Privacy Policy
1. What we collect
mnnr.app is a B2B governance layer; we do not run consumer accounts. The personal data we process in the ordinary course of business is limited to:
- contact data you submit (name, email, company, role) when you request a demo, sign a contract, or send us a message;
- billing and tax data necessary to invoice merchant customers (handled by Stripe Inc. as data processor);
- technical telemetry from the website (IP, user-agent, referrer, anonymized analytics counters) for security, abuse-prevention, and aggregate traffic measurement.
We do not collect end-user payment-card data on this site. Agentic-payment transactions governed by the mnnr layer in production are processed by the underlying rail (Visa, Mastercard, Stripe, PayPal, Crossmint) and audited via append-only ledger; mnnr signs policy decisions, it does not store cardholder data.
2. Legal basis (GDPR Art. 6)
Where the General Data Protection Regulation applies (EU/EEA visitors), our lawful bases are: (a) contract performance for customer onboarding and billing; (b) legitimate interest for security telemetry and abuse-prevention; (c) consent for any optional marketing email, which you may withdraw at any time.
3. Data residency
Production governance data for EU-region customers is processed in Frankfurt (eu-central). Marketing-site traffic is served from Cloudflare's global edge network with no persistent user-identifying storage at the edge.
4. Sharing
We do not sell personal data. The authoritative, dated list of every processor and sub-processor we use is published at /legal/subprocessors/; that page governs if it and this paragraph ever diverge. In summary, we share limited operational data with Cloudflare (edge serving, DDoS protection, cookieless Web Analytics, DNS, and the Turnstile anti-abuse challenge described below), Stripe (billing), Google Workspace (email), Resend (transactional email delivery), our application hosting and authentication providers, and counsel or auditors under confidentiality. Each processor is contractually bound to GDPR-Article-28 standards where applicable.
Cloudflare Turnstile. Our contact and updates forms load Cloudflare Turnstile from challenges.cloudflare.com to distinguish human submissions from automated abuse. Turnstile receives your IP address, browser and device characteristics, and an anti-abuse token; it does not use advertising cookies and does not profile you across sites. Legal basis: legitimate interests under GDPR Article 6(1)(f) in keeping our forms usable and our systems secure.
No third-party CDNs or fonts. Every font, stylesheet, script, and image on this marketing site is served from our own origin. We load no Google Fonts, no third-party font or script CDN, and no advertising or social tracking pixels. The only third-party origins your browser contacts on this site are Cloudflare's, as described above.
5. Retention
Contact and contract data: for the life of the customer relationship plus 7 years for tax and audit compliance. Technical logs: 90 days. Marketing inquiries that don't convert: 24 months, then deleted.
6. Your rights
If GDPR or California Consumer Privacy Act applies to you, you have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to processing or lodge a complaint with a supervisory authority. Email privacy@mnnr.app to exercise any of these. We respond within 30 days.
7. Security
Production governance traffic uses TLS 1.3 with X25519MLKEM768 hybrid post-quantum key exchange at the edge. Signed governance attestations use ML-DSA-65 (FIPS 204). See /crypto/ for live public keys and the genesis attestation.
8. Changes
We post material changes here with a revised "last updated" date. Continued use after a change constitutes acceptance.
9. Contact
MNNR LLC, 1603 Capitol Ave, Suite 413 PMB #1750, Cheyenne, WY 82001, USA. Email: privacy@mnnr.app.