Privacy Policy - AgenticCart | GDPR Compliant
Legal

Privacy Policy

Effective date: October 20, 2025 · Last updated: July 26, 2026

This Privacy Policy explains how AgenticCart ("AgenticCart", "we", "our", "us") collects, uses, discloses, and protects personal data when you use our website, the AgenticCart plugin, and related cloud services (together the "Service"). It also explains your rights under the EU General Data Protection Regulation (GDPR) and Austrian law.

By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Who we are and how to contact us

Controller for data described in this Policy:
AgenticCart
Austria
Email: legal@agenticcart.ai

If you are a Merchant, AgenticCart also acts as processor for the catalog you send us and for the conversations Shoppers have on your hosted storefront. In that role you are the controller. See Section 5 and the Data Processing Addendum in Annex 1 of our Terms of Service.

Data Protection Officer: If we appoint a DPO we will publish the contact details here. You can always contact legal@agenticcart.ai.

Supervisory authority: Austrian Data Protection Authority (Datenschutzbehörde, "DSB"). Website: www.dsb.gv.at

2. Scope

This Policy applies to visitors of agenticcart.ai, Merchant account holders, and users who interact with the Service, including our APIs and cloud relay. It does not cover processing performed by Merchants on their own WooCommerce stores, which is governed by each Merchant's privacy notices.

3. Categories of personal data we process

We process the following categories of data, depending on your interaction with the Service:

Account and identity data

Name, company, role, email address, authentication identifiers, password hash (stored by Supabase Authentication), profile preferences.

Sign in with Google

If you choose to sign in with Google, we receive basic profile information from Google, such as your name, email address, and optional profile picture. We use this data only to create and maintain your AgenticCart account, authenticate you, and display your profile inside the dashboard. We do not access any other data from your Google account such as Gmail content, Google Drive files, Calendar events, or contacts. We do not use Google user data for advertising or sell it to third parties.

Commercial and subscription data

Plan, billing status, license state, service usage entitlements, transaction history with us.

Technical and usage data

IP address, timestamps, user agent, device and browser metadata, API call identifiers, request and response logs, error codes, performance metrics, idempotency keys.

Merchant catalog and store configuration

Product records, descriptions, prices, availability, images, category and attribute data, plus the store policy texts and FAQ entries a Merchant configures. This data is processed on behalf of the Merchant and normally contains no personal data, unless the Merchant includes it.

Shopper conversations on a hosted storefront

When a Shopper uses a Merchant's AI shopping storefront we process, on that Merchant's behalf: the content of the Shopper's messages, which may contain whatever the Shopper chooses to type; the assistant's replies; a pseudonymous session identifier generated in the browser; the detected language and the storefront the conversation originated from; the search terms derived from the conversation; and product interaction events such as adding an item to a cart or wishlist. Where a Shopper creates a share link, a read-only snapshot of that conversation is stored. We do not store Shopper IP addresses or user agent strings for these conversations.

Support and communications data

Support tickets, emails, chat transcripts, attachments, issue diagnostics, feedback.

Marketing and deliverability data

Mailing opt-in state, unsubscribe tokens, campaign opens and clicks, bounce information, and similar standard email deliverability metrics.

Cookies and similar technologies

Cookies, local storage, and similar technologies as described in Section 12.

We do not intentionally collect special categories of data within the meaning of Article 9 GDPR. We do not direct the Service to children and do not knowingly collect data from persons under 18.

4. Purposes and legal bases

We process personal data for the purposes and on the legal bases below. Where multiple bases apply we rely on each as appropriate.

Provide and operate the Service

Create accounts, authenticate users, ingest and index a Merchant's catalog, operate the hosted AI shopping storefront and the merchant dashboard, and maintain core functionality.
Legal bases: performance of a contract Article 6(1)(b), legitimate interests Article 6(1)(f).

Operating the AI shopping assistant

To answer a Shopper we send the current message, a limited window of recent messages from the same conversation, the relevant product records and the Merchant's configured store information to our model provider, and we create vector embeddings of the message and of the catalog in order to run the product search. We record the conversation so the Merchant can review it in the dashboard and see analytics. We do not use this data to train, fine-tune or improve any machine learning model, and we have contracted with our model provider on terms that exclude such use.
Legal basis: performance of a contract Article 6(1)(b) towards the Merchant. For the Shopper, the Merchant is the controller and determines the legal basis.

Security and abuse prevention

Detect, investigate, and prevent fraud, abuse, misuse, and security incidents, enforce rate limits, protect our infrastructure.
Legal bases: legitimate interests Article 6(1)(f), legal obligation Article 6(1)(c) where applicable.

Service improvement and diagnostics

Monitor performance, fix bugs, improve reliability, develop new features, and analyze aggregated usage patterns.
Legal basis: legitimate interests Article 6(1)(f).

Communications

Transactional messages about your account, service notices, security alerts, and changes to terms.
Legal bases: performance of a contract Article 6(1)(b), legal obligation Article 6(1)(c).

Marketing

Send product updates and marketing emails to business contacts where permitted by law. You can opt out at any time.
Legal bases: consent Article 6(1)(a) or legitimate interests Article 6(1)(f), depending on jurisdiction and context.

Legal compliance

Fulfill legal obligations, respond to lawful requests, maintain business records, tax and accounting.
Legal basis: legal obligation Article 6(1)(c).

5. Roles: controller and processor

AgenticCart as controller

We are controller for account, website, and platform data that we collect for our own purposes, including identity, contact, subscription, security, and marketing data.

AgenticCart as processor for Merchants

We act as processor for the catalog a Merchant sends us and for the conversations Shoppers have on that Merchant's hosted storefront, including the related analytics events and share snapshots. In that context the Merchant is the controller: it decides which catalog to send, how the assistant is configured and which storefront to publish. We process such data only to provide the Service, on the Merchant's instructions, subject to the Data Processing Addendum in Annex 1 of our Terms of Service. We do not decide the purposes or means of processing for the Merchant's store, and we do not use the data for our own purposes.

If you are a Shopper who used a Merchant's storefront, that Merchant is your controller: please address requests to them, and they can delete an individual conversation directly in their dashboard. We will assist the Merchant as required by law. If you contact us instead, we will refer you to the Merchant unless the law requires us to act.

6. How the hosted storefront works, and what we do not do

When a Shopper opens a Merchant's AI storefront and sends a message:

  • The message reaches our servers over TLS, together with a pseudonymous session identifier created in the Shopper's browser.
  • We search the Merchant's catalog, then send the message, recent conversation context, the relevant product records and the Merchant's store information to our model provider to compose a reply.
  • The reply is streamed back to the Shopper, and the conversation is recorded for the Merchant's dashboard and analytics.
  • If the Shopper triggers an action such as adding an item to a cart, that request is submitted from the Shopper's own browser to the Merchant's store, which executes it. Checkout takes place on the Merchant's own store.

No payment data reaches us

We are not a payment service provider and no Shopper payment is processed by us or passes through our systems. We never receive card numbers, CVC values or expiry dates. The only payments we are involved in are Merchants' own subscription fees, which are handled entirely on Stripe-hosted pages; we receive subscription status, not card data.

7. Sources of data

We collect data directly from you, from your use of the Service, and from the integrations you connect, which currently include the WooCommerce plugin, the Shopify application, product feeds you supply and file imports. Shopper conversation data originates from Shoppers using a Merchant's storefront. We also receive data from our subprocessors, for example subscription status from Stripe and authentication events from Supabase, and may receive basic company and contact data from public sources where permitted by law.

8. Disclosures and recipients

We disclose personal data to the following categories of recipients, only as necessary and subject to appropriate safeguards.

Subprocessors that help us deliver the Service

  • OpenAI: language model and embedding provider for the AI shopping assistant
  • Supabase: managed Postgres database, object storage, and authentication
  • Stripe: subscription billing for the Merchant's AgenticCart plan, hosted checkout and customer portal
  • Cloud hosting and CDN providers
  • Email delivery and customer support tooling
  • Logging, monitoring, and security vendors

Merchants and integration partners

When acting as processor, conversation data and analytics are made available to the Merchant whose storefront the Shopper used, in that Merchant's dashboard. Shopper messages and the relevant catalog records are transmitted to our model provider in order to generate a reply. Commerce actions are submitted by the Shopper's own browser directly to the Merchant's store, not relayed by us.

Professional advisors and legal authorities

Auditors, accountants, lawyers, and government authorities where legally required.

Corporate transactions

If we engage in a merger, acquisition, reorganization, or asset sale, data may be transferred to the relevant parties subject to confidentiality.

We do not sell personal data.

9. International transfers

Our own infrastructure is operated in the European Union. The practically relevant transfer outside the EEA is to our model provider, OpenAI, in the United States, which receives Shopper messages and the relevant catalog records in order to generate replies. Where we transfer personal data internationally we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer impact assessment and supplementary technical and organizational measures. Details are in the Data Processing Addendum in Annex 1 of our Terms of Service and in Annex A below.

10. Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy.

  • Account and contract data: for the life of the account and a reasonable period thereafter to comply with legal, tax, and audit requirements.
  • Security and logs: for the time needed to ensure security, investigate incidents, and improve reliability, then deleted or anonymized.
  • Marketing data: until you opt out and for a short period to document your preference.
  • Shopper conversations and their messages: deleted 365 days after the conversation was last active.
  • Analytics and product interaction events: deleted after 30 days on entry-level plans and where no subscription is active, and after 365 days on higher plans. This matches the analytics retention shown on our pricing page.
  • Conversation share snapshots created by a Shopper: deleted 90 days after creation. A Merchant can delete a shared snapshot earlier by deleting the conversation.
  • Merchant catalog data and search indexes: kept while the Merchant's account is active, and removed when the Merchant deletes the account or the data source.
  • Short-lived processing caches used to hold conversation context: no longer than one hour.

These are maximum periods, which we may shorten but will not silently extend. A Merchant can delete an individual conversation at any time in the dashboard. Deletion propagates to encrypted backups only as those backups expire on their normal cycle, and we retain data longer where the law requires it.

11. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit using current TLS, encryption at rest for our databases and backups, logical separation of tenants enforced both in the application and in the search index, least-privilege access with individual accounts for personnel, audit logging of administrative actions, secret management outside application code, environment hardening, monitoring and alerting, and routine vulnerability management. No system can be guaranteed one hundred percent secure. You remain responsible for securing your own store, hosting and administrative accounts, for managing who in your organisation has dashboard access, and for protecting the API keys and access tokens you hold.

12. Cookies and similar technologies

We use cookies and similar technologies to provide and secure the Service, remember preferences, and measure performance.

Types

  • Strictly necessary cookies: required for authentication and core functionality.
  • Functional cookies: remember settings and preferences.
  • Analytics cookies: help us understand usage and improve the Service.
  • Marketing cookies: used for permitted B2B communications and campaign measurement.

Consent

We obtain your consent for non-essential cookies in jurisdictions where consent is required under the ePrivacy rules. You can change your preferences at any time via the Cookie Settings link in the footer.

Browser controls

You may set your browser to block or delete cookies. Some features may not function if you disable certain cookies. We do not respond to Do Not Track signals.

Google Analytics (GA4)

We use Google Analytics 4 operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 helps us understand how our website and dashboard are used. GA4 may collect device identifiers, approximate location, and event data. We configured GA4 with Consent Mode v2. Analytics data is only collected after you give consent. Before consent, Consent Mode prevents analytics cookies from being set.

Legal basis: your consent under Article 6(1)(a) GDPR for analytics cookies. You can withdraw consent at any time via Cookie Settings. Where data is transferred to the United States, Google relies on the EU United States Data Privacy Framework and, where applicable, the Standard Contractual Clauses together with additional safeguards.

Settings we apply for privacy:

  • Google Signals disabled unless you consent to marketing.
  • Ads personalization disabled unless you consent to marketing.
  • Data retention set to a minimal period.
  • No transmission of personal data such as names, email addresses, exact postal addresses, or other identifiers.

Provider: Google Ireland Limited. Privacy information and terms are available in Google's documentation. You can opt out of analytics at any time via our Cookie Settings or by using browser level opt out tools.

13. Your rights under GDPR

Subject to conditions and exceptions under GDPR, you have the following rights:

  • Access: request confirmation whether we process your personal data and obtain a copy.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion where there is no overriding reason to continue processing.
  • Restriction: request limitation of processing in certain cases.
  • Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Objection: object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent: withdraw consent at any time where processing is based on consent.
  • Complaint: lodge a complaint with a supervisory authority, especially in the EEA Member State of your habitual residence, place of work, or place of the alleged infringement. In Austria you may contact the DSB.

Exercising rights for Merchant-controlled data

If you are an End User of a Merchant's store, please contact that Merchant. We will assist the Merchant to respond to your request where we act as processor.

14. How to exercise your rights

You can submit requests by emailing legal@agenticcart.ai. We may need to verify your identity and your relationship to the account or Merchant. We aim to respond within one month as required by GDPR, or let you know if more time is needed due to complexity.

15. Children's privacy

The Service is intended for business users and is not directed to individuals under 18. If you believe a child has provided personal data to us, contact legal@agenticcart.ai so we can take appropriate action.

16. Changes to this Policy

We may update this Policy from time to time. The updated version will be posted at agenticcart.ai/privacy with a new Last updated date. If changes are material, we will provide additional notice where required by law. Continued use of the Service after changes means you accept the updated Policy.

17. Data Processing Addendum for Merchants

Our Data Processing Addendum is Annex 1 to our Terms of Service. It applies automatically to every Merchant and needs no separate signature; it governs our processor processing on your behalf, including the Standard Contractual Clauses for any transfer outside the EEA. The subprocessor register in Annex A below is the authoritative list referenced by that Addendum.

18. Contact

AgenticCart Privacy
Email: legal@agenticcart.ai
Postal: AgenticCart, Austria

Annex A: Subprocessors

We use carefully selected subprocessors to deliver the Service. Each subprocessor only processes data necessary for its function and is bound by written agreements that include confidentiality, security, and data protection obligations. The current list may include:

Supabase

Function: managed Postgres database, object storage, and authentication
Data: account data, authentication identifiers, application data, limited logs
Location: EEA region where available or other regions depending on configuration
Safeguards: encryption at rest and in transit, SCCs for any international transfers

OpenAI

Function: large language model and embedding provider for the AI shopping assistant
Data: the Shopper message being answered, a limited window of recent messages from the same conversation, the relevant product records including descriptions and prices, and the store information and FAQ entries configured by the Merchant
Contracting entity and location: for customers in the EEA the processor is OpenAI Ireland Limited (Ireland). OpenAI Ireland transfers data onward to its United States affiliate to operate the models.
Safeguards: under the provider's API terms, inputs and outputs are not used to train models and are retained for no longer than 30 days for abuse monitoring, then deleted. We do not currently use a zero-retention configuration. No adequacy decision is relied on for this provider; the contractual safeguards for the onward transfer to the United States, including the European Commission's Standard Contractual Clauses, are being completed with the provider.

Stripe

Function: subscription billing for the Merchant's AgenticCart plan, hosted checkout and customer portal
Data: billing contact and address, tax identifiers, subscription and invoice metadata. Card details are entered on Stripe pages and are never received or stored by AgenticCart
Location: EU and other regions depending on Stripe's architecture
Safeguards: SCCs where applicable, PCI DSS certification by Stripe

Cloud hosting and CDN, including Cloudflare

Function: application hosting, databases, networking, content delivery
Data: application data and logs as necessary
Location: as configured, including EEA and other regions
Safeguards: SCCs where applicable

Email delivery and customer communications

Function: transactional and permitted marketing emails, support tickets
Data: contact data, message content, deliverability metrics
Location: EEA and or other regions depending on vendor
Safeguards: SCCs where applicable

Logging, monitoring, and security tooling

Function: application logs, metrics, incident response
Data: technical and usage data, error details, pseudonymized identifiers
Location: EEA and or other regions
Safeguards: SCCs where applicable

We may update this list as our Service evolves. Merchants can request change notifications for subprocessors.

Annex B: Data flow summary

Account creation and login

Data flows from your browser to Supabase Authentication, which issues session tokens. Account profile data is stored in Supabase DB.

Shopper conversation on a hosted storefront

A Shopper's message reaches us over TLS with a pseudonymous session identifier created in the browser. We search the Merchant's catalog, then send the message, recent context and the relevant product records to our model provider, which returns the reply. The conversation is stored for the Merchant's dashboard and analytics, and deleted per Section 10.

Catalog ingestion and indexing

Product data flows from the Merchant's store or feed to us, is normalized, and is turned into vector embeddings so the assistant can search it. It normally contains no personal data.

Commerce action on the Merchant's store

When a Shopper adds an item to a cart or proceeds to checkout, the request is submitted from the Shopper's own browser to the Merchant's store, which executes it in the Shopper's session. Checkout happens on the Merchant's store. No such request and no payment is relayed through us.

Merchant subscription billing

A Merchant subscribes on Stripe-hosted pages. Stripe collects payment and tax details and sends us subscription status. We never receive card data.

Email and support

We send transactional emails and service notices. Marketing emails are sent only where permitted, with an unsubscribe link.