Early-bird: $45/month · lock your rate before the price goes up
what you need to know

Privacy Policy

Your Privacy Matters

This privacy policy has been compiled to better serve those who are concerned with how their 'Personally Identifiable Information' (PII) is being used online. PII, as described in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website.

What personal information do we collect from the people that visit our blog, website or app?

When ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, mailing address, phone number, credit card information or other details to help you with your experience.

How do we use your information?

We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:

  • To personalize your experience and to allow us to deliver the type of content and product offerings in which you are most interested
  • To improve our website in order to better serve you.
  • To allow us to better service you in responding to your customer service requests.
  • To administer a contest, promotion, survey or other site feature.
  • To send periodic emails regarding your order or other products and services.
  • To follow up with them after correspondence (live chat, email or phone inquiries)

How do we protect your information?

Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible. We do not use Malware Scanning. Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. We implement a variety of security measures when a user places an order enters, submits, or accesses their information to maintain the safety of your personal information. All transactions are processed through a gateway provider and are not stored or processed on our servers.

Do we use 'cookies'?

Yes. Cookies are small files that a site or its service provider transfers to your computer's hard drive through your Web browser (if you allow) that enables the site's or service provider's systems to recognize your browser and capture and remember certain information. For instance, we use cookies to help us remember and process the items in your shopping cart. They are also used to help us understand your preferences based on previous or current site activity, which enables us to provide you with improved services. We also use cookies to help us compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future.

  • Help remember and process the items in the shopping cart.
  • Understand and save user's preferences for future visits.
  • Compile aggregate data about site traffic and site interactions in order to offer better site experiences and tools in the future. We may also use trusted third-party services that track this information on our behalf.

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Since browser is a little different, look at your browser's Help Menu to learn the correct way to modify your cookies. If you turn cookies off, some features will be disabled. It won't affect the user's experience that makes your site experience more efficient and may not function properly. However, you will still be able to place orders.

Third-party disclosure

Do we disclose the information we collect to Third-Parties?

We do not sell, rent or trade your personally identifiable information. We do not exchange personal information for money or for anything else of value, and we never disclose it to data brokers.

We disclose personal information only in the limited circumstances below:

  • Subprocessors — the infrastructure providers listed further down this page, who process data only to operate MKOS on our behalf.
  • Where the law requires it — to comply with a legal obligation, court order or lawful request, or to protect our rights, safety or property.

Third-party links

Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party sites have separate and independent privacy policies. We, therefore, have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.

Advertising and third-party trackers

This website does not serve advertising and does not run advertising or analytics trackers. We do not use Google AdSense, the Google Display Network, DoubleClick, remarketing tags, or a Meta pixel on mkos.ai. No third-party advertising cookie is set by this site, so there is no interest-based advertising to opt out of here.

If that ever changes, this section will be updated before the tracker is deployed, and any non-essential tracker will be gated behind a consent banner.

Meta Marketing API (MKOS internal advertising tools)

Klebanov, LLC d/b/a MKOS operates a private application registered with Meta, used to manage our own advertising. This section describes it because our Meta app links to this policy.

Who can use it: nobody outside our business. The application is private, is not listed or distributed, cannot be installed by a third party, and has no end users. It authenticates as a single system user belonging to Klebanov, LLC.

What it reaches: only advertising accounts, Facebook Pages, Instagram accounts and advertising datasets that Klebanov, LLC owns. It has no access to the data of any other business, and that limit is enforced by Meta through per-asset permissions rather than by configuration on our side.

What it does: creates and manages our advertising campaigns, publishes our own organic posts, reads performance reporting for our own accounts, and retrieves enquiries submitted to our own lead forms.

Lead data: where a person submits a lead form on one of our brands, the details they enter are retrieved and used only to reply to that enquiry. Lead data is never sold, never shared with a third party, and never used to build advertising profiles.

Retention and deletion: data obtained through the Meta APIs is retained only as long as needed for the purpose it was obtained for, and is deleted on request. Write to paul@mkos.ai and we will action a deletion request within 30 days.

Terms: our use of Meta platform data is governed by the Meta Platform Terms, including its restrictions on data retention, onward transfer and permitted use.

COPPA (Children Online Privacy Protection Act)

When it comes to the collection of personal information from children under the age of 13 years old, the Children's Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States' consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children's privacy and safety online. We do not specifically market to children under the age of 13 years old.

Fair Information Practices

The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:

  • We will notify you via email
  • Within 7 business days

We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.

CAN-SPAM Act

The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

To be in accordance with CAN-SPAM, we agree to the following: If at any time you would like to unsubscribe from receiving future emails, you can reach out to paul@mkos.ai and we will promptly remove you from ALL correspondence.

Shopify Data Handling (MKOS Analytics)

This section applies when a merchant installs the MKOS Analytics app on their Shopify store. Under the GDPR, the merchant is the data controller and MKOS is the data processor. MKOS only processes Shopify data on behalf of, and under the written instructions of, the merchant.

What we read from Shopify: order totals, line-item counts, discount amounts, shipping amounts, tax amounts, refunds, currency, created-at timestamps, the customer's order position index (customerJourneySummary.customerOrderIndex) used solely to classify an order as first-time vs. returning, and aggregated product / inventory metadata required for cost-of-goods calculations.

What we do NOT read or store: shopper names, email addresses, phone numbers, physical addresses, billing or shipping addresses, IP addresses, payment card data, or any other shopper personally identifiable information (PII). Our GraphQL selection sets explicitly omit these fields, and a build-time CI check (scripts/shopify-readonly-lint.mjs) fails the build if any write scope or PII field ever enters the Shopify module.

Read-only: MKOS never creates, modifies, or deletes data in your Shopify store. The only GraphQL mutations we call are infrastructure operations that do not touch merchant data: bulkOperationRunQuery and bulkOperationCancel (which start and stop background READ jobs on Shopify's side) and webhookSubscriptionCreate/Delete/Update (which manages where Shopify sends compliance event notifications).

Retention: order data is retained while the MKOS subscription is active. When you uninstall the app, we stop all syncs and delete your data within 30 days, or immediately upon receipt of a valid shop/redact webhook from Shopify (whichever is sooner). We respond to customers/data_request and customers/redact webhooks as required by the Shopify Protected Customer Data policy. Because we store no shopper PII, our response to those topics is a compliant 200 OK with no data to produce or delete.

Security: your Shopify access token is encrypted with AES-256-GCM using a versioned server-side key before persistence. In transit, all communication with Shopify's API, our servers, and your browser is over TLS.

Subprocessors: we use the following trusted infrastructure providers to deliver MKOS:

  • Supabase — managed Postgres database (US region)
  • Vercel — serverless application hosting
  • Cloudflare R2 — object storage for non-PII static assets (future use)

Your rights: under the GDPR and CCPA you have the right to request access to, correction of, or deletion of data we process about your store. Contact paul@mkos.ai and we will respond within 30 days.

Last modified: August 19, 2026

Get Started

Ready to Transform Your Marketing?

Learn how MKOS.AI can help you scale your DTC brand with AI-powered automation and expert support.

Get started