Privacy notice
Who operates the service
Merchant Outcome is operated by the Ainetcafe project team. This free beta has no user charges: the project subsidizes listing, model, and agent processing costs. The beta does not yet have a monitored support mailbox; participants must use the channel through which they received their invitation. A responsible legal entity and monitored privacy contact will be published before any future paid release.
What we process
- Product-sheet content that you submit, such as SKU, title, description, category, material, price, and currency.
- Workspace and security data, including a random session identifier, a verified recovery email when you claim a workspace, session expiry/revocation records, and rate-limit hashes.
- Outcome and compatibility records, including task status, validation findings, and (only if legacy test data exists) credits or Stripe reconciliation metadata. The current free beta creates no user payment.
- Operational data, such as skill and validator versions, timing, aggregate usage, error codes, and content digests.
- Privacy-limited product analytics, such as funnel event names, a day-rotated pseudonymous visitor hash, relative page path, referrer hostname, campaign dimensions, and a short allowlisted property set. Raw IP addresses, email addresses, cookies, query strings, filenames, and free-form event text are not stored as analytics fields.
Do not upload identity documents, health or financial records, or customer personal information. The beta is designed for product catalogs, not sensitive data.
Why we process it
We use submitted data to structure and validate listing rows, return an export, prevent abuse, operate the workspace, measure subsidized capacity, investigate security issues, and meet legal obligations. The current beta does not calculate a user charge or process a payment. We do not sell uploaded catalog content.
Retention and deletion
During the current beta, raw task inputs are removed after processing or at the configured retention limit, which is no more than 24 hours on the verification deployment. Result rows are retained only for the published product retention period, and may be deleted sooner from the workspace. Privacy-limited anonymous funnel events expire after the configured 30-day analytics retention window unless the deployment explicitly documents a different bounded value. Account deletion removes user content immediately from the live database and leaves a minimal financial/audit tombstone. Encrypted backups expire on their separate retention schedule.
Use Data deletion for the self-service procedure. A claimed workspace owner can also download the account export directly in the app.
Providers and transfers
The current listing path uses deterministic rules and does not send submitted rows to a model provider. If a model or agent is enabled for this free beta, its processing remains subsidized at a $0.00 user charge. Any provider, processing purpose, region, retention, and training policy will be disclosed before that provider receives user content; see Model providers. Stripe compatibility code is dormant and no checkout is offered.
The current verification deployment stores data on a server in mainland China. It is not represented as the final global data region. A public global beta requires a documented US or EU primary region, an appropriate transfer basis, and an approved backup region.
Security
Merchant API and Postgres are private to the host, sessions use HttpOnly cookies, recovery links are one-use and stored only as hashes, and backups are access-controlled. No internet service can guarantee absolute security. Private-beta participants should report suspected abuse through their invitation channel.
Your choices
You may stop using the service, claim or sign out of a workspace, export eligible workspace records, request correction, or delete the workspace. You may also contact your local data-protection authority where applicable.
Changes
We will update this page when processing, providers, regions, or retention materially change and will update the effective date.