Privacy Policy
Last updated: August 17, 2026
This Privacy Policy describes how Qentrax, Inc. (“Qentrax,” “we,” “us”) handles information in connection with the Qentrax website (qentrax.io), the Qentrax application, and the Qentrax Model Context Protocol (MCP) service used with ChatGPT and other compatible clients.
1. Information we process
Depending on how you use Qentrax, we may process:
- Account and authentication data — email address, password (hashed by our auth provider), OAuth subject identifier, and sign-in events when you create or connect a Qentrax account (including via the MCP OAuth flow used by ChatGPT).
- Organization and membership data — organization name/type, role, and membership status for publishers and advertisers on the network.
- MCP and tool request data — vertical, geography, product filters, preflight attributes you supply, and performance query parameters when you use the ChatGPT / MCP tools. Phase 1 MCP tools do not require consumer contact PII for demand discovery or requirements lookup.
- Opportunity / preflight data — non-PII or limited attributes (e.g., state, zip, intent signals, consent flags) you choose to send for eligibility checks. Contact fields (name, email, phone) are not required for Phase 1 preflight and should be minimized.
- Performance and transaction metrics — aggregated or organization-scoped metrics such as submission counts, acceptance rates, and revenue figures visible to authorized members of that organization.
- Technical data — IP address, user agent, request identifiers, and logs needed to operate, secure, and debug the service.
2. How we use information
- Authenticate users and authorize organization access.
- Provide demand discovery, requirements, preflight, and performance tools.
- Operate, secure, and improve the marketplace infrastructure.
- Comply with law and respond to lawful requests.
- Communicate with you about the service (e.g., support, security notices).
3. Consumer PII and minimization
Phase 1 MCP tools are designed for marketplace discovery and preflight. They do not submit, distribute, or sell consumer leads. We encourage users to avoid sending consumer contact PII (name, email, phone, full address) unless a later product capability explicitly requires it. Organization performance views do not expose another tenant’s consumer-level records.
4. Service providers / infrastructure
We use infrastructure and service providers to operate Qentrax, including:
- Hosting and edge (e.g., Vercel for the application site, Render for the MCP service).
- Database and authentication (Supabase).
- Payment processing for marketplace billing (Stripe), when used.
These providers process data on our behalf under contractual obligations. We do not sell personal information.
5. Retention and deletion
We retain account, organization, and operational records for as long as needed to provide the service and meet legal obligations. You may request account disconnection or deletion by contacting support (see below).
6. OAuth and ChatGPT account linking
When you connect Qentrax to ChatGPT (or another MCP client), you authorize the client to call Qentrax tools on your behalf using an access token bound to your Qentrax account. You can disconnect by revoking access in the client and/or by contacting support to disable your Qentrax account access.
7. Contact
Privacy and data requests: privacy@qentrax.io
General support: support@qentrax.io
This policy may be updated from time to time. Material changes will be posted on this page.