Legal

Privacy Policy

Effective October 5, 2026. Written to be read — clear language, with a short summary first.

Effective date: October 5, 2026 · Last updated: October 5, 2026

This Privacy Policy explains what personal data MerkleBot collects when you visit our website, request a demo, or use our robotics and IoT data platform, why we collect it, who we share it with, and the choices and rights you have. We have tried to write it in plain English. Where the machine data you send through our platform belongs to your organization, we process it on your behalf and under your instructions, and we explain how that works below.

The short version

  • We collect only what we need: the details you type into our contact and demo forms, account and billing information for platform customers, and limited technical data needed to run and secure our services.
  • Our marketing website does not load third-party analytics or advertising trackers by default. It uses only strictly necessary browser storage, such as remembering your cookie choice.
  • Machine and telemetry data that customers send through the platform belongs to the customer. For that data we act as a processor or service provider, and a Data Processing Agreement is available.
  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
  • Decentralized storage has real limits on deletion. We explain those limits honestly and support encryption before upload where it is configured.
  • You can ask to access, correct, delete or export your personal data at any time by writing to [email protected].

1. Who we are and how to reach us

MerkleBot ("MerkleBot", "we", "us" or "our") provides a business-to-business data platform for robotics and IoT fleets. We connect machine data through a RESTful API, a command-line interface (CLI) and the on-device MerkleBot Agent, and offer hybrid storage (edge, local data centers and decentralized networks), Docker-based compute and ROS bag extractors, third-party connections including our Smart Lease financing product, and a remote-access robotics lab.

We are based in the San Francisco Bay Area, California, USA. Contact us about privacy at [email protected], or use our contact page.

2. Scope of this policy

2.1 Who this policy covers

This policy applies to personal data we handle about:

  • Website visitors who browse merklebot.com, including our blog;
  • Demo requesters and other contacts who use our "Book a demo" or contact form or email us;
  • Platform customers and their authorized users who hold accounts, use our API, CLI or Agent, or book the remote lab; and
  • Business partners and suppliers, to the extent we hold their staff's contact details.

2.2 Website personal data versus customer machine data

  • Personal data we control. Form submissions, account details, billing contacts, support conversations and website technical data. For this information MerkleBot is the "controller" (EU and UK GDPR) or "business" (California law), and this policy governs our use of it.
  • Customer machine data. Telemetry, sensor readings, logs, video, point clouds, ROS bag files, device identifiers and other content customers send to or process through the platform ("Customer Data"). Customers decide what to collect and why, and MerkleBot acts as a "processor" or "service provider" on their behalf (see Section 6).

If your information appears within Customer Data (for example, a worker visible in a robot's camera feed), please contact the organization operating the robot or device. We will assist our customers in responding.

2.3 What this policy does not cover

This policy does not cover third-party websites or services that you reach through our site or connect to the platform. Those have their own privacy policies.

3. Personal data we collect

3.1 Information you provide directly

  • Demo and contact requests: name, work email, company, role, fleet size, topic, message, and a record of your consent checkbox and when it was given.
  • Account information: names, work emails, organization, roles and permissions, and credentials (passwords are stored only hashed; API keys in protected form).
  • Billing information: billing contact, address, tax identifiers and payment history. Card details go directly to our payment processor; we do not store full card numbers.
  • Support and communications: the content of emails, tickets and calls, and any attachments.
  • Remote lab bookings: participant names, booking times and the experiment description.
  • Financing enquiries: business contacts and company information you share about Smart Lease or other financing, such as fleet plans.

3.2 Information collected automatically

  • Website: standard request data received by our servers and hosting provider (IP address, browser type, page requested, referrer, time), used for delivery, security and troubleshooting. We also store your cookie-consent choice and interface preferences in your browser; see our Cookie Policy. No third-party analytics or advertising trackers are loaded by default.
  • Platform usage data: sign-in events, API calls, request volumes, errors, feature usage and audit trails from the platform, API, CLI and Agent.
  • Agent and device metadata: Agent version, connection status, customer-assigned device identifiers and resource usage. This is generally treated as Customer Data unless used in aggregated form to run our service.

3.3 Information from third parties

  • Your organization, when an administrator creates an account for you.
  • Payment processors, which confirm payments and provide limited card details (brand and last four digits).
  • Single sign-on providers, where your organization uses them.
  • Financing partners, which may share the status of a financing application your organization asked us to facilitate.
  • Public business sources, such as a company website, to prepare for a demo.

3.4 Summary table

CategoryExamplesSourcePurposeLegal basis (GDPR/UK GDPR)Retention
Contact and demo request dataName, work email, company, role, fleet size, topic, message, consent recordYou, via our form or emailRespond to your request, schedule demos, follow up about our servicesLegitimate interests; consent where required for marketingUp to 24 months after last interaction, unless you become a customer
Account dataName, work email, organization, role, permissions, hashed credentialsYou or your organization's administratorProvide and secure the platform, manage accessPerformance of contract; legitimate interestsLife of the account, plus up to 90 days
Billing dataBilling contact, address, tax ID, invoices, payment statusYou; payment processorInvoicing, payments, tax and accountingPerformance of contract; legal obligationUp to 7 years, or as required by tax law
Support and communicationsEmails, tickets, call notes, attachmentsYouProvide support, improve the services, keep recordsPerformance of contract; legitimate interestsUp to 3 years after the ticket is closed
Website technical dataIP address, browser type, pages requested, timestampsAutomatically, from your browserDeliver the site, security, troubleshootingLegitimate interestsServer logs up to 30 days
Browser storage preferencesCookie-consent choice, interface preferencesYour browserRemember your choicesLegitimate interests; strictly necessary storageUntil you clear it; consent re-requested after 12 months
Platform usage and audit dataSign-ins, API calls, errors, feature usageAutomatically, from the platform, API, CLI and AgentOperate, secure, bill and improve the servicesPerformance of contract; legitimate interestsUp to 13 months; security audit logs up to 24 months
Remote lab booking dataParticipant names, booking times, experiment description, session logsYouSchedule and run lab sessions safelyPerformance of contract; legitimate interestsUp to 24 months after the session
Financing enquiry dataBusiness contacts, company and fleet information, application statusYou; financing partnersFacilitate Smart Lease or financing at your requestPerformance of contract or steps before a contract; legitimate interestsUp to 7 years where linked to a financing agreement; otherwise 24 months

4. How we use personal data

We use personal data to:

  • respond to demo requests, enquiries and support questions;
  • create and manage accounts and authenticate users;
  • provide, operate and secure the website and platform, including the API, CLI, Agent, storage, compute and remote lab;
  • process payments and meet tax and accounting obligations;
  • send service notices, such as security alerts and billing reminders;
  • send product updates to business contacts, where permitted and subject to opt-out;
  • facilitate third-party connections, including Smart Lease, when your organization asks us to;
  • analyze service usage in aggregated form to fix problems and improve features;
  • detect and investigate fraud, abuse, security incidents and breaches of our Terms of Service; and
  • comply with legal obligations and enforce our rights.

We do not use Customer Data for our own marketing or to train general-purpose machine learning models. We use it only to provide the services to the relevant customer (see Section 6).

If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:

  • Performance of a contract, where processing is needed to provide services you or your organization have signed up for, or to take steps at your request before entering into a contract.
  • Legitimate interests, where we have a legitimate business reason that is not overridden by your rights and interests. Examples include responding to business enquiries, securing our systems, improving our services and keeping business records. You can ask us for more information about how we balanced these interests.
  • Consent, where the law requires it, for example for certain marketing emails or for any non-essential cookies or analytics we might introduce in future. You can withdraw consent at any time without affecting processing that happened before.
  • Legal obligation, where we must process data to comply with the law, such as tax record-keeping or responding to lawful requests from authorities.

6. Machine and telemetry data processed for customers

6.1 Our role

Customers use MerkleBot to collect, store, process and route data from robots and IoT devices. That Customer Data may include personal data, for example images or video that capture people, location traces linked to an operator, or logs containing user names. For Customer Data, the customer is the controller (or "business") and MerkleBot is the processor (or "service provider" or "contractor"). We process Customer Data only to provide the services, according to the customer's documented instructions, our agreement with the customer, and applicable law.

6.2 Data Processing Agreement

A Data Processing Agreement (DPA) is available to customers on request by writing to [email protected], and may already be incorporated into your order form. The DPA describes the subject matter, duration, nature and purpose of processing, our security commitments, our use of sub-processors, assistance with data subject requests, breach notification, and deletion or return of data at the end of the services.

6.3 Customer responsibilities

Customers are responsible for having a lawful basis to collect Customer Data, for providing any notices required to people whose information is captured by their robots and devices (for example, workplace camera notices), and for configuring the platform, including encryption and retention settings, in a way that meets their own legal obligations.

7. How we share personal data

We share personal data only as described below.

7.1 Service providers and sub-processors

Vendors who help us run the services may use personal data only to serve us, under written agreements. Categories include cloud hosting, edge and local data center providers; decentralized storage and pinning services (see Section 9); payment and invoicing providers; email, support and communication tools; identity and security monitoring providers; and professional advisers. Customers may request our current sub-processor list from [email protected].

7.2 Third-party connections you choose

When a customer connects a third-party monitoring, analytics, payment or financing service, we send that service the data the customer has configured. We share information with Smart Lease financing partners or other lenders only at the customer's request and only as needed for that financing. These third parties apply their own terms and privacy policies.

We may disclose personal data where we believe in good faith that the law or legal process requires it, or to protect the rights, property or safety of MerkleBot, our customers or others. Where permitted, we will try to notify the affected customer first and will challenge overbroad requests.

7.4 Business transfers

Personal data may be transferred in a merger, acquisition, financing, reorganization or sale of assets. We will require the recipient to honor this policy or will notify you of material changes.

We may share personal data for other purposes with your consent or at your direction.

7.6 No sale and no cross-context behavioral advertising

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under 16.

8. International data transfers

MerkleBot is based in the United States, and our service providers may operate in other countries. If you are located outside the United States, your personal data will be transferred to, stored in and processed in the United States and possibly other countries whose data protection laws may differ from those of your country.

Where we transfer personal data from the EEA, the United Kingdom or Switzerland to countries that have not been recognized as providing adequate protection, we use appropriate safeguards. Depending on the circumstances, we may rely on:

  • the European Commission's Standard Contractual Clauses (SCCs);
  • the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs;
  • the EU-U.S. Data Privacy Framework, together with its UK Extension and the Swiss-U.S. framework, where MerkleBot or a relevant recipient is certified and the framework applies; and
  • other lawful transfer mechanisms or derogations permitted by applicable law.

Customers can configure where certain Customer Data is stored, including on edge devices or in specific data center regions. You can request more information about the safeguards we use by contacting [email protected].

9. Decentralized storage: how it works and its limits

Some customers store Customer Data on decentralized storage networks, which work differently from conventional cloud storage.

9.1 Content-addressed and immutable storage

These networks typically identify each file by a cryptographic hash of its contents, so stored content cannot be edited in place. Once published, data may be retrieved, cached and replicated by independent storage providers that MerkleBot does not control.

9.2 Encryption before upload

Where encryption is configured, the platform encrypts Customer Data before upload, so storage providers hold only ciphertext. Customers can choose who controls the keys. We strongly recommend never sending personal data to decentralized storage unencrypted.

9.3 What deletion means

When Customer Data stored on a decentralized network must be deleted, we will: delete or revoke the relevant encryption keys that we control; remove ("unpin") the content from storage nodes we operate or contract with; stop renewing, and where possible terminate, any storage deals; and delete our references and indexes to that content. Where the data was encrypted and the keys are destroyed, the remaining ciphertext should be unreadable in practice.

9.4 Honest limits

We cannot guarantee that every copy held by independent third-party nodes will be physically erased, particularly where data was uploaded without encryption, where a storage deal has a fixed minimum term, or where third parties have independently copied publicly available content. Customers should take these limits into account when deciding what to store on decentralized networks and should use conventional or edge storage for data that may need to be fully erased.

10. How long we keep personal data

We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law. When the retention period ends, we delete or anonymize the data. Typical periods are:

DataRetention period
Demo and contact form submissions (non-customers)Up to 24 months after our last interaction with you
Marketing preferences and opt-out recordsAs long as needed to honor your choice (suppression lists are kept indefinitely so we do not contact you again)
Account dataFor the life of the account, then up to 90 days
Customer DataAs configured by the customer; deleted within the export window after termination (generally 30 days), subject to Section 9 for decentralized storage and to backup cycles of up to 35 days
Billing and tax recordsUp to 7 years, or longer if required by law
Support tickets and communicationsUp to 3 years after closure
Website server logsUp to 30 days
Platform usage logsUp to 13 months
Security and audit logsUp to 24 months
Browser storage (consent and preferences)Until you clear it; consent is requested again after 12 months

11. How we protect personal data

We use administrative, technical and physical measures designed to protect personal data, including:

  • TLS encryption in transit and encryption at rest for managed storage;
  • optional client-side encryption before upload to decentralized storage;
  • role-based, least-privilege access and multi-factor authentication for staff;
  • scoped API keys that customers can rotate or revoke;
  • logging and monitoring of production access, and container isolation of customer compute; and
  • vendor reviews and incident response procedures, including legally required notifications.

No system is perfectly secure. You are responsible for keeping your credentials, API keys and devices secure. If you suspect your account has been compromised, contact [email protected] immediately.

12. Your privacy rights

Depending on where you live, you may have some or all of the rights described below. We will honor these rights as required by applicable law. For Customer Data, please direct your request to the customer that controls the data; we will support them in responding.

12.1 EEA, UK and Swiss residents

Under the GDPR and UK GDPR, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data in certain circumstances;
  • restrict our processing in certain circumstances;
  • data portability, meaning to receive data you provided in a structured, machine-readable format;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • withdraw consent where we rely on consent; and
  • lodge a complaint with a supervisory authority (see Section 21).

12.2 California residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), California residents, including business contacts, have the right to:

  • Know and access the personal information we collected, its sources, our purposes, and the categories of recipients;
  • Delete personal information, subject to legal exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information (we do neither, but you may still submit a request);
  • Limit the use of sensitive personal information. We use sensitive information, such as log-in credentials, only for purposes the CCPA permits, such as providing and securing the services; and
  • Non-discrimination for exercising any of these rights.

In the past 12 months we collected the categories described in Section 3: identifiers, professional information, commercial information, internet activity information and account log-in credentials, and disclosed them for business purposes to the service providers in Section 7.1.

12.3 Residents of other U.S. states

Residents of other states with comprehensive privacy laws, such as Colorado, Connecticut, Virginia, Texas and Oregon, generally have similar rights to access, correct, delete and port their data and to opt out of targeted advertising, sale and certain profiling. We honor these rights as required. Where the law provides one, you may appeal our decision by writing to [email protected] with the subject "Privacy appeal".

13. How to exercise your rights and verification

To make a request, email [email protected] with a description of your request and the email address associated with your interactions with us. Account holders can also update many details directly in their account settings.

We will verify your identity before acting, usually by confirming control of the email address on file. For more sensitive requests we may ask for additional details matching information we hold, which we use only for verification.

We aim to respond within one month for GDPR and UK GDPR requests and within 45 days for CCPA and other U.S. state requests. If we need more time, as the law allows, we will tell you why. We do not charge a fee unless a request is manifestly unfounded or excessive.

14. Authorized agents

Where permitted by law, you may use an authorized agent to make a request on your behalf. We will ask the agent to provide proof of your signed permission or a valid power of attorney, and we may ask you to verify your identity directly with us and confirm that you gave the agent permission.

15. Do Not Track and Global Privacy Control

There is no common standard for "Do Not Track" (DNT) signals, so our website does not change its behavior in response to them; in any case, it does not track you across third-party sites.

We treat a Global Privacy Control (GPC) signal as a valid request to opt out of sale, sharing and targeted advertising for that browser. If we introduce optional analytics or marketing technologies in future, GPC will be honored as a refusal of them.

16. Children's privacy

Our website and services are designed for businesses and are not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact [email protected] and we will delete it.

17. Automated decision-making

We do not make decisions about individuals based solely on automated processing, including profiling, that produce legal effects or similarly significant effects. We use automated tools for routine operations such as fraud and abuse detection, rate limiting and security monitoring, and a person reviews any action that would significantly affect an account. Any credit or eligibility decisions for Smart Lease or other financing are made by the relevant financing partner under its own policies.

18. Cookies and similar technologies

Our marketing website uses only strictly necessary browser storage, such as remembering your cookie-consent choice in a local storage item named mb_cookie_consent, and remembered interface preferences. We do not load third-party analytics or advertising trackers by default. If we introduce analytics in future, we will enable it only with your consent where the law requires consent. Fonts and scripts on our website are self-hosted, so loading our pages does not send your IP address to font or script providers. For details, see our Cookie Policy.

19. Marketing communications

We may send demo requesters and customer contacts occasional emails about our products and events, where permitted by law, and will ask for consent first where it is required. You can opt out at any time using the unsubscribe link in any marketing email or by writing to [email protected]. We may still send service messages, such as security and billing notices.

20. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, our practices or the law. When we do, we will update the "Last updated" date at the top of this page. If the changes are material, we will provide additional notice, such as an email to account owners or a notice on our website, before the changes take effect. We encourage you to review this policy periodically.

21. Contact us and complaints

MerkleBot
San Francisco Bay Area, California, USA
Privacy: [email protected]
General: [email protected]

We would appreciate the chance to address your concerns first. If you are in the EEA, you may complain to the supervisory authority where you live or work or where an infringement occurred. In the UK you can contact the Information Commissioner's Office (ICO), and in Switzerland the Federal Data Protection and Information Commissioner (FDPIC). California residents may also contact the California Privacy Protection Agency.