Skip to content

Commerce MCP

Policies

Aiptimise Technologies Inc · data-use terms version 2026-09-26

Data-use terms

What you may do with merchant data served by the Aiptimise commerce MCP. Accepting these terms is required before any API key is issued.

Permitted use

  • Use the data only to answer shoppers inside your AI product: product discovery, comparison, availability, price, promotions, loyalty and store policies.
  • Present merchant content as the merchant published it. Do not alter prices, availability, claims or policies in a way that changes their meaning.

No resale or redistribution

  • Do not sell, license, syndicate or otherwise redistribute the data, in whole or in part, to any third party.
  • Do not build a copy of a merchant catalog, price history or inventory dataset from MCP responses.

Caching limits

  • Live offers (price, stock) may be shown only until their `valid_until` time; after that, call the tool again.
  • Catalog and enriched content may be cached for at most 24 hours.
  • Delete cached data for a store within 24 hours of losing access to it.

Merchant control

  • Merchants decide which AI platforms may read their stores and can block you at any time. When a store stops being served, stop presenting its data.
  • Do not try to reach stores or products your key is not served, and do not probe identifiers.

Security and accounts

  • Keep API keys secret, server-side only, and rotate a key immediately if it may have leaked.
  • Your organization is responsible for every request made with its keys and portal accounts. Remove members who leave.

Suspension

  • Aiptimise Technologies Inc may suspend or revoke access for any breach of these terms, abuse, or at a merchant’s request.

Attribution requirements

How shoppers must reach the merchant.

  • Link shoppers to the merchant with the `product_url` returned by the tools, unmodified. It carries the UTM parameters that credit your platform with the visit.
  • Checkout happens on the merchant’s own site. Do not embed third-party checkout or collect payment on the merchant’s behalf.

Naming

  • Name the merchant (the seller returned by the tools) wherever you present its products or offers.

Privacy

What the MCP records about requests.

What is logged

  • Per call: the consumer and the key or OAuth client used, the tool, the store, the outcome, timing and result count.
  • Locale and country from request metadata, used to pick the market. A session reference and, for unauthenticated calls, the client IP are stored only as keyed hashes.
  • When enabled for your consumer, redacted structured search arguments (never the shopper’s prompt): emails and long digit runs are removed. Kept 90 days.

What is never logged

  • Prompts, conversations, raw tool arguments or results, API keys, and shopper identities.

Retention

  • Raw call records are deleted after 90 days; daily aggregates are kept for usage reporting.

Service terms

Tiers, limits and availability.

Tiers

  • Sandbox: the demo store only, low rate limits, for building and review.
  • Production: merchant stores that allow your platform, with the scopes and limits Aiptimise sets after reviewing your application. Merchants are told when you reach production.

Limits and availability

  • Requests over your rate limit are answered with HTTP 429 and `Retry-After`.
  • The service is read-only and may change tool schemas with notice in the portal.