Privacy Policy
Last updated: September 7, 2026
Overview
Vertical Bar Agent and the ChatGPT app
When you connect Vertical Bar Agent to ChatGPT or another MCP client, the app receives the inputs that client supplies to our tools and uses your authorized CrossCheck and Vertical Bar access to carry out the request. These inputs can include workspace and environment selections, dates, filters, record references, queries, test definitions, release-package content, and briefing content. We receive conversation content when the client includes it in a tool input, such as the prompt used to create a briefing.
Account and access information: authentication tokens and session records, user and OAuth subject identifiers, OAuth client identifiers, granted scopes, email address or display name, account status, roles, and permissions. These support sign-in, access control, and identifying the connected account. Account-identification responses may include your email address and granted scopes. Tokens are used for authentication, not as business-analysis output.
Organization and workspace information: organization, workspace, project, environment, and NetSuite account names and identifiers; workspace membership and access; configuration and status; and links to authorized records. These identify which customer data a request may access and where results belong.
Business records and people represented in them: query rows, transaction identifiers, dates, amounts, invoice or payment status, accounting classifications, customer and vendor records, contact names, email addresses, phone numbers and business addresses, employee identifiers, names, email addresses, departments, roles, and activity actors. The fields returned depend on the selected tools, authorized source data, and query. Authorized business data may also contain employment or compensation fields, credit limits, or business tax identifiers.
Analysis and technical records: process cases and events, actor and timestamp information, transaction relationships, paths, variants, exceptions, performance measures, snapshot and customization metadata, script or configuration source, dependencies, execution telemetry, test definitions and revisions, test results, release-package items, Git repository or revision references, workflow stages, deployment evidence, and creator or approver information. These may contain the same personal or business information as the underlying records.
Prompts, artifacts, and activity history: briefing titles, HTML and report contents, the basis prompt supplied by the client, model and host identifiers, and provenance describing how an artifact was produced. Tool activity includes tool names, timestamps, status, sequence, correlation identifiers, and digests of inputs. Publishing a briefing stores its content and provenance in the selected workspace, where authorized users can view it; publishing a new version can replace the topic’s latest-version reference.
Nested metadata and diagnostics: information in nested objects and arrays is included in these categories, even when it is not displayed in the chat answer. Examples include job and run identifiers, idempotency keys, workspace and record references, provenance, summaries, counts, limits, timing, status and error codes, diagnostic messages, and upstream API error details. Error details may repeat submitted values or source-record information. Routine results are not a guarantee that every field has been de-identified.
Operational and security records: our service may record the acting user or API-key identifier, organization and workspace, requested action and resource, timestamps, outcome, query text or other action metadata, request IP address, and user-agent information. App audit records are separate from the website analytics system described below. A query can leave an audit record or a short-lived result cache even when it does not change ERP records; asynchronous analysis creates job records.
How app information is used and shared
We use app information to authenticate users, enforce workspace and environment access, retrieve and analyze authorized data, run requested jobs and governed workflows, create and display artifacts, support the service, diagnose failures, and maintain security and auditability. The app is intended for business workflows. Do not put passwords, authentication secrets, full payment-card details, health records, or other unrelated sensitive information into queries or briefing content.
Tool responses, including their nested contents and error details, are returned to the AI platform you use: OpenAI for ChatGPT, or the provider of another connected MCP client. That platform can use these results to produce your answer and may retain them in conversation history under its own terms, privacy policy, and account settings. A request for a summary can still return structured source data to the platform. Disconnecting the app does not erase data already present in that platform’s conversations.
Vertical Bar and CrossCheck services process the request using our hosted infrastructure, including Amazon Web Services for compute, storage, identity, and operational logging. Authorized NetSuite queries and governed test or deployment actions communicate with the customer’s connected NetSuite environment. Optional integrations and AI features may involve OpenAI, Anthropic, GitHub, or support providers as described in our Data Processing Agreement. Customer administrators and other authorized workspace users may access shared artifacts and associated activity according to their permissions. Service providers may process information in the United States.
We do not sell customer personal data provided under the Data Processing Agreement. The website analytics and newsletter services described below have their own purposes; they are separate from the app’s business-data workflows. We do not use customer personal data to train or fine-tune our own machine-learning models. Where you connect a third-party AI platform, that platform's handling of the results returned to it is governed by its own terms, as described above.
App retention and deletion
Connected business data, snapshots, jobs, tests, workflow histories, and published artifacts are retained to provide the customer’s ongoing service and instructed workflows. A completed tool call does not automatically delete these records. Published briefings, their supplied prompts and provenance, and persistent audit histories do not have an automatic expiry for each call. Objects created in a connected commerce store by a governed test run are an exception: they are removed at the end of that run, as described under Connected commerce platforms. Applicable customer deletion instructions and service-agreement requirements govern their removal, subject to legally required retention.
Short-lived caches and infrastructure records have separate lifetimes. Live-query result caching defaults to 30 seconds and can vary with service configuration. Our standard production infrastructure configuration retains application and MCP runtime logs for three months, selected authentication-helper logs for one month, and rolling database backups for 7 to 14 days, depending on the database. These periods do not apply to persistent business or audit records stored in the service database, and retained recovery copies are separate from live records.
To request access, correction, export, or deletion of personal information held by Vertical Bar, contact hello@vertical.bar. Identify the account and workspace involved without sending passwords or tokens. For information held on an organization’s behalf, we coordinate with its authorized administrator. Customer deletion and return requests are handled under the applicable service agreement, Data Processing Agreement, and law; we may need to verify identity and authority before acting.
You can disconnect the app in your AI platform and revoke the relevant authorization to stop future app access. Disconnecting does not itself delete CrossCheck or Vertical Bar business records, published artifacts, audit history, source NetSuite records, or copies held by the AI platform. Use the relevant service’s deletion controls or contact the provider for those copies.
Connected commerce platforms
CrossCheck connects to commerce platforms alongside NetSuite. Where a customer connects a Shopify store, we process store configuration: themes and theme files, products and collections as configuration objects, metafield and metaobject definitions, markets, locations, publications, delivery profiles, discounts, translations, navigation menus, checkout and delivery customizations, and app and webhook settings — together with the identifiers, timestamps and status information needed to snapshot, compare and deploy that configuration. We also record store staff as an identifier, display name, active flag, owner flag and account type; we do not read staff email addresses or phone numbers.
We do not read customer names, email addresses, phone numbers or postal addresses from a connected store. Our webhook subscriptions cover configuration topics only and include no order, customer, checkout, cart or fulfilment topic.
Two features read order, draft order or customer records, and both are limited to non-identifying fields: object identifier, order or draft number, creation and update timestamps, financial and fulfilment status, order total and currency, test flag, tags, and closure or cancellation timestamps. A customer record is read only as its identifier, timestamps and tags. No name, email address, phone number or address is requested or stored by either.
Governed test runs may create and then remove an order, draft order or customer record and read it back to check the result. Such a run executes only against a development or sandbox store confirmed as a Shopify partner development store; it cannot run against a live store. The records a run creates carry no person — their line items are fixed test values. Objects a run creates are removed at the end of that run by the run's cleanup step; where the platform refuses a deletion, the run records the remaining object so it can be resolved rather than silently left behind. The non-identifying run evidence above is kept with the run record under the retention terms above.
Integration health checks, where the customer has linked a store to a NetSuite environment and enabled them, read recent orders from the connected store on a schedule — including a live store — in the same reduced form, to report whether each order reached NetSuite and how long it took. This feature reads no customer record and writes nothing to either system.
We do not use Shopify store data, or anything derived from it, to train or fine-tune machine-learning models. AI-assisted features do not receive connected-store data unless the customer's agreement with us expressly permits it.