← Back to MGO Data
Privacy Policy
MGO Data · Contact: [email protected]
The short version
When you apply to work with us, you email us your name, your business website, and whatever you choose to tell us. We use it to review your application, run your audit, and reply to you. We do not sell your information. Ever. You can ask us what we have on you, ask us to correct it, or ask us to delete it, and we will.
Who we are
MGO Data is an ecommerce SEO and AI-visibility software company that builds DT 1.5, an approval-gated Shopify SEO automation platform. We also provide separate human SEO, advertising, and branding services.
Contact for anything in this policy: [email protected]
What we collect
What you send us when you apply:
Our contact page does not submit anything to our servers. The application form opens a pre-filled email in your own mail app, addressed to [email protected]. Nothing is sent unless you press send yourself. What you choose to send us typically includes:
- Your name
- Your business website address
- Your email address
- Anything you write in the message
What you give us if you become a client:
- Business details needed to do the work, such as your business address, phone number, hours, and, where you grant it, the access or authorization needed to work on your site, ad accounts, or business listings on your behalf
- Payment is handled by our payment processor, Stripe. We do not see or store your full card number.
What we collect if you create a DT 1.5 account:
- Your email address and sign-in credentials, handled by our authentication provider (Supabase); we never see your password
- During the current open beta, DT 1.5 account access requires no payment. If paid access returns, Stripe will process payment; we will not see or store your full card number
- Platform credentials you choose to connect (for example a Shopify Admin API token or an AI provider key) are stored encrypted server-side, are never shown back to a browser, are never logged, and are used only to run the work you ask for and approve
- The work product itself: your audit findings, drafted fixes, approval decisions, assistant conversations, and business facts you ask the assistant to remember, kept so your workspace persists between visits. Do not put passwords, API keys, customer lists, or other sensitive personal data into assistant chat or memory.
What we collect automatically:
- Our website host may log standard technical data such as IP address and browser type. We do not run advertising trackers.
- If you run an audit in the public demo or DT 1.5 dashboard, the website address you type is sent to our audit service so it can crawl that site's public pages. The address and public page content are processed to return the report. Do not submit private, password-protected, signed-preview, or customer-specific links.
How we use it
- To review your application and run the audit or services you asked for
- To email you results, invoices, and service updates
- To do the marketing work you hired us for
- To respond when you contact us
We do not use your information for anything else. We do not send marketing email unless you asked for it, and every marketing email includes a working unsubscribe.
What we do not do
- We do not sell your personal information.
- We do not share it with third parties for their marketing.
- We do not buy lists or add you to lists.
Who else touches your data
We use a small number of service providers to run the business. They process data only to provide their service to us:
- Email: applications and contact go straight to our email inbox at [email protected]; no form vendor sits in the middle
- Stripe: human-service and any future software payments; Stripe handles your card, we never store it
- Supabase: DT 1.5 account sign-in and app data
- Cloudflare: website hosting and the servers that run audits and store connected credentials in encrypted form
- AI model and answer-engine providers: when you use the Assistant or an AI-answer scan, the provider you select, or the provider clearly labeled as included with MGO, processes the prompt and the business/public-site context needed to answer it. Depending on what is enabled, this can include OpenAI, Anthropic, Google, Groq, Perplexity, xAI, Mistral, DeepSeek, or Moonshot. Connected API keys are sent only to that provider as request credentials, not placed into the prompt. Provider privacy and retention rules also apply.
If the work you hire us for includes correcting your business listings (part of the branding lane), we submit your public business information (name, address, phone, hours, website) to directories and data sources. That is the service itself, and that information is business information you asked us to publish or correct.
How long we keep it
- Application emails: deleted within 12 months if you never become a client
- Client records: kept while you are a client and for as long as tax and accounting rules require afterward
Your rights and data requests
Email [email protected] and we will, within 30 days:
- Tell you what information we have about you
- Correct it
- Delete it, unless we are legally required to keep it (for example, invoices)
- Stop emailing you
We honor these requests for everyone, regardless of where you live. Note: we are a small business that does not meet the coverage thresholds of laws like the California Consumer Privacy Act (roughly $26.6 million in annual revenue or data on 100,000 or more consumers, per the California Privacy Protection Agency and Clym's 2026 applicability guide), but we follow the spirit of those laws anyway.
Children
Our service is for businesses. We do not knowingly collect information from anyone under 18.
Changes
If we change this policy, we will post the updated version here. If a change is significant, we will email active clients before it takes effect.
Contact
MGO Data · [email protected]