ShopMind

ShopMind Privacy Policy

Effective date: September 12, 2026 · Version 2026-09-12

ShopMind LLC, a Utah limited liability company (“ShopMind,” “we,” or “us”), provides business software for planning, scheduling, shop operations, file management, and manufacturing intelligence. This Privacy Policy explains how we collect, use, disclose, and retain personal information in connection with the ShopMind Web OS, our Discover website, account registration, billing, and communications with us.

Privacy contact: shopmind@shopmind.com
Billing questions: shopmind@shopmind.com
Mailing address: ShopMind LLC, PO Box 83, Providence, UT 84332

This Policy does not transfer ownership of customer files or shop data. Our Terms of Service address ownership and the limited permission needed to provide the Service. Independent third-party websites and services have their own privacy notices.

1. Business customers and their personnel

When a business uses ShopMind, it decides which personnel to invite, which records to enter, and how to use its workspace. We generally process personal information within that workspace on the business's behalf and under its instructions. The business is responsible for its own employee notices, lawful collection, and use of work records.

We also make decisions about information used to manage our own customer relationships, account security, billing, support, and business operations. Our legal role may differ depending on the processing and applicable law.

If your employer or another organization provides your account, its authorized Owner and administrators may access your identity, permissions, and work records according to their roles. Removing a seat or ending employment does not automatically erase historical records. Contact that organization first about its records; you may also contact us for help directing a request.

2. Information we collect

Category Examples and sources
Account and organization details Name, work email, company name, business country and intended user locations where requested, role, seat assignment, account status, and onboarding details provided by you or your organization.
Authentication and signup records Password hashes, session identifiers, verification-token hashes and expiration times, security verification records, and the versions and timestamps of accepted terms. We receive a password when you set or enter it; account authentication stores a hash rather than a readable password.
Shop and personnel records Job assignments, programming and setup activity, clock-in and clock-out events, operation progress, schedules, notes, and related work history entered or generated through use of the Service.
Files and workspace content Drawings, CAD files, CNC programs, images, documents, filenames, file metadata, and other uploaded or imported material. These may contain personal information supplied by your organization.
Intelligence information Questions, conversation messages, responses, authorized source excerpts, extracted text, and search representations used to retrieve relevant content. Processing records may include model identifiers, source references, token counts, latency, and provider request identifiers.
Billing records Billing contact details, selected edition, seat quantities, subscription and payment status, invoice information, and payment-provider customer and transaction identifiers. Payment credentials are entered in the payment provider's interface.
Communications and interest in ShopMind Information you provide through support, sales inquiries, demonstrations, and lead forms, including name, work email, company, business country, and message contents. Lead records may include referral sources, campaign tags, and related actions such as requesting a demo or viewing a sales document.
Technical and browser information Network addresses, request and error records, timestamps, browser or device information available to our infrastructure, session cookies, and browser-stored preferences.

We collect information directly from you, from your organization and authorized users, through use of the Service, and from payment and other providers supporting the Service. Information required to authenticate an account, provide a requested feature, or process payment may be necessary for that function to work.

Do not send passwords, full payment-card numbers, government identity documents, or unrelated sensitive personal information to support. Obtain our written agreement before submitting information requiring specialized safeguards, such as regulated health information or export-controlled technical data.

3. How we use information

We use information to create and verify accounts; provide workspaces and authorized access; process customer files and requested intelligence functions; manage subscriptions and payments; maintain work history; respond to requests; diagnose problems; secure the Service; prevent fraud and misuse; communicate service changes; and comply with legal obligations.

We use early-access inquiry details, including business country, to respond to requests, assess service availability, and arrange onboarding. An inquiry does not authorize payment or general newsletter enrollment. Please do not include shop files or employee records in the inquiry form.

We may use business contact and inquiry information to follow up on requested demonstrations and, where permitted, communicate about ShopMind products. Marketing preferences are separate from necessary account, billing, security, and service messages.

We use operational measurements to understand reliability, performance, and feature usage. Information that has been aggregated or de-identified so it cannot reasonably identify a person or customer may be used for service analysis. We do not treat merely removing a name as sufficient de-identification, and we do not attempt to re-identify information we maintain as de-identified except as legally permitted to assess the de-identification process.

4. Intelligence processing

When an authorized user uses ShopMind Intelligence, we may process the question, relevant conversation history, and source material the user is authorized to access. Uploaded material selected for intelligence processing may be converted into extracted text and search representations so relevant passages can be retrieved.

Our commercial Intelligence implementation uses OpenAI's API for model processing. Requests can include questions, conversation context, filenames, and authorized excerpts of shop material. The amount and kind of material sent depend on the feature and request. This processing is not limited to content visible in the question box.

We do not use Customer Content to train a general-purpose AI model or authorize an AI provider to do so without a separate customer opt-in. Generating an answer and creating search representations for the customer's workspace are different from training a general-purpose model. Permission to use a document for Intelligence is not permission to use it for model training.

For protected Lockbox documents, users select and authorize the specific documents for Intelligence processing. Uploading a file or selecting a folder does not by itself authorize every file in that folder, including future uploads. Access remains subject to workspace permissions. Revoking Intelligence access prevents future authorized use through that grant; it does not retract material already processed or automatically erase previously generated answers.

Our commercial answer-generation requests are configured to disable optional storage of the response object at OpenAI. Relevant conversation history can still be included with a subsequent question. This setting does not mean zero retention: security and abuse-monitoring records, model-specific processing caches, and ShopMind's own records may remain. OpenAI describes default abuse-monitoring retention of up to 30 days, with exceptions for legal or protective purposes. See OpenAI's data controls documentation. We do not promise US-only AI processing or a zero-retention arrangement.

Intelligence outputs can be incorrect. ShopMind is intended to assist human decisions; customers remain responsible for reviewing outputs before making manufacturing, safety, or personnel decisions.

5. Who receives information

We disclose information as necessary to the following recipients:

Our service delivery includes DigitalOcean application infrastructure, Stripe billing, Resend transactional email, and OpenAI model processing. The Discover website and its inquiry database use OpenAI's Sites hosting. Different providers receive different information for their functions; for example, a billing provider does not need your shop drawings to process a subscription.

We do not sell personal information or share it for cross-context behavioral advertising. We do not disclose customer files to another customer for that customer's use.

6. Cookies and browser storage

ShopMind uses cookies to maintain authenticated sessions. It also uses local or session browser storage for features such as remembering a sign-in email when selected, visual preferences, workspace layouts, and interface state. Some feature state may include information associated with shop records.

You can clear or restrict cookies and browser storage through your browser. Doing so may sign you out, remove preferences, or prevent features from working. On shared computers, sign out and avoid saving account details in the browser.

Discover uses information in a page link—such as campaign labels and a Facebook click identifier—and the referring website domain to attribute a submitted inquiry. These details are saved with the request. The form does not send those details to Meta or enroll visitors in a newsletter. We do not use Google Analytics or Meta Pixel in the Discover website. Hosting providers may process technical request records to deliver and secure the site. If we introduce optional tracking that requires consent or an opt-out, we will provide the required choice before using it.

7. Retention and deletion

Retention depends on the purpose of a record and the obligations that apply to it. We use the following criteria when deciding whether information remains necessary:

Records Retention criteria
Signup, verification, recovery, and session records Completing or securing the requested account action, preventing abuse, investigating access disputes, and demonstrating authorization. Verification and recovery links expire after 30 minutes; expiration invalidates a link but does not immediately delete its database record.
Account, permissions, and legal acceptance records Maintaining the customer relationship, proving agreed terms and permissions, and meeting applicable legal or dispute-record requirements after closure.
Billing, subscription, and transaction records Operating subscriptions, reconciling payments, handling refunds or disputes, and meeting applicable accounting and tax record requirements. Stripe may retain its own records under its policy and legal obligations.
Shop records, uploaded files, and derived Intelligence information Providing the customer's workspace and work history, carrying out authorized instructions and data-return or deletion requests, and resolving specific security or legal obligations.
Inquiries and support communications Responding to the request, arranging onboarding, maintaining an ongoing business discussion, and documenting how a request or complaint was resolved. Marketing opt-out records may be kept to honor the preference.
Transactional email records Sending and reconciling account messages, resolving delivery failures, and documenting necessary customer communications. A delivery record does not establish that a recipient read a message.
Logs and backups Investigating operational or security issues, recovering from failures, and meeting specific preservation duties. Backup copies are subject to provider backup cycles and may remain after removal from active systems.

Cancellation, removal of a user, and revocation of Intelligence access do not automatically delete all associated records. Historical work activity may remain part of the organization's records. We do not promise automatic deletion of an entire workspace on a fixed day after cancellation.

Contact shopmind@shopmind.com to request deletion or return of retained information. We verify the requester and scope, identify applicable legal and customer-instruction requirements, and explain any limits or records that must be retained. Customer-controlled records may require the organization's authorization. We do not recreate deleted information. Independent provider records are also subject to that provider's obligations. Retained information remains protected and is not used for unrelated purposes.

8. Security

We use safeguards designed to protect personal information, including account authentication and role-based access controls. Security also depends on customer permissions, protected credentials, provider configurations, and operational practices. No service or transmission method is completely secure.

“Lockbox” is a feature name, not a guarantee of absolute security or a claim that ShopMind is unable to process stored content. This Policy does not claim a particular security certification, end-to-end encryption, or zero-knowledge architecture. Report suspected unauthorized access to shopmind@shopmind.com. We will provide notices of security incidents when required by applicable law.

9. Your requests and choices

Contact shopmind@shopmind.com with the subject “Privacy request.” Tell us what you are requesting and identify the account or organization involved. Do not include unnecessary sensitive documents. We may need to verify identity and authority before accessing or changing records.

Depending on your location, our role, and applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict or object to certain processing, withdraw consent, or opt out of specified uses. Where applicable, an authorized agent may act on your behalf with appropriate verification. We will respond within the period required by applicable law and explain a refusal where required. You may ask us to reconsider a decision by replying to our response; statutory appeal or regulatory complaint rights remain available where applicable.

For organization-controlled workspace data, we may refer your request to the organization and assist it in responding. We may retain or decline to delete information where permitted or required, including to protect other people's rights or preserve necessary business records. We will not unlawfully discriminate against you for exercising privacy rights.

You may opt out of marketing emails using the unsubscribe mechanism provided or by contacting us. Necessary transactional and security communications may continue. Subscription cancellation and a privacy deletion request are separate actions; specify if you want both.

10. Processing locations

ShopMind is based in Utah, United States. Information may be processed in the United States and other countries where our contracted providers operate. Privacy laws may differ from those in your location. When applicable law requires safeguards for international transfers, we will put those safeguards in place before the relevant transfer.

Where relevant international-transfer restrictions apply, we will identify and implement the applicable safeguard before the transfer. Depending on the parties and destination, this may involve an applicable adequacy decision or approved contractual safeguards and any required assessment and additional protections. We do not represent that ShopMind holds a Data Privacy Framework certification or has already executed every required transfer agreement. Contact shopmind@shopmind.com for information about safeguards applicable to your data and a copy where available, subject to necessary redactions.

EEA and UK information

This section applies where EEA or UK data-protection law applies. Country availability and any required processing or transfer arrangements are reviewed before paid onboarding.

For information we control, the lawful basis depends on the purpose and relationship:

Purpose Basis where applicable
Responding to a business representative's inquiry, assessing early access, and managing a corporate customer relationship Legitimate interests in responding to business requests and operating the service, balanced against the person's rights.
Providing a service to an individual who is personally a party to the contract, such as an eligible sole trader Contract necessity for the processing objectively needed for that contract or requested pre-contract steps. A corporate contract is not automatically this basis for its employees' data.
Account security, abuse prevention, troubleshooting, and defending claims Legitimate interests in secure operations and protecting rights, subject to the applicable balancing assessment; legal obligation where a specific duty requires the processing.
Required tax, accounting, and regulatory records Compliance with applicable legal obligations.
Optional marketing or nonessential tracking requiring consent Consent, which may be withdrawn without affecting the lawfulness of earlier processing. Where another basis is permitted for a particular communication, we will apply the relevant marketing rules and honor opt-outs.

When processing workspace information on a business customer's behalf, we follow its lawful documented instructions under the applicable processing agreement. The customer determines its lawful basis for its personnel records. This does not remove ShopMind's own processor obligations.

Where applicable, you may request access, correction, erasure, restriction, or portability, object to processing based on legitimate interests, and withdraw consent. These rights have legal conditions and exceptions. You may object to use of your personal information for direct marketing at any time. You may complain to the relevant EEA supervisory authority or the UK Information Commissioner's Office without first contacting us.

An early-access review does not remove privacy rights attached to the inquiry itself. Availability of the Service in a country is separate from the rights applicable to information already collected.

11. Children

ShopMind is business software and is not directed to children under 13. We do not knowingly collect their personal information. If you believe a child under 13 has supplied information, contact us so we can investigate and take appropriate action. Our Terms separately require the person creating the business account to be at least 18. An employer is responsible for lawful use of the Service for its personnel, including any minors.

12. Changes and contact

We will post the effective date of this Policy and provide notice of material changes as appropriate, including by email or an in-product notice. Where required, we will obtain consent before materially changing how we use previously collected information. A policy update alone does not override applicable law or customer contractual restrictions.

For privacy questions and requests, contact shopmind@shopmind.com or write to:

ShopMind LLC
PO Box 83
Providence, UT 84332