ACOS

Privacy Policy

Last updated: 4 September 2026

Who we are

Agentic Commerce OS (“ACOS”, “we”) is a platform that measures and improves how AI shopping agents see, rank and buy from online retailers. It is operated from Australia. For anything in this policy, contact admin@ac-os.ai.

What we collect

Account details. Your name, work email, and a password (stored only as a bcrypt hash), plus your organisation’s name.

Workspace data you add. Merchant and catalog details, probe configurations and results, scorecards, and notes you enter.

API keys you bring (BYOK). If you add your own LLM or carrier API keys, they are encrypted at rest with AES-256-GCM, shown back only in masked form, and used solely to run the probes and features you request. We never use your keys for anything else.

Observed answers and screenshots. If you use the capture extension, pressing Capture sends the sellers/prices read from the page and a screenshot of that tab’s visible area to your workspace for review — so the image contains whatever was on screen at the time. Nothing is captured unless you press it. Saved screenshots are stored privately (in encrypted object storage, reachable only through your authenticated workspace) as evidence you control, and you can delete them individually or with the whole workspace at any time.

Billing. Payments are processed by Stripe. We store your plan, a Stripe customer reference and subscription state — never your card details.

Public readiness checks. The free readiness tool stores the checked domain and its results; if you ask for a report by email, we store that email to send it. Those results are not published — our public directory lists only a curated set of retailers we audit as published research, and a domain you check never joins it. If your store appears there and you want it re-checked or removed, email us and we’ll action it.

How we use it

To provide the service you signed up for: running the checks and probes you request, showing your results, sending the emails you trigger (sign-in links, password resets, alerts and digests you opt into), and billing your plan. We do not sell personal information, and we do not use your data to advertise to you or anyone else.

Where it lives

ACOS runs on infrastructure provided by Vercel (web hosting), Neon (database), and Railway (background worker), with Stripe for payments and Resend for transactional email. These providers may process data in the United States and Australia. Each acts as a processor on our instructions.

Retention and deletion

Your data is kept while your workspace exists. An organisation OWNER can permanently delete the whole workspace — merchants, probe history, observed answers and screenshots, encrypted keys and member accounts — from Settings → Danger zone. Deletion is immediate and irreversible. Individual observed answers and screenshots can be deleted at any time from the app.

Your rights

We handle personal information in line with the Australian Privacy Principles (Privacy Act 1988). You can ask us to access, correct, or delete personal information we hold about you — email admin@ac-os.ai and we’ll respond promptly. If you’re unsatisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).

Cookies

ACOS sets essential cookies only: your sign-in session, a super-admin support flag, and your theme preference. There are no analytics, tracking, or advertising cookies.

Changes

If this policy changes materially we’ll note it here with a new date, and tell active workspaces by email for significant changes.