← Back to home

Privacy Policy

Last updated: March 23, 2026

Command Shift ("we," "us," or "our") operates the commandshiftai.com website and platform. This Privacy Policy explains how we collect, use, and protect your information when you use our services.

1. Information We Collect

Personal Information

We may collect the following personal information when you interact with our platform:

Usage Data

We automatically collect certain information when you visit our platform, including pages viewed, time spent on pages, referral sources, and browser/device information.

Cookies & Local Storage

We use minimal client-side storage. JWT authentication tokens are stored in localStorage. We do not use third-party tracking cookies. There are no advertising pixels or social media trackers on our platform.

2. How We Collect Information

Email Collection

We collect email addresses through:

Email Communications

We may send you marketing emails, product updates, and audit reports. All email communications are CAN-SPAM compliant. Every email includes an unsubscribe link. You can opt out of marketing emails at any time without affecting your account access.

SMS / Text Messaging

We may offer SMS notifications in the future for users who opt in. If enabled, standard messaging and data rates apply. You may opt out at any time by texting STOP to the number from which you received the message. We will never sell your phone number to third parties.

Phone / Calling

If you request a strategy call, we may contact you at the phone number you provide. We do not use auto-dialing systems. We do not sell or share phone numbers with third parties.

3. Third-Party Services

We integrate with the following third-party services to power our platform:

Each of these services has its own privacy policy. We only share the minimum data necessary with each provider to deliver our services.

4. Data Storage & Security

Your data is stored in a SQLite database on an encrypted DigitalOcean server. API keys provided by users are encrypted at rest using AES-256-GCM encryption. Passwords are hashed using bcrypt and are never stored in plaintext. All connections to our platform are encrypted via HTTPS with Let's Encrypt SSL certificates.

5. Data Sharing

We do not sell your data. We do not share your personal information with third parties for marketing purposes. We share data with service providers only as necessary to operate the platform (as described in Section 3). We may disclose information if required by law, court order, or government request.

6. Your Rights (CCPA / GDPR)

You have the right to:

To exercise any of these rights, email us at hello@commandshiftai.com. We will respond to your request within 30 days.

7. Children's Privacy

Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision. For material changes, we will notify you by email if you have an account with us.

9. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

hello@commandshiftai.com