Privacy Policy

Last updated: September 15, 2026

This policy explains how Shapely Labs collects, uses, shares and protects personal data on our website and through the Shapely platform, including the Shapely Agent application for Salesforce.

1. Who We Are and Scope

Shapely Labs builds an AI orchestration layer for pharmaceutical patient support programs. Shapely Agent assists case managers during live patient calls by guiding program workflows, surfacing information and updating connected systems such as Salesforce.

We act in two different roles, and this policy is organized accordingly:

As a controller

For data about visitors to shapelylabs.com, prospective customers, business contacts and job applicants. We decide how and why that data is processed.

As a processor and business associate

For data that our customers submit to the Shapely platform (“Customer Data”), including patient information. Our customers decide how and why that data is processed; we process it only on their instructions.

2. Data We Collect on the Website

Demo requests

When you book a demo or leave your details, we collect your first and last name, work email address, company, role and any notes you include. Demos scheduled through our booking link are handled by Cal.com under its own privacy policy.

Waitlist and newsletter sign-ups

When you join a waitlist or sign up for updates, we collect your email address and the page you signed up from.

Job applications

When you apply for a role, we collect the information you provide, such as your name, contact details, résumé and application answers.

Usage data and cookies

We use Google Tag Manager, Google Analytics and Vercel Analytics to understand how the site is used. These tools collect information such as pages viewed, referring site, approximate location, device and browser type, and may set cookies or similar identifiers. We also log IP addresses briefly to protect our forms against abuse.

Business communications

When you correspond with us by email or through other channels, we keep the contents of that correspondence and your contact details.

3. How We Use Website Data

We use the data described above to:

Respond and follow up

Schedule and deliver demos, answer your questions and follow up about our products and services, which may include marketing communications to business contacts. You can opt out of marketing at any time by replying to a message or contacting us.

Recruit

Evaluate job applications and communicate with candidates.

Operate and improve the site

Measure traffic, understand which content is useful, protect the site from abuse and fix problems.

Comply with the law

Meet legal obligations and enforce our terms.

Where the GDPR or similar laws apply, we rely on your consent (for analytics cookies and marketing where required), our legitimate interests in running and promoting our business, and the performance of a contract or pre-contractual steps you request.

4. Customer Data Processed Through the Shapely Platform

When a customer deploys Shapely Agent, the platform may process, on that customer’s behalf, call audio and transcripts, CRM and case records (including Salesforce data), documents and program configuration, and information about the operators who use the tool. This can include protected health information (“PHI”) about patients enrolled in a customer’s support program.

We process Customer Data solely to provide, secure, support and improve the Service for that customer, as set out in the customer’s subscription agreement and, where PHI is involved, a Business Associate Agreement under HIPAA. We do not use Customer Data for advertising, do not sell it, and do not use patient data to train models for other customers.

Patients and operators whose data is handled by the platform should direct questions or requests to the pharmaceutical company or hub that operates the program. We will support our customers in responding to such requests.

5. Shapely Agent for Salesforce

Shapely Agent installed from the Salesforce AppExchange runs within the customer’s Salesforce org and accesses only the objects and fields the customer’s administrator has configured it to use. Data stays subject to the customer’s Salesforce security settings, and Salesforce’s handling of that data is governed by Salesforce’s own agreements and privacy policy. Shapely Labs does not receive Salesforce credentials; access is granted through the customer-authorized connection.

6. How We Share Data

We do not sell personal data. We share it only in the following cases:

Service providers

Vendors that host and support our operations, currently including Vercel (website hosting), Google (Workspace, Sheets, Analytics and Tag Manager), Amazon Web Services (email delivery and cloud infrastructure), Cal.com (demo scheduling) and Salesforce (when a customer uses the Salesforce integration). They may access data only to perform services for us and are bound by contractual confidentiality and security obligations.

Our customers

Customer Data is shared with, and controlled by, the customer that submitted it.

Legal requirements

Where required by law, regulation, legal process or to protect the rights, safety or property of Shapely Labs, our customers, patients or others.

Business transfers

In connection with a merger, acquisition or sale of assets, subject to the commitments in this policy.

7. SMS communications

If you agree to receive text messages from Shapely Labs, we collect your mobile number and your consent to be contacted by SMS. We use this only to send the follow-up messages you agreed to, such as confirming next steps after a call or sharing information you requested. Mobile information and SMS consent are not shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. You can opt out at any time by replying STOP to any message.

8. International Transfers

Shapely Labs operates in the United States and the European Union, and our service providers may process data in either region. Where data is transferred out of the EU, UK or Switzerland, we rely on appropriate safeguards such as standard contractual clauses. Customer Data hosting locations are set out in the applicable customer agreement.

9. Data Security

We maintain administrative, technical and physical safeguards designed to protect personal data and Customer Data, aligned with HIPAA requirements. These include encryption of data in transit, role-based access controls, audit logging of platform activity, and staff confidentiality obligations. No system is completely secure; if we become aware of a breach affecting your data we will notify you and any relevant authorities as required by law and by our customer agreements.

10. Data Retention

We keep website and business-contact data for as long as needed for the purposes above, generally for the duration of our relationship with you and a reasonable period afterwards, unless a longer period is required by law. Job applicant data is retained for the recruitment process and, with your consent, for future opportunities. Customer Data is retained for the term of the customer agreement and returned or deleted afterwards in line with that agreement.

11. Your Rights

Depending on where you live, you may have the following rights regarding personal data we hold as a controller. To exercise them, contact us using the details below. We may need to verify your identity before responding.

Access

You may request access to the personal data we hold about you and receive a copy.

Correction

You may ask us to correct any inaccurate or incomplete personal data.

Deletion

You may request deletion of your personal data, subject to applicable legal requirements.

Objection and restriction

You may object to processing based on legitimate interests, ask us to limit how we process your data, or withdraw consent where processing is based on consent.

Portability

You may ask to receive data you provided to us in a structured, machine-readable format.

Complaints

You may lodge a complaint with your local data protection authority. We would appreciate the chance to address your concerns first.

If your data is processed through the Shapely platform on behalf of one of our customers, please contact that customer directly; we will assist them in handling your request.

12. Children

Our website and services are intended for business users and are not directed to children. We do not knowingly collect personal data from children through our website. Any patient data relating to minors is processed only on behalf of our customers under the safeguards described in Section 4.

13. Policy Updates

We may revise this Privacy Policy periodically. Changes will be published on this page with a revised “last updated” date, and material changes affecting customers will be communicated as required by their agreements.

14. Contact

Questions about this policy or your data rights? Reach out at privacy@shapelylabs.com