Privacy Policy
Last updated: August 5, 2026
Effective Date: February 25, 2026 Last Updated: August 5, 2026
Barrelmaker Consulting ("we", "us", "our") operates the Sygentic AI Commerce WordPress plugin (including the Agentic Commerce distribution) and the website at https://acommerce.app (together, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service.
1. Information We Collect
1.1 Account and purchase information
When you purchase a Pro license or create an account, we collect:
- Full name
- Email address
- Billing address
- Payment information (processed by Stripe; we do not store full card numbers)
1.2 License validation data (Pro)
When you activate or renew a Pro license, the plugin contacts our licensing endpoints on acommerce.app (including REST routes under /wp-json/ecai-mkt/v1) and may send:
- Your WordPress site URL (domain)
- License key / tokens
- Plugin version and related activation metadata
This is used for license validation and entitlement. Product catalog content is not required for license checks alone.
1.3 Product and store context processed by the middleware
When you use managed AI, bulk optimization, or agentic protocol features that call our middleware, relevant store/product context may be sent to acommerce.app over HTTPS. Typical fields include product titles, descriptions, attributes, categories, and protocol/checkout session fields required for the requested operation.
- Pro subscribers (managed AI): Product/context data is processed via Sygentic AI Commerce middleware. We select and manage the underlying LLM vendor (currently OpenAI and, optionally, DeepSeek). Merchant LLM API keys are not required for managed Pro mode.
- Free plan: Free first-run is activate + A2A discovery. There is no bring-your-own API key settings tab, and Free does not forward product data to an LLM provider using a merchant key.
Product data retention: We do not retain product payloads as a standing archive. Data is processed to fulfill the request and discarded from request-handling memory after the response is returned, subject to short-lived operational logs described below.
1.4 Website analytics
As of August 5, 2026, the public acommerce.app site does not load Google Analytics 4 (gtag) or similar third-party marketing analytics tags.
If we enable Google Analytics 4 or another analytics provider later, we will update this policy and disclose the provider, cookies/identifiers used, and any consent mechanism before or at the time of activation. Until then, do not assume Plausible, Fathom, or GA4 are active.
1.5 Cookies
The acommerce.app website uses essential cookies required for:
- Shopping cart and checkout functionality
- Login / account session management
- CSRF and security protections
We do not currently use advertising cookies, tracking pixels, or third-party marketing cookies on acommerce.app.
1.6 Plugin visitor overlay (optional, consent-gated)
Optional AI Agent Overlay features in the plugin may use browser storage or fingerprinting-style signals only when a consent signal is granted. See the plugin FAQ (“Does the AI Agent Overlay track visitors?”) in readme.txt / WordPress.org listing materials.
2. How We Use Your Information
We use collected information for:
- License fulfillment: Delivering and validating Pro license keys.
- Service delivery: Processing AI/protocol requests via the middleware and related operator tooling.
- Payments: Processing subscriptions and invoices via Stripe.
- Customer support: Responding to support and billing inquiries.
- Transactional emails: Sending purchase receipts, license keys, and renewal/cancellation notices.
- Security and reliability: Error monitoring, abuse prevention, and service continuity.
We do not use your information for:
- Marketing emails (unless you explicitly opt in)
- Selling or renting personal information to third parties
- User profiling for third-party behavioral advertising
3. External services and third-party processors
We share or transmit data to the following external services.
| Service | Role | Typical data | Privacy / terms |
|---|---|---|---|
Sygentic AI Commerce middleware (acommerce.app) |
Managed AI, agentic protocol support, license validation, operator tooling | Store URL/metadata, product/context needed for generation or protocols, license keys/tokens, checkout-session fields for delegated flows | Privacy · Terms |
| OpenAI (via middleware for managed Pro) | Large-language-model processing | Product title/description/context for Pro managed-AI requests | Privacy · Terms |
| DeepSeek (optional managed vendor via middleware for Pro) | Alternate LLM processing when selected | Same pattern as OpenAI | Privacy · Terms |
| Stripe | Pro subscription billing and optional Stripe-backed agentic checkout | Amount, currency, email, PaymentIntent/Customer references, webhook events | Privacy · Legal |
| Sentry (middleware error monitoring) | Application error reporting | Error stack traces and sanitized request metadata (configured to scrub API keys and sensitive product payloads where practical) | Privacy |
| Transactional email provider | Receipts, license delivery, account mail | Name, email, purchase/license details | Disclosed when the production From-domain provider is finalized |
3.1 Code that may ship but is inactive in Agentic Commerce
Shared plugin packages may include Google OAuth / Search Console / Analytics module code and Google/Bing sitemap-ping helpers used by other distributions. In the Agentic Commerce WordPress.org-oriented distribution, those modules are not part of the active commerce allowlist and are not enabled for normal commerce runtime. If you enable SEO/analytics modules in another distribution, Google APIs may receive OAuth tokens and Search Console / Analytics read scopes, and sitemap URLs may be pinged to Google/Bing. Those optional features are not the default Agentic Commerce surface.
4. Data Retention
- Purchase records: Retained for as long as your account exists, plus any legally required retention period (often up to 7 years for financial records).
- License validation logs: Retained for up to 90 days, then purged.
- Product data sent to middleware for generation: Not retained as a catalog archive; discarded after request handling.
- Error logs: Retained for up to 30 days; scrubbed of API keys where configured.
5. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Delete your personal data (“right to be forgotten”).
- Export your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email barrelmakerconsulting@gmail.com (ops inbox until brand-domain mail authentication is complete). We aim to respond within 30 days.
5.1 GDPR (EU/EEA/UK)
We process personal data under the following legal bases:
- Contract performance: Fulfilling your Pro license purchase and delivering the Service.
- Legitimate interest: Operating and securing the Service, fraud prevention.
- Consent: Marketing communications (opt-in only) and optional overlay tracking signals.
5.2 CCPA (California)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
6. Security
We protect data with:
- HTTPS for data in transit.
- Managed Pro AI so merchants need not store vendor LLM keys for Pro mode.
- Free first-run is activate + A2A discovery and has no bring-your-own API key settings tab.
- Error reporting scrubbing for API keys and sensitive fields where configured.
- Restricted server access and routine security updates.
7. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If we learn that we have collected such data, we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date. For material changes, we will notify you via email or a prominent notice on our website.
9. Contact Us
Barrelmaker Consulting Email: barrelmakerconsulting@gmail.com (current ops contact) Website: https://acommerce.app Related: Terms of Service · Refund Policy