In Plain Language
- • We collect only what we need to run your stores and improve the platform.
- • Your store business data (orders, products, customers) stays in your isolated environment. We don't read it.
- • We send store configuration (not secrets, not business data) to our AI provider for AI features.
- • We never sell your data or share it with advertisers.
- • You can export all your data and delete your account at any time.
1. Who We Are
Reqursor Technologies (“Reqursor”, “we”, “us”) is an AI platform that builds, migrates, and operates ecommerce stores for agencies. We are the data controller for the data we process about you and your organization.
2. Data We Collect
Account Data
When you create an account: name, email address, organization name, and authentication credentials (password stored as a salted hash, never in plaintext).
Store Configuration Data
Store definitions, design tokens, page compositions, managed configuration, deployment history, and run artifacts. This is the data that powers the deterministic execution engine.
Store Business Data
Product catalogs, customer orders, media uploads, and WooCommerce settings that are not managed by Reqursor. This data lives in your store's isolated Docker volumes and is not accessed, processed, or read by Reqursor except during AI migration (with your explicit consent, read-only, and only for the duration of migration).
Usage Data
Platform usage metrics: deployment counts, AI operation counts, feature usage patterns. Used to improve the product and calculate billing. No personally identifiable information from your store visitors is collected.
AI Interaction Data
When you use AI features, we send store configuration metadata (design tokens, block configurations, drift evidence) to our AI provider (Anthropic / Claude API). We never send: secret values, database credentials, store business data, customer information, or data from other organizations.
3. How We Use Your Data
- • To operate the platform: provision stores, execute deployments, detect drift, perform rollbacks.
- • To power AI features: generate stores from natural language, migrate existing stores, diagnose issues, propose remediations.
- • To bill you: track store counts, AI operations, and resource usage.
- • To improve the platform: aggregate, anonymized usage patterns to prioritize features.
- • To communicate: service notifications, security alerts, product updates (with your consent).
4. AI Provider Data Handling
Our AI features use the Anthropic Claude API. Data sent to the AI provider is:
- • Scoped to one tenant per request — no cross-organization data in any AI prompt.
- • Minimized — only the configuration metadata needed for the specific operation.
- • Excluded from training — Anthropic does not train models on API customer data.
- • Free of secrets — passwords, API keys, salts, and credentials are never included.
- • Free of business data — orders, products, and customer records are never included.
5. Data Isolation
Each organization operates in structural isolation. Your stores run in dedicated Docker containers with private networks and volumes. No store can access another store's data. No organization can see another organization's configuration, health status, or operational data. This is enforced architecturally, not by policy.
6. Data Retention
- • Store definitions: retained as long as the organization exists.
- • Deployment artifacts: 90 to 365 days depending on type.
- • Audit logs: 365 days.
- • AI interaction logs: 30 days.
- • After account deletion: all data permanently purged within 30 days of the grace period ending.
7. Your Rights
Under GDPR and applicable data protection laws, you have the right to:
- • Access your data (via the Data Export feature).
- • Portability — export in standard formats (JSON, CSV).
- • Rectification — update your profile and organization data.
- • Erasure — delete your account and all associated data.
- • Object to processing for analytics (via cookie preferences).
8. Cookies
We use essential cookies for authentication and session management (required). Optional cookies include analytics (to understand usage patterns) and error reporting (Sentry, to fix bugs). You can manage your preferences via the cookie banner or in your account settings under Data & Compliance.
9. Security
We use TLS encryption for all data in transit, encrypt secrets at rest, enforce per-store isolation via Docker, drop all Linux capabilities from containers, and never store plaintext credentials in Git, logs, or artifacts. See our Security Architecture for full details.
10. Contact
Data Protection Contact
[email protected] · Reqursor Technologies, Rotterdam, Netherlands