Skip to main content
Last updated: August 3, 2026 | Contact: contact@shieldlabs.ai

1. Who We Are

ShieldLabs Inc, a Wyoming corporation, 30 N Gould St Ste R, Sheridan, WY 82801, USA (“ShieldLabs”, “we”, “us”). Contact: contact@shieldlabs.ai

2. Roles & Scope

This Privacy Policy describes how we process personal data in connection with the ShieldLabs SaaS platform, APIs, and customer portal. We act as a processor for Customer end-user technical data processed on Customer’s behalf, and as a controller for our own account, billing, marketing, and website data. As processor, we act only on Customer’s documented instructions; Customer, as controller, determines the purposes and means of that processing.

3. Processor Data (on Customer’s behalf)

We process technical and operational data about Customer’s end-users as necessary to provide the Service, in accordance with Customer’s configuration and plan. Categories may include device and browser signals (including fingerprinting-related signals), network identifiers (e.g., IP address), behavioral and event signals, WebRTC/network connectivity metadata, and derived risk scores or labels. The exact composition of signals and processing methods is proprietary.

4. Controller Data (our own)

When you register for or use our portal, we process account and contact information, authentication and access logs, billing and payment records, support communications, product usage metrics, and marketing preferences. We process Controller Data to provide and secure the Service, authenticate users, process payments, prevent abuse, analyze product and website performance, provide support, and send service-related and marketing communications where permitted. Where applicable data protection law applies, we rely on performance of a contract, our legitimate interests in operating and securing the Service, consent (where required for marketing or non-essential cookies), and compliance with legal obligations.

6. Marketing Communications

We may send product updates, newsletters, and other marketing emails to business contacts who register for or use the Service. You may opt out of marketing emails at any time using the unsubscribe link in the message or by contacting contact@shieldlabs.ai. Service-related communications (e.g., security, billing, or material changes to terms) may still be sent.

7. Retention

Customer Data retention is up to twelve (12) months and may vary by plan, including on the Free Plan. Aggregated or anonymized metrics may be retained longer for analytics and quality. Controller Data is retained as long as needed for the purposes above and as required by law.

8. Data Location & Cross-Border Transfers

Primary processing and storage for the Service are in the European Union (Germany / Frankfurt region). Data may also be accessed from or transferred to other regions as needed to operate, support, and secure the Service. Where required, we use appropriate contractual safeguards, including Standard Contractual Clauses under a Data Processing Addendum when executed with Customer. Separately from the Service, the analytics and platform providers used on our own websites and portal are described in our Cookie & Tracking Policy. Plausible Analytics processes data in the European Union; Google (Google Analytics), PostHog, Mintlify (our documentation platform) and Cloudflare (content delivery and performance measurement) process data in the United States. Where those transfers involve personal data of EEA or UK individuals, we rely on the safeguards referenced in this section.

9. Sharing & Subprocessors

Access is limited to personnel and systems that need it. We use subprocessors under written confidentiality and data-protection obligations, including cloud hosting providers, an email delivery provider, website and product analytics providers (currently Google Analytics, Plausible Analytics, and PostHog), a documentation platform (Mintlify), a content delivery provider (Cloudflare), a live chat provider (Crisp), and payment processors made available through the Service. A current subprocessor list is available upon request at contact@shieldlabs.ai. We will provide notice of material new subprocessors with a reasonable opportunity to object where required by contract or law.

10. Security

We implement commercially reasonable organizational and technical measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, proportionate to the nature of the data and risks involved. As processor, we will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.

11. Data Subject Requests

We handle requests from individuals (e.g., access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority) within a reasonable time, subject to identity verification and applicable limitations. For end-user data we process on Customer’s behalf, we will forward requests to Customer or assist Customer as its processor. Contact: contact@shieldlabs.ai

12. Automated Decision-Making

The Service produces risk scores, signals, and labels to support Customer’s fraud and security decisions. These outputs are decision-support tools only. ShieldLabs does not make binding legal or similarly significant decisions about end-users on Customer’s behalf. Customer is solely responsible for how it uses outputs, including any solely automated decision-making or profiling under applicable law.

13. U.S. State Privacy (including CCPA/CPRA)

Where U.S. state privacy laws apply to our processing as a business or service provider, we process personal information only as needed to provide the Service and as described in this Policy and our agreements with Customer. We do not sell or share personal information for cross-context behavioral advertising. California residents may contact contact@shieldlabs.ai to exercise applicable rights, subject to verification and legal limits.

14. Customer Responsibilities

Customer is responsible for having a valid legal basis and providing clear end-user disclosures and consent via Customer’s own interfaces or consent management platform where required, and for any decisions it makes using the outputs.

15. Customer Controls

Customer controls visibility and export of fields in the admin console and via supported interfaces, within plan limits and retention windows.

16. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 18 years of age.

17. Changes

We may update this Policy from time to time. Material changes will be notified at least thirty (30) days in advance by email and/or in-app notice where practicable.

18. Contact

ShieldLabs Inc, a Wyoming corporation, 30 N Gould St Ste R, Sheridan, WY 82801, USA Email: contact@shieldlabs.ai