Our Privacy Policy

Effective September 14, 2026

This privacy policy explains what information Ayasoftware ("we", "us") collects and how we use it when you visit ayasoftware.com, use the customer portal, connect a Magento store to the Magento Store Assistant (our Model Context Protocol service used from ChatGPT, Claude, Codex and other AI assistants), or buy our Magento extensions.

1. Information we collect

Account information. When you create an account we store your name, email address and, if you sign in with Google, your Google account ID and profile picture. If you register with a password we store only a salted hash of it.

Billing information. Subscriptions and extension purchases are processed by Stripe. We store your Stripe customer and subscription identifiers, plan status and invoice history. We never see or store full payment card numbers.

Magento store connection. To use the Magento Store Assistant you provide your store's URL and a Magento integration access token. In database mode these are stored in our database and used only to call your store's REST API on your behalf. In runtime mode they are sent with each request by your own MCP client and are never stored on our servers.

Connected applications. When you connect an AI assistant such as ChatGPT through OAuth, we store an access token and refresh token for that connection, the application's name, the permissions you granted, and when the connection was created and last used. You can revoke any connection from the dashboard at any time.

Store data processed on your behalf. When you or your AI assistant run a tool, we retrieve the requested data from your Magento store (for example products, categories, orders, customers, inventory, promotions, reviews, CMS content and sales reports) and return it to the assistant you are using. This data is processed transiently to answer the request. We do not build profiles from it and we do not retain it, except that generated charts are cached for up to one hour at unguessable URLs and server logs may record request metadata (see below). Payment card details, gateway payloads, IP addresses of your shoppers and authentication secrets are removed from tool responses before they are returned.

Service logs. Our servers record request metadata such as timestamps, the tool that was called, response status, and the IP address of the client, for security, abuse prevention and troubleshooting. Logs are rotated on a rolling basis and are not used for marketing.

Website usage. Like most websites we use cookies and Google Analytics to understand traffic to ayasoftware.com. Our contact and registration forms are protected by Google reCAPTCHA, which may collect device and interaction data under Google's privacy policy.

2. How we use information

  • To provide the customer portal, the Magento Store Assistant and the extension store, and to authenticate you and the applications you connect.
  • To call your Magento store's API only when you or your AI assistant ask us to.
  • To process payments, manage subscriptions and trials, and deliver licence keys.
  • To secure the service, enforce rate limits, prevent abuse and diagnose problems.
  • To respond to support requests and send service notices about your account.

We do not sell personal information and we do not use your store data to train AI models.

3. AI assistants and other third parties

The Magento Store Assistant works inside third-party AI platforms such as OpenAI's ChatGPT, Anthropic's Claude and OpenAI's Codex. When you use the assistant from one of those platforms, the store data you request is delivered to that platform and is then handled under its own terms and privacy policy. We only send data in response to requests you authorise through that platform.

We also rely on the following providers to run the service: Microsoft Azure (hosting), Stripe (payments), Google (sign-in, analytics, reCAPTCHA) and our email delivery provider (transactional email). Each receives only the information needed to perform its function.

We may disclose information when required by law, to protect our rights or the safety of others, or to investigate fraud or unauthorised transactions.

4. Retention

  • Account and billing records are kept while your account exists and as required for tax and accounting purposes.
  • Stored Magento credentials are kept until you remove them or delete your store configuration in the dashboard.
  • OAuth access tokens expire after one hour; refresh tokens expire after thirty days of inactivity or immediately when you disconnect the application.
  • Store data retrieved for a tool call is not retained beyond the request, other than the one-hour chart cache described above.
  • Service logs are rotated automatically and typically kept for no more than a few weeks.

5. Your choices and controls

  • Update or remove your store credentials, regenerate your API key, or switch to runtime mode from the dashboard.
  • Disconnect any connected application from the "Connected Apps" section of the dashboard.
  • Cancel your subscription from the dashboard billing section.
  • Ask us to export or delete your account and associated data by contacting us. We will respond within 30 days.

6. Security

All traffic to our services is encrypted with TLS. Passwords are hashed, OAuth tokens and authorization codes are stored only as cryptographic hashes, and access to production systems is restricted to authorised staff. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, and you should keep your API key and Magento tokens confidential.

7. Children

Our services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.

8. Changes to this policy

We may update this policy from time to time. The effective date at the top of the page shows when it was last revised. Material changes will be announced on this page or by email to account holders.

9. Contact

Questions about this policy or your data can be sent through our contact page.