Privacy Policy
Last updated: 3 July 2026
PRISM is an autonomous marketing platform operated by AI Foundry Ventures LLP (“PRISM”, “we”, “us”), Bengaluru, India. This policy explains what data we collect from the brands who use PRISM, why we access it, how we protect it, and how you can remove it. We collect only what the platform needs to compute your marketing audit and run the agents you authorise.
Who this covers
This policy applies to the brands and their teams who create an account and connect their commerce, advertising and analytics accounts to PRISM. It does not describe the handling of your own customers’ personal data on the connected platforms — that remains governed by your agreements with those platforms.
Data we collect
- Account data. The email address you sign in with. We authenticate with single-use magic links; we do not ask for or store a password on your behalf.
- Connection credentials. The API tokens and account identifiers you provide to connect Shopify, Meta and Google Analytics 4. These are encrypted at rest and never returned over the API after you save them.
- Connected-platform data. The commerce, advertising and analytics data PRISM reads on your behalf to produce your audit — for example Shopify orders and catalogue, Meta ad spend and reported conversions, and Google Analytics 4 purchase counts by channel.
- Files you upload. Any CSV or spreadsheet exports you upload during onboarding, stored per-brand and encrypted at rest.
Google user data
With your explicit authorisation, PRISM accesses your Google Analytics 4 data using the analytics.readonly scope. This access is:
- Read-only. We only read aggregated reporting data — specifically the count of e-commerce purchases GA4 attributes to each default channel group. We never create, modify or delete anything in your Google account.
- Purpose-limited. We use it solely to verify, inside your audit, how many paid-social purchases your store independently records — the figure that exposes ad-platform over-attribution. It is shown only to you and your authorised team.
- Granted by you, revocable by you. You grant our platform identity (ga4@aifoundryventures.com) Viewer access on your GA4 property; removing that access, or deleting the connection in PRISM, immediately ends our access.
Limited Use disclosure.PRISM’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, do not use it for advertising, do not transfer it except as needed to provide the service you requested (or as required by law), and do not allow humans to read it except with your consent, for security, or to comply with law.
How we use your data
- To authenticate you and give your team access to your brand’s workspace.
- To compute your Spend Truth and Settlement Truth audits and the agents’ recommendations.
- To operate, secure, debug and improve the platform.
We do not sell your data or use it to train models for other customers.
How we protect it
- Connection tokens and uploaded files are encrypted at rest.
- All traffic is served over HTTPS; API access requires authentication and is scoped to your brand.
- We do not log secrets or full payloads containing personal data.
- Access follows least privilege; the platform reads only the scopes you grant.
Retention and deletion
We keep your data only while your account is active. You can delete a connection at any time, which removes the stored credentials and ends our access to that platform. Deleting a brand removes its records, its uploaded files and its derived data. To request deletion of your account and all associated data, email us at the address below and we will action it promptly.
Sub-processors
We rely on a small set of infrastructure providers to run PRISM — cloud hosting and a transactional email provider for magic-link sign-in. They process data only to provide their service to us and under their own security commitments.
Changes
We may update this policy as the platform evolves. Material changes will be reflected on this page with a new “last updated” date.
Contact
AI Foundry Ventures LLP, Bengaluru, India.
Questions or deletion requests: sunjoyrao@aifoundryventures.com