Privacy Policy
Last updated: February 19, 2026
1. Introduction
Harvest Strain ("we," "us," or "our") operates the harveststrain.com website and platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our platform. Harvest Strain is operated by GeoShepard, Inc., based in Castle Pines, Colorado.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you sign up, we collect your name, email address, company name, and password (stored as a cryptographic hash).
- Business Information: During onboarding, you may provide your business name, website URL, logo, brand materials, license information, product details, and other content used to generate your website.
- Uploaded Documents: Files you upload for knowledge base ingestion (SOPs, product catalogs, guides) are stored securely and used solely to power your AI features.
- Contact Form Submissions: If you submit a contact or lead capture form, we collect the information you provide (name, email, phone, message).
- Payment Information: Payment processing is handled by third-party providers. We do not store credit card numbers on our servers.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, timestamps, and general interaction patterns within the platform.
- Device & Browser Data: IP address, browser type, operating system, and device identifiers.
- Cookies: We use essential cookies for authentication and session management. We do not use third-party advertising cookies.
2.3 Information from AI Features
- Chatbot Conversations: Messages sent to public and internal chatbots are logged to improve responses and for your review in the dashboard. Conversations are scoped to your tenant and not shared with other customers.
- Generated Content: Blog posts, site copy, and other AI-generated content are stored in your account and belong to you.
- Embeddings: Text from your uploaded documents and crawled web pages is converted into vector embeddings for search and retrieval. These are stored in a vector database isolated to your tenant.
3. How We Use Your Information
- To create, maintain, and improve your AI-generated website
- To power chatbot responses and knowledge base retrieval
- To generate blog content and SEO recommendations
- To capture and manage leads on your behalf
- To provide customer support and respond to inquiries
- To send service-related communications (account alerts, billing, updates)
- To monitor platform performance, security, and abuse prevention
- To comply with legal obligations
We do not sell your personal information to third parties. We do not use your data to train AI models beyond providing service to your specific account.
4. Data Sharing & Third Parties
We may share information with:
- AI Providers: Text content is sent to OpenAI's API for generation and embedding. OpenAI's data usage policy applies to API calls. We use API endpoints that do not train on customer data.
- Infrastructure Providers: Our platform runs on Amazon Web Services (AWS). Data is stored on servers in the United States.
- CRM Integration: If you enable HubSpot integration, lead data is synced to your HubSpot account per your configuration.
- Analytics: We may use privacy-friendly analytics tools that do not use cookies or track individuals across sites.
- Legal Requirements: We may disclose information if required by law, court order, or governmental request.
5. Data Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit
- Passwords hashed with bcrypt
- Database-level tenant isolation (PostgreSQL Row-Level Security)
- Vector database collections isolated per tenant
- Role-based access control (RBAC) for all authenticated endpoints
- Rate limiting on public APIs
- Regular security updates and monitoring
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Retention
- Account Data: Retained for the duration of your account plus 90 days after cancellation.
- Generated Websites: Taken offline within 30 days of account cancellation. Source files deleted within 90 days.
- Chat Logs: Retained for 12 months, then automatically purged.
- Lead Data: Retained for the duration of your account. Exportable at any time via CSV.
- Uploaded Documents & Embeddings: Deleted within 30 days of account cancellation or upon your request.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data in a portable format
- Opt out of non-essential communications
- Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@harveststrain.com. We will respond within 30 days.
8. Cannabis Industry Considerations
Harvest Strain is designed exclusively for licensed cannabis operators in jurisdictions where cannabis is legal. We do not:
- Facilitate the sale or distribution of cannabis products
- Store cannabis license numbers or state compliance credentials (e.g., METRC API keys) unless explicitly provided for integration purposes
- Make medical claims about cannabis products
- Knowingly provide services to unlicensed operators
9. Children's Privacy
Our Service is not intended for individuals under the age of 21. We do not knowingly collect personal information from anyone under 21. If we become aware that we have collected data from someone under 21, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at:
Harvest Strain / GeoShepard, Inc.
1012 Pinefield Lane
Castle Pines, CO 80108
Email: privacy@harveststrain.com
Phone: (720) 275-0556