Commercer LLC – Policy
Privacy Policy
How Commercer LLC collects, uses, discloses, and protects personal information.
- Provider:
- Commercer LLC (Wyoming, USA)
- Address:
- 33 N Gould St, Sheridan, WY 82801, USA
- Effective date:
- July 10, 2026
- Version:
- v1.0
1. Who we are
Commercer LLC ("Commercer," "we," "us") provides the Commercer software-as-a-service platform. This Privacy Policy explains how we handle personal information when you visit our marketing website, create an account, or use the service. For account and service data submitted by our business customers, Commercer generally acts as a processor on behalf of the customer; see Section 12.
Contact: privacy@commercer.io. Data protection contact: dpo@commercer.io. Postal: Commercer LLC, 33 N Gould St, Sheridan, WY 82801, USA.
2. Information we collect
2.1 Information you provide
- Account information: name, email, password hash, company, role.
- Billing information: name, billing address, tax identifiers, and card details (processed by Stripe; we do not store full card numbers).
- Content you submit: catalog data, product content, brand assets, images, and any data you connect from third-party platforms such as Shopify.
- Support communications: messages, attachments, and metadata when you contact support.
2.2 Information collected automatically
- Device and connection information: IP address, browser, operating system, device identifiers, and language.
- Usage telemetry: pages viewed, features used, actions taken, error events, timestamps.
- Cookies and similar technologies: see Section 8.
2.3 Information from third parties
- Data from connected platforms such as Shopify, based on the scopes you authorize.
- Data from payment processors (transaction status, last four digits of the card).
- Where you use single sign-on, basic profile data from the identity provider.
3. How we use information
- Provide, maintain, and secure the service, including authentication, billing, and support.
- Operate AI-assisted features on your behalf, using inputs you or your team submit.
- Communicate with you about the service, billing, security, and product updates.
- Diagnose and fix issues, monitor performance, and detect abuse or fraud.
- Improve the service, including through aggregated and de-identified analytics.
- Comply with law and enforce our agreements.
4. Legal bases (EEA/UK/Swiss users)
- Performance of a contract: to provide the service you or your employer signed up for.
- Legitimate interests: to secure the service, prevent abuse, improve product quality, and communicate about the service in ways you would reasonably expect.
- Consent: for marketing communications where required, for non-essential cookies, and for advertising cookies.
- Legal obligation: to meet tax, accounting, and compliance requirements.
5. AI and machine learning
The service uses machine-learning models, some operated by third-party providers routed through the Lovable AI Gateway. When you or your team runs an AI action (for example, canonicalization, deduplication, image generation, or copy generation), inputs are sent to the model provider on a per-request basis to produce the requested output.
5.1 Training scope
Commercer does not use identifiable Customer Data to train shared or foundation models. We may use aggregated and de-identified operational signals – for example, latency distributions, error rates, dedupe precision metrics, and heuristic quality scores that do not contain your product data, prompts, or outputs – to improve orchestration, prompts, and evaluation.
Because no identifiable data leaves the tenant boundary for training, we do not offer or require an opt-out from training. If a future feature would use identifiable content for training, we will disclose it and obtain consent before doing so.
5.2 Third-party model providers
Third-party model providers may retain prompt and response data for a short abuse-monitoring window under their own terms. Where a no-training tier is available (for example, OpenAI's API default), Commercer routes traffic on that tier so that provider does not train its own models on Commercer traffic. Provider identity for a given feature is available on request.
5.3 Human review
AI actions run automatically. Commercer personnel do not routinely review the content of your prompts or outputs. Limited human review may occur to investigate reported issues, safety incidents, or suspected abuse, subject to access controls and confidentiality obligations.
6. Disclosures
We disclose personal information to:
- Subprocessors that provide infrastructure, AI inference, payments, email, and analytics on our behalf (see Section 11).
- Third-party platforms you connect (for example, Shopify), only as directed by you.
- Professional advisers, auditors, and insurers under confidentiality.
- Government, law enforcement, or regulators where legally required.
- A successor in interest in the event of a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
We do not sell personal information for money.
7. Advertising and tracking on the marketing website
Commercer's marketing website may use advertising and measurement technologies to understand campaign performance and reach relevant audiences. Where enabled, these include Google Ads (including Google tag and Consent Mode v2 signals ad_storage, ad_user_data, ad_personalization, analytics_storage), Meta Pixel and the Meta Conversions API, and comparable tools from LinkedIn, TikTok, or Reddit.
For EEA, UK, and Swiss visitors, these technologies are loaded only after prior, freely given, specific, informed, and unambiguous consent, collected through our consent management platform.
For US visitors in states that grant a right to opt out of "sale" or "sharing" of personal information (including California under the CPRA), we treat pixel-based advertising as "sharing" and honor opt-out requests, including via the Global Privacy Control signal. A "Do Not Sell or Share My Personal Information" link is available in the site footer.
These technologies apply only to the marketing website. The authenticated Commercer application does not run advertising pixels or share application data with ad platforms.
You can withdraw consent or change your preferences at any time from the cookie settings link in the marketing site footer.
8. Cookies and similar technologies
We use the following categories of cookies and similar technologies. Details are surfaced through our consent management platform on the marketing website.
You can control cookies through your browser settings and, on the marketing website, through the consent management platform. Blocking strictly necessary cookies will break core functionality such as sign-in.
9. Retention
- Account data: for the life of the account and up to seven years after closure for tax, accounting, and legal defense.
- Customer Data: processed on your instructions; on termination, deleted from active systems within thirty days and rotated out of backups within ninety additional days.
- Support communications: up to three years.
- Server logs and security telemetry: up to twelve months.
- Marketing-site analytics: up to twenty-four months.
- Advertising cookies: up to thirteen months.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal information, to withdraw consent, and to lodge a complaint with a supervisory authority. US residents in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have additional rights under their state privacy laws, including the right to opt out of "sale," "sharing," or targeted advertising.
To exercise a right, email privacy@commercer.io. If Commercer processes your data on behalf of a business customer (for example, if you are an end user of a customer's store data), we will refer you to that customer as the controller.
11. Subprocessors
Commercer uses the following categories of subprocessors to deliver the service. This list may change; the current list is maintained in-product and on the marketing site, and we will provide reasonable notice of material changes.
Shopify is not a subprocessor of Commercer; Shopify is a destination platform owned by the customer. Where you use Commercer to write to Shopify, Shopify processes that data under its own agreement with you.
12. Roles: controller and processor
For personal information that you or your team submit into the service (for example, catalog data that includes personal information, or team-member accounts), Commercer generally acts as a processor and you act as the controller. Our Data Processing Addendum ("DPA") governs that relationship. For information we collect on our own behalf (account registration, billing, marketing-site analytics, and support), Commercer acts as a controller.
13. International transfers
We are based in the United States and process data in the United States and, where our subprocessors are located there, the European Union. Where personal information is transferred out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (including the UK International Data Transfer Addendum and the Swiss addendum), on data-transfer impact assessments where required, and on supplementary technical measures such as encryption in transit and at rest.
14. Security
We use administrative, technical, and organizational measures designed to protect personal information, including transport encryption (TLS 1.2 or higher), storage encryption at rest, access controls, least-privilege permissions, secret management, audit logging, and periodic review of subprocessors and third-party dependencies. No system is perfectly secure; we cannot guarantee absolute security.
15. Children
The service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have collected data from a child, contact privacy@commercer.io and we will delete it.
16. Do Not Track
The marketing website does not respond to Do Not Track browser signals. We do honor the Global Privacy Control signal as an opt-out of "sale" and "sharing" for US visitors from states where that signal is recognized.
17. Changes to this Privacy Policy
We may update this Privacy Policy. We will post the updated version, update the "Effective date," and, for material changes, notify you by email or in-product notice at least fourteen days before the changes take effect.
