Privacy Policy
We collect the minimum needed to help you, we store it securely, and we never sell it. This page describes exactly what that means.
1. Who we are
"Atlais Shop", "we", "us", or "our" refers to the Atlais Shop personal services business operated in the United States. Atlais Shop is a personal AI concierge that helps individuals and families handle purchases, research, scheduling, and communication through WhatsApp. You can reach us at support@atlais.com.
2. What information we collect
We collect only what we need to perform the task you've asked us to do. Specifically:
- Your identifiers. Your name, phone number, email address, and the WhatsApp account you message us from. These are used to route our replies back to you and to remember context across conversations.
- The content of your messages. Everything you say to Atlais — your requests, preferences, follow-up questions — is stored so we can remember context across conversations and learn your preferences over time.
- Relationships and people you mention. If you tell Atlais about your family members, friends, coworkers, or the recipients of purchases, we store that information so Atlais can act on it in future conversations (for example, remembering your mother's address for future gifts). We do not contact those people unless you ask us to.
- Spending authorizations. Each time you authorize Atlais to spend money on your behalf, we record the scope (amount, merchants, validity window) so we can enforce the limits you set. Authorizations are logged for audit and dispute resolution.
- Purchase history and order confirmations. For every purchase Atlais handles, we store the merchant name, order id, amount, date, and delivery status. This is how we answer questions like "did my order ship yet?" and how we help you dispute a charge later if something goes wrong.
- Technical metadata. Standard server logs, network-level metadata (IP address, user agent), and error reports. This is necessary to operate the service, detect fraud, and diagnose bugs.
3. What we do NOT collect or store
- Your card numbers. Atlais never sees, handles, or stores your raw payment card data. Every purchase routes through Google Pay, which produces an encrypted token that the merchant's payment processor (Stripe) decrypts and charges. Atlais never touches the card itself.
- Your biometrics. When you authorize a payment with your fingerprint or face on the Google Pay sheet, your biometric data stays on your device. Google, not Atlais, handles the authentication; Atlais only learns whether the authentication succeeded.
- Other people's private information without consent. If you mention someone in a message, we store the context you provided (e.g., "my mother Kinder in Connecticut"), but we do not independently look up, track, or contact them.
4. How we use your information
We use the information above for four purposes, and only these four:
- Performing the tasks you ask us to do. This includes finding products, comparing options, placing orders, scheduling meetings, sending messages, and answering your questions.
- Remembering context across conversations. So you don't have to repeat yourself every time you message us.
- Keeping you and the service safe. We use technical metadata to detect fraud, abuse, and attempts to use Atlais to harm others. We enforce the spending limits you set so no unauthorized purchases can occur on your card.
- Improving the service. We may use anonymized, aggregated patterns from user behavior to improve how Atlais works for everyone — for example, learning which merchants handle returns well. We do not sell this data or share it with advertisers.
5. Who we share your information with
We share your information only in the following narrow circumstances:
- Merchants you're buying from. When you place an order, the merchant needs your name, shipping address, email, and any order-specific details you provided. They do not receive your conversation history or information about other purchases.
- Service providers we use to run Atlais. WhatsApp (via Twilio), Google Pay, Stripe, Google Cloud (hosting), Anthropic and other AI model providers (for language understanding), and similar infrastructure. Each of these only receives the specific information needed for its role. None of them receive your full conversation history for their own use.
- Legal requirements. If we receive a valid subpoena or court order, we will comply to the extent legally required. We will notify you when we are legally permitted to do so.
- Business transfers. If Atlais is acquired, merged, or its assets sold, your information may transfer to the new owner. The new owner is bound by the terms of this privacy policy unless you agree to different terms.
We do not sell your data to advertisers, marketers, or data brokers. Period.
6. How we protect your information
Your data is stored in encrypted databases hosted on Google Cloud infrastructure in the United States. All access is authenticated and logged. Payment tokens and spending authorization records are additionally isolated with per-customer row-level security so staff cannot browse your records without an active support ticket. We follow industry standard practices for vulnerability management, access review, and incident response.
No system is perfectly secure. If we discover a security breach that affects your information, we will notify you promptly with a description of what was exposed and what we're doing about it.
7. Your rights
You have the right to access, correct, export, and delete the personal information we hold about you. To exercise any of these rights, email support@atlais.com from the email address associated with your account. We respond within 30 days.
Specifically, you can:
- Access — request a copy of everything we know about you, including your conversation history and purchase records.
- Correct — ask us to fix anything that's wrong in your records.
- Delete — request permanent deletion of your account and all associated data. We will remove your data from active systems within 30 days. Backup retention periods may extend slightly beyond this, and we retain minimal transaction records as required by tax and financial regulations.
- Export — receive a machine-readable copy of your data (typically JSON) so you can take it elsewhere.
- Revoke authorizations — cancel any spending authorization immediately by messaging Atlais or via the customer support process. Revocation takes effect immediately and cannot be reversed.
8. California residents
If you are a California resident, the CCPA and CPRA grant you additional rights. You can request information about the categories of personal information we've collected, the business purposes for collection, and the categories of third parties we've shared the information with. You may also opt out of the sale or sharing of personal information — though since we don't sell or share personal information for advertising purposes, this opt-out is automatic.
9. European residents
If you are in the European Economic Area, United Kingdom, or Switzerland, the GDPR grants you the rights described above plus the right to lodge a complaint with your national data protection authority. We process personal data under the legal basis of contract performance (performing the tasks you ask us to do) and legitimate interest (improving and securing the service). We do not currently offer Atlais commercially in the EEA; if you reach us from the EEA we will make reasonable efforts to accommodate your rights on request.
10. Children
Atlais is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has interacted with Atlais, contact us and we will delete the associated data.
11. Changes to this policy
We may update this privacy policy from time to time. The "Effective date" at the top reflects the most recent update. If we make material changes that affect how we use your existing data, we will notify you by email or WhatsApp before the changes take effect. Continued use of Atlais after the effective date constitutes acceptance of the updated terms.
12. Contact
Questions about this privacy policy or about how your data is handled? Email support@atlais.com.