DaClerk Privacy Policy

Version 2026-09-09. Effective 2026-09-10.
Published at https://daclerk.com/privacy and linked, as "Privacy Policy", from every Storefront that runs on DaClerk.

Operator: DaDeveloper LLC, a California limited liability company, which operates the DaClerk software under the brand DaClerk ("we", "us", "DaDeveloper LLC").

On a Storefront this document is the Shop's privacy policy for that Storefront. The Shop has adopted it under the DaClerk Merchant Terms and is the business responsible for shopper data collected there (Section 4); DaDeveloper LLC publishes it on the Shop's behalf and for its own role as service provider.


1. Who we are and what this policy covers

DaClerk is software. It runs an online storefront for a retail shop (a "Shop"), where an AI clerk answers questions and puts together an order that the shopper pays for and collects in the Shop or, where the Shop offers delivery, at handover. It also runs an admin area where the Shop's owner and staff manage products, orders and customers.

This policy explains what personal data is collected, by whom, why, who sees it, how long it is kept, and how to ask for it to be reviewed, corrected or deleted. It covers three groups of people:

  • Shoppers who visit or order on a Shop's Storefront (Section 5 and Section 6).
  • Shop owners and staff who use the DaClerk Admin (Section 7).
  • Visitors to daclerk.com, including people who book a demo (Section 8).

Sections 9 to 18 apply to everyone.

2. Words we use

  • Shop means the retailer whose Storefront you are using. On a Storefront this policy shows the Shop's name as the Shop and its contact for data requests as the contact shown on its storefront.
  • Storefront means the Shop's DaClerk site, for example the Shop's site at its own domain or at a daclerk.com subdomain.
  • Admin means the staff-only area of DaClerk used by a Shop.
  • AI clerk means the automated assistant on the Storefront that answers questions and assembles orders. It is software, not a person.
  • AI providers means OpenRouter, the gateway that routes each chat message, and the companies that run the language models behind the AI clerk (Section 6 and Section 9.3). The notice above the age-gate button calls DaDeveloper LLC and these companies together "the Shop's AI providers": DaDeveloper LLC runs the store and sends your chat to them.
  • Personal data means information that identifies you or could reasonably be linked to you.

3. In brief

  • The Shop is the business responsible for shopper data collected on its Storefront. We hold and process that data as the Shop's service provider.
  • Chats with the AI clerk are processed by AI providers and stored. We keep a chat for 90 days after its last message; a scheduled job then deletes it.
  • No payment is taken online. The Storefront never asks you for a payment card number.
  • We do not sell personal data and do not use it for advertising. We do not use your chats to train AI models. Our AI gateway account is set so that paid model endpoints that would use inputs for training are switched off, and the AI clerk uses paid models only (Section 6).
  • We do not track visitors across other websites and do not use analytics or advertising scripts.
  • To review, correct or delete your data, contact the Shop at the contact shown on its storefront; if you write to us at privacy@daclerk.com instead, we pass your request to the Shop (Section 12).

4. Who is responsible for your data

Shoppers. The Shop decides what shopper data is collected on its store and is the business responsible for it. DaDeveloper LLC processes that data only to run the store for the Shop and on the Shop's instructions. Send access, correction and deletion requests to the Shop at the contact shown on its storefront; if you send one to us, we pass it to the Shop and help the Shop answer it.

The Shop, not DaDeveloper LLC, decides what it sells, who it sells to, how it checks age and identity, and what it writes in its own customer records. Records the Shop's staff make about a customer, including any notes made when checking ID in the Shop, are the Shop's records; we hold them as its service provider. We do not use them for our own purposes, and we open them only to run the service, to help the Shop at its request (Section 7), to investigate a security or abuse problem, to mask card-shaped numbers that should never have been stored, or as the law requires.

Shop owners and staff, and visitors to daclerk.com. For the data described in Sections 7 and 8, DaDeveloper LLC is the business responsible.

What stays ours. We decide how DaClerk stores and secures data, which providers we use to run it, and the base instructions we give the AI clerk about how to behave. The Shop writes its own instructions to its clerk, its facts, its listings and its warnings (Section 7); those are the Shop's content. This policy describes our decisions.

5. Shoppers: what is collected on a Storefront

5.1 Before you sign in

  • A session cookie (sc_session): a random identifier set on your first visit. It links your draft cart, your chat and a per-session usage limit. It is a random value that does not itself contain your name or contact details, but it links your cart and chat to your browser, so we treat it as personal data.
  • Your age confirmation (sc_age_ok): a cookie set when you confirm you are 21 or older. The same button is where you agree to the Storefront Terms and this policy, so confirming also records, against your session, the time you agreed and the versions of the terms and this policy you were shown (Section 6). That record is kept with the chat record for your session, which is created for it even if you never send a message. If you decline, nothing is recorded, the cookie is removed and you are shown a page saying the store is for adults.
  • Your chat messages: everything you type to the AI clerk is stored word for word, including any personal detail you choose to type (for example a name or phone number). The last 40 messages of each chat are kept.
  • Your draft cart: the products and quantities you add.
  • Your IP address: recorded with each chat request, and when you confirm your age, in a rate-limit record used to stop abuse. It is not shown to the Shop or sent to the AI providers.

5.2 When you sign in

Sign-in is by email only: we send a one-time code or link to your email address. There is no password, no social login and no phone sign-in.

  • Email address (required), used to sign you in and to find your customer record at that Shop.
  • Name (optional at sign-in; asked for at checkout).
  • Phone number (asked for at checkout, or saved if you type it into the chat and the AI clerk uses it to place your order).
  • Preferences: free text the Shop can keep about what you like. The AI clerk can see it.
  • Your draft cart and chat from before you signed in are joined to your customer record, and the anonymous session cookie is removed.
  • During sign-in your browser's session storage briefly holds the email address you entered so the sign-in screen can resume if you reload. It is cleared when the browser tab closes.
  • Login session: a sign-in cookie set by our authentication provider (Supabase).

5.3 When you order

  • Order details: the items, quantities, prices at the time, whether you chose pickup or delivery, any note you add for the Shop, an estimated total, and the payment method you say you will use (for example "card on file", "in person" or "phone"). This is a stated choice only; no card details are collected.
  • Delivery address, only if the Shop offers delivery and you choose it.
  • Order status and timestamps.

5.4 Records the Shop keeps about you

  • Verified flag: a mark that the Shop treats you as age-verified. Shop staff set it after checking ID in person, or the Shop brought it over from its earlier records when it moved to DaClerk. We store which staff account set it and when; the check itself, and its basis, are the Shop's. We do not store ID photos, ID document numbers or dates of birth as fields.
  • Staff notes: free text that Shop staff write about a customer, or that the Shop brought over from its earlier records when it moved to DaClerk. For Shops that record in-store age checks, these notes may contain identity document numbers, dates of birth and home addresses. Records a Shop brought over from an earlier system may also contain other details the Shop recorded there, including payment details the Shop itself wrote down. We never ask for payment details. We ask Shops to remove any such text and may mask card-shaped numbers ourselves. These notes are the Shop's records and the Shop is responsible for what its staff wrote; we hold them as the Shop's service provider. Staff notes are never sent to the AI providers and are never shown to the AI clerk.
  • Default address, if the Shop has saved one for you.

5.5 What the Storefront never asks you for

  • Payment card numbers, bank details or online payments. No payment is taken online; orders are paid for at pickup or at handover, and the Shop is responsible for checking age and identity at that point.
  • ID photos or scans.
  • Location from your device.
  • Anything from other websites you visit.

6. The AI clerk

Your chat with the AI clerk is processed by third-party AI providers and is stored by us. Before you can chat, the Storefront's entry screen asks you to agree to the Shop's Storefront Terms and this policy and to consent to your chat being processed by the Shop's AI providers, including DaDeveloper LLC. We record the time you agreed and the version of the terms and this policy you saw. Nothing you type is sent to an AI provider before you give that consent. If you do not consent, do not use the chat.

The AI clerk is an automated system. It is not a person and will tell you so if you ask.

Who processes the chat. Each message is sent through OpenRouter, an AI gateway, to a language model. The primary model is Google's Gemini 2.5 Flash; if it fails, Meta's Llama 3.3 70B is used instead. The AI clerk's replies are generated by these models, not written or reviewed by DaDeveloper LLC or the Shop.

What the model receives with each message.

  • The Shop's public facts: name, address, phone, hours, policies, pickup and delivery options, and any instructions the Shop has written for its clerk.
  • The last 10 of your messages in that chat (older tool results are shortened).
  • If you are signed in: your name, whether a phone number is on file (yes or no, never the number itself), whether the Shop has marked you as age-verified, your preferences text, and up to three of your recent orders (order number, status, date and items, without prices).
  • Product information the clerk looks up: names, descriptions, prices, stock and your cart.

What the model never receives from your record. Your email address, your stored phone number, staff notes, your saved address, your IP address, cookies, and past prices. Anything you type into the chat yourself, including a phone number or email you choose to type, is sent to the model as part of your message (Section 5.1).

What the clerk can do. It can search products, show a product, change your cart and submit an order. It cannot look up past orders beyond what is listed above, cannot read staff notes and cannot take payment.

Training. We do not use your chats to train AI models. OpenRouter states that it does not train on the data it routes. Our OpenRouter account is set so that paid model endpoints that would use inputs for training are switched off, the AI clerk uses paid models only, and we mark every request so that no provider may retain it for training. Each AI provider handles a request under its own terms, which may include keeping a short-term log to detect abuse; Google, for example, states that its paid Gemini API keeps prompts and responses for up to 55 days for abuse monitoring, where a request is served through that tier, and does not use them to improve its products. Which of Google's endpoints serves the primary model is set by OpenRouter; we will update this section if that changes.

The clerk can be wrong. Its answers are generated text. Prices, stock and totals are confirmed at the counter. It is not an age-verification, licensing or product-safety control; those are the Shop's responsibility.

7. Shop owners and staff: what is collected in the Admin

  • Sign-in email and the login session set by our authentication provider.
  • Staff record: your role at the Shop, whether your access is active, and, if the Shop uses staff PINs, a hashed PIN (we cannot read the PIN itself).
  • Owner PIN recovery: a one-time code, stored only as a hash, emailed to the owner's address together with the Shop's name.
  • Acting-staff cookie (sc_staff): set when you unlock the Admin; it lasts 12 hours.
  • Live order feed: staff devices keep an open connection that receives new and updated orders (the order itself: items, note, pickup or delivery and, for delivery, the address) and then load the customer record the order belongs to (name and phone) so it can be handled at the counter.
  • Browser storage on staff devices: the Admin keeps drafts and preferences in the browser (an unsent counter order, unsaved settings, sound and alert choices, which orders have been seen, install and idle-lock state). An unsent counter-order draft can hold a customer's name, phone and address. Drafts are cleared when you sign out.
  • What you enter: products, prices, categories, restricted-item flags, images, Shop facts, hours, policies, clerk instructions, warning text, and the customer records and notes described in Section 5.4. All of this is the Shop's content. The Shop is responsible for it, including for anything personal that staff write in notes.

Imports. When a Shop gives us an export of its earlier records (products and customers), we load it into DaClerk at the Shop's request. Under the DaClerk Merchant Terms the Shop confirms that the files are its own lawfully held business records, is the author and publisher of what is loaded, and reviews the loaded records in the Admin. We do data entry and formatting only and do not review or verify the content.

Support access. At a Shop's request we may access its Admin to load data, fix a problem or help with a task. We use that access only for the task the Shop asked for, or to investigate a security or abuse problem.

8. Visitors to daclerk.com

  • The site sets the same sc_session cookie described in Section 5.1 on the first visit. Beyond the hosting provider's server logs described in Section 9.3, we record nothing about a plain visit and load no analytics, advertising or tracking scripts.
  • Book a demo: we collect the shop name, your name, your phone number and, if you give them, an email address and a note. This is emailed to our sales inbox through our email provider. It is not written to our database.

9. How we use data and who receives it

9.1 Why we process data

  • To run the Storefront and Admin for the Shop: chat, cart, orders, pickup and delivery, customer records, sign-in.
  • To generate the AI clerk's replies (Section 6).
  • To send sign-in codes, owner recovery codes and demo-lead emails.
  • To protect the service: rate limiting, blocking abuse, keeping backups.
  • To provide support to Shops.
  • To meet legal obligations and respond to lawful requests.

We do not use personal data for advertising, marketing profiles, or any purpose other than running DaClerk for the Shop. We may keep and use aggregated or de-identified usage statistics (for example counts of chats and orders) that cannot reasonably be linked to you or to any customer, to run and improve the service. We do not sell personal data and do not share it for cross-context behavioural advertising.

9.2 The Shop

The Shop sees the customer records and orders made on its Storefront, and its staff use them to serve you. Chat transcripts are held for the Shop; its staff do not see them in the Admin today, and we provide a transcript to the Shop only on its request. What the Shop does with its records outside DaClerk is the Shop's responsibility and is covered by the Shop's own notices.

9.3 Our service providers (subprocessors)

We use the following companies to run DaClerk. Each acts on our instructions under its own contract terms.

ProviderWhat it does for usData it receivesWhere
Vercel Inc.Hosts the Storefront, Admin, daclerk.com and our serversAll web traffic in transit (IP address, cookies, page requests, form and chat data) and server logsServers in San Francisco, USA; global delivery network
SupabaseDatabase, sign-in (email codes and links), live order feed to staff devices, daily backupsCustomer records, orders, chats, sign-in accounts, rate-limit records, staff records, Shop settings and productsAWS, Northern California, USA
Cloudflare (R2 storage)Stores product images and logos; stores our nightly backup copyImage files (no personal data); the backup copy contains all customer, order, sign-in and chat dataCloudflare R2. Our backup bucket (daclerk-backups) is in Cloudflare's Western North America region; the image buckets are in the United States/North America region chosen when they were created
OpenRouterRoutes chat requests to the language modelsSee Section 6USA
Google (Gemini 2.5 Flash)Generates AI clerk repliesSee Section 6Google
Meta Llama 3.3 70B (hosted by an OpenRouter provider)Generates AI clerk replies when the primary model failsSee Section 6OpenRouter chooses the host from the providers it lists for this model, and we mark every request so it can only go to a host that does not keep it. We do not pin one host or one country; the providers OpenRouter lists are named at https://daclerk.com/subprocessors
ResendSends email from daclerk.comSign-in emails (your email address and the code or link); owner recovery emails; demo-lead emailsUSA-based provider
GitHub (GitHub Actions)Runs our nightly backup jobThe backup copy passes through GitHub's job runner each nightGitHub

A current list with any changes is kept at https://daclerk.com/subprocessors. We give Shops 30 days' notice before adding a provider that will handle shopper data.

9.4 Other disclosures

We disclose personal data outside the list above only: to the Shop it belongs to; when the law requires it (for example a valid subpoena or court order), in which case we tell the Shop unless the law forbids it; to protect the rights, safety or property of a Shop, shoppers or DaDeveloper LLC, as the Merchant Terms allow; to our professional advisers, insurers and auditors under confidentiality; to establish, exercise or defend legal claims, including under a Shop's indemnity; to enforce our terms; or to a successor if DaDeveloper LLC is sold or merged, who must honour this policy for data collected under it.

10. Cookies, browser storage and Do Not Track

All cookies are first-party. No advertising or analytics cookies are set. Our pages load no analytics, advertising or tracking scripts from third parties.

CookieSet whenPurposeLasts
sc_sessionFirst visit to any DaClerk siteDraft cart, chat and usage limit for a visitor90 days
sc_age_okYou confirm you are 21 or olderRemembers your confirmation365 days
sb-…-auth-token (may be split into parts)You sign inYour login sessionSet by Supabase; see Section 11
sb-…-auth-token-code-verifierDuring sign-inCompletes the sign-in flowNormally removed when sign-in completes (set by Supabase)
sc_staffStaff unlock the AdminRecords which staff member is acting12 hours

Browser storage: the Storefront uses session storage during sign-in (Section 5.2). The Admin uses local storage on staff devices (Section 7). The Storefront uses no local storage.

You can delete or block cookies in your browser. Blocking sc_session or sc_age_ok will stop the Storefront from working, because the age confirmation and the cart depend on them.

Do Not Track. We do not track visitors across third-party websites over time, so we do not respond to "Do Not Track" browser signals. We also do not currently read the Global Privacy Control signal; there is no sale or sharing of personal data for that signal to switch off.

Third parties. No third party collects personal data about your activity across different websites through DaClerk. Our service providers in Section 9.3 process data only to run DaClerk for us.

11. How long we keep data

DataKept for
Chat transcriptsKept for 90 days after the last message in the chat, then deleted by a scheduled job.
Customer records, orders and staff notesKept while the Shop is a DaClerk customer. When the Shop's DaClerk account ends, we keep them for 30 days so the Shop can export them, then delete them from live systems within a further 30 days; copies in backups expire on the schedule below. A Shop can also correct individual records at any time, and you can ask the Shop to (Section 12).
Sign-in accountsKept while the customer or staff record exists; deleted when we delete that record on the Shop's instruction or when the Shop's account ends.
Rate-limit records containing IP addressesDeleted by a daily job once the record has been idle for a day, meaning a day after the last request it counted.
CookiesSee the table in Section 10. The Supabase login cookie is written with the 400-day maximum age our sign-in library applies by default. It carries a short-lived access token that is renewed for you while you keep using the Store; signing out deletes the cookie.
Owner PIN recovery codesA code can be used once and stops working 15 minutes after it is issued. We store only a scrambled form of it, one row per owner, which the owner's next recovery request overwrites; that row is not on a deletion schedule today.
Demo-lead emailsKept in our sales mailbox for 12 months after our last contact with you, then deleted.
Server logs held by VercelUnder Vercel's own retention terms.
BackupsSupabase keeps a daily backup of the database; on our plan the last 7 days of daily backups are kept. Our nightly backup copy in Cloudflare R2 is deleted 30 days after it is made, by a rule set on that bucket. Data deleted from the live database stays in backups until those backups expire. We restore from a backup only to recover from data loss.

12. Your choices and rights: how to review, correct or delete your data

If you are a shopper. Shopper data collected on a Storefront is the Shop's to answer for (Section 4). Send requests to see, correct or delete your data to the Shop at the contact shown on its storefront. If you write to us instead at privacy@daclerk.com, we forward your request to the Shop within 5 business days and help the Shop answer it. The Shop's staff can correct your contact details, address, preferences and notes in the Admin, and can blank out notes. Deletion of a customer record, its orders or its chats is done by us at the Shop's written request; we complete it within 30 days of the Shop's instruction, and the Shop tells you when it is done. Chats are deleted on the schedule in Section 11; the Shop can ask us to delete a specific chat sooner.

If you are a Shop owner or staff member, or you booked a demo. Write to privacy@daclerk.com. We answer within 45 days.

Checking it is you. We confirm requests using the email address on the account, or another reasonable check, before releasing or deleting data.

We honour these requests whether or not a particular privacy law requires us to. We do not sell or share personal data, so there is no sale or sharing to opt out of; if that ever changes we will update this policy first (Section 16). Where the California Consumer Privacy Act applies, DaDeveloper LLC is the Shop's service provider for shopper data and the Shop is the business that answers your request; for the data in Sections 7 and 8 we answer it ourselves within 45 days.

Email choices. We send only service emails (sign-in codes, recovery codes, replies to you). We do not send marketing email to shoppers.

13. Security and incidents

We protect data with access controls, not promises of perfection. In particular:

  • Database rules limit what each role can read: shoppers see only their own records; staff see only their Shop's records; staff notes, saved addresses and verification history are reached only through server code that first checks the person is Shop staff.
  • Staff notes and the email address on your record are never sent to the AI providers.
  • Images of restricted products are served only through short-lived links after a check that you are a verified customer.
  • Staff PINs and recovery codes are stored as hashes.
  • Traffic between your browser and DaClerk is encrypted (HTTPS); plain HTTP requests are redirected to HTTPS.

No system is fully secure. If we discover a breach of security of personal data we hold for a Shop, we notify the Shop immediately on discovery and in any case within 72 hours, with what we know at that time, so the Shop can notify its customers as the law requires. The Shop, as the business responsible for that data, decides and sends any notice to shoppers and regulators. If a breach affects data for which we are the responsible business (Sections 7 and 8), we notify the people affected as California law requires.

14. Children and age

DaClerk and its Storefronts are not directed to children under 13, and we do not knowingly collect personal data from anyone under 13. Storefronts are intended for adults aged 21 and over. Shops may sell age-restricted goods and are responsible for checking age and identity before handing them over; DaDeveloper LLC does not verify age. If you believe a child under 13 has given us personal data, write to privacy@daclerk.com and we will delete it.

15. Where data is stored

Our database and servers are in the United States (Northern California). Backup copies are held with the providers in Section 9.3. If you use DaClerk from outside the United States, your data is transferred to and processed in the United States.

16. Changes to this policy

When we change this policy we post the new version at https://daclerk.com/privacy with a new version and effective date, and we keep a note of what changed. For a material change (one that expands how we use personal data, adds a category of data we collect, or reduces your choices) we give at least 30 days' notice before it takes effect: by email to every Shop owner, and by a notice at the top of this page and on each Storefront's entry screen. A change that expands how we use personal data does not apply to data we already hold: for shopper data, only with the Shop's written agreement; for data we are responsible for (Sections 7 and 8), only with your consent. Other changes (corrections, clearer wording, added detail that does not expand our use of data) take effect when posted.

17. This policy and our terms

This policy describes how personal data is handled. It is a notice, not a contract, and gives no rights or remedies beyond those in the applicable terms and the law. Our obligations to shoppers are those of the Shop's service provider. Your rights and obligations as a shopper are in the Shop's Storefront Terms, which name DaDeveloper LLC as an intended third-party beneficiary of their disclaimers, limitation of liability and dispute-resolution clauses. A Shop's rights and obligations are in the DaClerk Merchant Terms at https://daclerk.com/terms. The Shop is responsible for its products, its listings, its age and identity checks, the lawfulness of its sales and delivery, and the content of its own records; DaDeveloper LLC provides the software and processes data as the Shop's service provider. Where this policy and those terms differ about liability or disputes, the terms control.

18. Contact

  • Privacy and data requests: privacy@daclerk.com
  • Legal notices: legal@daclerk.com (notice by email; a postal address is available on written request)
  • Copyright notices: dmca@daclerk.com
  • General support: support@daclerk.com

DaDeveloper LLC, a California limited liability company. Any dispute about this policy is governed by California law and resolved as set out in the applicable terms (the DaClerk Merchant Terms for Shops; the Shop's Storefront Terms for shoppers), which name DaDeveloper LLC as an intended third-party beneficiary.


Version history: 2026-09-09 — first published version.

Book a demo

Leave your number and we will call you.