Privacy Policy
Last updated: 3 October 2026
Changed in this version: where the service is hosted (our own server, not Vercel, Render, Supabase or Cloudflare; Vercel now only hosts our DNS records), who else receives data, what the usage log holds, where the text you send to lookup tools goes, and how long things are kept. The previous version was dated 2026-08-26.
1. Who we are
HatchLoop and AgentBroker are products of Techmate (شركة الرفيق التقني), a company registered in the Sultanate of Oman, CR 1661879, Muscat. Techmate is the legal entity behind this site and the data controller for everything described below; HatchLoop is the name of the product, not a separate company.
This policy covers the website hatchloop.dev and the AgentBroker service at hatchloop.dev and api.hatchloop.dev: an MCP server and API that lets AI agents check and find businesses and, on the channels that are enabled, message and book with them. Contact for anything in this policy: hello@hatchloop.dev.
2. What we collect
When you visit hatchloop.dev or call the API.
- Our web server keeps an access log of every request: time, IP address, the address requested (with session tokens and key parameters removed), user agent, response status and size. API key headers are replaced with a placeholder before anything is written.
- We measure visits with Umami, which runs on our own server and not at an analytics company. It sets no cookies. It records the page address, referrer, page title, browser, operating system, device type, screen size, language and approximate location (country, region, city). Its database has no field for your IP address.
- Every page asks our API whether you are signed in, which is a request to our server like any other. The only cookie we set is the sign-in session cookie (
hl_portal, 30 days) after you sign in; your browser also remembers, in local storage, which credit package you chose while signing in.
When your agent calls a tool. For each call the usage log records:
- the time, the tool name, the outcome and status, and how long it took;
- the client name and version your software reports, and whether a key was used and its state;
- the names of the arguments you sent, never their values, and a short one-way hash of the arguments;
- a short one-way hash of your IP address, and your user agent.
- The values you pass to lookup and screening tools (a company name, a person’s name, a place) are not written to the usage log and are not stored by the service. Tools that change state (sending a message, capturing a lead, booking, escalating) store a record of the operation, described under “Messaging” below.
- A billing record of each charge: the tool, the amount, the status, the time and your key identifier.
Keys, sign-in and payments.
- If you request a free key we store your email address (lower-cased), a verification token with an expiry (deleted once you use the link), and the key we issue to you.
- Sign-in is by an emailed link; there are no passwords. We keep your email, your plan, your credit balance and the ledger of credits granted and spent.
- Card payments are handled by Polar as merchant of record. We receive your email address, the order and the amount. We never see or store card numbers.
Forms and email.
- The feedback form stores the note you type and your browser’s user agent. The waitlist forms store your email address, the page you used and an optional note. Neither is sent to anyone else.
- Email you send to hello@hatchloop.dev is received by our email-forwarding provider and delivered to a Gmail mailbox read by our team.
3. Lookup tools: where the text you send goes
screen_sanctionsand the party screening insidemap_trade_restrictioncompare the name with copies of the OFAC, EU and UK sanctions lists that we download from their publishers and hold on our server. The name is not sent to the publishers or to anyone else.verify_company_recordsends the company name (and country, if given) to the GLEIF LEI registry. For US public companies it downloads the SEC’s public company file and matches the name on our server.lookup_us_contractssends the company name to the USAspending.gov public API.find_businesssends the place text you give it (up to 200 characters), the search area and the business category to the public OpenStreetMap services (Nominatim for geocoding and the Overpass API for businesses), together with our server’s IP address. Treat that field as public and do not put a private person’s home address in it. Results are cached on our server for up to 7 days.import_booking_urlfetches the booking page address you give it, from our server.- The Retail Broker at hatchloop.dev/retail forwards a visitor’s product search to the public catalogue endpoints of the stores it searches.
The service does not send tool inputs, messages or personal data to any AI model provider. HatchLoop is operated with the help of AI assistants, and the people and assistants who operate it can read the records described in this policy.
4. How we use it
To provide and bill the service, run the compliance gate (including opt-outs), prevent abuse and keep the service reliable. We do not sell personal data and we do not use message content for advertising. The legal bases we rely on, where GDPR or UK GDPR applies, are contract (delivering the service you asked for), legitimate interests (abuse prevention, security logging, reliability) and legal obligation (tax records and regulatory disclosures).
5. Messaging
Messaging tools work on the channels enabled on the current deployment, which are WhatsApp and email. SMS and voice calling are not enabled, and nothing is sent to an SMS or voice provider. When your agent sends a message we process its content and the recipient’s identifier to deliver it and to run the compliance gate (TCPA, GDPR, CASL and PDPL checks, consent and opt-out enforcement). Replying STOP on a channel, including WhatsApp, records an opt-out that blocks further messages to you on that channel.
What these tools store:
- The compliance audit log keeps a SHA-256 hash of each recipient identifier, with the channel, the decision and the reason, and no plaintext identifier.
- Other records hold identifiers in readable form: opt-outs (the recipient and the channel), leads your agent captures (name, phone, email, notes), conversation records (the numbers involved and the message text) and replies received on WhatsApp (sender number, profile name and text), which are kept so the requesting agent can read them.
- Receipts of operations that change state, which can include the free text your agent supplied (for example a note passed to a human escalation).
6. Who else receives data
Providers we use to run the service.
- Hostinger (Hostinger International Limited) rents us the virtual server that runs the website, the API, the database and its backups.
- Vercel hosts the DNS records (the name servers) for hatchloop.dev. It does not serve the site or carry its traffic.
- Resend sends our email: sign-in links, key verification, billing notices, and email sent through the messaging tools. It receives the recipient address and the message.
- Polar is the merchant of record for card payments, and receives your email and order details.
- Forward Email and Google (Gmail) receive and hold the email you send to our contact address.
- Telegram receives internal purchase alerts for our team, in which the customer’s email address is masked. The Telegram Mini App page at hatchloop.dev/app loads a script from telegram.org.
Providers involved only in particular cases.
- Meta (WhatsApp Business Platform) carries WhatsApp messages and receives the recipient’s number and the text. Meta’s own terms and privacy policy also apply to that channel.
- Cal.com receives the attendee’s name, email address and notes when a booking is made.
- Render runs only a redirect from our former address (smb-broker.onrender.com) to api.hatchloop.dev. A client that still uses the old address sends its first request there, so Render sees that request.
Public sources that receive the text you ask us to look up are listed in section 3: GLEIF, OpenStreetMap services, USAspending.gov and the stores searched by the Retail Broker.
Integrations that exist but are switched off and receive nothing: SMS (Twilio), voice calls (Vapi) and on-chain payments (Coinbase).
7. Where data is processed
The server is in Kuala Lumpur, Malaysia. We operate from Oman, and the database backups are also copied to a company computer. The providers in section 6 process data in their own locations, which include the United States and Europe.
8. How long we keep it
- Web server access logs are kept in rotating files limited by size (20 MB a file, 10 files per site), which at current traffic is a matter of days. The server’s system journal keeps at most 7 days.
- Database backups are written every 12 hours and kept for 30 days, on the server and on that company computer.
- We do not yet delete the other records described above on a fixed schedule. Usage, billing and compliance audit records are kept so that we can bill, prevent abuse and show what the compliance gate decided; account records are kept while the account exists; opt-outs are kept indefinitely because that is what makes them enforceable.
- To have your records deleted, email hello@hatchloop.dev; we respond within 30 days. Billing and tax records can only be deleted where the law allows it.
9. Your rights
You may ask for access to, correction, deletion, restriction or portability of your data. Residents of the EU and UK may also complain to their supervisory authority. We do not sell personal information, including for California residents. Email hello@hatchloop.dev; we respond within 30 days.
10. Children
The service is for adults (see the Terms of Service) and is not directed at children. We do not knowingly collect data from them.
11. Changes
We will update this page when our practices change and adjust the date above. Material changes will be noted on this page.