Privacy Policy
1. Scope
This Privacy Policy explains how Dahlia Labs Inc. ("Dahlia," "Daydream," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use Daydream websites, mobile applications, and other services, including the AI-powered search and conversational shopping experiences that we provide on participating merchants’ websites under the “Powered by Daydream” name (collectively, the “Services”).
When you use Powered by Daydream on a merchant’s website, both this Privacy Policy and the merchant’s privacy policy may apply. The merchant determines how it handles information it collects through its website, account, checkout, and payment processes. Dahlia does not control the merchant’s privacy practices.
This policy applies to U.S. users. The Services are not currently intended for use outside the United States.
2. Personal Information We Collect
“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked - directly or indirectly - with a person, household, or device. Information does not need to include a name to be personal information. Cookies, device identifiers, IP addresses, and other persistent or unique identifiers may be personal information. Hashed email addresses, hashed telephone numbers, and other pseudonymous identifiers remain personal information when they can be matched to an account or device.
| Category | Examples | Sources |
|---|---|---|
| Identifiers and contact information | Name, email address, telephone number, postal address, username, account identifiers, IP address, device identifiers, cookie or local-storage identifiers, and hashed versions of contact identifiers. | You; your device or browser; merchants; service providers. |
| Account and profile information | Login credentials (stored in protected form), preferences, saved products, shopping interests, and profile content. | You; your use of the Services. |
| Shopping and commercial information | Products viewed, searched, saved, clicked, or purchased; shopping preferences; transaction and fulfillment information; order value, currency, and item details. | Your interactions; participating merchants; service providers. |
| Powered by Daydream interactions | Search queries, prompts, chat messages, responses, feedback, session activity, product recommendations, and links or products selected. Please do not submit sensitive personal information in a chat or prompt. | You; the merchant site; our Services. |
| Conversion-attribution information | A short-lived attribution token; a hashed order identifier; order value; currency; and purchased items. Dahlia does not receive through this conversion flow the shopper’s name, email, postal address, telephone number, payment details, or merchant customer ID. | Participating merchants’ order-confirmation pages and the Daydream SDK. |
| Internet, device, and usage information | Browser and device type, operating system, pages and features used, referring and destination pages, timestamps, clicks, session duration, approximate location inferred from IP address, crash and diagnostic data, and cookies or similar technologies. | Your browser or device; cookies, SDKs, pixels, local storage, logs, and analytics tools. |
| Communications and support information | Messages, support requests, survey responses, and other communications with us. | You. |
| Inferences | Likely shopping preferences, interests, style, product affinities, and recommendations derived from activity and interactions. | Generated from information described above. |
| Advertising matching and measurement data | Hashed email address or telephone number; advertising, campaign, click, conversion, and purchase identifiers; order value; and related conversion information. | You; your use of the Services; our records; participating merchants where contractually permitted. |
We may also create aggregated or deidentified information. We treat information as deidentified only when it is not reasonably linkable to a person, household, or device and we maintain measures designed to prevent reidentification.
3. How We Collect Personal Information
- Directly from you, including when you create an account, provide an email address or telephone number, enter a query or chat message, save a product, contact us, or otherwise use the Services.
- Automatically from your browser or device through cookies, pixels, SDKs, local storage, logs, and similar technologies.
- From participating merchants, including product-catalog data and, where a merchant enables conversion measurement, the limited transaction fields described above.
- From service providers and integration partners that help us operate, secure, analyze, and improve the Services.
4. Powered by Daydream and AI
Powered by Daydream is an AI-powered shopping experience embedded on participating merchants’ websites. It uses your queries, chat messages, browsing and product interactions, and related session information to generate search results, recommendations, and conversational responses. AI-generated results may be inaccurate or incomplete and should not be treated as professional advice.
We may use Powered by Daydream interactions and associated feedback to evaluate, maintain, develop, and improve our search, recommendation, and machine-learning systems. This may include automated analysis and limited review by authorized personnel or service providers for quality, safety, troubleshooting, and model improvement. Please do not include sensitive personal information, confidential information, or payment information in prompts or chats.
5. Cookies Local Storage Pixels and Similar Technologies
We and our service providers use cookies, local storage, pixels, SDKs, and similar technologies to operate the Services; keep sessions functioning; remember preferences; understand use; prevent fraud; measure performance; personalize content; measure whether a Powered by Daydream interaction resulted in a purchase; and measure or improve advertising. We may also create hashed versions of contact identifiers for permitted advertising measurement and matching.
Some identifiers may remain in your browser for up to 30 days unless you delete them sooner or your browser removes them. The conversion-attribution token currently used to connect a click-out with a later purchase is designed to expire after approximately 24 to 48 hours. Nothing in that conversion flow is stored on the merchant’s domain by Dahlia, although the merchant may use its own technologies under its privacy policy.
You can adjust browser settings to block or delete cookies and local storage. Doing so may affect features of the Services. We honor Global Privacy Control signals as described below.
6. How We Use Personal Information
- Provide, operate, personalize, maintain, and troubleshoot the Services.
- Respond to searches and chats and generate product recommendations.
- Maintain accounts, saved preferences, and shopping features.
- Connect a Powered by Daydream session with a completed purchase and provide participating merchants with conversion and performance reporting.
- Measure and optimize advertising by matching hashed contact identifiers and associated conversion or purchase information with accounts maintained by advertising partners, subject to applicable choices and law.
- Analyze use, measure performance, and improve our products, algorithms, and machine-learning models.
- Communicate with you about the Services, support requests, transactions, updates, and - where permitted - marketing.
- Detect, investigate, and prevent fraud, misuse, security incidents, and technical problems.
- Comply with law, enforce agreements, protect rights and safety, and establish, exercise, or defend legal claims.
- Create aggregated or deidentified information for analytics, research, and business purposes.
7. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for the purposes described in this policy:
- Participating merchants. We disclose information needed to provide the embedded experience and reporting, including session, product-interaction, and conversion-attribution information. A merchant may be able to associate a transaction with a customer using information in its own systems.
- Service providers and contractors. These include hosting, cloud infrastructure, AI and machine-learning, analytics, communications, customer support, security, payment, and professional-service providers that process information for us under contractual restrictions.
- Analytics and advertising partners. Subject to applicable choices and law, we may disclose hashed versions of email addresses or telephone numbers, device and online identifiers, commercial information, and conversion or purchase information to advertising partners such as Meta and Google. These partners compare the hashed identifiers with identifiers associated with their users to measure conversions, attribute purchases to advertisements, optimize campaigns, and, where enabled, create or use advertising audiences. Hashing reduces direct readability but does not make the information anonymous.
- Business transaction recipients. Information may be disclosed in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business or assets.
- Authorities and other parties for legal or safety reasons. We may disclose information when reasonably necessary to comply with law or legal process; enforce our terms; protect rights, property, or safety; or detect and address fraud, security, or technical issues.
- Other recipients at your direction or with your consent.
We do not sell personal information for money. Some laws define “sale,” “sharing,” or “targeted advertising” broadly enough to include disclosures of hashed contact identifiers, device identifiers, commercial information, or online activity to advertising and analytics partners. We treat these activities as subject to the applicable opt-out rights described in Section 11 unless and until a documented service-provider or processor exception applies.
8. Data Retention
We retain each category of personal information only for as long as reasonably necessary and proportionate to the purposes described in this policy, unless a longer period is required or permitted by law. We determine retention periods based on the nature and sensitivity of the information; the purpose for which it was collected; the duration of the user or merchant relationship; operational, security, fraud-prevention, and support needs; legal, accounting, and reporting obligations; applicable limitation periods; and whether the information is subject to a legal hold or dispute.
| Data category | Current retention period or criterion |
|---|---|
| Browser and attribution identifiers | Browser identifiers may remain for up to 30 days; the current conversion-attribution token is designed to expire after approximately 24-48 hours. |
| Account and profile information | While the account is active and generally for up to two years after inactivity, unless deletion is requested or a longer period is required or permitted. |
| Order and transaction information | Generally seven years from the transaction when maintained for tax, accounting, fraud, support, or dispute purposes. |
| Powered by Daydream interactions | For the period reasonably necessary to provide the experience, maintain session continuity, evaluate quality and safety, improve the Services, and meet legal or security obligations. Dahlia applies deletion or deidentification according to its internal retention schedule. |
| Operational logs | Generally 90 days; security-related logs may be retained for up to one year. |
| Merchant product data | While the product is listed and generally for up to one year after delisting; performance caches generally expire within 24 hours. |
| Financial and corporate records | Generally seven to ten years, depending on the record and applicable requirements. |
| Legal holds and disputes | Until the hold is lifted or the dispute and applicable limitation periods have ended. |
| Advertising matching and measurement data | Only for as long as reasonably necessary for advertising measurement, campaign optimization, suppression, legal compliance, and documented partner processes. Daydream will not retain clear-text identifiers solely for an advertising upload beyond the period otherwise applicable to the underlying account or transaction record. |
Deletion from active systems may not immediately remove information from backups. Backup copies are isolated from ordinary use and are deleted or overwritten according to established backup cycles, unless preservation is legally required.
9. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for protecting account credentials and devices used to access the Services.
10. Your Choices
- Account information. You may review or update certain account information through your account settings.
- Marketing communications. You may unsubscribe from marketing emails using the link in the message. We may still send transactional or service communications.
- Cookies and similar technologies. You may use browser settings and any cookie-preference tool we provide. Blocking technologies may affect functionality. A cookie setting does not necessarily apply to advertising matching that uses account information. A Global Privacy Control signal will be handled as described below.
- AI chat. You may choose not to use Powered by Daydream. Avoid submitting personal or sensitive information in prompts.
- Privacy requests. You may exercise applicable state-law rights as described below.
- Targeted advertising and advertising matching. Daydream honors Global Privacy Control (GPC) signals nationwide as requests to opt out of future advertising disclosures associated with the browser or device sending the signal and, when technically feasible, the signed-in Daydream account that we can reasonably associate with the signal. Daydream does not currently provide a separate advertising opt-out control.
11. U S State Privacy Rights
Depending on where you live and subject to legal exceptions, you may have rights to request access to or confirmation of personal information we process; obtain a portable copy; correct inaccuracies; delete personal information; opt out of sale, sharing, or processing for targeted advertising; limit certain uses of sensitive personal information; and appeal a decision regarding a request. You also have the right not to receive unlawful discriminatory treatment for exercising privacy rights.
To submit an access, correction, deletion, or portability request, email legal@daydream.ing with the subject line “Privacy Request.” Tell us the right you wish to exercise and the state in which you reside. We will verify requests only to the degree appropriate for the information requested. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and verification of your identity. If we deny a request, you may appeal by replying to our decision and stating that you wish to appeal.
Opt-out preference signals. Daydream treats a GPC signal as a request to opt out of sale, sharing, or targeted advertising for the browser or device that sends the signal and, when technically feasible, the signed-in Daydream account that we can reasonably associate with it. The signal may not apply across browsers, devices, or profiles that Daydream cannot associate with the signal. Daydream does not currently provide a separate advertising opt-out control.
12. Merchant Sites and Third Party Services
The Services may link to or appear within websites and services operated by merchants or other third parties. Their privacy policies govern their collection and use of personal information. We encourage you to review both this policy and the applicable merchant’s policy before using Powered by Daydream or completing a purchase.
13. Children
The Services are intended only for individuals who are at least 18 years old and are not directed to children. We do not knowingly collect personal information from children under 13, and we do not knowingly sell, share, or use for targeted advertising personal information when we have actual knowledge that the individual is under the age for which applicable law restricts those activities. If you believe a minor has provided personal information to us, contact legal@daydream.ing so that we can take appropriate action.
14. Changes to This Policy
We may update this policy from time to time. We will post the updated policy, revise the effective date, and describe material changes through a prominent notice on the Services and, when appropriate, an email or in-product notice. We may apply an updated policy to information collected before the effective date after providing appropriate notice and honoring applicable legal rights and GPC signals. Where applicable law requires consent for a materially different use, we will obtain that consent.
15. Contact Us
Questions or privacy requests may be sent to:
Dahlia Labs Inc.
80 Pine St.
New York, NY 10005
Email: legal@daydream.ing
Advertising opt-out: Enable Global Privacy Control in a supporting browser or extension.