Privacy Policy

Last updated 2026-09-07. Operated by ooasis. Contact: sunh11373@yahoo.com.

UCP Agent ("the service") lets AI shopping agents place orders on a merchant's store through the Universal Commerce Protocol (UCP). This policy describes what the service processes on behalf of merchants who install it.

Data the service processes

How data is used

Only to execute checkouts and keep the merchant's platform order in sync: quoting, charging through the merchant's own Stripe account, creating the order, and sending order-status webhooks back to the agent platform that placed the order. The service does not sell data, does not build marketing profiles, and does not use buyer data for its own purposes.

Sharing

Data is shared only with the merchant's commerce platform, the merchant's Stripe account, and the agent platform that placed the order. Infrastructure is hosted on Cloudflare.

Retention

Merchant configuration is kept while the app is installed. Uninstalling disables the tenant and removes platform credentials. Checkout sessions and order records are retained for order reconciliation and can be deleted on request from the merchant.

Security

All endpoints are served over HTTPS. Inbound agent requests may be verified with RFC 9421 HTTP message signatures; outbound webhooks are signed. Platform webhooks are verified against the platform's signing keys. Secrets are encrypted at rest under a key held outside the database.

Your rights

Merchants can request export or deletion of their data at any time by contacting sunh11373@yahoo.com. Buyers should contact the merchant they purchased from; the service acts as a processor on the merchant's behalf.