Legal

Privacy policy

How Root collects, uses, and protects your data, written to be read.

Last updated June 2026

Root is operated by Mekanism AI LLC. This policy explains what we collect, why we collect it, and the choices you have. It applies to our website, our demo requests, and the Root product. If anything here is unclear, email us and we will answer.

What we collect

We collect the information needed to run the service and to talk to you. That includes:

  • Account information. Your name, email, business name, and the credentials used to sign in.
  • Demo form submissions. When you ask for a demo, we collect what you give us: name, email, business type, number of locations, and your message.
  • Usage and analytics. Basic data about how the product and site are used, such as pages viewed, features used, device and browser type, and approximate location from your IP address.
  • Operator transaction data. For customers who run their business on Root, we process the data your business runs through the system: orders, payments, customers, inventory, staff, and the records that make the books work.

How we use it

We use the information we collect to:

  • Provide, operate, and support the service.
  • Respond to demo requests and answer your questions.
  • Improve the product, fix problems, and understand what is and is not working.
  • Keep accounts and data secure, and detect and prevent abuse.

We use the information for the purposes above, and we do not repurpose it for things you would not expect.

Payments and cards

Card data is tokenized at the point of capture. Card numbers do not pass through or rest on Root's servers, and Root never stores them. This keeps our PCI scope minimized and keeps the sensitive part of a payment with the certified processor, not with us.

AI and your data

Your data is never used to train models. Root uses AI to help you run your business, but your business's data, your customers, and your transactions are not used to train any model, ours or a third party's.

Sharing

We do not sell personal data. We share data only with the subprocessors needed to run the service: payment processing, email and SMS delivery, and hosting. Each one operates under a contract that limits how they may use the data and requires them to protect it. We also share data when the law requires it.

Security

Data is encrypted in transit and at rest. Access to production systems is limited and logged. A SOC 2 audit is in progress. No system is perfect, and we will not claim otherwise, but security is treated as part of the product, not an afterthought.

Your rights

You can ask us to access the personal data we hold about you, export it, or delete it. Operator customers can export their business data at any time. To make a request, email us and we will verify the request and act on it.

Cookies and analytics

We use a small set of cookies and similar technologies to keep you signed in, remember preferences, and measure how the site and product are used. You can control cookies through your browser settings. Blocking some of them may affect how the site works.

Contact

Questions about this policy, or a request about your data? Email us and a person will respond.