Privacy Policy
Last updated: 2026-07-23
Controller
The controller responsible for processing personal data on this service is Ian Helmrich, Karolingerallee 9, 69181 Leimen, Germany. Contact: info@aigentably.com. For full legal details see the Impressum.
Data we collect
Account data. When you create an Aigentably account we store your email address, a salted password hash (or OAuth identifier if you sign in with a third party), and basic profile data you choose to provide.
Site configuration. For each website you connect we store the public domain, tool definitions you create, and a public site identifier used in our embed script.
Shopify shop data. When you connect a Shopify store we store the shop domain, the OAuth access token (encrypted at rest with AES-256-GCM), the theme identifier used for the app embed, and metadata about installation status. We request only the scopes listed on the Shopify App Store listing; tokens never leave our servers.
Tool call logs. For each call made by an AI agent to one of your tools we record the tool name, timestamp, originating site, the result status, a classified failure reason, the calling agent where it identifies itself, and the call arguments. Before the arguments are stored they are automatically scrubbed of obvious personal data (email addresses, phone numbers, card, account and IBAN numbers, and fields whose name signals a secret); such values are replaced with a typed placeholder. Non-personal content, such as a search query, is kept. We do not deliberately collect end-user personal data; if your tool definitions cause personal data to flow through Aigentably, you remain responsible for that decision under your own privacy policy.
Generation records. When you use the AI tool-generation feature we store a record of each generation: the structured signals extracted from your publicly crawled pages, the model and prompt version used, and the resulting tool suggestions together with whether you saved, edited, or dismissed them. These records let us operate the feature and improve its quality over time.
Guide download and marketing consent.If you request our WebMCP readiness checklist we store your email address to send it. If you additionally tick the marketing checkbox, we also store the exact consent text, the time, a hashed IP address, and a confirmation status, described further under "Legal basis" below.
Billing data. Payment processing is handled by Stripe. We store the Stripe customer ID, subscription status, and the Shopify billing charge ID; we never see or store full card numbers.
Legal basis (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) for account, site, Shopify integration, and billing data.
- Legitimate interests (Art. 6(1)(f)) for security logs, fraud prevention, tool call logs used for debugging and analytics, and the use of aggregated, de-identified data to operate, secure, and improve the service (see "Product improvement" below).
- Consent (Art. 6(1)(a)) where you opt in to optional features such as marketing emails. Marketing emails use double opt-in: ticking the checkbox does not by itself subscribe you, we send a confirmation email and only start sending once you click the link in it. We record the wording you agreed to, the time, and a hashed IP address as proof of consent, and every marketing email includes an unsubscribe link that takes effect immediately.
- Legal obligation (Art. 6(1)(c)) for tax-relevant records and Shopify privacy-compliance webhook responses.
Subprocessors
- Hetzner Online GmbH (Germany): hosting and database storage.
- Stripe, Inc. (USA, SCCs in place): subscription billing for non-Shopify customers.
- Shopify Inc. (Canada): OAuth, merchant-managed billing, and Admin API access for shops you connect.
- Resend (USA, SCCs in place): transactional email delivery.
- OpenAI / Anthropic (USA, SCCs in place), used only when you explicitly use the AI tool-generation feature. Prompts and generated outputs pass through these providers; we do not send your tokens or customer data.
Product improvement
We use data generated through the service to operate, secure, and improve it. This includes improving our site crawling and AI tool-generation quality, ranking and suggesting tools, and producing aggregate statistics about how AI agents interact with WebMCP-enabled sites. For these purposes we work with de-identified and aggregated data: the structured signals from publicly crawled pages, the record of which AI suggestions were saved, edited, or dismissed, and tool-call telemetry whose arguments have already been scrubbed of personal data as described above.
We do not sell personal data. Any insights we publish or share externally, such as benchmarks or trend reports, are aggregated and do not identify you, your end users, or your business. You can object to processing based on legitimate interests at any time by contacting us.
Retention
Account data is kept while your account is active and for up to 30 days after deletion to handle reversal requests and abuse investigations. Tool call logs and generation records are retained for as long as we operate the service, since we use them on an ongoing basis for analytics and to improve crawling and AI generation quality. This is proportionate because the personal-data footprint is minimized before storage: arguments are scrubbed of personal data as described above, and IP addresses are stored only as a one-way hash, never in plain form.
Shopify-specific retention. When a merchant uninstalls Aigentably from their store, or when Shopify sends a shop/redact webhook, all shop data (access tokens, theme metadata, install state) is deleted within 48 hours. customers/redact and customers/data_requestwebhooks are handled per Shopify's privacy-compliance requirements; since Aigentably does not persist Shopify customer records, these requests are completed by confirming no such data exists in our systems.
Your rights (GDPR Art. 15–22)
You have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data. To exercise any of these rights email info@aigentably.com. We respond within 30 days.
You may also lodge a complaint with a supervisory authority. The competent authority for the controller is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
International transfers
Where subprocessors are located outside the EU/EEA, transfers are governed by the EU Standard Contractual Clauses (Commission Decision 2021/914) and supplementary measures where required.
Security
All Shopify access tokens are encrypted at rest with AES-256-GCM. All traffic to the service is TLS-encrypted. Webhook signatures are verified with HMAC-SHA256 before processing.
Changes
We may update this policy from time to time. Material changes will be announced by email to active account holders at least 14 days before they take effect.