Skip to main content

Privacy Policy

Effective date: April 30, 2026

Last updated: April 30, 2026

This Privacy Policy describes how GoaTech AI LLC, a California limited liability company (CA entity number B20260198511) with a principal office at 2108 N Street #4923, Sacramento, CA 95816 (“Sheepit,” “we,” “us,” or “our”) collects, uses, and protects your personal information when you use the platform at goatech.ai, our courses, our SDKs, and any associated services (collectively, the “Services”).

1. Information We Collect

When you create an account we collect your name, email address, country, preferred language, and a hashed password. When you purchase a course or subscription we process payment through our payment provider (Paddle and/or Stripe); we never store full card numbers on our servers.

We automatically collect usage data such as page views, feature-flag evaluations, click and scroll signals, error reports, and event analytics to improve the platform. This data is associated with your account and is accessible from your dashboard.

Categories of Personal Information We Collect (CCPA / CPRA)

We do not collect sensitive personal information (Social Security numbers, government IDs, precise geolocation, biometrics, health data) from end users in the ordinary course of providing the Services.

2. How We Use Your Information

Legal Basis for Processing (EU / UK / EEA)

3. Data Sharing

We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We share information only with the following categories of recipients:

Each of the above acts under a written data-processing agreement (or as an independent controller, in the case of Paddle) and is bound to use the data only for the purposes for which it was disclosed.

4. Data Retention

We retain personal information only as long as needed for the purposes described in this policy or as required by law. Indicative retention windows:

You may request deletion of your account and associated data at any time from your account settings or by emailing us at the address below.

5. International Data Transfers

Sheepit is established in the United States, and our infrastructure providers process data in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to the United States. We rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK's International Data Transfer Addendum (IDTA), together with supplementary technical and organizational measures, as the lawful mechanism for such transfers.

6. Your Privacy Rights

California Residents (CCPA / CPRA)

You have the right to:

To exercise any of these rights, email security@goatech.ai from the email address on your account, or use the in-app account-deletion / data-export tools. We will respond within 45 days.

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

You have the right to:

We currently operate below the small-scale-processing threshold under GDPR Article 27(2) and have not appointed an EU representative. We will appoint one if our processing materially increases.

Do Not Track

Some browsers transmit a Do-Not-Track (DNT) signal. Because there is no industry-wide standard for how to interpret DNT, we do not currently respond to DNT signals. Our analytics are first-party and we do not share data with third-party advertising networks.

7. Children's Privacy

The Services are not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If we learn that we have collected personal information from a child under 16, we will delete that information promptly. If you believe a child has provided us with personal information, contact security@goatech.ai.

8. Cookies and Similar Technologies

See our Cookie Policy for the specific cookies and storage keys we set and how to manage them.

9. Security

We protect your data with encryption in transit (TLS), hashed passwords (bcrypt), hashed API keys (SHA-256), and HttpOnly session cookies. We conduct regular security reviews of our codebase and dependencies. No method of electronic storage is 100% secure; we cannot guarantee absolute security.

10. Changes

We may update this policy from time to time. Material changes will be communicated via email or an in-app banner at least 30 days before they take effect. Continued use of the Services after the effective date constitutes acceptance.

11. Contact

Questions about this policy or to exercise any of the rights described above? Email security@goatech.ai or write to us at:

GoaTech AI LLC
2108 N Street #4923
Sacramento, CA 95816
United States