Privacy Policy
Last updated September 6, 2026
Onticord connects to the systems a merchant already runs and does work inside them on the merchant's instructions. We collect what we need to sign you in, run the workflows you delegate, keep a record of what happened, and bill you. We do not sell personal information, and we do not use your customers' data to train AI models.
Who this policy covers
This policy explains how Onticord (“Onticord”, “we”, “us”) handles personal information when you visit onticord.ai, create an account, connect an AI agent, or use the Onticord service (together, the “Service”).
It covers three kinds of people:
- Visitors to this website.
- Merchants and their teams: the people who create an Onticord account, set up a business, and delegate work to Onticord.
- A merchant's customers: the shoppers and subscribers whose orders, tickets, subscriptions, and messages live in the systems a merchant connects. We process that information on the merchant's behalf and under the merchant's instructions. If you are a merchant's customer and have questions about how your information is handled, contact the merchant first; their privacy policy governs, and we will help them respond.
Information we collect
Information you give us
- Account details: your name, email address, and password (stored hashed), plus the name of your business and your role in it.
- Team details: the email addresses of people you invite, the roles and permissions you assign, and the notification preferences you set.
- Billing details: when paid plans are enabled, your billing contact and the subscription you choose. Card details go directly to our payment processor; we never see or store full card numbers.
- Messages to us: anything you send to our support or legal contacts.
Information from your AI agent
When you connect an agent such as Claude, ChatGPT, Cursor, or another client that supports the Model Context Protocol (MCP), we receive the requests that agent makes on your behalf: the workflows it asks Onticord to start, the inputs it provides, and the status it checks. Each agent connection is authorized by you through OAuth and stays bound to the business you chose when you authorized it. We do not receive your conversation history with the agent, only the requests it sends to Onticord.
Information from the systems you connect
When you connect a system such as Shopify, Gorgias, ShipBob, Recharge, Klaviyo, or a loyalty, returns, or shipping provider, Onticord reads and, where you have allowed it, writes the business records needed for the workflows you run. Depending on the workflow, that can include:
- orders, fulfillments, shipments, tracking events, returns, and refunds;
- customer profiles, order history, subscription status, loyalty balances, and marketing consent;
- support tickets and the messages inside them;
- product, inventory, review, and campaign data.
Access is scoped to the permissions you grant during each connection's OAuth consent. Provider access tokens are held in a separate credential vault and are never exposed to your agent, to other members of your business, or to other Onticord customers.
Information collected automatically
- Service logs: request metadata such as IP address, browser or client type, timestamps, and the pages or endpoints used, retained for security and reliability.
- Audit records: for every workflow run, the evidence gathered, the plan proposed, who approved or declined each step, the actions performed in your systems, and their outcomes. Audit records are a core feature of the Service, so you can always see what Onticord did and why.
- Cookies: a session cookie to keep you signed in and, where present, a cookie that remembers which business you last selected. We do not use advertising cookies or third-party tracking pixels on this site.
How we use information
- To provide the Service: sign you in, run the workflows you delegate, prepare recommendations, carry out approved actions in your connected systems, and show you what happened.
- To bring decisions to a person: send approval requests and notifications by email, Slack, or the channel you choose.
- To keep the Service safe and reliable: detect abuse, enforce permissions, investigate incidents, and keep audit trails.
- To bill you and communicate about your account, including service and security notices.
- To improve the Service, using aggregated or de-identified information about how workflows perform.
- To comply with law and enforce our Terms of Use.
How AI is used
Onticord uses large language models to interpret evidence, summarize what happened, and draft proposed actions and customer messages. Business records needed for a specific workflow are sent to our model provider for that purpose only. Our model providers process this information under contracts that prohibit using it to train their models. Model output is treated as a proposal: anything that reaches a customer, changes a subscription, or moves money waits for a human decision in your business, and provider data is never treated as an instruction to Onticord.
When we share information
We do not sell personal information and we do not share it with advertisers. We share information only:
- With the systems you connect, to read from them and carry out the actions you approve. Those providers handle the information under their own terms with you.
- With your AI agent, which receives workflow status, identifiers, available actions, and non-secret setup details in response to its requests. It never receives provider credentials or approval links that could authorize a protected action.
- With members of your business, according to the roles and permissions you set.
- With service providers that help us run Onticord: cloud hosting and databases, durable workflow execution, our AI model provider, an integration and credential vault, transactional email, Slack delivery when you enable it, payment processing when billing is enabled, and error monitoring. Each is bound by contract to use information only to provide its service to us.
- When required by law, to respond to valid legal process, protect the rights and safety of merchants, their customers, or Onticord, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you before your information becomes subject to a different policy.
International transfers
Onticord is operated from the United States and our service providers may process information in the United States and other countries. Where we transfer personal information out of the United Kingdom, the European Economic Area, or Switzerland, we rely on standard contractual clauses or another lawful transfer mechanism.
Retention
- Account and business records are kept while your account is active and deleted or de-identified within 90 days after you close it, except where we must keep them for legal, billing, or security reasons.
- Workflow evidence and audit records are kept for as long as your business exists, because they are the record of what Onticord did in your systems. You can ask us to delete a business and its records at any time.
- Provider tokens are revoked and deleted when you disconnect a system or close your account.
- Service logs are kept for up to 12 months.
Security
We use encryption in transit and at rest, isolate each business's data at the database level, keep provider credentials in a separate vault, require OAuth consent for every agent and system connection, and record every action Onticord takes. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you without undue delay and tell you what we know.
Your choices and rights
- You can view and update your account details, disconnect systems, revoke agent connections, and remove team members from within the Service or through your agent.
- You can close your account or delete a business by contacting us at [email protected].
- Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to complain to a data protection authority. We honor those rights as required by law and will respond within the time the law allows.
- We do not discriminate against anyone for exercising their privacy rights.
If you are a merchant's customer, we will pass your request to the merchant and help them respond, since they decide how their customer information is used.
Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
When we make material changes we will update the date above and, for changes that affect how we use your information, notify account owners by email before the changes take effect.
Contact
Questions, requests, or concerns about privacy can be sent to [email protected].
See also the Terms of Use.