Privacy Policy
# ComOS Privacy Policy
**Effective Date:** April 28, 2026
**Last Updated:** September 22, 2026
---
## Plain English Summary
ComOS is a commerce operating system. Merchants use it to run their stores. AI agents — like Claude, Gemini, or ChatGPT — connect to ComOS through the Federation Gateway to act on a merchant's behalf: searching catalogs, managing carts, completing checkouts, and reviewing orders.
This policy describes what data we collect, how we use it, who we share it with, and what rights you have. We don't sell your data. We don't share it for advertising. We don't train AI models on your data.
---
## 1. Introduction
This Privacy Policy explains how ComOS, operated by **ComOS Federation, Inc.**, a Delaware corporation (incorporated; effective July 20, 2026), with its principal place of business at 7550 Freedom Blvd, Aptos, CA 95003 ("ComOS," "we," "us," or "our"), collects, uses, discloses, and protects information when you use the ComOS commerce operating system, the ComOS Federation Gateway, and our marketing website (collectively, the "Platform"). ComOS Federation, Inc. is the operator, and all obligations under this policy are those of the corporation.
This policy applies to:
- **Merchants**: Businesses using ComOS to operate their commerce stores
- **Managers**: Users with administrative access to a Merchant's account
- **Connected AI Clients**: AI agent platforms (such as Claude.ai, ChatGPT, or Gemini) that a Merchant has authorized to access their tenant via OAuth
- **Website Visitors**: Visitors to comos-portal.com and our documentation
**For end customers of a Merchant's store**: Your data is controlled by that Merchant, not by ComOS. Please refer to the Merchant's privacy policy for information about how they handle your data.
---
## 2. Information We Collect
### 2.1 Information You Provide
**Account Information:**
- Name, email address, phone number
- Business name and address
- Billing information and payment details
- Account credentials
**Business Data:**
- Product catalogs and inventory
- Order and transaction data
- Customer lists and communications
- Analytics, dashboards, and reports you create
**Communications:**
- Support requests and correspondence
- Feedback and survey responses
### 2.2 Information Collected Automatically
**Usage Data:**
- Pages visited and features used
- Time spent on the Platform
- Actions taken (clicks, searches, agent runs)
- Error logs and performance data
**Device and Technical Data:**
- IP address and approximate location
- Browser type and version
- Operating system
- Device identifiers
**Cookies and Tracking:**
- Session cookies for authentication
- Preference cookies for settings
- Analytics cookies for usage data
### 2.3 Information from Third Parties
- Payment processor transaction data
- Identity verification services
- Public business information
- Integration partners (when you connect third-party services)
### 2.4 MCP and AI Agent Connections
When a Merchant connects an AI client (such as Claude.ai) to the ComOS Federation Gateway via OAuth, ComOS collects and processes:
- **OAuth tokens and credentials**: access tokens, refresh tokens, scope grants, and the client identifier of the connected AI service
- **MCP audit logs (metadata only)**: for each MCP tool call, ComOS records that a named tool was invoked — the tool name, the tenant ID, the calling agent/OAuth identity, the scope required versus the scope granted, the allow/deny outcome, the timestamp, and the call latency. **ComOS does not store the argument values passed to a tool, and does not store the response bodies returned by a tool, in the audit log.** The audit trail is a record of *which tool was invoked against which tenant, under what authorization, with what outcome* — not a copy of the request or response payloads.
- **Federation routing data**: which tenant a request was routed to and latency.
These records are stored under the Merchant's tenant for authorization audit, security, and abuse prevention. MCP audit logs are retained for **90 days**, then automatically deleted by a database time-to-live (TTL) policy.
The OAuth scopes a Merchant can grant are:
- `agents:read` — read agent metadata and run history
- `agents:admin` — run and configure autonomous agents
- `cart:manage` — read and modify cart state
- `orders:read` — read order history and status
- `orders:write` — create or modify orders
- `catalog:write` — modify catalog (categories, products)
A Merchant can revoke an active OAuth connection at any time, in either of two ways: (1) **self-serve** — the connected client calls the Gateway's standard OAuth token-revocation endpoint (`POST /oauth/revoke`, RFC 7009), and the revoked token stops authorizing within seconds across all Gateway instances; or (2) by emailing **support@comos-federation.com**, and ComOS will revoke the connection on the Merchant's behalf. Revocation does not undo actions already taken by the client before revocation.
---
## 3. How We Use Your Information
### 3.1 To Provide the Service
- Create and manage your account
- Process transactions and payments
- Provide customer support
- Send service-related communications
- Maintain and improve the Platform
### 3.2 For Business Operations
- Analyze usage and improve features
- Detect and prevent fraud and abuse
- Ensure security and prevent unauthorized access
- Comply with legal obligations
- Enforce our Terms of Service
### 3.3 For Communications
- Send product updates and announcements
- Provide tips and best practices
- Marketing communications (with consent)
### 3.4 For AI Features and Connected Agents
- Power in-Platform AI features (search, recommendations, automation, brand voice, policy enforcement)
- Route MCP tool calls from connected AI clients to the correct tenant
- Generate audit logs and monitor for abuse
**ComOS does not use your business data, customer data, or MCP tool-call data to train any AI model, our own or a third party's.** Where we use third-party AI processors (see Section 4.1), we have not enabled any data-sharing-for-training option offered by those providers; however, training-policy guarantees are ultimately governed by each provider's own terms.
---
## 4. How We Share Your Information
### 4.1 Service Providers
We share information with vendors who help operate the Platform:
- **Cloud Infrastructure (Google Cloud, MongoDB Atlas)**: Hosts and stores Platform data in the United States.
- **AI Model Provider (Google Vertex AI / Gemini)**: Powers in-Platform AI features (search, recommendations, brand voice, policy engine, NLU intent detection, RAG retrieval).
- **Payment Processor (Stripe)**: Processes payments and prevents fraud on behalf of Merchants.
- **Email Delivery (Resend)**: Sends transactional and marketing emails.
This is the complete list of ComOS sub-processors and it is identical to Appendix A of the [Data Processing Agreement](/legal/data-processing-agreement). All sub-processors are contractually required to protect your data. All service providers are located in the United States.
### 4.2 Connected AI Clients (Merchant-Authorized)
When a Merchant connects an AI client to the ComOS Federation Gateway, the connected AI client — chosen by the Merchant (e.g. Claude, ChatGPT, Gemini, or other) — processes prompts, tool arguments, and tool responses to perform the actions the Merchant has authorized. Each AI provider is governed by its own terms and privacy policy, and the Merchant is responsible for reviewing those terms before connecting that provider.
ComOS does not control what data a Merchant or end-user submits to a connected AI client. Once data is sent to a connected AI client, it is processed under that provider's terms.
### 4.3 Legal Requirements
We may disclose information when required to:
- Comply with law, regulation, or legal process
- Respond to lawful requests from authorities
- Protect rights, property, or safety
- Enforce our Terms of Service
### 4.4 Business Transfers
In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to this Privacy Policy.
### 4.5 With Your Consent
We may share information for other purposes with your explicit consent.
### 4.6 What We Don't Do
- We do **not** sell your personal information.
- We do **not** share your data for third-party advertising.
- We do **not** share your business data with competitors.
- We do **not** train AI models on your data.
---
## 5. Data Retention
### 5.1 Active Accounts
We retain your data while your account is active and as needed to provide services.
### 5.2 After Termination
After account termination:
- **30 days**: Data available for export
- **90 days**: Data deleted from production systems
- **1 year**: Data purged from backups
### 5.3 MCP Audit Logs
MCP audit logs (call metadata, as described in §2.4 — not tool arguments or responses) are retained for **90 days** from the date of the event, then automatically deleted by a database TTL policy.
### 5.4 Extended Retention
We may retain data longer when required for legal obligations (tax records, compliance), dispute resolution, or fraud prevention.
---
## 6. Your Rights and Choices
### 6.1 Access and Portability
- Access your data through the Platform dashboard
- Export your data in standard formats (CSV, JSON)
- Request a copy of personal data we hold about you
### 6.2 Correction and Deletion
- Update account information in settings
- Request correction of inaccurate data
- Request deletion of your account and data
### 6.3 Marketing Communications
- Opt out of marketing emails via unsubscribe link
- Manage communication preferences in settings
### 6.4 OAuth Connection Management
- Revoke an active OAuth connection yourself via the Gateway's standard OAuth token-revocation endpoint (`POST /oauth/revoke`, RFC 7009); the revoked token stops authorizing within seconds. Alternatively, email **support@comos-federation.com** and we will revoke the connection for you.
- Request a list of currently active OAuth connections at **support@comos-federation.com**.
### 6.5 Cookies
- Manage cookies through browser settings or our cookie preference center.
### 6.6 How to Exercise Rights
Email **support@comos-federation.com** with your account email and the specific request. We respond within 30 days.
---
## 7. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- **Right to Know** — Request the categories and specific pieces of personal information collected, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share data.
- **Right to Delete** — Request deletion of your personal information, subject to legal exceptions.
- **Right to Opt-Out of Sale** — We do not sell personal information.
- **Non-Discrimination** — We will not discriminate against you for exercising your privacy rights.
- **Authorized Agents** — You may designate an authorized agent to make requests on your behalf.
---
## 8. European Privacy Rights (GDPR)
If you are in the European Economic Area, UK, or Switzerland, you have rights under the General Data Protection Regulation:
### 8.1 Legal Basis for Processing
- **Contract**: To provide services you requested
- **Legitimate Interests**: For business operations, security, abuse prevention, and improvement
- **Consent**: For marketing communications
- **Legal Obligation**: To comply with laws
### 8.2 Your Rights
- **Access**: Obtain a copy of your data
- **Rectification**: Correct inaccurate data
- **Erasure**: Request deletion ("right to be forgotten")
- **Restriction**: Limit processing of your data
- **Portability**: Receive data in machine-readable format
- **Object**: Object to processing based on legitimate interests
- **Withdraw Consent**: Withdraw consent at any time
### 8.3 International Transfers
We transfer data to the United States. We rely on Standard Contractual Clauses approved by the European Commission to protect EEA/UK/Swiss personal data.
### 8.4 Privacy Inquiries
For GDPR-related inquiries, contact **support@comos-federation.com**.
### 8.5 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
---
## 9. Data Security
### 9.1 Security Measures
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- OAuth 2.1 with PKCE for all Federation Gateway connections (RFC 8414, RFC 9728)
- Per-tenant scope-based authorization on every MCP tool call
- Timeout-bounded upstream calls with session recovery to isolate misbehaving connections
- Multi-factor authentication available on Merchant accounts
- Access controls and audit logging
- Incident response procedures
### 9.2 Your Responsibilities
- Maintain strong account credentials
- Enable two-factor authentication
- Control access by your team members and connected AI clients
- Review and revoke OAuth connections you no longer use
- Report suspected security incidents promptly to **support@comos-federation.com**
### 9.3 Breach Notification
In the event of a data breach affecting your personal information, we will notify affected parties without undue delay and in any case within **72 hours** of becoming aware of the breach where required by GDPR, and in accordance with applicable law in other jurisdictions.
### 9.4 Data Storage Location
Tenant data is stored in Google Cloud and MongoDB Atlas in the United States. Transfers from the EEA, UK, or Switzerland to the United States are governed by Standard Contractual Clauses.
---
## 10. Merchants as Data Controllers
### 10.1 Customer Data
When Merchants collect end-customer data through ComOS:
- The **Merchant is the Data Controller**.
- **ComOS is the Data Processor**.
Merchants are responsible for:
- Providing privacy notices to their customers
- Obtaining necessary consents
- Responding to customer data subject requests
- Ensuring lawful data collection and use
- Reviewing the privacy and data-handling terms of any AI client they connect via OAuth
### 10.2 Data Processing Agreement
Our [Data Processing Agreement](/legal/data-processing-agreement) ("DPA") is **incorporated by reference into the [Terms of Service](/legal/terms-of-service) and applies automatically** — with no separate signature or request required — to any Merchant who processes personal data of data subjects protected by GDPR, UK GDPR, or CCPA. You do not need to request it; accepting the Terms puts the DPA into effect for your processing. A countersigned copy for your records is available on request at **support@comos-federation.com**.
---
## 11. Children's Privacy
The Platform is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, contact us at **support@comos-federation.com** and we will delete it.
---
## 12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated with at least 30 days' notice by:
- Posting the updated policy with a new effective date
- Sending an email notification to active Merchants
- Displaying an in-Platform notice
Continued use after the effective date constitutes acceptance.
---
## 13. Contact Us
**ComOS** — operated by ComOS Federation, Inc., a Delaware corporation (incorporated; effective July 20, 2026)
7550 Freedom Blvd
Aptos, CA 95003
United States
Email: **support@comos-federation.com**
---
*By using ComOS, you acknowledge that you have read and understood this Privacy Policy.*