Skip to content
Legal

Privacy Policy

Draft — Requires Legal Review Before Public Launch

Draft — Requires Legal Review Before Public Launch. This document is a working draft prepared for the private beta. It is not legal advice and is not a finalized agreement.

1. Information we collect

We collect the information you provide when creating an account or workspace, the data you enter into the product, information generated as you use the product, and any information you send us through support channels. We do not ask for and do not want passwords to third-party services, Seller Central credentials, API keys, or financial account credentials submitted through public forms.

2. Account and workspace data

Account data includes your name, email address, and authentication identifiers managed by our identity provider. Workspace data includes the business name, settings, team members, and role assignments you configure. Workspace data is isolated to your workspace.

3. Application usage data

We record operational events needed to run the service: automation runs, decision lifecycle changes, sync job outcomes, error reports, and privileged administrative actions. These records exist to make the product auditable and debuggable.

4. Marketplace data

When you connect a marketplace, we process the catalog, order, inventory, and settlement data required to operate the product on your behalf. Marketplace credentials are encrypted at rest and are never returned to a browser. Live marketplace synchronization is not active during the private beta.

5. Support data

Messages you send us, and the context you include, are used to answer your request. Internal support access to a workspace is read-only, time-limited, requires a stated reason, and is recorded in an immutable audit log.

6. Cookies

We use cookies and equivalent browser storage that are necessary to keep you signed in and to remember your preferences. See the cookie policy for details.

7. Data retention

Workspace data is retained while your workspace is active. Audit records are retained for a longer period because they are append-only and exist for accountability. When a workspace is closed, we delete or anonymize data on request, subject to records we are required to keep.

8. Security

We apply workspace isolation enforced at the database layer, role-based access control, least-privilege server functions, encrypted credential storage, and immutable audit logging. No system is perfectly secure, and we make no guarantee against every possible compromise.

9. Data sharing

We do not sell your data. We share data with infrastructure providers strictly as needed to operate the service, with marketplaces you explicitly connect, and where required by law. We do not share your business data with other customers.

10. Your choices

You can access and correct your data in the product, invite or remove team members, adjust notification preferences, and request an export or deletion of your workspace data by contacting us.

11. Contact

Privacy questions: hello@commerce-os.app. Security reports: security@commerce-os.app. Both mailboxes are monitored directly by the team during the private beta.