StoreMCP
Documentation menu

Store MCP Security and Data Privacy

Give each client the minimum access it needs, and review what leaves the store.

Credentials and access

Saved provider tokens and notification configuration use versioned AES-GCM encryption bound to the owning record. Provider tokens do not become client tokens. Store ownership and scope are checked before commerce requests. Never paste credentials into a prompt.

Data boundaries

Store MCP does not maintain a synchronized orders or customers database. Authorized responses reach your chosen AI provider and its policies apply. Buyer details require the explicit sensitive read described in Permissions. Events and notification messages exclude buyer details and raw provider payloads.

Activity retains allowlisted summaries and client attribution, not raw arguments or arbitrary listing text. Mutation receipts retain the results needed for safe replay; they are distinct from Activity. Activity storage is retained for 90 days with plan-specific visibility; commerce-event metadata is retained for 30 days.

Control and policies

Revoke client grants and API keys in Connect AI. Disconnect removes saved store credentials; revoke the provider-side app grant separately when appropriate. Account deletion disables access promptly and follows the published deletion policy. See Privacy, Terms and DPA for the governing documents.

Next steps and troubleshooting

Privacy · Terms · Data Processing Agreement