Privacy Policy
Last Updated: June 17, 2026
At Multraverse.ai, we are committed to protecting your privacy and the privacy of your customers. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our software-as-a-service platform (the "Platform") for SMS messaging, email communications, payment processing, tax documentation, booking, calendar integration, and business automation services.
1. Definitions
- "Platform Users" or "Tenants" means businesses and individuals who register for and use the Multraverse.ai Platform.
- "End Customers" means customers, clients, or contacts of Platform Users who receive communications or services through the Platform.
- "Personal Information" means information that identifies or can be used to identify an individual.
- "We," "Us," or "Multraverse" means Multraverse.ai and its affiliates.
2. Information We Collect
We collect information in several ways:
Information You Provide
- Account registration information (name, email, phone number)
- Business information (company name, address, tax ID, business type)
- Payment and banking information for receiving disbursements
- Tax documentation (W-9, TIN, EIN, SSN)
- Service preferences and configuration settings
- Communications with our support team
Information Collected Automatically
- Device information and browser type
- IP address and location data
- Platform usage data and analytics
- Log files and error reports
End Customer Information Processed on Your Behalf
- Contact information (names, phone numbers, email addresses)
- Appointment and booking data
- Payment transaction records
- Communication history (SMS, email content)
- Consent records and preferences
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Platform and its services
- Process transactions and send related information
- Send SMS messages and emails on your behalf to your End Customers
- Process payments and disbursements through our payment processor
- Generate tax documents as required by law
- Manage bookings, appointments, and scheduling
- Respond to your inquiries and provide customer support
- Send you service announcements and updates about the Platform
- Monitor and analyze trends, usage, and activities
- Detect, prevent, and address fraud and security issues
- Comply with legal obligations
4. SMS Messaging Privacy
SMS Opt-In Data and Consent
When you or your End Customers provide phone numbers and opt-in to receive text messages through the Platform:
- Mobile phone numbers collected for SMS purposes will NOT be shared with third parties or affiliates for marketing or promotional purposes
- SMS opt-in consent data will NOT be shared with or sold to any third party
- Message frequency varies based on account activity and service engagement
- Standard message and data rates may apply from mobile carriers
- Recipients may opt out at any time by replying STOP to any message
- Reply HELP for assistance with the messaging service
This non sharing commitment applies to all SMS related data processed through the Platform, including phone numbers, consent records, and messaging preferences. This commitment is absolute and applies regardless of any other data sharing described in this Privacy Policy.
5. Email Communications Privacy
When we send emails on your behalf:
- Email addresses are used only to deliver your communications
- We track delivery status, open rates, and click rates to provide you with analytics
- Unsubscribe requests are honored and maintained in a suppression list
- Email content and recipient information are stored securely and retained as necessary for service delivery and legal compliance
6. Payment Information Privacy
Payment processing is handled by Stripe. When you or your End Customers make payments:
- Multraverse.ai does not store credit card numbers or bank account details
- Payment information is collected and processed directly by Stripe
- Stripe's handling of payment data is governed by the Stripe Privacy Policy
- We receive only transaction confirmations and limited payment details (last 4 digits, card type)
6.1 Platform Billing Transactions
Multraverse.ai currently offers fixed monthly subscription pricing to all new clients. To bill you for your subscription and any usage-based overages (such as SMS, email, or AI usage above your plan limits), we collect and process the following billing related information:
- Your Stripe customer ID and the payment method token issued by Stripe
- Your selected tier, billing cycle, and subscription status
- Aggregated usage counters (e.g., SMS sent, emails sent, AI tokens consumed) used to calculate overage charges
- Invoice history, payment status, and any refund or chargeback records
This information is used solely to operate your account, calculate fees, issue invoices, and meet our tax and accounting obligations. It is not used for advertising or sold to third parties.
6.2 Grandfathered Revenue Share Plans
A limited number of clients remain on legacy revenue share (percentage-based) plans entered into prior to April 2026. For these clients, we additionally process:
- The gross transaction volume processed through your connected Stripe account
- The platform's contractual percentage share of those transactions
- Reconciliation records used to compute and collect the platform fee from your Stripe payouts or via direct invoice
This information is collected from Stripe via the Stripe Connect API only to the extent necessary to administer your existing plan. Revenue share processing will continue under the original terms of your agreement until you migrate to a current fixed monthly tier or your agreement otherwise terminates. New signups are not offered the percentage based model.
7. Data We Process on Your Behalf
As a Platform, we process certain data on behalf of our Tenants (business customers). This includes:
- End Customer contact information (names, emails, phone numbers)
- Appointment and booking data
- Payment transaction records
- Communication history (SMS and email content)
- Consent records and preferences
For this data, Tenants are the "Data Controllers" and Multraverse.ai acts as a "Data Processor."
Tenants are responsible for:
- Providing appropriate privacy notices to their End Customers
- Obtaining necessary consents for data processing
- Responding to data subject access requests from their End Customers
- Ensuring lawful basis for processing End Customer data
8. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
Third Party Service Providers
We use the following services to operate the Platform:
- Stripe: Payment processing (Stripe Privacy Policy)
- Twilio: SMS and voice communications (Twilio Privacy Policy)
- Resend: Email delivery (Resend Privacy Policy)
- Google: Google Calendar integration for availability and booking sync (Google Privacy Policy)
Other Sharing
- When required by law, subpoena, or legal process
- To protect our rights, property, or safety, or that of our users
- In connection with a merger, acquisition, or sale of assets (with notice)
- With your explicit consent
AI Agents & Agentic Commerce
When a Tenant enables Stripe's Agentic Commerce Protocol ("ACP"), AI agents (such as ChatGPT, Meta, and other Stripe approved agents the Tenant has entered an Orchestrated Commerce Agreement with) may submit cart contents, buyer contact details, and shipping information on behalf of an End Customer to complete a purchase from that Tenant. For these agent initiated checkouts:
- The data the agent submits is forwarded to Stripe for payment authorization and to the Tenant for fulfillment.
- Shared payment tokens received from the agent are used solely to create a Stripe PaymentIntent on the Tenant's connected account and are not retained by Multraverse.ai after the transaction is processed.
- The Tenant is the data controller for End Customer information collected through ACP. The agent platform and Stripe are independent third parties governed by their own privacy policies and the Tenant's OCA.
- We log minimal request metadata (timestamps, session IDs, response codes) to operate, debug, and meter the integration. We do not log raw payment tokens or full card details.
Important Exception: All categories above exclude SMS text messaging originator opt-in data and consent. This information will NOT be shared with any third parties under any circumstances, except as required by law.
9. Google Calendar Integration and Google User Data
The Platform offers an optional Google Calendar integration. A Tenant's authorized staff member may choose to connect their Google account so the Platform can show accurate availability and keep bookings in sync with their calendar. This feature is initiated only by an authorized staff user and is never enabled for a Tenant's End Customers.
Google Data We Access
With the connecting user's consent, we request the following Google Calendar scopes:
- Free/busy information (
calendar.freebusy) read-only busy times, used to display accurate availability and hide times that are already booked. - Calendar events (
calendar.events) used to create, update, and cancel the appointment events that correspond to bookings made through the Platform.
How We Use, Store, and Share Google Data
- We use Google Calendar data solely to provide the availability and booking features the user requested.
- We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models.
- We store the OAuth access and refresh tokens issued by Google encrypted at rest so the Platform can continue to read availability and manage booking events on the user's behalf. We do not copy or retain the contents of your calendar; only the identifiers needed to manage events the Platform creates are stored within the relevant Tenant's own application.
- We do not sell Google user data, and we do not share it with third parties except as necessary to transmit requests to Google's APIs to provide the feature, or as required by law.
Revoking Access
You can disconnect the integration at any time from within the connected application, or revoke the Platform's access directly from your Google Account at myaccount.google.com/permissions. Disconnecting or revoking access deletes the Google tokens we store. Events already created on your calendar remain there unless you delete them.
Limited Use Disclosure: Multraverse.ai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. International Data Transfers
The Platform is operated from the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Platform, you consent to such transfers.
11. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- Employee training on data protection
However, no internet transmission is completely secure, and we cannot guarantee absolute security.
12. Data Retention
We retain information for the following periods:
- Account information: Duration of account plus 3 years
- Transaction records: 7 years (tax compliance)
- SMS consent records: 4 years (TCPA compliance)
- Communication logs: 2 years or as required by law
- Tax documents: 7 years (IRS requirements)
Upon account termination, you may request export of your data within 30 days. Data may be deleted after 90 days following termination.
13. Your Rights
Depending on your location, you may have the right to:
- Access and receive a copy of your personal information
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Object to or restrict certain processing
- Data portability (receive your data in a structured format)
- Opt-out of marketing communications
- Opt-out of SMS text messages by replying STOP
- Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@multraverse.ai.
14. End Customer Privacy
If you are an End Customer who has received communications from a business using the Multraverse.ai Platform:
- The business that contacted you is the Data Controller for your information
- For questions about how your data is used, please contact that business directly
- To opt-out of SMS messages, reply STOP to any message
- To unsubscribe from emails, use the unsubscribe link in any email
- For data access or deletion requests, contact the business that has your information
15. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and authentication
- Remember your preferences
- Analyze Platform usage and performance
- Provide security features
You can configure your browser to refuse cookies, but some Platform features may not function properly.
16. Children's Privacy
The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete that information promptly.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Platform at least 30 days before the changes take effect. The "Last Updated" date at the top indicates when the policy was last revised.
18. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Privacy Inquiries: privacy@multraverse.ai
General Inquiries: contact@multraverse.ai