Privacy Policy
Last updated: September 3, 2026
Overview
Hellyeah AI Inc. ("Hellyeah", "we", "us") provides AI-native growth infrastructure for marketing teams. This policy explains what data we collect when you use our website, CLI, SDK, and platform, how we use it, and the choices you have.
Data we collect
Account data (name, work email, role), workspace operational data (run metadata, prompts, outputs, costs), telemetry (anonymized product usage), and the integration tokens you authorize. Where you connect your own warehouse through our adapters, customer-owned marketing data (ad spend, conversions, customer records) stays there and we read it without retaining a long-term copy. Data from the platform integrations described below, and analytics data collected through our own tracking, is held in systems Hellyeah operates as described under Where data lives.
How we use data
To operate the platform, route runs to LLMs, enforce spend caps and policies, write outcomes to your memory, support you, and improve the product. We do not sell personal data and we do not use customer data to train foundation models.
Google Tag Manager integration
You choose whether to connect Google Tag Manager and which Google Tag Manager account and container Hellyeah may manage. Hellyeah requests only 3 OAuth scopes: tagmanager.edit.containers, tagmanager.edit.containerversions, and tagmanager.publish. We use this access to list your available Tag Manager accounts and containers, create a dedicated Hellyeah workspace in the selected container, read the existing entities in that container and workspace so we can preview the change and detect conflicts, sync that workspace with your container when it falls behind, create the Hellyeah tag and All Pages trigger, create a container version, and publish that version when you ask us to. We do not use it for any other purpose. Apart from listing the accounts and containers available to you so that you can choose one, we work only within the account and container you select. We do not delete containers, and we limit our changes to the workspace, tag, trigger, and version that Hellyeah creates for this integration.
If you install again into the same container, Hellyeah creates a new workspace, trigger, and tag. Tags from an earlier install stay in your container untouched. You can remove them in Tag Manager yourself.
Nango provides the OAuth connection. Nango stores and refreshes your Google access and refresh tokens. Hellyeah does not store those tokens. Hellyeah stores only the Nango connection identifier, the selected Tag Manager account and container identifiers, identifiers for the workspace, tag, and version that Hellyeah creates, connection and publishing status, error details, and timestamps needed to operate and troubleshoot the integration.
Hellyeah shares Google API data with Google, Nango, and the cloud-hosting or error-monitoring sub-processors that process the integration metadata described above, only as needed to provide the integration you request and with your consent. We do not sell it, transfer it to data brokers, use it for advertising or personalized targeting, or use it to determine creditworthiness. Humans access Google API data only when you affirmatively authorize us to view specific data for support, when access is necessary for security or abuse investigations or to comply with applicable law, or when the data is aggregated for internal operations in accordance with applicable privacy and other laws.
When you disconnect, Hellyeah immediately stops using the connection and no further Tag Manager calls are made with it, including any work already queued. We then ask Nango to delete the OAuth credentials it holds. That deletion runs as a background job, and if it does not succeed on the first attempt a scheduled job retries until it does. Hellyeah keeps the connection metadata described above so the integration can be reconnected and troubleshooted, and deletes it when your organization is deleted. You may request its deletion sooner at any time under Your rights.
You can also revoke Hellyeah's access from your Google account. Google does not notify us when you do. We find out the next time we check the connection or attempt a Tag Manager call, and we then mark the connection as needing reconnection.
Hellyeah's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Shopify integration
If you install the Hellyeah app on your Shopify store, you grant it a single Admin API scope: read_orders. Hellyeah rejects any access token that carries a broader scope. We use it to receive the orders you complete so we can attribute them to the marketing that produced them, and for nothing else. We also subscribe to notifications telling us when an order is paid and when the app is uninstalled.
From your store Hellyeah stores the shop domain, the credentials and webhook subscription identifiers for the connection, connection status, error details, and timestamps. For each order we store identifiers we derive from the Shopify order, the order value and currency, the time the order was updated, and whether we have attributed it. Alongside it we keep the attribution data the visit itself produced: the landing page address including its query string, the advertising click identifiers and campaign parameters it carried, and approximate location and device information. Where a visitor provides an email address or phone number, we keep a hashed form of it as described below. Where you enable it, we also store the visitor's IP address and browser user agent. Hellyeah does not store payment details or order line items, and outside the privacy requests described below we do not store customer names or postal addresses.
Order notifications from Shopify include the customer email address. We convert it to a SHA-256 hash as soon as we receive it, store only that hash, and never write the address itself to our database or our logs. We handle a phone number the same way when one is provided.
Where a Hellyeah tracking snippet or storefront pixel is installed, how this works depends on the integration. Our Shopify storefront pixel hashes the email in the visitor's browser and sends us only the hash. Where your site calls our tracking snippet with an email address or phone number directly, that value reaches our servers in transit over an encrypted connection, and we hash it on receipt and retain only the hash. Hashing lets us match a conversion to the marketing that produced it without holding the underlying contact details, though a hash is a pseudonymized identifier rather than anonymous data, and we treat it as personal data throughout this policy.
If you use Hellyeah to measure advertising, we send the conversions from your store to the ad platforms running your campaigns, Google Ads and Meta. What we send is the hashed email, a hashed phone number where one is available, the order value and currency, the click identifiers that brought the visitor to your store, the page the conversion happened on, and our own event and visitor identifiers. Meta additionally receives the visitor's IP address and browser user agent where you have enabled storing them. We do not send the customer's name, postal address, payment details, or what they bought. These platforms use these signals to match the order to an ad click, and their handling of them is governed by their own terms.
Shopify sends us three kinds of privacy request. When a customer asks your store for a copy of their data, we verify and record the request, and a member of our team assembles the response. Write to us at hi@hellyeahai.com if you need it sooner than Shopify's 30 day window. When a customer asks to be erased, or when you uninstall the app and Shopify asks us to erase the shop, we delete the records we can match to that request, which means the orders, attribution records, and sessions reachable from the email address or order numbers Shopify gives us, and we clear the stored email hash. Where a request carries neither, there is nothing for us to match on and nothing is deleted. We verify that each of these requests genuinely came from Shopify before acting on it. Erasure applies to our own systems. We cannot recall conversion data already delivered to an ad platform, so you should raise those requests with the platform directly.
Merchants and their customers may exercise the rights described under Your rights by writing to us directly, and store owners can also raise a request through Shopify.
Where data lives
We host the control plane in the region you choose (US, EU, AU) on AWS and GCP. Where you connect your own Postgres and S3 through our adapters, memory writes there and we do not hold a copy. Analytics and integration data, including everything described under Shopify integration, is different: it is stored in databases Hellyeah operates, encrypted at rest and replicated across availability zones.
Sharing and sub-processors
We share data with sub-processors strictly to deliver the service (model providers, cloud hosting, error monitoring, billing). The current list is available on request to hi@hellyeahai.com.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Email hi@hellyeahai.com to exercise these rights; we respond within 30 days.
Retention
We retain operational metadata for as long as your workspace is active, and for up to 7 years afterwards where we need it for audit and compliance. Marketing-site attribution snapshots, consent decisions, IP addresses, user agents, normalized booking and lead-quality signals, and advertising-delivery diagnostics are deleted after 90 days. You can request deletion of your workspace and data at any time. When you do, we wipe the operational metadata we are not required to keep and overwrite encrypted artifacts within 24 hours. Data covered by a Shopify privacy request is deleted as described under Shopify integration, regardless of this period.
Cookies and analytics
We use first-party cookies for authentication, analytics, and advertising attribution on this marketing site. X-Ray may store campaign parameters and advertising click identifiers in first-party cookies. Where advertising tracking is enabled, Google Tag Manager loads Meta Pixel, which may set Meta attribution cookies and send controlled page-view and accepted-lead events to Meta. The accepted-lead event does not contain the form's name, email, company, or spend fields.
Our hosting provider derives an approximate two-letter country code from the request's public IP address. Advertising tracking is disabled for requests identified as coming from the European Economic Area, the United Kingdom, or Switzerland. It is enabled without a banner for a valid country code outside those regions. A missing or invalid country code leaves advertising tracking disabled. IP-based location can be inaccurate. This geographic rule describes the site's current technical behavior and is not a determination that no separate legal permission is required.
When advertising tracking is enabled and a person later books a meeting or a lead is marked High Quality in Pipedrive, we may send the resulting conversion to Google Ads and Meta. Matching data may include permitted advertising click identifiers, hashed contact identifiers, the event page and time, IP address, and browser user agent. Google and Meta process these signals under their own terms. Use your browser's controls to clear or block cookies at any time.
Children's privacy
Hellyeah is a B2B product. We do not knowingly collect data from anyone under 16.
International transfers
When data moves across borders, we rely on Standard Contractual Clauses and equivalent legal mechanisms. EU customers can keep all data in our EU region.
Updates to this policy
We'll post material changes here with at least 30 days of notice. You can subscribe to product changelog at hellyeahai.com/changelog.
Contact
Email hi@hellyeahai.com for any privacy question or vulnerability disclosure.