Hubricon Legal · Privacy

Privacy Policy

Effective September 2, 2026 · Terms of Service

Hubricon is a founder-operated quantitative service for brands selling on Amazon and Shopify. This page says what we collect, why, who else touches it, and how to get it back or erased. It is written to be read, not skimmed past.

Hubricon is operated by Hagen Simmons, doing business as Hubricon, in Dallas, Texas, United States. Questions go to hagen.simmons@hubricon.com and land with the founder.

1. What we collect, and why

Visiting the website

The application on our site asks four questions: where you sell, revenue band, business model and catalog size. They travel with your booking to Calendly so the call starts from your numbers, and we keep them on your booking record so we know which platform to set you up on. The four answers, and the fit note we derive from them, are also counted in our own analytics so we can see which kinds of seller apply. Our host, Vercel, records anonymous, cookieless analytics: pages viewed, country, device type, referrer. We run no advertising pixels and no retargeting.

Booking a call

Calendly collects your name, email, a phone number for the call, and your answers to the booking questions, under Calendly's privacy policy. We receive that information by email and keep it in our mailbox.

Email

If you write to us, we keep the correspondence. If you received an email from us that you did not ask for, it came from a Hubricon address, it tells you who we are and where we are, and one reply or one click stops it. We honour opt-outs immediately.

Clients: the seat on your store

On Amazon, you add one Hubricon user to your Seller Central with exactly four permissions: Business Reports (view), Fulfillment reports (view), Pricing (view and edit), and Advertising Campaign Manager (view and edit). Through that seat we download sales and traffic reports, SKU economics and fee reports, advertising reports, inventory, reimbursement and returns reports, and settlement data, and we make the pricing and advertising changes you have authorised.

On Shopify, you approve one collaborator account limited to Orders, Products, Analytics, Reports, Marketing and Discounts. It has no access to Settings, Finances or payouts. Through it we read your order, product, inventory and payout history and make the pricing and discount changes you have authorised.

Neither seat can see banking, tax or account settings. On Amazon, the reports we pull describe your products, orders in aggregate, fees and campaigns, and contain no customer names, addresses or payment details.

Shopify orders are the one exception, and we handle it deliberately. A Shopify order record carries the customer's name, email and shipping address, because that is how the platform stores an order. We do not want that data and we do not keep it. Our parser reads ten fields from an order — order name, status, dates, refund total, SKU, quantity, price and discount — and writes a per-SKU, per-month aggregate. No customer name, email, address, phone or payment detail is ever written to our database. If you upload the orders CSV rather than granting a seat, you are welcome to delete the customer columns first; the models never read them. The file you upload is stored as sent, in the encrypted bucket described below, and is deleted with the rest of your data when you ask.

You can revoke either seat in one click, any day.

Clients: files you upload

If you would rather send files than grant a seat, you get a private upload link that expires after ninety days. Files go straight into an isolated, access-controlled storage bucket and are parsed into structured tables. Nothing is sent by email. The unit-cost template you fill in contains your cost, freight and lead time per SKU, and we treat it as confidential.

Billing

Invoices go out by email and are paid by ACH. Payment details are handled by Stripe under its own privacy policy. We never see or store your bank account numbers, and no card is kept on file.

2. What we do with it

We do not sell or rent data, share one client's data with another, use your data to train AI models, or run advertising on the strength of it.

3. AI drafting

The wording of your written briefs is drafted by Anthropic's Claude from a short table of results our engine has already computed, for example your net margin, your Health Score and the decisions on your desk, together with your first name and company name. Our code inserts every figure afterwards, and rejects any draft that contains a number the table did not supply. Raw reports, uploaded files and credentials are never sent to an AI provider. Anthropic's commercial terms prohibit it from training on data submitted through its API.

4. Who else touches your data

Each of these providers processes data under its own terms and security programme. We add nothing to this list without updating this page.

ProviderWhat for
SupabaseDatabase and file storage, encrypted in transit and at rest
VercelWebsite hosting and cookieless analytics
Google WorkspaceEmail
ResendDelivery of transactional email such as your welcome and alerts
CalendlyScheduling
StripeInvoicing and ACH payment
LoomHosting a video brief on the occasions the founder records one personally, in place of the generated one
ElevenLabsSpeaking the narration of your video brief. It receives the narration text, which contains figures from your own numbers; it never receives your raw reports or uploads
InstantlyOur cold outreach before you were a client: name, work email, company, and the text of any reply. Never used for client data
AnthropicDrafting the wording of written briefs, and of replies to prospect enquiries, as described above
GitHubRuns our weekly monitoring job; your data passes through that job in memory and is not stored there

5. Security

Your store access is one named, permission-scoped user that you can revoke in one click. Raw data and model outputs live in a database with row-level security. Your desk signs you in with a one-time link sent to your own address — we never set, see or store a password, so there is no password to steal, and row-level security scopes every read to your workspace alone. The engine's own tables are reachable only by our server-side service, never by a signed-in session. Data is encrypted in transit and at rest. One person, the founder, holds access to production. Upload links are single-purpose and expire after ninety days. If we learn of a breach affecting your data, we tell you within seventy-two hours of confirming it.

6. Retention and deletion

While you are a client we keep your data to run the service and maintain the Decision Ledger. When you leave, an export of your data and your full ledger is free, any time, including the day you cancel. Ask, and we delete your raw reports, uploads and model outputs within thirty days, keeping only what invoicing and the law require and any results you agreed we may publish in anonymised form. Booking and correspondence records are kept for our own bookkeeping. Analytics data is anonymous from the start.

7. Your rights

Wherever you are, you can ask to see what we hold about you, correct it, export it, have it deleted, or object to a use of it. Email hagen.simmons@hubricon.com. It lands with the founder, and you get an answer within seven days. We do not sell or share personal information in the sense of the California Consumer Privacy Act. For clients in the European Union or the United Kingdom, we act as your processor for your store's data and as a controller for booking and correspondence data, and the rights in the GDPR apply.

8. Cookies

We set none of our own. Vercel's analytics uses no cookies. The embedded Calendly scheduler may set Calendly's own cookies when you use it.

9. Children

Hubricon is a business service and is not directed at anyone under eighteen.

10. Changes

When this policy changes we post the new version here with a new effective date, and we email clients about anything material.

11. Contact

Hagen Simmons, founder · hagen.simmons@hubricon.com
Hubricon · Dallas, Texas, United States