This Privacy Policy explains how Cnnex Limited Company ("Cnnex", "we", "us"), operator of the Hasmord platform (the "Service"), collects, uses, discloses, and protects personal data, and the rights you have. By using the Service you agree to this policy. Where we act as a processor of data you upload, we process it on your instructions to provide the Service.
Google user data and Limited Use
Hasmord accesses Google user data only when you explicitly connect your Google Analytics account, and only to power the AI-referral analytics described in this policy. This section describes that access specifically.
- What we access: read-only Google Analytics reporting data through the Google Analytics Data API, using the
https://www.googleapis.com/auth/analytics.readonly scope. We read aggregated session and referral metrics (traffic source / medium, landing page, and session and event counts) for the GA property you choose to map to your workspace, plus your name and email address from your Google sign-in. We do not access Gmail, Google Drive, Contacts, Search Console, or any other Google service, and we do not request write access.
- Why we access it: to attribute visits sent by AI assistants (such as ChatGPT, Perplexity, Gemini, and Copilot) to your specific products, so you can measure real AI-driven traffic to the pages you optimize with Hasmord.
- What we store: only the aggregated daily metrics needed to render your reports, scoped to your workspace. We store your Google OAuth refresh token in encrypted form solely to keep the connection active; you can revoke it at any time by disconnecting in Settings → Integrations, or from your Google Account’s third-party access settings.
- No AI training, no sale, no ads: we do not use Google user data to develop, improve, or train generalized/non-personalized AI or machine-learning models, and we never sell it, transfer it to data brokers, or use it for advertising.
Limited Use. Hasmord’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Data we collect
- Account data: your name and email from your OAuth provider (Google, Microsoft, or Apple) when you sign in, and your role and workspace membership.
- Product & content data: the product URLs, categories, brand/model fields, and content you submit for analysis, plus the reports, drafts, and results generated from them.
- Analytics data: when you connect Google Analytics, read-only referral and session metrics used to attribute AI-driven traffic to your products. We request the minimum scope needed and you can disconnect at any time.
- Billing data: subscription status and identifiers from our payment processor. We never receive or store your full card number.
- Usage & technical data: logs, device/browser metadata, and diagnostic information needed to operate, secure, and troubleshoot the Service.
- Website analytics cookies: our public website (hasmord.com) uses Google Analytics 4 (GA4) to understand traffic sources and usage. These analytics cookies are set only after you accept the cookie banner; you can decline it, in which case analytics runs in a cookieless, privacy-preserving mode (Google Consent Mode). You can change your choice by clearing this site's data in your browser.
2. Commerce integrations (Shopify & Amazon)
If you install our Shopify app (“Hasmord — AI Answer Optimization”), the following applies to your Shopify store data:
- What we access: read-only product information via Shopify’s Admin API (the
read_products scope) — product titles, types, handles, status, online-store URLs, and images. We do not request access to orders, customers, or customer personal data.
- How we use it: we send your product page URLs and category to our scoring service to compute AI-readiness (AEO) scores and suggested fixes, which we show back to you in the app. Scoring is performed statelessly — product content is not retained after a score is returned.
- What we store: only your Shopify session/authentication tokens (to keep you signed in) in our secured database. We do not store your customers’ personal data.
- Mandatory privacy webhooks: we implement Shopify’s GDPR/compliance webhooks —
customers/data_request, customers/redact, and shop/redact. Because the app stores no customer personal data, data-request and customer-redact requests are acknowledged with nothing to return or erase; a shop-redact request deletes your store’s session data from our systems.
- Uninstalling: when you uninstall the app we delete your store’s session tokens. You can contact us to request deletion of any remaining app data.
Amazon Selling Partner API. If you connect your Amazon seller account (via Amazon’s Login with Amazon OAuth), the following applies to your Amazon Selling Partner data:
- What we access: your own product listing content through the Amazon Selling Partner API, using the Product Listing role only (
putListingsItem / patchListingsItem, including A+ content) — item titles, bullet points, descriptions, search terms, and listing images. We do not request or access orders, buyer information, or any buyer personal data, and we request no restricted (PII) roles.
- How we use it: to publish AI-optimized listing content back to your own listings, on your behalf and at your direction, so AI answer engines and shoppers surface your products more accurately. Each seller’s data is isolated to that seller’s workspace and used solely to optimize that seller’s own listings.
- What we store: your Amazon OAuth refresh token in encrypted form (solely to keep the connection active) and the listing content you choose to generate and publish. We do not store Amazon orders or buyer data.
- Sharing: Amazon Information is processed only within our own systems and the subprocessors listed in “Sharing & subprocessors” below (cloud hosting and LLM providers, used only to generate listing copy from your product data). We never sell or disclose Amazon Information to any other party.
- Disconnecting: you can disconnect your Amazon account at any time in the app and request deletion of the associated data; disconnecting revokes our access.
3. How we use data
- To generate AEO reports, product information, citation probes, and analytics for your workspace, and to provide the features you use.
- To operate, secure, maintain, debug, and improve the Service, and to prevent fraud and abuse.
- To process payments, manage subscriptions, and send service and account communications.
- We do not sell your personal data, and we do not use your Customer Data to train our own or third parties' foundation AI models.
4. Legal bases
Where applicable law (such as the GDPR) requires a legal basis, we rely on: performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (for example, connecting Google Analytics), and compliance with legal obligations.
5. Sharing & subprocessors
We share data only with service providers that help us run the Service, under contractual confidentiality and security obligations:
- Cloud hosting and database providers used to run and back up the platform.
- Stripe, for payment processing (we never store your full card number).
- LLM API providers (OpenAI, Anthropic, Google, Perplexity) used only to run the citation probes and enrichment you request; we send only the content needed for that request.
- The Google Analytics Data API, only when you explicitly connect it.
We may also disclose data if required by law, to protect our rights and users, or in connection with a merger or acquisition (with notice where required).
6. International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for such transfers.
7. Retention
We retain personal data only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Retention is limited to what your reports and analytics require. You may request deletion of your workspace data at any time (see below).
8. Security
We use tenant isolation, encryption in transit, access controls, and encrypted backups to protect data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. See our Security page for details.
9. Your rights
Subject to applicable law, you may access, correct, export, restrict, or delete your personal data, object to certain processing, or withdraw consent. To exercise these rights, email hs_privacy@cnnex.us and we will respond within a reasonable time. You may also have the right to complain to your local data-protection authority.
10. Cookies
We use only the cookies necessary to authenticate your session and operate the Service. We do not use non-essential advertising cookies.
11. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect data from children.
12. Changes
We may update this policy; material changes will be posted here with a new "last updated" date.
13. Contact
Privacy questions or requests: hs_privacy@cnnex.us. General support: ha_support@cnnex.us. Data controller: Cnnex Limited Company.