Commerce MCP
Policies
Aiptimise Technologies Inc · data-use terms version 2026-09-26
Data-use terms
What you may do with merchant data served by the Aiptimise commerce MCP. Accepting these terms is required before any API key is issued.
Permitted use
- Use the data only to answer shoppers inside your AI product: product discovery, comparison, availability, price, promotions, loyalty and store policies.
- Present merchant content as the merchant published it. Do not alter prices, availability, claims or policies in a way that changes their meaning.
No resale or redistribution
- Do not sell, license, syndicate or otherwise redistribute the data, in whole or in part, to any third party.
- Do not build a copy of a merchant catalog, price history or inventory dataset from MCP responses.
Caching limits
- Live offers (price, stock) may be shown only until their `valid_until` time; after that, call the tool again.
- Catalog and enriched content may be cached for at most 24 hours.
- Delete cached data for a store within 24 hours of losing access to it.
Merchant control
- Merchants decide which AI platforms may read their stores and can block you at any time. When a store stops being served, stop presenting its data.
- Do not try to reach stores or products your key is not served, and do not probe identifiers.
Security and accounts
- Keep API keys secret, server-side only, and rotate a key immediately if it may have leaked.
- Your organization is responsible for every request made with its keys and portal accounts. Remove members who leave.
Suspension
- Aiptimise Technologies Inc may suspend or revoke access for any breach of these terms, abuse, or at a merchant’s request.
Attribution requirements
How shoppers must reach the merchant.
Links
- Link shoppers to the merchant with the `product_url` returned by the tools, unmodified. It carries the UTM parameters that credit your platform with the visit.
- Checkout happens on the merchant’s own site. Do not embed third-party checkout or collect payment on the merchant’s behalf.
Naming
- Name the merchant (the seller returned by the tools) wherever you present its products or offers.
Privacy
What the MCP records about requests.
What is logged
- Per call: the consumer and the key or OAuth client used, the tool, the store, the outcome, timing and result count.
- Locale and country from request metadata, used to pick the market. A session reference and, for unauthenticated calls, the client IP are stored only as keyed hashes.
- When enabled for your consumer, redacted structured search arguments (never the shopper’s prompt): emails and long digit runs are removed. Kept 90 days.
What is never logged
- Prompts, conversations, raw tool arguments or results, API keys, and shopper identities.
Retention
- Raw call records are deleted after 90 days; daily aggregates are kept for usage reporting.
Service terms
Tiers, limits and availability.
Tiers
- Sandbox: the demo store only, low rate limits, for building and review.
- Production: merchant stores that allow your platform, with the scopes and limits Aiptimise sets after reviewing your application. Merchants are told when you reach production.
Limits and availability
- Requests over your rate limit are answered with HTTP 429 and `Retry-After`.
- The service is read-only and may change tool schemas with notice in the portal.