StoreMCP

Privacy

Effective September 17, 2026. Store MCP is operated by Moss Systems LLC, a Tennessee limited liability company. Questions and privacy requests can be sent to support@store-mcp.com.

Information we process

We process your account email (and GitHub identifier when you use GitHub sign-in), workspace settings, encrypted merchant OAuth tokens, hashed API keys, MCP client grants, explicitly created canonical products and listing links, encrypted notification destinations, plan and subscription identifiers, and operational records needed to secure and run the service.

Normalized commerce events contain resource identifiers and timestamps, never buyer data or raw provider payloads. Activity records contain an allowlisted action summary, store, status and latency rather than raw tool arguments or provider responses. Authorized store data is fetched when requested and returned to your chosen AI client; that client's privacy terms also apply.

How we use and share information

We use information to authenticate you, connect stores and AI clients, perform requested commerce operations, enforce permissions and plan limits, prevent abuse, deliver configured notices, troubleshoot failures and maintain billing records. We share only what is necessary with the commerce platform you direct us to call, your authorized AI client, and infrastructure or billing providers that help operate Store MCP. We do not sell personal information or use buyer data for advertising.

Retention and security

Provider credentials and destination configuration are encrypted. Completed mutation receipts are retained for 30 days, commerce-event identifiers for 30 days, activity for 7–90 days according to plan, and monthly usage counters for 400 days. Some security, billing and deletion records may be kept longer when required to prevent fraud, resolve disputes or comply with law. No networked service can promise absolute security.

Your choices and deletion

You can revoke AI grants and API keys, disconnect stores and disable notification destinations in Store MCP. Disconnecting removes saved credentials; also revoke Store MCP in the provider's settings to end the provider-side grant. Request workspace deletion from Settings; access is disabled promptly and workspace data is erased within 30 days, subject to limited legal and security retention. Contact support for access, correction or deletion questions.

Changes

We may update this policy as the service changes. Material changes will be posted here with a new effective date.