Privacy Policy

Effective Date: August 11, 2026

ClariPoint provides publishing infrastructure. This Privacy Policy explains how ClariPoint (“ClariPoint,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use ClariPoint websites, ClariPoint-operated services and APIs, software integrations, and related services.

By using ClariPoint, you acknowledge the practices described in this Privacy Policy.

Scope

This Privacy Policy applies to claripoint.ai and to ClariPoint-operated services, APIs, integrations, and hosted deployments.

ClariPoint Core can also be deployed and operated independently by software publishers on infrastructure they control. When a publisher operates a self-hosted ClariPoint Core deployment, that publisher is responsible for its own privacy practices and for the data processed through its deployment, except to the extent information is separately provided to ClariPoint.

Software publishers using ClariPoint may also have their own privacy policies governing their relationships with their customers.

Information We Collect

The information ClariPoint processes depends on how the service is used.

Publisher and account information. We may process names, email addresses, organization information, account or service identifiers, configuration information, integration credentials, and communications you send to us.

Commerce integration information. When a publisher connects a supported commerce platform such as Squarespace, ClariPoint may process information necessary to connect the publisher’s store and establish software ownership and licensing.

For Squarespace integrations, this may include Squarespace website or account identifiers, authorization information, order and line-item information, customer identifiers and email-address snapshots, product and variant identifiers, SKU and product-name snapshots, payment status and totals, fulfillment and refund information, and synchronization metadata.

ClariPoint does not intentionally import full Squarespace order payloads, postal addresses, telephone numbers, checkout answers, or payment-card information for its commerce and entitlement functions.

OAuth access credentials, refresh credentials, and related integration secrets are treated as sensitive credentials and protected accordingly.

Software ownership and licensing information. ClariPoint may process customer email addresses, purchase sources, external transaction identifiers, product ownership and entitlements, refund or revocation status, manual grants, product identifiers, and related audit information.

Verification, authentication, and activation information. When software uses ClariPoint for verification or licensing, we may process verification requests, authentication or access-token information, activation status, device references, first- and last-seen information, and information needed to enforce applicable activation limits.

Where device identification is required, ClariPoint is designed to use pseudonymous device references and keyed fingerprints rather than storing raw hardware identifiers where practicable.

Release, update, and download information. ClariPoint may process product and software version information, release channels, platform and architecture information, update requests, authorization status, installer or artifact information, and records related to authorized downloads.

Technical and security information. ClariPoint may process technical information necessary to operate and secure the service, such as timestamps, request identifiers, requested endpoints, response status, error information, and security events. Hosting and network providers may also process IP addresses and connection metadata as part of providing and securing Internet services.

ClariPoint is designed to redact credentials and personal information from application logs where that information is not needed for legitimate operational purposes.

Website information. The ClariPoint website is hosted using Squarespace. Squarespace and related website technologies may process browser, device, cookie, and connection information needed to deliver, secure, and measure use of the website. Squarespace’s processing of information is also governed by its own privacy practices.

How We Use Information

We use information to provide and operate ClariPoint; connect publisher commerce systems; determine purchases, ownership, and software entitlements; verify customers; administer licenses and device activations; publish and distribute software releases and updates; authorize secure downloads; maintain service security and prevent abuse; provide customer and publisher support; diagnose errors and maintain reliability; maintain transaction, entitlement, and audit records; comply with legal obligations; and protect the rights, security, and integrity of ClariPoint, publishers, and users.

Where applicable law requires a legal basis for processing, processing may be based on performance of a contract, legitimate business interests, compliance with legal obligations, or consent where consent is required.

Squarespace Integration and OAuth

Publishers may authorize ClariPoint to access permitted Squarespace information using Squarespace OAuth.

ClariPoint uses this access to perform the commerce and software-publishing functions authorized by the publisher. OAuth credentials and related integration secrets are treated as sensitive credentials and are protected using appropriate security controls, including encryption where implemented by the service.

A publisher may revoke ClariPoint’s authorization through Squarespace. Revocation prevents future API access that requires the revoked authorization. Information previously imported or generated by ClariPoint may still be retained where necessary to preserve software ownership and entitlement records, reconcile transactions, maintain security or audit records, resolve disputes, or comply with legal obligations.

ClariPoint does not obtain or store customers’ payment-card numbers through the Squarespace integration.

How We Share Information

ClariPoint does not sell personal information for money and does not use personal information to provide third-party behavioral advertising.

We may disclose information to software publishers when the information relates to customers, products, licenses, purchases, or services administered by that publisher.

We may also use service providers to perform functions such as website hosting, application hosting, databases, object storage, transactional email, commerce integration, monitoring, security, backups, and other infrastructure services. These providers may process information only as necessary to provide their services to ClariPoint or as otherwise permitted by applicable law.

We may disclose information when reasonably necessary to comply with law, legal process, or governmental requests; protect the rights or security of ClariPoint or others; investigate fraud, abuse, or security incidents; or establish, exercise, or defend legal claims.

If ClariPoint or relevant assets are involved in a merger, acquisition, financing, reorganization, or sale, information may be transferred as part of that transaction subject to applicable law.

ClariPoint Core and Publisher-Controlled Data

ClariPoint Core is designed to allow software publishers to operate ClariPoint on infrastructure they select and control.

When a publisher operates its own ClariPoint Core deployment, the publisher generally determines what customer information is processed, where that information is stored, which service providers are used, and how long information is retained. In those circumstances, questions or requests concerning customer information should normally be directed to the publisher operating that deployment.

ClariPoint does not automatically receive customer data merely because a publisher uses self-hosted ClariPoint Core.

Data Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

Depending on the service and type of information, these measures may include encrypted communications, encrypted storage of sensitive integration credentials, hashed authentication or verification credentials, pseudonymous device identifiers, access controls, tenant and organization isolation, private software-artifact storage, temporary authorized download URLs, dependency and security auditing, and sensitive-data redaction in application logs.

No Internet-connected system can be guaranteed to be completely secure, and we cannot guarantee absolute security.

Data Retention

We retain information for as long as reasonably necessary for the purposes for which it was collected, including providing ClariPoint services, maintaining software ownership and entitlement records, administering licenses and downloads, supporting publishers and customers, maintaining security and audit records, resolving disputes, and complying with legal obligations.

Different categories of information may be retained for different periods.

Temporary verification information and authentication credentials may have defined expiration or revocation lifecycles. Commerce, purchase, entitlement, refund, and ownership records may need to be retained for longer periods because they establish a customer’s right to use software or document historical transactions.

Disconnecting an external integration does not necessarily require deletion of historical purchase, entitlement, or audit records.

When information is no longer reasonably required, we may delete, anonymize, or otherwise dispose of it consistent with applicable law and operational requirements.

Your Privacy Rights

Depending on where you live and applicable law, you may have rights concerning your personal information, including rights to request access, correction, deletion, or a copy of certain information; object to or restrict certain processing; withdraw consent where processing relies on consent; or appeal certain privacy decisions.

We may need to verify your identity before completing a request.

When ClariPoint processes information on behalf of a software publisher, the publisher may be primarily responsible for responding to the request. In that situation, we may direct you to the applicable publisher or assist the publisher as appropriate.

To make a privacy request, contact us at privacy@claripoint.ai.

Children’s Privacy

ClariPoint is intended for software publishers, developers, businesses, and users of their software. It is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 through ClariPoint-operated services.

If we learn that information was collected from a child in violation of applicable law, we will take appropriate steps to address it.

International Processing

ClariPoint and its service providers may process information in the United States and in other countries where infrastructure or service providers operate.

Where required by applicable law, appropriate safeguards will be used for international transfers of personal information.

Third-Party Services

ClariPoint may integrate with third-party services such as commerce platforms, hosting providers, storage providers, email providers, and other software infrastructure.

Those third parties may separately process information under their own terms and privacy policies. ClariPoint is not responsible for the independent privacy practices of third-party services.

Changes to This Privacy Policy

We may update this Privacy Policy as ClariPoint evolves, new integrations or services are introduced, or legal or operational requirements change.

When we make changes, we will update the effective date displayed at the top of this policy. If a change materially affects how personal information is handled, we will provide additional notice when required by applicable law.

Contact Us

Questions about this Privacy Policy or ClariPoint’s privacy practices may be sent to:

ClariPoint
Email: privacy@claripoint.ai