Legal

Privacy Policy

Last updated: August 2026

This policy describes the information Mopshy AI collects through mopshy.com and related inquiry, account, and scheduling flows, why we use it, and the service providers involved. It is intended to describe current operations rather than make claims about data we do not collect or controls we have not implemented.

Information you provide

  • Inquiry details such as your name, work email, phone number when provided, company, website, workflow description, and other information you enter into a form.
  • Assessment information you submit through lead-audit or AI-readiness experiences, including scores or answers when those are part of the form.
  • Account information such as email and authentication data when you use a Mopshy sign-in flow for private workspaces or connected tools.
  • Client-provided information shared during an engagement, subject to the applicable agreement and the systems selected for that project.

First-party attribution data

When you visit the site, we may store a small first-party attribution record in your browser so an inquiry can be connected to the marketing source that brought you to Mopshy. This can include UTM source, medium, campaign, content and term values; common advertising click IDs; the first landing-page path; the time of that first visit; and an external referrer with its query string removed. We also keep the most recent non-direct acquisition touch so we can distinguish first-touch and last-touch attribution.

This attribution record is stored in browser local storage under a Mopshy-owned key. A session-scoped lead identifier may also be stored after a form submission so a later booking click can be associated with that inquiry.

Optional analytics

The application supports an optional Google Analytics 4 integration for aggregate website and conversion measurement. GA4 is loaded only when a production Measurement ID is configured and the visitor chooses “Allow analytics.” If enabled with consent, Mopshy may measure page views, successful inquiry submissions, and booking-link clicks. Choosing “Only necessary” prevents the application from loading this optional integration.

Bot and abuse protection

Mopshy can use Cloudflare Turnstile to protect public inquiry forms from automated abuse. When enabled, Turnstile produces a short-lived challenge token in the browser and Mopshy’s server validates that token before accepting the lead. This security check is not used to read the contents of the inquiry itself.

How we use information

  • Respond to inquiries and evaluate whether an automation engagement is a fit.
  • Operate requested website, account, and scheduling functions.
  • Understand which pages and acquisition sources lead to genuine business inquiries.
  • Maintain lead status, follow-up context, and basic sales-operations records.
  • Protect public forms from automated abuse when security controls are enabled.
  • Secure, troubleshoot, and improve the website and delivered systems.
  • Deliver client work according to the applicable agreement.

Current website service providers

The Mopshy marketing application is hosted on Vercel. Supabase is used for website authentication and lead-data services. Cal.com is used when you choose an external meeting booking link. Google Analytics 4 and Cloudflare Turnstile are optional integrations that apply only when configured for the production site as described above. Additional providers used for a client project depend on that engagement and should be disclosed when relevant to client data.

Sharing and sale of personal information

We do not sell personal information as part of our current business model. We disclose information to service providers or professional advisers when reasonably necessary to run the website, respond to an inquiry, deliver an engagement, protect the business, or meet an applicable legal obligation. We do not describe every provider as operating under a specific legal agreement unless that agreement actually applies.

Retention

Inquiry and sales-operations records are kept while they remain reasonably useful for the business relationship, follow-up, recordkeeping, security, or applicable legal obligations. Client-project retention is governed by the engagement, the selected systems, and applicable requirements. We avoid publishing a blanket retention period where the actual rule depends on the data and context.

Your choices and requests

Depending on where you live and the data involved, you may have rights concerning access, correction, deletion, objection, or portability. You can contact privacy [at] mopshy.com with a privacy request. We may need to verify the request and may retain information where an applicable obligation or legitimate recordkeeping need requires it.

You can clear Mopshy's browser local storage through your browser settings. Doing so may reset first-touch attribution and the saved analytics preference on that device.

Third-party destinations

Links to scheduling, social, or other third-party services take you to systems that have their own privacy practices. This policy covers Mopshy's handling of information, not every action a third-party service takes after you leave mopshy.com.

Contact

Mopshy AI · Pittsburgh, PA · privacy [at] mopshy.com

For regulated or contract-specific privacy requirements, the applicable agreement and current supporting documents should be reviewed in addition to this public policy.