Privacy Policy.
Last updated: July 17, 2026
1. Who we are
EverCore (available at evercore.app) is a product of MECHANICX LLC, a limited liability company registered in the State of Wyoming, United States. In this policy, "we", "us", and "our" refer to MECHANICX LLC, and "EverCore" refers to the service we operate.
EverCore helps merchants ("you", when you hold an EverCore account) manage cash-on-delivery orders: it receives orders from connected stores, converses with the merchant's customers over the messaging channels the merchant connects, confirms orders, and hands confirmed orders to delivery carriers.
For any privacy question or request, contact us at support@evercore.dev.
2. What data we collect
Merchant account data
When you create an EverCore account we collect your name, email address, store name, and password (stored hashed). If you subscribe to a paid plan, billing details are collected and processed by our payment provider, Stripe. We do not store full card numbers on our servers.
Customer conversation data
EverCore processes messages exchanged between a merchant and their customers on the merchant's behalf. This includes message content, sender identifiers (such as a phone number or platform account handle), and timestamps. We process this data solely to provide the service to the merchant: answering customer questions, confirming orders, and following up on pending orders.
Order data
Orders flowing into EverCore from a connected store or spreadsheet contain customer name, phone number, delivery address, ordered products, price, and order status.
Integration credentials
When you connect a third-party service (such as a store platform, a spreadsheet, a delivery carrier, or a messaging account), we store the access tokens or API keys needed to operate that connection. These credentials are used only to provide the integration you enabled and are removed when you disconnect the integration.
3. Meta Platform Data (Instagram)
This section describes how EverCore handles data received from Meta Platforms when a merchant connects an Instagram professional account.
What we access. When a merchant connects an Instagram professional account, EverCore accesses, through the Instagram API: (a) profile information of the connected account and of customers who message it (such as username, name, and profile picture), and (b) direct messages sent to the merchant's connected account, including message content and attachments.
Why we access it. We access this data for one purpose: to receive customer messages sent to the merchant's account and to send replies on the merchant's behalf, for order confirmation and customer support. We do not use Meta Platform Data for advertising, profiling, model training, or any purpose outside providing the service described in this policy.
How long we keep it. Meta Platform Data is retained for the duration of the merchant's EverCore account. When a merchant disconnects their Instagram account or deletes their EverCore account, the associated Meta Platform Data is deleted from our systems within 30 days.
We never sell it. We do not sell, rent, or license Meta Platform Data to anyone, and we do not share it with third parties except with the sub-processors listed below, strictly to the extent needed to operate the service.
4. How we use data
- To operate the service: receiving orders, messaging customers on the merchant's behalf, confirming orders, and dispatching to carriers.
- To generate AI-assisted replies. Conversation text may be processed by our AI sub-processor (OpenAI) to produce a reply. It is not used to train models.
- To send merchants transactional emails about their account, billing, and service activity.
- To secure the service, prevent abuse, and comply with legal obligations.
We do not sell personal data, and we do not use it for third-party advertising.
5. Deleting your data
Merchants. You can disconnect Instagram or any other integration at any time from the Settings area of your EverCore dashboard. Disconnecting an integration triggers deletion of the data received through it. To request full deletion of your account and all associated data, email support@evercore.dev from the address on your account, or use the account deletion option in Settings. Deletion is completed within 30 days of the request.
End users (customers of merchants). If you have messaged a business that uses EverCore and want your data deleted, you can either contact that business directly and ask them to delete your conversation, or email us at support@evercore.dev with the business name and the phone number or account you used to contact them. We will complete the deletion within 30 days and confirm once it is done.
6. Sub-processors
We rely on a small set of infrastructure providers to run EverCore:
- Railway (hosting and databases): all application data is stored on infrastructure operated by Railway.
- Stripe (payments): processes merchant subscription payments and stores billing details.
- Resend (email): delivers transactional emails to merchants.
- OpenAI (AI processing): processes conversation text to generate suggested and automated replies.
Each sub-processor receives only the data needed for its function and is bound by its own data processing terms.
7. Security
All data is encrypted in transit using TLS. Integration credentials and passwords are stored using industry-standard protections (encrypted or hashed at rest). Access to production systems is restricted to authorized personnel and protected by access controls. No method of storage or transmission is completely secure, but we work to protect your data using measures appropriate to the risk.
8. Changes to this policy
We may update this policy as the service evolves. When we make material changes, we will update the "Last updated" date above and notify merchants by email or through the dashboard. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
9. Contact
MECHANICX LLC
Wyoming, United States
support@evercore.dev