer controls the information it chooses to submit in a question, draft, context field, or client workspace (“Customer Content”). Customers must not submit personal or regulated data unless they have authority to do so and Retail Reason has agreed in writing to any required data-processing terms.

1. Information we collect

Category Examples Main sources
Identity and account Name, business email, WorkOS subject and organization or membership identifiers, account role, invitation and membership status You; your account owner or administrator; WorkOS
Business and workspace Customer legal name, account type, workspace name, channel, Scintilla tier, client-authority attestation, plan and licensed limits You; your account owner or administrator; accepted Orders
Billing and commercial Billing address, plan, price, cadence, subscription, invoice, payment-intent, refund and dispute identifiers, tax and terms-acceptance records You; Stripe; accepted Orders; our account records
Customer Content and Output Current question or draft, pasted context, short prior-question excerpts when a session identifier is used, generated answer, review draft, sanitized evidence and feedback You or a client you choose; the Service; OpenAI
Usage, protection and diagnostics Date and time, tool and workspace, routed-topic and token counts, HMAC-keyed question fingerprint, delivery and error state, feedback, review status, cost and protection events Automatically from use of the Services and providers
Sanctions screening and compliance Names, addresses, countries, entity roles, ownership or control relationships, account and organization references, list-snapshot identity, screening result, potential-match candidates, cases, dispositions, provider-hold actions, and regulatory or reporting evidence You; your account owner or administrator; accepted Orders; sanctions-list sources; Stripe and other providers; authorities; our compliance records
Device, network, assent and preference IP address and user-agent or request metadata processed transiently by Retail Reason and visible to hosting or identity providers; HMAC-keyed IP-address and user-agent fingerprints recorded with account or commerce acceptance; browser and security signals; necessary cookies; theme preference; tab-scoped command keys Your browser; Cloudflare; WorkOS; our acceptance records
Communications Support, legal, sales, invitation and transactional-email content and delivery status You; account users; Resend; our mailbox provider

Retail Reason does not ask for or store full payment-card numbers or card security codes; Stripe handles payment credentials. Retail Reason does not hold Walmart portal credentials, connect to a Walmart account, or read information from Customer systems.

2. How we use information

We use the categories above to:

  • authenticate users and establish account, role, seat, and workspace boundaries;
  • create and administer accounts, invitations, trials, plans, subscriptions, invoices, refunds, cancellation, and account closure;
  • route a request, produce an AI-assisted answer, run a paid review, deliver Output, and preserve short session continuity when requested;
  • enforce licensed limits and workspace authority and detect fraud, credential abuse, systematic extraction, security threats, billing disputes, and cross-account access;
  • screen customers, organizations, owners, counterparties, and transactions against applicable sanctions restrictions; investigate and resolve potential matches; restrict access or payment activity; preserve compliance evidence; and make legally required reports;
  • provide support and required account, billing, legal, security, and operational notices;
  • measure reliability, model cost, quality, and usage using minimized operational metadata;
  • document authority, assent, transaction instructions and notices; comply with law; enforce agreements; resolve disputes; and preserve records or evidence where required; and
  • improve the Service using ideas and suggestions in voluntary product feedback and aggregate operational observations. We do not use identifying information, underlying questions, drafts, context, or confidential material embedded in feedback for this purpose.

Retail Reason does not use Customer Content to train its own models, build cross-customer profiles, or create a shared customer-content dataset. We do not use personal information for advertising.

For sanctions screening, Retail Reason uses submitted names and addresses transiently to compare a subject with applicable sanctions data. The sanctions screening receipt does not persist those raw submitted names or addresses. Instead, it persists a secret-keyed HMAC commitment to the screened input together with the subject’s roles and internal or provider references needed to bind the result to the relevant account, organization, onboarding, offer, invoice, checkout, or provider action. Potential-match candidates, cases, dispositions, ownership attestations, provider-hold actions, incidents, and regulatory or reporting evidence are restricted compliance records. This receipt design does not mean that the same identity or address information is absent from account, billing, support, infrastructure, communications, or external-provider records described elsewhere in this Policy.

3. AI processing

The customer-selected AI client first processes what Customer enters and then sends the tool request to Retail Reason. For answer generation, Retail Reason sends OpenAI the current question or draft, pasted context, selected reference material, and, when a session identifier is used, up to three recent question or draft excerpts of no more than 300 characters each. A paid review may additionally send the generated draft answer and sanitized evidence needed to assess it. Retail Reason sends the resulting Output back through the selected client.

Retail Reason sends OpenAI Responses API requests with store: false, which disables ordinary persisted Response objects but does not disable prompt caching. For GPT-5.6 requests, Retail Reason uses explicit-only prompt caching. If an eligible static Retail Reason instruction and skill-workflow prefix is long enough to cache, the request marks a cache boundary immediately after that static prefix and requests the API’s currently supported minimum cache lifetime of 30 minutes. The current question or draft, pasted context, session excerpts, per-request reference tail, generated draft, and review material follow that boundary and are not eligible for that request’s prompt cache. If there is no eligible static prefix, explicit-only mode creates no prompt cache. OpenAI states that cached prefixes may be held as encrypted key/value tensors in GPU-local storage and remain eligible for reuse for longer than that minimum, but, under its current API controls, not longer than 24 hours. Separately, OpenAI states that business/API content is not used to train its models unless the customer organization affirmatively opts in, and that default abuse-monitoring logs may contain prompts and responses for up to 30 days, subject to stated safety or legal exceptions. A verified zero-data-retention or modified-monitoring configuration may change applicable periods or features. The current OpenAI terms, project settings, and data controls govern provider-side handling.

Do not submit passwords, access keys, payment-card data, government identifiers, health information, children’s information, unnecessary personal data, or raw confidential information you are not authorized to send to OpenAI. Use a minimized summary whenever possible.

4. When and with whom we disclose information

We disclose information only for the purposes described above:

  • Cloudflare provides website and Worker delivery, D1 database, R2 object storage, KV, queues, Durable Objects, network security, and operational logs.
  • WorkOS provides AuthKit identity, sessions, organizations, memberships, invitations, and identity-event delivery.
  • OpenAI provides API model generation and review under the data handling described in Section 3.
  • Stripe provides customer, subscription, invoice, tax calculation, payment, refund, dispute, and billing-portal services. Stripe and financial participants may act independently where payment law requires.
  • Resend provides transactional email delivery. The recipient’s and our mailbox providers also process email independently.
  • Professional advisers, authorities, and transaction participants may receive information where reasonably necessary for legal advice, audit, compliance, a corporate transaction, or to respond to valid legal process, protect rights and safety, or prevent fraud.
  • Customer administrators and authorized users receive account, membership, workspace, billing, or usage information according to their role. A client guest is limited to the one authorized workspace and is not shown account-wide billing, directory, aggregate usage, or other workspace metadata.
  • A customer-selected AI client or platform independently processes the conversation, tool request, request content, returned Output, and related metadata under Customer’s agreement with that provider. That independent client handling is not processing by a Retail Reason subprocessor under our instructions.

We maintain a subprocessor register that identifies providers authorized to process information for the Services and describes their roles.

We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or rent contact lists. We do not disclose Customer Content to data brokers or use it to train another customer’s system.

5. Cookies, local storage, tracking, and browser signals

The public website stores a local theme preference named rr-theme. The account application uses necessary WorkOS authentication and PKCE cookies, security and Cloudflare Access cookies where applicable, a theme preference, and tab-scoped identifiers that keep a customer command from being submitted twice. These technologies support sign-in, security, preferences, and reliable transactions; they are not advertising cookies.

Retail Reason does not use advertising cookies, behavioral-advertising tags, or analytics that track people across unrelated websites. We will update this Policy and obtain any consent required by law before introducing such technologies.

Because Retail Reason does not currently sell or share personal information for cross-context behavioral advertising or use targeted advertising, browser “Do Not Track” and Global Privacy Control signals do not change current processing. If our practices change, we will recognize legally required opt-out signals and explain their effect before the change takes effect. Other sites and providers may collect information about activity under their own notices; Retail Reason does not authorize them to track users across unrelated sites for our advertising.

6. Retention

We retain information only for the period reasonably necessary for the disclosed purpose, security, dispute resolution, and legal obligations. The principal design periods are:

Record Retail Reason retention period
Session continuity Up to three 300-character question or draft excerpts and session state expire 24 hours after the latest session write. The context field is not stored in session state.
Raw questions, context, and answers in D1 Not stored in Retail Reason’s D1 query log. A question produces a secret-keyed HMAC fingerprint and operational metadata instead. Provider-side copies are governed separately, including the OpenAI period in Section 3.
Ordinary resolved telemetry and operational records Generally deleted, redacted, or anonymized after 90 days. This includes the HMAC-keyed question-content fingerprint, which is pseudonymous rather than anonymous.
Invitations and certain security or recovery records Some are retained or redacted on a one-year schedule. Most ordinary security and administration audit records are retained for approximately one year.
Routine clear, non-commerce sanctions screening evidence Generally retained for one year. If onboarding is abandoned, the screening was clear, and no organization is ever created, that clear onboarding evidence may be deleted after 90 days unless an investigation, legal obligation, or hold requires longer retention.
Commerce, non-clear, case, hold, and reporting sanctions evidence Screening evidence connected with commerce, a non-clear result, a compliance case or disposition, a provider hold, an incident, or regulatory reporting is generally retained for 10 years, or longer when required by law or a documented hold. Records concerning blocked property are retained while the property remains blocked and for at least the legally required period after unblocking, which may be 10 years, and longer where another obligation or hold applies.
Commercial, legal, and approval evidence Terms acceptances and necessary billing, tax, offer, renewal-notice, refund, credit, financial-allocation, and associated approval evidence are generally retained for seven years. This evidence includes the HMAC-keyed IP-address and user-agent fingerprints captured with account and commerce acceptance.
Account and workspace configuration after access ends Designed to remain recoverable for 30 days, followed by deletion or anonymization after required identity-provider and safety work completes.
Email Successfully sent transactional outbox rows are generally deleted after 90 days. The email itself remains subject to recipient and mailbox-provider retention.
Provider logs, payment, identity, and backups Subject to each provider’s terms, legal duties, deletion cycles, and backup or recovery schedules.

An unresolved payment, refund, identity, email, deletion, security, or reconciliation obligation is retained until it is safely resolved; the applicable post-resolution period then runs. We may also retain information longer for a documented legal hold, fraud or security investigation, tax or accounting requirement, or to establish, exercise, or defend legal claims. We will not represent that a row deletion proves immediate removal from every provider or recovery copy.

Access to sanctions candidates, cases, dispositions, provider-hold records, and reporting evidence is limited to authorized personnel and service providers that need the information for compliance, security, legal, payment, or reporting work.

7. Security

Retail Reason uses transport encryption, Cloudflare encryption at rest for D1, role and workspace authorization, one-time-display access keys that are hashed at rest, secret-keyed telemetry fingerprints, environment separation, provider-signature verification, idempotency controls, and minimized operational logs. Access is restricted to people and providers that need it for the purposes described here.

No security measure is perfect. Retail Reason does not currently offer a SOC 2 report or penetration-test report. If a security incident affects personal information, we will investigate, contain it, and give legally required notices. Vulnerabilities may be reported through security.txt or by emailing [email protected] with the subject “Security Report.”

8. Customer responsibilities and privacy roles

Retail Reason determines the purposes and means of processing account identity, billing, usage, fraud, security, legal, and support information and acts as controller or business for that information where those concepts apply.

Customer determines what it submits as Customer Content and is responsible for its legal basis, notices, permissions, minimization, rights handling, and instructions for client or employee data. Retail Reason is intended to act only as Customer’s processor or service provider for authorized personal data in Customer Content, but self-service Terms do not by themselves authorize regulated personal-data processing. Before submitting personal data that requires an Article 28 agreement, state service-provider terms, sector-specific terms, a transfer mechanism, or a separately negotiated DPA, Customer must email [email protected] and obtain our written agreement.

9. Privacy rights and requests

Depending on location and applicable law, an individual may have rights to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; restrict or object to processing; opt out of sale, sharing, targeted advertising, or certain profiling; limit use of sensitive personal information; and appeal a denied request. We do not discriminate against a person for exercising a privacy right.

Send a request to [email protected] with the subject “Privacy Request.” For postal requests, use the seller address shown on Customer’s invoice or accepted Order. State the relationship to Retail Reason, the right requested, and the relevant account email; do not send a password, access key, government ID, payment-card number, or unnecessary sensitive information.

We will verify the requester using information appropriate to the request and risk. An authorized agent must provide proof of authority, and we may separately verify the individual. We will respond and, where applicable, offer an appeal within the time required by applicable law. An account download is a convenient product export, not necessarily a complete response to a statutory access request. We may deny or limit a request where law permits, including when we cannot verify identity, must preserve another person’s rights, or must retain a record for legal, security, fraud, tax, or contractual reasons. We will explain a denial unless prohibited.

10. International processing

Retail Reason is operated from the United States and permits Authorized Users to access the Services only while they are physically located in the Launch Territory. Some providers listed above may process information in the United States and other countries, which may have different data-protection laws. Before submitting personal data that requires a DPA, transfer mechanism, localization commitment, or provider-region commitment, Customer must email [email protected] and obtain our written agreement. We do not promise United States-only storage or a particular transfer mechanism unless agreed in writing.

11. Children

The Services are business tools for adults. A person under 18 may not use them, and Customer must not submit a minor’s personal information. We do not knowingly collect personal information directly from anyone under 18. If you believe a minor has provided information, email [email protected] so we can investigate and delete it where required.

12. Changes to this Policy

We will not use already-collected personal information for a materially incompatible new purpose without the notice or consent required by law. We will post each revision with its effective date and preserve its canonical text record. For a material change, we will give reasonable advance notice through the account or owner email; a legally required or urgent security change may take effect sooner with notice as soon as reasonably possible.

13. Contact

Startup Success Lab LLC, a Missouri limited liability company, owns and operates Retail Reason. Privacy questions, requests, and complaints may be sent to [email protected] with the subject “Privacy.” For postal correspondence, use the seller address on Customer’s invoice or accepted Order.