# AI Shopping Experience — Privacy Policy
**Effective 08/21/26** This policy covers the AI Shopping Experience
service operated by F5 Digital Marketing (“we”, “us”), São Paulo, Brazil,
260736410001-60. Privacy contact: contact@f5digitalmarketing.com.
Data protection officer / *encarregado* (LGPD art. 41): [DPO NAME], reachable at
contact@f5digitalmarketing.com. Our representative for data subjects in the EEA and the UK is
[EU/UK REPRESENTATIVE — or delete this sentence if none is appointed].
It explains what reaches our servers when a shopper talks to the assistant on a
merchant’s store, what we do with it, and what we keep. It does not describe
what an individual merchant stores on their own site — that is theirs to
document, and the plugin supplies suggested wording for it.
## 1. Who is responsible for what
**The merchant is the controller** of shopper conversations. They decide to
install the plugin, they configure the assistant, and the conversations are
stored in their own WordPress database.
**We are a processor** for that data: we process it on the merchant’s
instructions in order to return an AI reply, and for nothing else.
**We are the controller** of merchant account data — the details you give us
when you register for a licence, and the record of your subscription and usage.
## 2. What we receive, and when
**On each chat turn**, the plugin sends our gateway:
– the shopper’s message;
– a trimmed history of that conversation;
– relevant excerpts from the merchant’s uploaded knowledge-base documents;
– a compact summary of the products and cart under discussion — ids, names,
prices, quantities;
– when a signed-in shopper asks about their own orders: that shopper’s order
numbers, statuses, dates, totals, currency, and the names and quantities of
items ordered;
– the merchant’s licence key, site URL and plugin version.
**When a merchant uploads a knowledge-base document**, the extracted text of
that document is sent so it can be turned into embeddings.
**When a licence is activated, re-validated (once a day) or deactivated**, the
licence server receives the licence key, the site URL and the plugin version.
### What we do not receive
Shopper names, email addresses, postal or shipping addresses, phone numbers and
payment details are not sent to the gateway. Order lookups deliberately omit
addresses and per-line totals. We never receive the merchant’s WordPress
credentials or database.
A shopper can of course type personal information into a chat message. Merchants
should tell shoppers not to, and the assistant is instructed not to ask for it.
## 3. Why we process it
– **To provide the service** (performance of a contract): generating replies,
embedding documents, validating licences, metering usage and billing.
– **To keep the service secure and available** (legitimate interests): rate
limiting, abuse prevention, and blocking attempts to extract credentials or
bypass safety controls.
– **To comply with law** where we are required to.
We do not sell personal data, we do not use it for advertising, and neither we
nor our AI provider use it to train AI models.
## 4. What we keep, and for how long
**The gateway does not store conversations.** It is a stateless proxy: a request
arrives, it is checked and forwarded, the reply is streamed back, and nothing
about the content is written to disk. Prompts, replies and document text are
held in memory only for the life of the request.
| Data | Where | Retention |
|—|—|—|
| Prompts, replies, document text | Gateway (in memory only) | Life of the request |
| Hash of the licence key + request timestamps, used for rate limiting | Gateway counter store | About 2 minutes. The key itself is never stored — only a SHA-256 hash of it |
| Licence key, plan, status, expiry, quota, tokens used, allowed models, document limit | Licence server | Life of the licence, plus [RETENTION] after it lapses |
| Site URLs a licence is activated on, with activation dates | Licence server | Same as above |
| A one-way key of stores that have used a free licence | Licence server | Kept indefinitely, so a free allowance cannot be reset by re-registering |
| Account, order and subscription records | Our storefront (WooCommerce) | As required for tax and accounting law |
| Operational logs (errors, availability) | Hosting platform | Short-lived platform retention; they contain no prompt content |
## 5. Who else processes it
| Subprocessor | Role | Where |
|—|—|—|
| OpenAI | Generates replies and embeddings from the content in section 2 | United States |
| Vercel | Hosts and runs the gateway | Global edge, US-based |
| [KV PROVIDER — Vercel KV / Upstash] | Rate-limit counters (hashed licence key only) | US/EU region of the attached database |
| Our storefront hosting | Licence server, accounts, billing | [HOSTING REGION] |
OpenAI states that data submitted through its API is not used to train its
models and is retained only for a limited period for abuse monitoring. See
<https://openai.com/policies/row-terms-of-use> and
<https://openai.com/policies/row-privacy-policy>.
Merchants who bought their licence from a different storefront in our network
have their licence validated by that storefront’s licence server instead of
ours; the AI gateway is the same.
## 6. International transfers
The gateway and OpenAI process data in the United States. Where data originates
in the EEA, the UK or Brazil, transfers rely on the European Commission’s
Standard Contractual Clauses (and the UK addendum where applicable), together
with the technical measures in section 8. A copy of the relevant safeguards is
available on request.
## 7. Your rights
Depending on where you are, you may have the right to access, correct, delete,
port, restrict or object to the processing of your personal data, and to
withdraw consent where processing rests on it. Write to [PRIVACY EMAIL] and we
will respond within the time your law allows.
**Shoppers** should contact the store they were chatting with: the merchant is
the controller of that conversation, and the conversation is stored on the
merchant’s own site. If you contact us instead, we will pass the request to the
merchant. Merchants can honour it directly — the plugin supports WordPress’s
personal-data export and erase tools for signed-in customers, and lets an admin
delete conversations.
You may also complain to your local supervisory authority (in Brazil, the ANPD).
## 8. Security
– All traffic runs over TLS.
– The AI provider’s key exists only in the gateway’s environment. It is never in
the plugin, never on the merchant’s server and never in a browser.
– The merchant’s licence key is encrypted at rest on their site (AES-256-CBC,
key derived from the site’s own WordPress salts) and is decrypted only
server-side when calling us.
– Licence entitlements are RSA-SHA256 signed by the issuing storefront and
verified before they are trusted, so a spoofed licence server cannot grant
access.
– Replies are scanned and credential-shaped text is redacted before it reaches a
browser, on both the streaming and non-streaming paths.
– Requests are rate limited per licence, and quotas are enforced per plan.
No system is perfectly secure. If we become aware of a breach affecting personal
data we will notify affected merchants and the relevant authority as required by
law.
## 9. Children
The service is sold to businesses and is not directed at children. We do not
knowingly collect personal data from children. A merchant whose store serves
minors is responsible for the additional obligations that brings.
## 10. Changes
We may update this policy. Material changes will be notified by email or in the
plugin’s admin screens at least 30 days in advance, and the effective date above
will change.
## 11. Contact
F5 Digital Marketing, São Paulo, Brazil — contact@f5digitalmarketing.com.