Privacy Policy

Effective August 29, 2026

This policy is written to describe what Adeptra actually does, not a template. It is reviewed alongside our Terms of Service, which governs use of the service.

1. Who we are

Adeptra (“Adeptra,” “we,” “us”) is operated by Adeptra LLC, a Texas limited liability company. For any privacy question, request, or complaint, contact:

privacy@adeptra.ai

2. What Adeptra does

Adeptra audits a merchant’s online store for compliance with AI-shopping-agent standards (UCP, ACP, and related discovery/ readability signals), and generates fix artifacts a merchant or developer can implement. To do this, we analyze the merchant’s own public store pages, product feed, and declared configuration — we do not access anything behind the merchant’s login or admin systems unless the merchant explicitly connects an account (for example, a future Google Merchant Center connection — see Section 10).

3. Data we collect

We collect only what the service needs to function. In practice, this is:

  • Account data — the email address and password you use to sign in (managed by our authentication provider, Supabase Auth), and your account/organization name.
  • Store data you provide — the store URL(s), domain, platform, and product feed URL you register for analysis, plus any opt-in/opt-out attestations you make (e.g. identity-linking or AI-training opt-outs) — stored in our sites table.
  • Analysis results — the outcome of each audit we run against your store: per-signal pass/fail/partial results and supporting evidence (analysis_runs, signals, pillar_scores), generated fix files (artifacts), and downloadable report bundles (exports). None of this is data about you personally — it is data about your store’s public configuration.
  • Billing data — subscription tier and status (subscriptions). Payment card details are never collected or stored by Adeptra directly; Stripe integration is planned but not yet built (see Section 4).
  • Usage/support data — anything you send us directly, such as a support request.

We do not run analytics, advertising, or tracking scripts of any kind on this site or in the dashboard. There is nothing here to opt out of.

4. Who we share data with, and why

We use a small number of infrastructure providers to run the service. Each acts as a processor on our behalf, for the stated purpose only:

  • Supabase — our database, authentication, and file storage provider. All account data, store data, and analysis results are held here.
  • Vercel — our hosting provider. Vercel serves the dashboard and processes requests to it.
  • Resend — sends transactional emails only (for example, “your report is ready”). We do not send marketing email through Resend or any other provider.
  • OpenAI — two of our audit checks (comparing a product’s title/description for consistency, and scoring how complete a product’s structured attributes are) use OpenAI’s API. Only a small, sampled set of your product feed/page content is sent for this specific purpose — never your account credentials, and never more than a few sample products per audit. Per OpenAI’s own published API data usage policy, data submitted via the API is not used to train OpenAI’s models unless a customer explicitly opts in (Adeptra does not opt in). See Section 7 for what this means for deletion requests.
  • Google Merchant Center API — not yet connected. We are building an integration that, once live and only for merchants who explicitly connect their Merchant Center account, will read product data to check eligibility for Google’s AI shopping surfaces more accurately. See Section 10 for the specific commitments that will govern this data once it ships.
  • Stripe — not yet connected. Billing is currently manual. When Stripe is integrated, this policy will be updated before it goes live, and Stripe will process payment data directly — Adeptra will not receive or store card numbers.

We do not sell your data. We do not share it with data brokers, advertisers, or any party for their own independent use.

5. Retention

Honestly: today, there is no automatic retention or deletion schedule. Account and analysis data is kept for as long as your account exists, unless you request deletion (Section 7). We are recording this plainly rather than asserting a retention period we don’t yet enforce. If you request deletion, see Section 7 for exactly what is and isn’t removed today.

6. Security

We protect data with layered, real controls:

  • Row-Level Security (RLS) is enabled on every table in our database that holds customer data — access is enforced at the database layer, not only in application code.
  • Encryption in transit — all traffic to and from Adeptra is served over TLS (HTTPS).
  • Staff access controls — internal staff access to the admin console is gated by role checks enforced at the database layer, and by multi-factor authentication. MFA is enforced for every staff account: a staff member who has not yet enrolled a second factor is routed to enroll one before reaching the admin console, and every session after that must verify that factor before any admin route is served.

7. Your rights, and what we can actually do today

A policy that promises a right we cannot yet deliver is worse than one that states the gap plainly. Here is the honest, current state of each right, for every user regardless of location — not just where a law requires it:

  • Deletion. Email privacy@adeptra.ai to request deletion. We can delete your account, every site you registered, every audit run, every signal result, every generated artifact, and every export record — this cascades cleanly through our database when we delete your account record. Two things require a separate, manual step on our side and are not yet automated: (1) your downloadable report bundles held in file storage (a separate system from the database) must be removed individually, and (2) your login/authentication record must be deleted through a separate call to our authentication provider. Until we automate both, expect deletion to take up to 30 days rather than being instant. Content already sent to OpenAI for the two checks described in Section 4 is subject to OpenAI’s own retention terms (currently up to 30 days for abuse-monitoring purposes) — we cannot force an earlier deletion on OpenAI’s side, and we are recording that limitation here rather than promising something we can’t guarantee.
  • Access / portability. Email privacy@adeptra.ai to request a copy of what we hold about you and your stores. We can produce this today by querying our database directly; a self-serve export button does not exist yet. Expect a response within the windows stated below, not an instant download.
  • Correction (rectification). Your store’s platform selection and compliance attestations can be corrected directly in the dashboard. For anything else (account email, store URL, billing details), email privacy@adeptra.ai.
  • Opt out of sale/sharing. Not applicable — we don’t sell or share your data as those terms are defined under CCPA/CPRA (Section 9), so there is nothing to opt out of.

8. If you are in the EU or UK (GDPR)

Lawful basis for processing. We process account and store data under contract — it is necessary to provide the audit and fix-generation service you signed up for. We process security and abuse-prevention data under legitimate interests. We process data as needed to comply with a legal obligation where one applies (for example, responding to a lawful request).

Your rights. Under GDPR you have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. See Section 7 for what we can deliver today for each of these, honestly.

International transfer. Adeptra is a U.S. company and our infrastructure (Supabase, Vercel) is hosted in the United States. If you are in the EU or UK, your data is transferred to and processed in the U.S. We rely on our providers’ own standard contractual safeguards for this transfer; a lawyer should confirm this is sufficient for our specific processing before launch (see the note at the bottom of this policy).

Response window. We will respond to a verified GDPR request within 30 days.

9. If you are a California resident (CCPA/CPRA)

Categories of personal information we collect: identifiers (email, account name), commercial information (billing tier/status), and internet activity to the extent your store’s own public data is analyzed (this is business/store data, not personal information about you as an individual, in almost every case).

Purpose: solely to provide the audit and fix-generation service, bill for it, and communicate with you about it.

We do not sell or share your personal information as those terms are defined under CCPA/CPRA. Every third party listed in Section 4 receives data only to perform a specific service for us, under our direction, and does not use it for their own independent purposes.

Your rights: to know what we collect, to delete it, to correct it, and to opt out of sale/sharing (not applicable, per above). See Section 7. We will respond to a verified CCPA/CPRA request within 45 days, extendable by another 45 days when reasonably necessary, with notice to you.

10. Google API data — Limited Use disclosure

This section exists specifically to satisfy Google’s API Services User Data Policy Limited Use requirements, for the Google Merchant Center integration described in Section 4.

  • Adeptra’s use of information received from Google APIs is limited to providing and improving the user-facing features of this service — auditing and reporting on your store’s AI-shopping-agent readiness.
  • We do not transfer or sell this data to third parties, including advertising platforms or data brokers.
  • We do not use this data to serve advertising of any kind, including retargeting or interest-based advertising.
  • We do not use this data to train generalized or non-personalized AI or machine-learning models.
  • No human at Adeptra reads this data except where necessary for security, to comply with law, with your affirmative consent, or in aggregate for internal operations — never to read your individual data as a matter of course.
  • You can revoke Adeptra’s access to your Google account data at any time via your Google Account’s third-party access settings, or by emailing privacy@adeptra.ai.

11. Cookies

We use only the essential session cookies our authentication provider (Supabase) sets to keep you signed in. These are strictly necessary for the service to function and are not used for tracking or advertising — no consent banner is required for them under GDPR’s ePrivacy rules, and we don’t set any other kind.

12. Changes to this policy

We will update this policy as the service changes — most immediately, when Google Merchant Center and Stripe integrations actually ship (Section 4), and as data-handling gaps described in Section 7 are closed. Material changes will be reflected here with an updated effective date.

This policy describes our systems and practices as accurately as we can. It is not a substitute for legal advice, and has not yet been reviewed by an attorney — see our internal decision log for the specific review this policy is pending before launch.