Privacy policy

Daybreak computes your store's daily profit. To do that it needs your commerce numbers and almost nothing else. This page says exactly what we collect, what we refuse to collect, where it lives, and how to get it deleted. Effective July 14, 2026.

Who we are

Daybreak is built and operated by MinCac (founder: Taha Iftikhar). For anything on this page, write to taha@mincac.com. You will get a reply from a human who can actually do the thing you asked.

What we collect

What we never collect

Your customers' names, email addresses, and shipping addresses. Our database has no columns for them, so a bug could not store them by accident. Our Shopify access is read-only and scoped to orders, products, and inventory. We do not run ad pixels or analytics trackers on your data, and we will never sell any of it to anyone.

Where it lives and how it is protected

How long we keep it

As long as your store is connected, plus 30 days after you disconnect, then it is deleted. You can request deletion sooner at any time and we will complete it within 30 days. You can also request a full export of every row we hold about your store at any time, including after you cancel. Your historical P&L is yours.

Who else touches it

A handful of infrastructure providers process data on our behalf: Supabase (database hosting), Vercel (application hosting), GitHub (code and the nightly job runner), Lemon Squeezy (billing, as our merchant of record), and Resend (report email delivery, plus account emails: verification, password resets, and a welcome note). Shopify, Meta, TikTok, Google Ads, and your 3PL are the sources you connect; we read from them under the permissions you grant and you can disconnect any of them at any time. That is the complete list. If it changes, this page changes first.

Cookies

We use only the cookies Daybreak needs to function: keeping you signed in, remembering your session, and (during signup) confirming your email was verified. We do not use advertising or cross-site tracking cookies, and we run no third-party analytics scripts on the app.

If something goes wrong

If we discover a security incident affecting your data, we will notify you by email within 72 hours of confirming it, tell you plainly what was exposed, and publish what we changed. The same honesty that drives our restatement log applies here.

Your rights

Access, correction, export, and deletion of your data, whatever your jurisdiction. One email to taha@mincac.com does it. If you are on the waitlist and want off, the same email works.

Changes

If this policy changes, the effective date at the top changes and material changes get called out to connected stores by email. We will not quietly swap terms under you.

Also see the terms of service.