Privacy notice placeholder
A transparent draft surface for the data-handling notice that must be completed before production use.
Roles and data scope
The reviewed notice must identify the operating legal entity and explain when OSTORE AI acts for merchant organizations. Expected data may include account identity, organization membership, customer conversations, order records, and provider event metadata.
Purposes and lawful basis
Production copy must describe each processing purpose and applicable lawful basis, including account security, service delivery, commerce operations, support, abuse prevention, and merchant-configured messaging.
Providers and international transfers
The final notice should name or categorize material subprocessors, explain cross-border transfers and safeguards, and distinguish live provider processing from local simulator data.
Retention and deletion
Retention periods are operational defaults pending legal review. The final notice must explain account, message, file, webhook, audit, analytics, order, and payment retention plus backup aging and lawful exceptions.
Security and access
OSTORE AI is designed around tenant isolation, least privilege, masking, secure token handling, and audited sensitive actions. These controls are not a certification claim and require ongoing verification.
Rights, choices, and contact
The production notice needs jurisdiction-appropriate rights, identity verification, complaint options, consent withdrawal behavior, a privacy contact, and any required supervisory-authority information.