haggl.ai Privacy Policy

Effective Date: March 11, 2026
Last Updated: September 14, 2026

1. Introduction

This Privacy Policy explains how Moojo ("we," "us," or "our") collects, uses, and protects information when you use haggl.ai ("Service"). haggl.ai is a negotiation infrastructure layer for the agentic web: vendors install a JavaScript embed on their website that enables AI agents acting on behalf of buyers to discover, negotiate, and receive personalized offers in real time.

This policy applies to two distinct groups: Vendors (businesses that install the haggl.ai embed and configure their negotiation settings) and Buyers / AI Agents (end-users or automated agents that interact with the haggl.ai negotiation endpoint on a vendor's site).

By using the Service, you agree to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Vendor Account Data

When a vendor registers for haggl.ai, we collect:

  • Account information: Name, business email address, company name, and website URL
  • Authentication data: Credentials managed via Firebase Authentication (passwords are hashed; we do not store plaintext passwords)
  • Billing information: Stripe processes payment details for vendors billed directly by haggl.ai. Shopify manages billing for the public Shopify app; we receive and store the selected app plan and subscription status to determine access to the Service. We do not store raw payment card data.
  • Configuration data: Ideal Customer Profile (ICP) parameters, discount rules, pricing tiers, and negotiation policies the vendor defines in their dashboard
  • Embed analytics: Aggregate statistics on agent visits, negotiation sessions, and offer outcomes on the vendor's site

2.2 Buyer / Agent Negotiation Data

When an AI agent or buyer initiates a negotiation via a vendor's haggl.ai-enabled site, we may receive and process:

  • Customer profile data: Structured attributes submitted by the agent to establish eligibility for a personalized offer (e.g., company size, industry, usage context). This data is provided voluntarily by the agent on the buyer's behalf.
  • Negotiation context: The products or plans under consideration, stated requirements, and any constraints provided during the session
  • Offer and outcome data: The personalized offer generated, whether it was accepted or declined, and session metadata (timestamps, session ID)
  • Verification evidence: Buyers or their agents may submit supporting claims and email evidence to establish eligibility for an offer. Evidence may include sender information, subject, date, an excerpt, and the original email message for signature verification. Our built-in negotiation service removes original email message fields before storing the negotiation or sending its context to the AI model. Submitted metadata and excerpts, content hashes, and verification results may remain in the negotiation record.

2.3 Information We Do Not Collect

We do not collect, request, or process:

  • Payment card information or financial account details from buyers (handled by vendors independently)
  • Protected health information (PHI)
  • Government-issued identifiers (e.g., Social Security numbers, passport numbers)
  • Authentication credentials, API keys, or passwords from buyers
  • Precise GPS location data
  • Full conversation transcripts from external AI assistants

2.4 Shopify App Data

When a merchant installs Haggl Agentic Negotiation, we process Shopify store and app identifiers, the store name and domain, catalog information such as products, prices, and collections, and the permissions and authorization tokens needed to operate the app. We use this information to connect the store, display eligible products, apply merchant-defined reward rules, and create and check single-use discount codes for Shopify checkout. Stored Shopify access and refresh tokens are encrypted.

The app processes paid-order and refund events to identify eligible merchandise, attribute negotiated discounts, calculate Haggl fees and reverse fees for refunded items. Financial records include order and line references, product and variant references, quantities, amounts, currency, discount attribution and timestamps. We do not need buyer names, email addresses, phone numbers or delivery addresses for this calculation. Mandatory Shopify privacy requests can contain customer or order identifiers; we use them to locate relevant records and prepare data exports or remove attributable records. Information and evidence submitted directly by buyers or their agents are processed separately as described in Section 2.2.

3. How We Use Your Information

3.1 Vendors

  • Provisioning and operating vendor accounts and dashboards
  • Calculating purchase-based Haggl fees, processing refunds and fee adjustments, and collecting fees through Stripe for directly billed merchants or Shopify app billing for Shopify merchants
  • Executing negotiation logic against vendor-defined ICP and pricing rules
  • Providing analytics and reporting on negotiation performance
  • Communicating service updates, usage alerts, and support

3.2 Buyers / Agents

  • Evaluating submitted customer profile data against the vendor's ICP to determine offer eligibility
  • Generating and returning a personalized offer to the agent
  • Recording negotiation outcomes for vendor reporting

3.3 Service Improvement

  • Aggregated, anonymized analytics to improve negotiation quality and protocol reliability
  • No individual buyer profiles are created for cross-vendor tracking or behavioral advertising

4. Data Sharing and Recipients

4.1 Sharing Between Vendors and Buyers

Customer profile data submitted by a buyer during a negotiation session is shared with the relevant vendor as part of delivering a personalized offer. Vendors receive this data subject to their own privacy obligations toward their customers.

For the public Shopify app, the relevant merchant can also view negotiation history, submitted profile information and evidence metadata or excerpts, verification results, and offer outcomes in the embedded haggl.ai dashboard within Shopify admin. Original email message fields are not included in that dashboard.

4.2 Service Providers

Provider CategoryPurposeData Shared
Cloud Infrastructure (Google Cloud / Firebase)Hosting, authentication, database storageEncrypted account and negotiation data
Payment Processing (Stripe)Billing and subscription managementVendor billing details
AI Model ProvidersGenerating negotiation analysis and offersSession context and customer profile attributes
Commerce Platform (Shopify)Store authorization, catalog access, native discount creation, and public app billingStore and app identifiers, catalog data, discount codes and rules, authorization requests, order and refund references and amounts, and app billing information

4.3 No Sale of Personal Information

We do not sell, rent, or trade personal information to third parties for marketing or advertising purposes.

4.4 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Moojo, our users, or others.

5. Data Retention

  • Vendor account data: Retained for the duration of the vendor's account and for up to 90 days after account deletion, then permanently deleted
  • Negotiation session data: Retained for up to 12 months to support vendor analytics and dispute resolution, then automatically deleted
  • Billing records: Retained as required by applicable law and Stripe's policies
  • Aggregated analytics: Anonymized usage statistics may be retained indefinitely for service improvement

For the public Shopify app, we disconnect access and remove stored Shopify authorization tokens when we process a confirmed uninstall. When Shopify subsequently requests shop-data deletion and the installation is no longer active, we delete the app-created Shopify workspace and its imported catalog, negotiation sessions, discount-delivery records, and usage records and attributable financial records held by haggl.ai. Prepared customer-data exports are encrypted and restricted to authorized merchant access for delivery in response to the request. We preserve any separate haggl.ai login and unrelated account information, removing only the link to the deleted Shopify workspace. We retain limited technical receipts, including request hashes, processing status, and timestamps, to manage privacy-request retries; these receipts do not contain the original notification body or customer identifiers. Shopify maintains its own billing records under its applicable policies.

6. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption in transit (TLS) for all data communications
  • Encryption at rest for stored data
  • Access controls limiting data access to authorized personnel
  • Regular security assessments and monitoring

7. Your Rights and Data Access

Depending on your jurisdiction, you may have the right to access, correct, delete, or restrict processing of your personal data. To exercise these rights:

  • Vendors may access and update their account data directly in the haggl.ai dashboard, or contact us at privacy@moojo.id
  • Buyers whose data was submitted during a negotiation session may contact us to request deletion of their session data

We will respond to verifiable requests within 30 days.

8. Children's Privacy

The Service is designed for business users and does not target children under 13 years of age. We do not knowingly collect personal information from children under 13. Users between 13 and 18 should have parental or guardian consent before using the Service.

9. International Data Transfers

Your information may be processed in countries outside your residence, including within the European Union and the United States. We ensure appropriate safeguards are in place for any international transfers in compliance with applicable data protection laws.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify vendors of material changes by email and by updating the "Last Updated" date at the top of this policy. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: