Privacy Policy
Effective date: TBD (Legal review pending) Last updated: 2026-05-26
Status: Engineering draft. Legal review pending per the project's locked decision that Eng drafts and Legal reviews + approves before publish.
This Privacy Policy describes how Solid Commerce, Inc. ("Solid Commerce," "we," "us") collects, uses, stores, and protects your data when you use our REST API, command-line interface (CLI), Model Context Protocol (MCP) server, software development kits (SDKs), and AI-assistant connectors (collectively, the "Services"). This policy applies to merchants, developers, and integrators who hold a Solid Commerce account and to authorized agents (AI assistants, scripts, third-party applications) acting on their behalf.
1. Who we are
Solid Commerce, Inc. is the Data Controller for the personal data described below. Contact: privacy@solidcommerce.com.
2. What we collect
When you use the Services, we collect the following categories of data:
2.1 Account data
- Your Solid Commerce account email, name, role, and company identifier.
- OAuth client identifiers (
client_id) and redirect URIs that you, or an assistant host on your behalf, register with our authorization server.
2.2 Authentication and authorization data
- OAuth 2.1 access tokens, refresh tokens, and PKCE code-verifier hashes issued by our authorization server.
- The set of scopes granted to each token (e.g.,
catalog:read,orders:write). - A unique install identifier (
install_id) minted at the time of OAuth consent and unique per (assistant host × company). This identifier lets us attribute usage to a specific host, revoke a specific install without revoking your entire account, and detect abusive token-fanout.
2.3 Operational data
- API request metadata: timestamp, HTTP method, path, status code, response time, request identifier (
request_id). - The MCP tool name, the originating host (
mcp_host_name∈ grok_cli), and theauth_mode(oauthorapi_key) for each invocation. - A coarse-grained
User-Agentstring from the host (e.g., "claude/1.5"). We do not collect device fingerprints, IP-based location, or browser cookies.
2.4 Business data
- The product, listing, inventory, order, vendor, and buyer-communication records that you store in Solid Commerce as part of normal Service use. This is your data; we are the processor, not the controller, for this content.
2.5 Data we do NOT collect
- Payment-card numbers (these go directly to our PCI-compliant payment processor and never enter Solid Commerce systems).
- Buyer personal data beyond what marketplaces send us (we forward to you; we do not enrich).
- Browser cookies on
docs.solidcommerce.combeyond a singlelocalStoragekey storing your preferred code-sample language.
3. How we use your data
We use the data above to:
- Operate the Services (authenticate you, route API calls, persist your business data).
- Maintain the security and integrity of the Services (detect abuse, enforce per-install rate limits, run audit-log reviews).
- Provide a per-surface usage dashboard to you on request, so you can see which assistant hosts are calling our API on your behalf.
- Diagnose technical issues and improve the Services.
We do not use your data:
- To train any machine-learning model, ours or a third party's.
- To sell to any third party.
- To target advertising.
- To enrich profiles for marketing.
4. How we share your data
We share your data only as follows:
- With the assistant host you authorize. When you grant a Claude / ChatGPT / Gemini / Copilot / Grok connector access via OAuth, the host receives the access token and the scope set you approved. The host may store the token to make subsequent calls. We do not share your password — only tokens scoped to the permissions you granted.
- With our infrastructure providers. Microsoft Azure (hosting), Microsoft Entra ID (identity for Copilot integration), and the Azure Key Vault that stores our signing keys. Each provider holds your data under their own enterprise contract.
- When required by law. Subpoena, court order, or other legal process. We will notify you when permitted.
We do not share with any other third party.
5. Where your data is stored and how long
- Primary region: United States (Azure US regions).
- Audit logs: retained 1 year, then deleted.
- Operational logs: retained 90 days.
- OAuth tokens: access tokens 1 hour; refresh tokens 90 days rolling.
- Business data: retained for the lifetime of your account; on account closure we offer a 30-day export window then delete within 90 days.
6. Your rights
You can:
- Export your business data via the REST API or by request to
privacy@solidcommerce.com. - Revoke any OAuth token or install at any time via the developer dashboard or by calling
/oauth/revoke. - Delete your account; we will delete your business data within 90 days. Audit-log entries that reference your account remain pseudonymous for the duration of our 1-year retention window.
- Request a copy of the personal data we hold about you, free of charge.
- Complain to a supervisory authority. For users in California, please see Section 8.
To exercise any right, email privacy@solidcommerce.com.
7. Security
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256, Azure-managed keys).
- OAuth signing keys live in Azure Key Vault; no signing material ever exists outside KV.
- We follow the principle of least privilege: every API call carries a scope-bound token, and our internal infrastructure access is role-bound and audited.
- We run periodic security reviews of our authentication and authorization surface. Our Phase 0 distribution work passed a security sign-off before we listed in any host directory.
8. California residents (CCPA / CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal data we collect (this policy).
- Right to delete your personal data, subject to legal retention obligations.
- Right to opt out of sale or sharing. We do not sell or share personal data; no action is required.
- Right to non-discrimination for exercising your CCPA rights.
To exercise CCPA rights, email privacy@solidcommerce.com and reference "CCPA request" in the subject.
9. International users (EU, UK)
We do not currently market the Services to consumers in the EU or UK. If you are an enterprise user in those regions and need a DPA, contact privacy@solidcommerce.com.
10. Children
The Services are not directed to children under 16. We do not knowingly collect data from children.
11. Changes to this policy
Material changes will be announced at least 30 days in advance via email to the address associated with your account. The current version is always at this URL.
12. Contact
privacy@solidcommerce.com
Solid Commerce, Inc.
[Mailing address — TBD by Legal]