Privacy Policy

How we protect your data

Last updated: September 28, 2026

Krabiclaw is operated by Aurelox LLC, a Utah limited liability company ("Krabiclaw," "we," "us," or "our"). Krabiclaw provides a multi-tenant commerce and website platform that allows merchants to create and operate storefronts, websites, customer communications, bookings, reservations, commerce experiences, and related services (the "Services").

This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Data when you use Krabiclaw, visit krabiclaw.com, interact with a Krabiclaw-powered merchant, connect a third-party service to Krabiclaw, or otherwise communicate with us.

"Personal Data" means information that identifies, relates to, describes, or can reasonably be linked with an individual, or any similar term under applicable privacy law.

This Policy applies to:

  • merchants and their personnel who use Krabiclaw to operate a business;
  • customers and visitors who interact with Krabiclaw-powered stores or websites;
  • developers, agencies, partners, and other people who work with Krabiclaw merchants;
  • visitors to Krabiclaw's own websites; and
  • people who contact Krabiclaw for support or other communications.

The supplemental Merchant and Partner Notice, Consumer Notice, Website Visitor Notice, United States Regional Privacy Notice, and Cookie Notice below provide additional information for particular interactions. If a supplemental notice conflicts with this general Policy for a particular interaction, the supplemental notice controls for that interaction.

Google user data

This section explains what information Krabiclaw receives from Google APIs ("Google user data"), how Krabiclaw uses, stores, shares, protects, retains, and deletes it, and how you can revoke access. It covers Sign in with Google and the Google Analytics and Google Search Console integrations that a merchant can connect in the Krabiclaw dashboard.

Limited Use. Krabiclaw's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When Krabiclaw asks for Google access

Krabiclaw asks for access to your Google account only when you choose a Google feature: when you sign in with Google, or when you press Connect on the Google Analytics or Google Search Console page under Settings → Integrations in the dashboard. Each integration asks only for the permissions it needs, at the moment you connect it. Declining a permission leaves the rest of Krabiclaw available.

What Krabiclaw accesses and how it is used

  • Sign in with Google (basic profile: OpenID, email address, and profile). Krabiclaw receives your Google account identifier, name, email address, and profile picture. It uses them to create your Krabiclaw account, sign you in, show your name and picture in the dashboard, and label which Google account is linked to your Krabiclaw account.
  • Google Analytics (https://www.googleapis.com/auth/analytics.readonly, read-only). When you connect Google Analytics, Krabiclaw uses the Google Analytics Admin API to list the Google Analytics accounts and GA4 properties your Google account can access (account names, property names, and property IDs) so you can choose one. For the property you choose, Krabiclaw reads its web data streams to find the measurement ID (a value such as G-XXXXXXX). Krabiclaw stores the chosen property's ID, name, and measurement ID with your organization and uses the measurement ID to add the Google Analytics tag to your Krabiclaw website, so that visits to your website are measured in your own Google Analytics property. Krabiclaw does not read your Google Analytics reports or visitor data, does not change any Google Analytics setting, and does not store the list of properties it showed you.
  • Google Search Console (https://www.googleapis.com/auth/webmasters). When you connect Google Search Console, Krabiclaw lists the Search Console properties for which your Google account is an owner or full user (the property address and your permission level) so you can choose one. If your Krabiclaw website's own address is not yet a property in your account, Krabiclaw adds it to your Search Console after Google has verified it. Krabiclaw stores the connected property's address with your organization. Krabiclaw does not read your search performance data, does not submit or remove sitemaps or URLs, and does not delete or change any other property.
  • Google Site Verification (https://www.googleapis.com/auth/siteverification). Used only when you connect your Krabiclaw website's own address and it is not already verified in your Search Console. Krabiclaw asks Google for a verification token for that one address, publishes it on your website as a <meta name="google-site-verification"> tag, and asks Google to confirm ownership. Krabiclaw stores the token for as long as the property stays connected, because Google checks for the tag again later. Krabiclaw does not verify any other website and does not read your list of verified websites.

Krabiclaw calls Google APIs only when you sign in with Google, or while you or another member of your organization is viewing or changing these integration settings. Krabiclaw does not access Google user data in the background and does not request Google Workspace data such as Gmail, Drive, Calendar, or Contacts.

Who can see it and with whom it is shared

  • Your organization. Members with organization-wide access can see the connected Google Analytics property name and measurement ID, the connected Search Console property address, and the connection status in the dashboard. An organization administrator who connects an AI assistant such as ChatGPT or Claude to Krabiclaw can ask it to read the organization's settings, which include those same values; Krabiclaw returns them to that assistant only at the administrator's request.
  • Your website's visitors. The Google Analytics measurement ID and the site verification tag are published in your website's pages, as Google requires for those features to work.
  • Service providers. Cloudflare hosts Krabiclaw's application, database, and logs, and delivers the Google Analytics tag to your website through Cloudflare Zaraz. Cloudflare processes this data on Krabiclaw's behalf to provide the Services.
  • Google. Krabiclaw sends requests to Google APIs only to perform the actions described above.

Krabiclaw does not otherwise transfer Google user data to anyone, except where necessary to comply with applicable law, to protect against security threats, fraud, or abuse, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent.

What Krabiclaw does not do with Google user data

  • Krabiclaw does not use Google user data for advertising, including targeted, personalized, retargeted, or interest-based advertising.
  • Krabiclaw does not sell Google user data and does not give it to advertising platforms, data brokers, or information resellers.
  • Krabiclaw does not use Google user data to determine creditworthiness or for lending purposes.
  • Krabiclaw does not use Google user data, including any data obtained through Google Workspace APIs, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
  • Krabiclaw uses Google user data only to provide and improve the user-facing features described above, and not for any other purpose.
  • Krabiclaw personnel do not read Google user data unless you give affirmative agreement for specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

How Krabiclaw protects Google user data

  • Krabiclaw exchanges data with Google and with your browser only over encrypted HTTPS connections.
  • The access and refresh tokens Google issues are stored on your linked account by Krabiclaw's authentication system, encrypted with a server-side secret. Krabiclaw uses them only on its servers to make the requests described above. They are not shown in the dashboard and are not given to other members or to connected AI assistants.
  • A Google account linked to your Krabiclaw account can be used to connect an integration only by you, and Krabiclaw checks that it has granted the permission the integration needs before using it. Only members with organization-wide access can view or change an organization's integrations.

Retention and deletion

  • Your linked Google account (identifier, profile details, granted permissions, and tokens) is kept while your Krabiclaw account exists and is deleted when you delete your Krabiclaw account from Account settings.
  • Your organization's Google selections (the Google Analytics property ID, name, and measurement ID, and the Search Console property address and verification token) are kept while the integration is connected. They are deleted when a member presses Disconnect on the integration's page, or when the organization is deleted. Disconnecting Google Analytics also removes the Google Analytics tag from your website, and disconnecting Search Console stops Krabiclaw from publishing the verification tag.
  • Disconnecting an integration does not unlink your Google account from your Krabiclaw account, because the same Google account may be used to sign in or by another organization.
  • Properties that exist in your own Google Analytics or Search Console account, including a Search Console property Krabiclaw added at your request, remain in your Google account; Krabiclaw does not delete them.
  • If a request to Google fails, the error Google returns may be recorded in Krabiclaw's operational logs, which are handled as described in Section 8.

You can revoke Krabiclaw's access to your Google account at any time at https://myaccount.google.com/permissions. After you revoke access, Krabiclaw can no longer call Google APIs for your account. To have Krabiclaw delete Google user data it holds about you, delete your account or organization in the dashboard, or email privacy@krabiclaw.com.

Facebook and Instagram integrations

A merchant can connect a Facebook Page and an Instagram professional account to Krabiclaw from Settings → Integrations in the dashboard. This section explains what Krabiclaw receives from Meta through those connections, how it is used, stored, and shared, and how to have it deleted.

What Krabiclaw accesses

  • Facebook: the identifier and name of the Facebook account you connect; the Pages that account manages (Page ID, name, category, follower count, and picture) so you can choose one; and, for the Page you choose, its posts (post ID, message text, the time it was posted, the post's photos and video, and its link), Page views, engagement and follower counts, and performance counts for its posts. Krabiclaw requests the Facebook permissions pages_show_list, pages_read_engagement, pages_manage_posts and read_insights.
  • Instagram: the identifiers and username of the Instagram professional account you connect, and its posts (post ID, caption, media type, its images and videos, including every item of a carousel, the time it was posted, and its link), account views, reach and interactions, and performance counts for its media. Krabiclaw requests the Instagram permissions instagram_business_basic and instagram_business_content_publish and instagram_business_manage_insights.
  • Authorization tokens that Meta issues for the connected Facebook account and Instagram account.

How Krabiclaw uses it

  • To connect the Facebook Page and Instagram account that you select, and to show which ones are connected.
  • To read posts from the channel you explicitly choose through the dashboard or your connected assistant. Reading a channel does not create or publish website posts, or copy its media into Krabiclaw. Website posts are managed separately and published only to the destinations you select.
  • To publish to your Facebook Page or Instagram account when you publish a post in Krabiclaw and choose that channel: the post's text, link, photos or video go to your Page, and its caption with its call to action and its image, carousel or Reel go to Instagram, exactly to the Page or account you choose.

Krabiclaw does not use Facebook or Instagram data for advertising, does not sell it, and does not use it to train artificial intelligence or machine learning models.

How it is stored and shared

  • Authorization tokens are stored on your linked account by Krabiclaw's authentication system, encrypted with a server-side secret, and used only on Krabiclaw's servers. A Facebook Page's own token is not stored; Krabiclaw obtains it from Meta each time it reads or manages a Page post.
  • Krabiclaw stores the connected Page's ID and name, or the connected Instagram account's ID and username, with your organization. Only members of your organization with organization-wide access can view or change the connection, and only the person who linked a Facebook or Instagram account can use it to connect an organization.
  • For each post published to Facebook or Instagram, Krabiclaw records the Page or account it went to, the Meta account that connected it, and the Facebook or Instagram post ID and its link.
  • Website posts and uploaded media belong to your organization. Members with access, and the assistants they connect, can manage them through the dashboard and MCP. Reading Facebook or Instagram does not automatically publish their content on your website.
  • Facebook and Instagram insights are read live for the date range you request and shown to authorized organization members in the dashboard or through the MCP analytics tool they connect. Krabiclaw does not store these provider insight results in its database. Disconnecting the selected account stops these reads.
  • Cloudflare hosts Krabiclaw's application, database, and media storage and processes this data on Krabiclaw's behalf. Meta receives the requests Krabiclaw makes to Facebook and Instagram, including content you choose to publish there.

Disconnecting

Pressing Disconnect on the Facebook or Instagram page in the dashboard removes the connected Page or account from your organization and stops reading and publishing to that channel. Website posts and uploaded media stay until you delete them. It also does not unlink the Facebook or Instagram account from your Krabiclaw account; that link, including its encrypted tokens, is deleted when you delete your Krabiclaw account. You can also remove Krabiclaw from your Facebook or Instagram settings at any time, after which Krabiclaw can no longer access that account: Krabiclaw disconnects every organization connected through it and deletes the linked account and its tokens.

Deleting your Facebook or Instagram data

To have Krabiclaw delete the data it holds from your Facebook Page or Instagram account, email privacy@krabiclaw.com from the email address on your Krabiclaw account, and include:

  • the name or web address of your Krabiclaw workspace; and
  • the Facebook Page name or Instagram username the request is about.

Never send your password, or your Facebook or Instagram login details; Krabiclaw will never ask for them. After verifying the request, Krabiclaw deletes the provider publication records, removes the connection from your workspace, and deletes the linked Facebook or Instagram account and its tokens, and confirms by email. Posts you wrote in Krabiclaw and published to Facebook or Instagram remain on Facebook or Instagram; delete them there.

When Meta sends us a data-deletion request for your Facebook or Instagram account, website posts and uploaded media stay. Krabiclaw deletes its record of which Facebook or Instagram post they became. It also removes the connection and deletes the linked account and its tokens.

1. Our role when merchants use Krabiclaw

Merchants generally decide why and how Personal Data from their customers is used. When Krabiclaw processes Personal Data on a merchant's behalf to provide the Services, the merchant is generally the controller or business and Krabiclaw acts as its processor or service provider, as those terms are defined by applicable law.

Krabiclaw may also process certain information for its own purposes, including account administration, platform security, fraud prevention, service analytics, billing, legal compliance, and operation of Krabiclaw's own websites. For those activities, Krabiclaw may act as a controller or business.

If you are a customer of a Krabiclaw-powered merchant and your request concerns information controlled by that merchant, contact the merchant first. Krabiclaw may assist the merchant with the request or route a request to the relevant merchant when appropriate.

2. Personal Data we collect

The information we collect depends on how you interact with Krabiclaw.

Merchant, account, and business information

We may collect:

  • name, email address, authentication information, and account identifiers;
  • organization membership, roles, permissions, and account settings;
  • business names, locations, contact information, domains, public profiles, and other business details;
  • website content, products, prices, menus, articles, media, policies, settings, and other material a merchant uploads, imports, creates, or publishes;
  • billing plan, subscription, invoice, and transaction information; and
  • information associated with connected services and integrations.

Store customer and transaction information

Depending on the merchant features being used, we may process:

  • name, email address, phone number, shipping or billing information when applicable, and merchant-specific customer account information;
  • contact messages, inquiries, support conversations, and other form submissions;
  • cart, product, order, invoice, payment-status, fulfillment, booking, reservation, review, and related commercial information;
  • communication preferences, consent records, and opt-out records; and
  • other information a customer chooses to provide to a merchant.

Customer accounts are specific to the merchant with which the customer is interacting. Krabiclaw does not currently operate a single shared customer account across all Krabiclaw merchants.

Payment and identity-verification information

Krabiclaw uses Stripe for payment processing, platform billing, and Stripe Connect merchant onboarding. Stripe may collect payment-card information, bank-account information, tax information, government identification, and other verification information directly from merchants or customers.

Krabiclaw does not store full payment-card numbers, CVVs, or the full bank or government-identification information collected by Stripe. Krabiclaw may receive and store limited Stripe-related information needed to operate the Services, such as Stripe account or customer identifiers, transaction or subscription status, country, capability status, verification requirement status, and related operational metadata.

Device, usage, and analytics information

We may collect:

  • IP address or a hashed or derived representation of an IP address;
  • browser, device, operating-system, user-agent, and language information;
  • pages viewed, page paths, referring domains, interactions, time on page, and conversion events;
  • session and visitor identifiers;
  • approximate location information such as country, region, or city derived from network information;
  • campaign, referral, and attribution information; and
  • diagnostic, performance, security, and error information.

Krabiclaw uses first-party analytics and may use Cloudflare Zaraz and Google Analytics or other configured analytics and advertising technologies.

Communications and support information

If you contact Krabiclaw or a merchant through the Services, we may process the contents of the communication and related metadata, including names, email addresses, phone numbers where provided, message contents, support history, and delivery status.

Media and files

We may process images, videos, documents, and other files uploaded to or published through the Services. Files intended for publication may become accessible through public URLs. Merchants are responsible for ensuring they have authority to upload and publish the material they provide.

Connected AI assistants and MCP clients

Krabiclaw provides Model Context Protocol (MCP) connections that authorized merchants can use with compatible services such as ChatGPT and Claude. When a merchant connects one of these services, Krabiclaw applies the authenticated user's technical account permissions to determine which information and operations the connected client can access. Depending on the request, returned information may include website content, analytics, submissions, customer contact information, booking or reservation information, or other merchant data within those permissions.

Technical permission to access an operation does not by itself establish action-specific authorization for every action a connected client may request. Where Krabiclaw requires an action-specific confirmation, that confirmation must be satisfied before execution. The absence of a general review screen in a connected client does not waive a confirmation Krabiclaw requires.

Krabiclaw records limited MCP operational telemetry for security, reliability, debugging, and auditing. This may include tool names, operation status, timing, user agent, hashed session or client identifiers, and shortened summaries of tool inputs and outputs. Sensitive structured fields are limited or redacted where designed to do so, but free-text information can still appear in diagnostic summaries. MCP tool-call telemetry is retained as described for operational records in Section 8.

Krabiclaw does not currently train its own generative AI models on merchant or customer content. A connected third-party AI provider processes information it receives under that provider's own terms and privacy practices. Krabiclaw makes no representation about that provider's training, retention, confidentiality, or deletion practices.

3. Sources of Personal Data

We may receive Personal Data:

  • directly from you;
  • from merchants whose Krabiclaw-powered sites you use;
  • automatically from browsers, devices, cookies, network requests, and platform interactions;
  • from payment providers and financial-service providers such as Stripe;
  • from identity, authentication, communications, analytics, advertising, security, hosting, and infrastructure providers;
  • from services a merchant chooses to connect, including Google services, analytics services, social or advertising services, and merchant-installed integrations;
  • from connected AI or MCP clients when they call Krabiclaw tools on an authorized user's behalf; and
  • from public or third-party business sources when a merchant requests an import or business lookup.

4. Why we process Personal Data

We process Personal Data to:

  • provide, maintain, secure, and operate the Services;
  • create and administer merchant accounts, organizations, permissions, and merchant-specific customer accounts;
  • host, publish, and deliver merchant websites and content;
  • process orders, bookings, reservations, payments, subscriptions, merchant payouts, refunds, and related transactions;
  • route communications between merchants and their customers;
  • provide support and respond to requests;
  • authenticate users and prevent fraud, abuse, unauthorized access, and other harmful activity;
  • measure platform and storefront usage, diagnose problems, and improve product performance;
  • measure marketing and advertising effectiveness and, where enabled and permitted, support advertising or targeted advertising;
  • operate merchant-selected integrations and connected services;
  • maintain business, accounting, security, and audit records; and
  • comply with law, enforce agreements, and respond to valid legal process.

Where applicable law requires a legal basis for processing, our legal bases may include performance of a contract, compliance with legal obligations, legitimate interests, and consent. The applicable basis depends on the context and the law that applies.

5. How we disclose Personal Data

We may disclose Personal Data to the following categories of recipients.

Merchants

If you interact with a Krabiclaw-powered merchant, we provide that merchant with the information needed to operate its business and respond to you.

Service providers and processors

We use providers for infrastructure, hosting, databases, storage, content delivery, payments, communications, analytics, security, fraud prevention, and other platform functions. These providers may process Personal Data as necessary to perform services for Krabiclaw.

Current platform providers and integrations include Cloudflare for infrastructure and related services, Stripe for payments and Connect, Google services for certain authentication, analytics, business, and location functions, and communications providers for email or messaging.

Payment and financial-service providers

Stripe and other payment or financial-service providers may receive information required to process transactions, perform merchant onboarding, conduct verification, prevent fraud, manage disputes, and comply with financial regulations.

Connected services and merchant-selected integrations

When a merchant enables an integration, Krabiclaw may disclose information to that integration as directed by the merchant. Third-party integrations may have their own privacy practices.

Connected AI assistants

If an authorized merchant connects a merchant-selected AI client such as ChatGPT, Claude, or another compatible MCP client, Krabiclaw sends the information required to perform the merchant's requested tool action to that connected service. These are merchant-selected clients, not Krabiclaw providers. The client's own terms and privacy practices apply to its handling of information.

Analytics and advertising providers

We may disclose device, browser, interaction, cookie, attribution, and related information to analytics or advertising providers when those tools are enabled. Some disclosures may be considered a "sale," "sharing," or processing for targeted advertising under certain U.S. state privacy laws even when no money is exchanged for the information.

We may disclose information when required by applicable law, regulation, court order, subpoena, or other valid legal process, or when reasonably necessary to protect the rights, safety, security, and integrity of Krabiclaw, merchants, users, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.

Business transactions

Information may be disclosed in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable law.

At your direction

We may disclose information when you ask us to, authorize us to, or use a feature that requires disclosure to another party.

6. Sale, sharing, and targeted advertising

Krabiclaw does not sell Personal Data for monetary consideration.

Krabiclaw and Krabiclaw-powered merchants may use analytics and advertising technologies. Depending on the technology, configuration, and applicable law, disclosures to analytics or advertising providers may constitute "sharing" for cross-context behavioral advertising, a "sale" under a statutory definition that does not require payment, or processing for targeted advertising.

Where applicable, privacy choices may be available through the cookie-preference controls presented on the relevant site or by contacting hello@krabiclaw.com. Merchant-controlled sites may provide additional merchant-specific choices.

If Krabiclaw materially changes its practices concerning the sale or sharing of Personal Data, we will update the applicable notice and provide any choices required by law.

7. Cookies and tracking technologies

We use cookies, local storage, pixels, web beacons, server-side event tracking, and similar technologies for authentication, security, session continuity, preferences, analytics, attribution, and advertising functions.

Krabiclaw uses Cloudflare Zaraz to load Google Analytics on Krabiclaw and Krabiclaw-powered sites. Google Analytics is on by default; a visitor can turn it off with Reject on the site's analytics notice or through the Cookie Preferences control, and that choice is remembered. Certain first-party security, account, session, fraud-prevention, and service analytics may continue where permitted by law because they are separate from optional third-party advertising or analytics tools.

Merchants may also configure their own analytics, advertising, or integration technologies. The merchant's privacy notice should explain merchant-specific uses.

Krabiclaw does not treat the legacy browser "Do Not Track" signal as a universal privacy instruction because there is no single agreed technical or legal meaning for that signal. Legally recognized opt-out preference signals are distinct from legacy Do Not Track signals and are handled as required when applicable law requires Krabiclaw to recognize them.

See the Cookie Notice below for additional information.

8. Data retention

We retain Personal Data for the period reasonably necessary for the purpose for which it was collected, including to provide the Services, complete transactions, maintain security, resolve disputes, enforce agreements, and comply with applicable legal obligations.

Current retention practices include:

  • Merchant accounts and business content: generally retained while the account or organization remains active and until deleted through applicable controls, subject to records that Krabiclaw may retain where applicable law permits or requires.
  • Store customer data: when Krabiclaw processes customer data for a merchant, the merchant generally determines the primary retention period. Data may remain until the merchant deletes it, the relevant merchant organization is deleted, or retention is otherwise permitted or required under applicable law.
  • Payments: Krabiclaw retains limited transaction and billing records as reasonably necessary for accounting, tax, fraud prevention, disputes, and other applicable legal obligations. Stripe separately retains information under its own policies and legal obligations.
  • Analytics: Krabiclaw's current cleanup processes are designed to remove raw pageview-event data after approximately 90 days and certain analytics session or aggregate data after approximately 740 days. Aggregated or de-identified information may be retained longer when it no longer identifies an individual.
  • MCP telemetry: MCP tool-call telemetry is retained for security, reliability, debugging, and auditing for up to 180 days from the time the record is created.
  • Media: media generally remains until deleted by an authorized user or removed through an account or organization deletion process. Copies may remain temporarily in caches or provider-operated recovery systems.
  • Backups and recovery copies: deleted information may remain temporarily in provider-operated backup, point-in-time recovery, disaster-recovery, or similar systems until those copies are overwritten or expire under the provider's applicable recovery process. Such copies are not used as ordinary active records. If a recovery copy is restored, Krabiclaw applies applicable deletion controls before data that was previously deleted is returned to ordinary production use.
  • Operational, security, and email delivery records: these records are retained only as reasonably necessary for security, fraud prevention, incident investigation, delivery troubleshooting, service operation, disputes, and applicable legal obligations. Krabiclaw does not state a fixed period where the applicable system does not enforce one.
  • Legal holds and claims: information may be retained beyond an otherwise applicable period when required by legal process, a legal hold, an investigation, or the establishment, exercise, or defense of legal claims.

9. Security

We use administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure. These safeguards include access controls, authentication and authorization boundaries, encrypted network transport, provider security controls, and operational monitoring appropriate to the Services.

No internet transmission, storage system, or security measure can guarantee absolute security.

Krabiclaw does not claim SOC 2 or other independent security certification in this Policy. Payment-card and payment-account information handled directly by Stripe is subject to Stripe's security and compliance program.

10. International processing and transfers

Krabiclaw is operated from the United States and uses service providers that may process information in the United States and other countries. As a result, Personal Data may be processed outside the jurisdiction where it was originally collected.

When applicable law requires a specific mechanism or safeguard for an international transfer, Krabiclaw will use an appropriate legally recognized mechanism or other lawful basis for the transfer as applicable. We do not represent in this Policy that every transfer currently relies on a particular transfer mechanism such as Standard Contractual Clauses.

11. Your privacy rights

Depending on where you live and how Krabiclaw processes your information, you may have rights to:

  • access or know about Personal Data processed about you;
  • correct inaccurate Personal Data;
  • delete Personal Data;
  • receive a portable copy of certain Personal Data;
  • object to or restrict certain processing;
  • opt out of certain sales, sharing, targeted advertising, profiling, or automated processing;
  • limit certain uses of sensitive Personal Data;
  • withdraw consent where processing is based on consent;
  • appeal certain privacy-request decisions; and
  • receive equal service and not be unlawfully discriminated or retaliated against for exercising privacy rights.

These rights are subject to applicable law and exceptions.

Requests involving a merchant

If your request concerns information a Krabiclaw merchant controls about you, contact that merchant first. Krabiclaw may assist the merchant or route your request to the merchant.

Requests involving Krabiclaw directly

For information Krabiclaw controls directly, submit a request to hello@krabiclaw.com. Describe the right you want to exercise and the account, merchant, store, email address, or interaction involved so we can locate the relevant records.

We may need to verify your identity, account ownership, or authority to act for a merchant before fulfilling access, correction, deletion, or similar requests. We will limit verification information to what is reasonably necessary. Where law prohibits identity verification for a particular opt-out request, we will not require it.

An authorized agent may submit a request where applicable law permits. We may request evidence that the agent is authorized to act for you and may separately verify your identity when permitted or required.

12. Children

Krabiclaw is a general-audience commerce platform and is not designed specifically for children. Merchants are responsible for complying with laws applicable to the audiences they serve.

Krabiclaw does not knowingly sell Personal Data of children for monetary consideration. If we learn that Personal Data of a child was collected or processed in a manner that requires parental consent or other protections and those requirements were not satisfied, we will take steps required by applicable law.

13. Changes to this Policy

We may update this Privacy Policy as our Services, data practices, providers, or legal obligations change. The "Last updated" date at the top identifies the current version. If applicable law requires additional notice or consent for a material change, we will provide it as required.

14. Contact

Aurelox LLC, doing business as Krabiclaw
Utah, United States
Email: hello@krabiclaw.com
Website: https://krabiclaw.com

Supplemental Merchant and Partner Privacy Notice

Last updated: September 25, 2026

This notice supplements the Krabiclaw Privacy Policy for merchants, merchant personnel, developers, agencies, partners, and others who use Krabiclaw to operate or support a business.

Information we process

In addition to the information described in the main Privacy Policy, Krabiclaw may process merchant and partner information including:

  • account identity and authentication data;
  • organization membership, roles, permissions, and team assignments;
  • business contact, location, domain, catalog, content, media, operational, and configuration data;
  • billing plan, subscription, invoice, and Stripe identifiers;
  • Stripe Connect account identifier, country, capability state, verification-requirement status, and related operational metadata;
  • support communications, audit records, activity history, and security information;
  • analytics and product-usage data; and
  • information returned to or received from merchant-authorized integrations.

Stripe and merchant payments

Stripe hosts merchant onboarding and collects verification, banking, tax, and other regulated financial information. Krabiclaw stores limited information needed to know whether a connected Stripe account is configured and capable of processing payments. Stripe remains the source of truth for Stripe Connect verification data.

Merchant customer data

A merchant generally determines the purposes for which its customer data is processed. Krabiclaw processes that data to provide the merchant's requested Services, including storefront hosting, customer communications, orders, reservations, bookings, analytics, and related operations.

Merchants are responsible for:

  • providing privacy notices appropriate to their own business and customers;
  • having a lawful basis or other authority for data they collect and instruct Krabiclaw to process;
  • configuring merchant-controlled cookies, pixels, integrations, and marketing tools consistently with applicable law;
  • responding to customer privacy requests for data the merchant controls; and
  • ensuring that merchant users and integrations access only information they are authorized to access.

Krabiclaw may provide tools or assistance to help a merchant respond to a privacy request.

Connected applications and MCP

Authorized merchant users can connect compatible AI assistants or MCP clients to Krabiclaw. Those clients can access only the Krabiclaw resources authorized for the authenticated merchant user, subject to Krabiclaw's authorization controls. A merchant is responsible for deciding whether to connect a third-party AI provider and for evaluating that provider's handling of information returned from the merchant organization.

Account and organization deletion

Krabiclaw provides separate controls to permanently delete an account or organization after explicit destructive confirmation. Deleting an account does not by itself delete an organization. Organization deletion is a separate action subject to the permissions and billing controls applicable to that organization.

When an organization is deleted, its organization data is removed and its members lose access. If an active subscription or other provider condition prevents organization deletion, it must be resolved through the applicable billing or provider controls before deletion can complete.

Account or organization deletion through Krabiclaw's product controls is distinct from a statutory Personal Data request. For a privacy-rights request, Krabiclaw responds within the period required by applicable law, subject to verification requirements and any extension permitted by that law. Krabiclaw may retain specific records after a deletion request only where an applicable legal basis permits or requires that retention, such as accounting or tax obligations, fraud or security needs, disputes, legal claims, or legal process. A technical or billing issue does not by itself create an independent basis to retain Personal Data.

Supplemental Consumer Privacy Notice

Last updated: September 25, 2026

This notice applies when you visit, communicate with, create a customer account for, or transact with a merchant using a Krabiclaw-powered website or store.

The merchant generally controls your store data

The merchant you interact with generally determines why your Personal Data is collected and how it is used. Krabiclaw provides the technical platform and ordinarily processes that information for the merchant.

If you have a privacy question about a purchase, booking, reservation, customer account, contact form, or other merchant interaction, contact the merchant first. If you send the request to Krabiclaw, we may route it to the merchant or assist the merchant with the request.

Information processed through a merchant store

Depending on the features used by the merchant, Krabiclaw may process:

  • name, email address, phone number, and merchant-specific account information;
  • messages and other form submissions;
  • cart, product, order, invoice, fulfillment, booking, reservation, review, and transaction details;
  • shipping and billing information where applicable;
  • payment status and limited Stripe identifiers;
  • consent and communication preferences; and
  • browser, device, pageview, referral, session, approximate-location, and analytics information.

Your customer account, if one exists, is associated with the specific merchant rather than a universal Krabiclaw shopper account.

Payments

Stripe processes payment-card information and other payment details. Krabiclaw does not store full payment-card numbers or CVVs.

Merchant integrations

A merchant may enable analytics, advertising, communications, fulfillment, social, or other third-party services. Those services may receive information as directed by the merchant and may have their own privacy practices.

Supplemental Website Visitor and Support Privacy Notice

Last updated: September 25, 2026

This notice applies when you visit Krabiclaw's own websites, create or use a Krabiclaw platform account, submit a support request, or otherwise communicate directly with Krabiclaw.

Krabiclaw may collect account information, business information, support communications, device and browser data, first-party analytics, Cloudflare Zaraz/Google Analytics data where enabled, referral and attribution information, and information you choose to submit through forms.

We use this information to operate the Krabiclaw website and platform, respond to requests, authenticate users, secure the Services, prevent fraud and abuse, measure performance and marketing effectiveness, administer subscriptions, and comply with law.

Where optional analytics or advertising tools are presented through the Krabiclaw consent interface, you can use the available cookie-preference controls. Certain first-party security, session, platform, and service analytics may continue where permitted by law.

United States Regional Privacy Notice

Last updated: September 25, 2026

This notice supplements the Krabiclaw Privacy Policy for residents of U.S. states that provide statutory privacy rights. The rights that apply depend on the state, the type of information, Krabiclaw's role, and whether the relevant law applies to Krabiclaw for the particular processing activity.

Categories of Personal Data

During the preceding 12 months, Krabiclaw may have collected the following categories of Personal Data:

Category Examples Primary sources Business or commercial purposes Categories of recipients
Identifiers Name, email, phone, account ID, IP address, Stripe IDs You, merchants, devices, service providers Accounts, transactions, support, security, communications Merchants, infrastructure providers, payment providers, communications providers
Customer-record information Contact information, billing or shipping information where used, merchant customer details You, merchants, Stripe Commerce, fulfillment, bookings, reservations, support Merchants, payment providers, fulfillment/integration providers
Commercial information Products viewed or purchased, carts, orders, subscriptions, bookings, reservations, invoices You, merchants, platform activity Commerce, merchant operations, analytics, support Merchants, Stripe, operational service providers
Internet or electronic-network activity Browser, user agent, page paths, referrer, interactions, session and visitor identifiers, attribution data Devices, browsers, cookies, Cloudflare, analytics tools Security, service operation, analytics, advertising measurement Cloudflare, analytics providers, advertising providers where enabled, merchants
Approximate geolocation Country, region, or city derived from network information Network and infrastructure data Fraud prevention, security, analytics, localization Infrastructure and analytics providers, merchants where relevant
Professional or business information Merchant business name, role, organization, location, business profile Merchants, partners, public/business sources Merchant onboarding, platform operation, integrations Service providers and merchant-authorized integrations
User content and communications Messages, support requests, media, files, website content, reviews, submissions You, merchants, customers Hosting, publication, support, communications, merchant operations Merchants, hosting and communications providers, connected services at user direction
Account-access information Authentication credentials or tokens, session information, permissions You, authentication providers, platform Authentication, authorization, security Authentication and infrastructure providers
Inferences and analytics Attribution, aggregated trends, inferred engagement or feature usage Platform activity and analytics Analytics, service improvement, marketing measurement Analytics providers and merchants where relevant

Krabiclaw does not intentionally collect biometric identifiers or precise device geolocation as part of its ordinary platform operation. Stripe may separately collect government identification, financial-account information, and other sensitive information for payment processing or merchant verification. Krabiclaw may receive limited status or metadata from Stripe without receiving the full underlying document or financial credential.

Free-text fields and uploaded content can contain sensitive information if a user chooses to submit it. Krabiclaw does not require users to place sensitive information in free-text fields unless the relevant merchant interaction specifically calls for it.

Sale, sharing, and targeted advertising

Krabiclaw has not sold Personal Data for monetary consideration.

Krabiclaw may disclose identifiers, device/browser information, internet or network activity, and related analytics or attribution information to analytics or advertising providers. Depending on applicable state law and how a technology is configured, such a disclosure may be considered "sharing," a statutory "sale," or processing for targeted advertising even where Krabiclaw receives no money for the Personal Data.

Where applicable, you may exercise available opt-out rights using the cookie-preference controls presented on the relevant site or by emailing hello@krabiclaw.com. If an applicable law requires another method or recognition of a qualifying opt-out preference signal, Krabiclaw will provide or process the legally required mechanism when the requirement applies.

Krabiclaw does not knowingly sell Personal Data of individuals under 16 for monetary consideration.

U.S. privacy rights

Depending on your state and the applicable law, you may have the right to:

  • confirm whether Personal Data is processed;
  • access or obtain specific Personal Data;
  • correct inaccurate Personal Data;
  • delete Personal Data;
  • obtain a portable copy of certain Personal Data;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive Personal Data;
  • obtain information about categories of Personal Data, sources, purposes, and recipients;
  • use an authorized agent where permitted;
  • appeal a denial of a privacy request in states that provide an appeal right; and
  • not receive unlawful discriminatory or retaliatory treatment for exercising privacy rights.

How to submit a request

Email hello@krabiclaw.com and identify the right you want to exercise. Include enough information for us to identify the relevant account, merchant, store, or interaction.

If the Personal Data is controlled by a Krabiclaw merchant, we may direct you to that merchant or forward the request so the merchant can respond.

Verification

For requests that require verification, Krabiclaw may compare information you provide with information already associated with your account or interaction. We may ask for additional information when reasonably necessary to prevent unauthorized access, deletion, or correction. We do not require identity verification for a statutory opt-out request when applicable law prohibits such verification.

Authorized agents

Where permitted, an authorized agent may submit a request on your behalf. We may require proof of the agent's authority and may separately verify your identity when allowed by law.

Appeals

If applicable state law gives you a right to appeal and we deny your request, you may appeal by replying to the decision email or contacting hello@krabiclaw.com and stating that you are appealing a privacy-request decision.

California-specific information

If the California Consumer Privacy Act applies to Krabiclaw for a particular processing activity, California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive Personal Data, and receive non-discriminatory treatment, subject to applicable exceptions.

Krabiclaw's categories of Personal Data, sources, purposes, and recipient categories for the preceding 12 months are described above. Krabiclaw does not sell Personal Data for monetary consideration. Certain analytics or advertising disclosures may constitute "sharing" or a statutory "sale" depending on the technology and legal definition.

Last updated: September 28, 2026

Krabiclaw and Krabiclaw-powered merchants use cookies and similar technologies to operate websites, maintain sessions, secure accounts, measure usage, attribute traffic, and support analytics or advertising functions.

Essential and security technologies

These technologies support functions such as authentication, session continuity, fraud prevention, security, network routing, load management, and preferences. Disabling them may prevent parts of the Services from functioning.

First-party analytics

Krabiclaw records first-party analytics such as page paths, referral information, session or visitor identifiers, approximate location, device/browser information, and time-on-page or conversion events. These records help merchants and Krabiclaw understand site performance and usage.

First-party analytics are technically separate from optional third-party tools managed through Cloudflare Zaraz. Cookie-preference choices presented for Zaraz do not necessarily disable first-party service, security, or analytics processing where that processing is permitted by applicable law.

Third-party analytics and advertising

Krabiclaw uses Cloudflare Zaraz to manage certain third-party analytics or advertising tools. Google Analytics may be enabled for Krabiclaw or merchant sites. Merchants may also configure other advertising, analytics, social, or conversion technologies.

These technologies may receive browser or device information, page activity, referral information, cookie identifiers, transaction or conversion information, and related data depending on their configuration.

Google Analytics is on by default. A notice on the site's first page offers Reject, which turns Google Analytics off; the choice is stored in a cookie so the site does not ask again. To change it later, use the site's Cookie Preferences control. Either choice leaves Krabiclaw's first-party analytics unchanged. You can also restrict or delete cookies through your browser settings, although doing so may affect site functionality.

Do Not Track and opt-out preference signals

Krabiclaw does not treat the legacy browser Do Not Track signal as a universal privacy instruction.

Some laws recognize separate browser-based opt-out preference signals for sale, sharing, or targeted advertising. Where such a requirement applies to Krabiclaw, Krabiclaw will process qualifying signals as required by that law. This is separate from legacy Do Not Track.

Merchant-controlled technologies

A Krabiclaw merchant may enable technologies for its own analytics, advertising, fulfillment, communications, or integrations. The merchant is responsible for describing its own technologies and providing any merchant-specific consent or opt-out controls required by applicable law.