Privacy Policy

Last Updated: October 3, 2026

Your Fellow Agent is owned and operated by Mr. Davis Clothing Company, a C corporation ("Mr. Davis," "we," "us," or "our"). Mr. Davis takes privacy seriously and is committed to adhering to industry standards, best practices, and legal requirements relating to consumer information and privacy.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal and non-personal information across the Your Fellow Agent platform, websites, and technology infrastructure. It applies to:

  • Account Holders / Business Owners: Individuals and organizations that register, configure, train, and manage customer-facing agents on our platform.
  • End Users / Website Visitors: Individuals who interact with an agent or contact form installed on a business customer's website.
  • Site Visitors: Individuals who browse our marketing website or test our interactive demonstrations.

1. Information We Collect

1.1 Account Holder Information (Collected Directly by Us)

We collect information directly from Business Owners and Account Holders when creating and managing accounts:

  • Account Registration & Credentials: Name, business email address, and authentication identifiers (such as Google OAuth profile information or magic login tokens).
  • Business Profile & Knowledge: Business name, website URL, public contact details (email, phone, address), business hours, services, products, FAQs, and custom instructions you submit to configure your agent.
  • Billing Information: Billing contact details, payment card details, and transaction records. All payment card details are handled directly by our third-party payment processor, Stripe; we do not store full payment card numbers on our servers.
  • Direct Support Inquiries: Information you submit when contacting our support or sales teams via email, contact forms, or help requests.

1.2 Merchant Customer Data (Processed Solely as a Service Provider)

When an End User interacts with an agent or contact form installed on a Business Owner's website, we collect and process visitor messages, inquiry details, and contact information (such as name, email address, telephone number, or job notes) strictly on behalf of and under the direction of the Business Owner ("Customer Data").

Service Provider & Data Processor Role

The Business Owner owns all Customer Data. As between Mr. Davis and the Business Owner, the Business Owner is the Business (Data Controller), and Mr. Davis acts solely as a Service Provider (under the California Consumer Privacy Act / CPRA § 1798.140(ag)) and Data Processor (under GDPR Art. 4(8)).

  • We do not sell or share Customer Data.
  • We do not retain, use, or disclose Customer Data for any purpose other than providing the conversational agent and messaging services specified in our agreement with the Business Owner.
  • We do not retain, use, or disclose Customer Data outside of the direct business relationship between Mr. Davis and the Business Owner.
  • We do not combine Customer Data with personal information received from or on behalf of any other customer or party, except for essential platform security, anti-abuse, and spam-filtering purposes.
  • We do not use Customer Data or customer chat transcripts to train shared, public, or foundation AI models.

1.3 Public Website Analysis and Crawling

When a Business Owner or authorized representative submits a business website during onboarding or knowledge refresh, our automated systems crawl its public web pages. We extract public business facts, policies, FAQs, service descriptions, hours, locations, and public contact information. This content is analyzed solely to generate starter knowledge, configure the agent, associate the setup session with the business, and detect misuse.

1.4 Non-Personally Identifiable Information (Non-PII)

We collect Non-PII via our websites, widgets, and technology platforms. Non-PII cannot be used by itself to contact or identify a single person or entity. This includes:

  • Browser type and version, operating system, device characteristics, and preferred language.
  • Internet Service Provider (ISP) and general, city- or region-level geographic location derived from IP addresses.
  • Referring URLs, pages visited, session duration, timestamps, interaction patterns, and widget load events.
  • Hashed request identifiers and windowed rate-limit counters used to prevent spam, denial-of-service, and abuse on forms and endpoints.

1.5 Homepage Interactive Demo

Messages submitted within the interactive demonstration on our homepage are processed in real time by our configured AI provider to simulate agent interactions. Demo sessions are isolated and ephemeral: they are not saved as customer conversation records, not stored in any business inbox, not billed against usage allowances, and never used to contact real businesses. Do not submit sensitive personal, financial, or confidential information in the demo.

2. Cookies and Web Beacons

We use cookies, session tokens, and similar web technologies to manage our websites, safeguard account sessions, and analyze usage patterns. Cookies are small data packets stored on your device that enable websites to remember preferences, maintain secure logins, and improve usability.

The installed widget uses lightweight local browser storage to preserve chat continuity during a visitor's active browsing session on the customer's website.

In limited business-run tests, a website may use first-party browser storage to keep a visitor in the same widget experience and compare engagement and purchases. The widget can provide non-sensitive interaction events such as a hint shown or clicked, chat opened, and first customer message sent. Those events do not include message text or contact details; the business controls its own website and order analytics.

You can configure your browser to decline, erase, or alert you about cookies. Note that disabling essential functional cookies may affect your ability to log in to the dashboard or retain active session states.

3. How We Use Information

3.1 Merchant Customer Data

We process Customer Data solely on behalf of the Business Owner and strictly to perform the contracted Services:

  • Facilitating automated conversational replies in accordance with the Business Owner's configured knowledge and instructions.
  • Relaying customer inquiries, escalation alerts, and quote/appointment requests to the Business Owner and their designated team members.
  • Maintaining conversation histories in the Business Owner's private portal for their customer service and review.

3.2 Account Holder Information

We use Account Holder and platform usage information to:

  • Account Administration: Manage subscriptions, process invoicing through Stripe, deliver administrative announcements, and provide customer support.
  • Platform Optimization: Monitor system performance, refine knowledge retrieval speed, and resolve technical issues.
  • Security & Fraud Prevention: Detect and prevent abusive behavior, unauthorized access, denial-of-service attempts, and violations of our Terms of Service.
  • Legal Compliance: Fulfill binding legal obligations, court orders, and law enforcement requests when legally required.

4. Chat Data Storage and Retention

Storage, AI Processing, and Retention Policies

  • Conversation History: End User chat conversations are stored to maintain thread context, enable escalations to human team members, and allow Business Owners to review past customer interactions in their portal.
  • Retention Period: Conversation data and associated Non-PII are retained for up to twenty-four (24) months from the date of the last interaction, consistent with our record-keeping standards, unless earlier deletion is requested by the Business Owner or End User.
  • AI Processing: Customer messages and business knowledge are processed through Google Gemini or OpenAI enterprise API interfaces to generate relevant answers. Under standard enterprise API terms, data submitted to these model providers is protected and is not used to train public foundation models.
  • Business Owner Control: Business Owners maintain access to conversation logs associated with their agents and can review or archive them through the dashboard.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your Personally Identifiable Information to third parties for marketing purposes.

We disclose information only under the following circumstances:

  • To Business Owners: When an End User interacts with an installed agent or fills out a contact form on a customer's site, the conversation messages, contact information, and metadata are shared directly with the Business Owner and their authorized team members. The Business Owner is the data controller for their customer communications.
  • To Connected Business Services: When a Business Owner enables an external tool, we send the information needed for that action to the configured service and store its result to continue the conversation. Connection credentials and detailed action records are encrypted at rest. The Business Owner controls which actions are enabled and is responsible for the connected service's handling of that information.
  • To Trusted Service Providers: We contract with vetted third-party vendors who provide infrastructure and technical services necessary to operate our platform, including:
    • Google Cloud / Gemini API: AI inference and Google grounding services for public business research.
    • OpenAI: AI inference, language models, and text embeddings.
    • TypeSafe / Jev: AI judgments, including checking a website-to-text permission exchange. That check receives the proposed recipient, business name, explanation, customer answer, and a short excerpt of preceding conversation.
    • Railway: Application hosting, server execution, and managed database storage.
    • Cloudflare: Content delivery network, DDoS mitigation, DNS security, and email routing.
    • Stripe: Payment processing, automated invoicing, customer subscription management, and billing portal.
    • Maileroo: Transactional email delivery and escalation notifications.
    • Sent.dm: SMS notifications and 10DLC messaging routing where enabled.
    • Slack: Customer requests, conversation messages, and team notifications when configured by the Business Owner. Conversation channels are public within the connected Slack workspace, so workspace members may see their contents.
  • Legal Requirements & Safety: We may disclose information when we reasonably believe disclosure is required by law, subpoena, court order, or to protect the safety, rights, or property of Mr. Davis, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy involving Mr. Davis Clothing Company, customer and account records may be transferred to the successor entity.

5.1 Mobile Phone Numbers & 10DLC SMS Disclosures

Strict Non-Sharing Policy for Mobile Information:

No mobile information or text messaging opt-in data will be shared with third parties or affiliates for marketing or promotional purposes. Service providers listed above may process the information needed to verify permission, deliver messages, and operate the service on our behalf; this is not permission to use your number for marketing.

If you provide your mobile phone number to receive escalation alerts, customer follow-up messages, or service updates, message and data rates may apply. Messaging frequency varies. You may reply STOP to any SMS to unsubscribe at any time, or reply HELP for assistance.

For website-to-text requests, we store the explanation, your affirmative answer in your own words, their message identifiers and timestamps, conversation reference, recipient and sending number references, policy version, and automated evaluation as evidence of permission. These records follow the access, deletion, and retention policies in this notice. A phone number alone is not permission to text.

6. Security Safeguards

Mr. Davis maintains industry-standard physical, technical, and administrative safeguards to protect your information against unauthorized access, loss, or alteration. Our security practices include:

  • End-to-end encryption in transit (HTTPS / TLS) and encryption of sensitive data at rest.
  • Role-based access controls and password-protected environments for account holder records.
  • Regular vulnerability monitoring, environment segregation, and automated security patches.

While we adhere to rigorous security standards, no method of transmission over the Internet or electronic storage is completely infallible, and we cannot guarantee absolute security.

7. Your Rights and Choices

7.1 Access, Correction, and Deletion

You have the right to request access to the PII we hold about you, request corrections to inaccurate information, or request the deletion of your data (subject to legal or contractual retention requirements). To submit a request, contact us at [email protected] with the subject line "Data Privacy Request."

7.2 California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act:

  • The right to know what personal information we collect, use, and disclose.
  • The right to request the deletion of your personal information.
  • The right to correct inaccurate personal information.
  • The right to non-discrimination for exercising your privacy rights.
  • We do not sell or share personal information for cross-context behavioral advertising.

7.3 European & UK Privacy Rights (GDPR)

If you reside in the European Economic Area or the United Kingdom, you have rights under the General Data Protection Regulation, including data portability, restriction of processing, objection to processing, and the right to lodge a complaint with your local data protection supervisory authority. Where we act as a data processor on behalf of a Business Owner, requests regarding customer chat data should be directed to the applicable Business Owner.

8. Children's Privacy

Our Services are designed for commercial use by businesses and are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us immediately and we will promptly delete it.

9. International Data Transfers

Your Fellow Agent and Mr. Davis Clothing Company are based in the United States. Information collected through our Services is processed and stored in the United States. By using our Services or submitting information to us, you acknowledge that your information will be transferred to and processed in the United States under applicable U.S. laws.

10. Policy Modifications

Mr. Davis Clothing Company reserves the right to modify this Privacy Policy from time to time. When changes are made, we will update the "Last Updated" date at the top of this page. Continued use of our platform after updates take effect constitutes your agreement to the revised policy.

11. Contact Us & Legal Notices

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our legal and privacy team:

Mr. Davis Clothing Company

Doing Business As: Your Fellow Agent

6347 W 110th St

Overland Park, KS 66211

Telephone: (833) 291-2907 (toll free)

Privacy Inquiries: [email protected]

Support: [email protected]

Corporate: [email protected]