EN
EN

Privacy Policy

Last updated: September 7, 2026

Overview

Vertical Bar Inc. provides the Vertical Bar website, CrossCheck, and Vertical Bar Agent, including the ChatGPT app and other MCP clients. This notice explains the personal and business information we receive, use, store, and return through these services, including information within nested tool results, metadata, and diagnostics. For customer-controlled business data, we act on the customer’s instructions under the applicable service agreement and Data Processing Agreement.

Vertical Bar Inc. provides the Vertical Bar website, CrossCheck, and Vertical Bar Agent, including the ChatGPT app and other MCP clients. This notice explains the personal and business information we receive, use, store, and return through these services, including information within nested tool results, metadata, and diagnostics. For customer-controlled business data, we act on the customer’s instructions under the applicable service agreement and Data Processing Agreement.

Vertical Bar Agent and the ChatGPT app

When you connect Vertical Bar Agent to ChatGPT or another MCP client, the app receives the inputs that client supplies to our tools and uses your authorized CrossCheck and Vertical Bar access to carry out the request. These inputs can include workspace and environment selections, dates, filters, record references, queries, test definitions, release-package content, and briefing content. We receive conversation content when the client includes it in a tool input, such as the prompt used to create a briefing.

Account and access information: authentication tokens and session records, user and OAuth subject identifiers, OAuth client identifiers, granted scopes, email address or display name, account status, roles, and permissions. These support sign-in, access control, and identifying the connected account. Account-identification responses may include your email address and granted scopes. Tokens are used for authentication, not as business-analysis output.

Organization and workspace information: organization, workspace, project, environment, and NetSuite account names and identifiers; workspace membership and access; configuration and status; and links to authorized records. These identify which customer data a request may access and where results belong.

Business records and people represented in them: query rows, transaction identifiers, dates, amounts, invoice or payment status, accounting classifications, customer and vendor records, contact names, email addresses, phone numbers and business addresses, employee identifiers, names, email addresses, departments, roles, and activity actors. The fields returned depend on the selected tools, authorized source data, and query. Authorized business data may also contain employment or compensation fields, credit limits, or business tax identifiers.

Analysis and technical records: process cases and events, actor and timestamp information, transaction relationships, paths, variants, exceptions, performance measures, snapshot and customization metadata, script or configuration source, dependencies, execution telemetry, test definitions and revisions, test results, release-package items, Git repository or revision references, workflow stages, deployment evidence, and creator or approver information. These may contain the same personal or business information as the underlying records.

Prompts, artifacts, and activity history: briefing titles, HTML and report contents, the basis prompt supplied by the client, model and host identifiers, and provenance describing how an artifact was produced. Tool activity includes tool names, timestamps, status, sequence, correlation identifiers, and digests of inputs. Publishing a briefing stores its content and provenance in the selected workspace, where authorized users can view it; publishing a new version can replace the topic’s latest-version reference.

Nested metadata and diagnostics: information in nested objects and arrays is included in these categories, even when it is not displayed in the chat answer. Examples include job and run identifiers, idempotency keys, workspace and record references, provenance, summaries, counts, limits, timing, status and error codes, diagnostic messages, and upstream API error details. Error details may repeat submitted values or source-record information. Routine results are not a guarantee that every field has been de-identified.

Operational and security records: our service may record the acting user or API-key identifier, organization and workspace, requested action and resource, timestamps, outcome, query text or other action metadata, request IP address, and user-agent information. App audit records are separate from the website analytics system described below. A query can leave an audit record or a short-lived result cache even when it does not change ERP records; asynchronous analysis creates job records.

How app information is used and shared

We use app information to authenticate users, enforce workspace and environment access, retrieve and analyze authorized data, run requested jobs and governed workflows, create and display artifacts, support the service, diagnose failures, and maintain security and auditability. The app is intended for business workflows. Do not put passwords, authentication secrets, full payment-card details, health records, or other unrelated sensitive information into queries or briefing content.

Tool responses, including their nested contents and error details, are returned to the AI platform you use: OpenAI for ChatGPT, or the provider of another connected MCP client. That platform can use these results to produce your answer and may retain them in conversation history under its own terms, privacy policy, and account settings. A request for a summary can still return structured source data to the platform. Disconnecting the app does not erase data already present in that platform’s conversations.

Vertical Bar and CrossCheck services process the request using our hosted infrastructure, including Amazon Web Services for compute, storage, identity, and operational logging. Authorized NetSuite queries and governed test or deployment actions communicate with the customer’s connected NetSuite environment. Optional integrations and AI features may involve OpenAI, Anthropic, GitHub, or support providers as described in our Data Processing Agreement. Customer administrators and other authorized workspace users may access shared artifacts and associated activity according to their permissions. Service providers may process information in the United States.

We do not sell customer personal data provided under the Data Processing Agreement. The website analytics and newsletter services described below have their own purposes; they are separate from the app’s business-data workflows.

App retention and deletion

Connected business data, snapshots, jobs, tests, workflow histories, and published artifacts are retained to provide the customer’s ongoing service and instructed workflows. A completed tool call does not automatically delete these records. Published briefings, their supplied prompts and provenance, and persistent audit histories do not have an automatic expiry for each call. Applicable customer deletion instructions and service-agreement requirements govern their removal, subject to legally required retention.

Short-lived caches and infrastructure records have separate lifetimes. Live-query result caching defaults to 30 seconds and can vary with service configuration. Our standard production infrastructure configuration retains application and MCP runtime logs for three months, selected authentication-helper logs for one month, and rolling database backups for 7 to 14 days, depending on the database. These periods do not apply to persistent business or audit records stored in the service database, and retained recovery copies are separate from live records.

To request access, correction, export, or deletion of personal information held by Vertical Bar, contact hello@vertical.bar. Identify the account and workspace involved without sending passwords or tokens. For information held on an organization’s behalf, we coordinate with its authorized administrator. Customer deletion and return requests are handled under the applicable service agreement, Data Processing Agreement, and law; we may need to verify identity and authority before acting.

You can disconnect the app in your AI platform and revoke the relevant authorization to stop future app access. Disconnecting does not itself delete CrossCheck or Vertical Bar business records, published artifacts, audit history, source NetSuite records, or copies held by the AI platform. Use the relevant service’s deletion controls or contact the provider for those copies.

Website analytics and business-network signals

When you visit, our first-party Cloudflare Worker may receive a query-free page path, referring domain, campaign parameters, engagement duration, scroll depth, coarse country or region, and network information such as autonomous system number and organization. The browser creates an opaque identifier in sessionStorage for the current tab. At the edge, that identifier and the request IP are transformed with a daily rotating HMAC; we do not store the raw IP address or user-agent string in this system.

When you visit, our first-party Cloudflare Worker may receive a query-free page path, referring domain, campaign parameters, engagement duration, scroll depth, coarse country or region, and network information such as autonomous system number and organization. The browser creates an opaque identifier in sessionStorage for the current tab. At the edge, that identifier and the request IP are transformed with a daily rotating HMAC; we do not store the raw IP address or user-agent string in this system.

We may use network organization data to make a probable company-level attribution. This does not identify a person. Consumer internet providers, VPNs, hosting networks, bots, missing data, and ambiguous matches remain unassigned. Edge events and export records are retained for up to 30 days; bounded session summaries are retained for up to 90 days.

We may use network organization data to make a probable company-level attribution. This does not identify a person. Consumer internet providers, VPNs, hosting networks, bots, missing data, and ambiguous matches remain unassigned. Edge events and export records are retained for up to 30 days; bounded session summaries are retained for up to 90 days.

Existing analytics and visitor tools

Some pages also use PostHog and lemlist to measure website use and possible business interest. Depending on their configuration, these services may process online identifiers, device or browser information, network information, and interaction data. Learn more in the PostHog Privacy Policy and the lemlist Privacy Policy.

Some pages also use PostHog and lemlist to measure website use and possible business interest. Depending on their configuration, these services may process online identifiers, device or browser information, network information, and interaction data. Learn more in the PostHog Privacy Policy and the lemlist Privacy Policy.

Snitcher provides company-level website visitor attribution using page-view and network context. Our configuration does not use Snitcher Contact Reveals, submitted form values, or its results to identify or create person profiles. Persistent browser recognition is disabled until cookie consent is provided. Learn more in the Snitcher Privacy Policy.

Snitcher provides company-level website visitor attribution using page-view and network context. Our configuration does not use Snitcher Contact Reveals, submitted form values, or its results to identify or create person profiles. Persistent browser recognition is disabled until cookie consent is provided. Learn more in the Snitcher Privacy Policy.

Newsletter

If you choose to subscribe, we process your email address, consent source and version, relevant campaign parameters, and subscription lifecycle events. EmailOctopus provides newsletter delivery and double opt-in. You must confirm your address before becoming subscribed, and every newsletter includes an unsubscribe option. We keep suppression records so an unsubscribe, complaint, or bounce is not accidentally bypassed. Learn more in the EmailOctopus Privacy Policy.

If you choose to subscribe, we process your email address, consent source and version, relevant campaign parameters, and subscription lifecycle events. EmailOctopus provides newsletter delivery and double opt-in. You must confirm your address before becoming subscribed, and every newsletter includes an unsubscribe option. We keep suppression records so an unsubscribe, complaint, or bounce is not accidentally bypassed. Learn more in the EmailOctopus Privacy Policy.

Form protection

Cloudflare Turnstile helps distinguish people from automated traffic. It processes browser and client-side signals needed for this security function and does not receive the newsletter form entries from our page. Learn more in Cloudflare’s privacy documentation.

Cloudflare Turnstile helps distinguish people from automated traffic. It processes browser and client-side signals needed for this security function and does not receive the newsletter form entries from our page. Learn more in Cloudflare’s privacy documentation.

How we use information

  • Operate and secure the website and forms.

  • Understand aggregate website use and probable company interest.

  • Respond to requests and maintain consent or suppression records.

  • Send newsletters only after double opt-in.

  • Operate and secure the website and forms.

  • Understand aggregate website use and probable company interest.

  • Respond to requests and maintain consent or suppression records.

  • Send newsletters only after double opt-in.

Your choices

Newsletter participation is optional, and you may unsubscribe at any time. Browser settings can clear sessionStorage and control cookies or similar technologies used by other analytics providers. Subject to applicable law, you may request access, correction, or deletion of personal information by emailing hello@vertical.bar.

Newsletter participation is optional, and you may unsubscribe at any time. Browser settings can clear sessionStorage and control cookies or similar technologies used by other analytics providers. Subject to applicable law, you may request access, correction, or deletion of personal information by emailing hello@vertical.bar.

Contact

Vertical Bar Inc.

Vertical Bar Inc.

Updates

We may update this notice as our services or legal obligations change. The date above identifies the current version.

We may update this notice as our services or legal obligations change. The date above identifies the current version.