Legal

Privacy policy.

Effective September 8, 2026

Summary

This policy is issued by Aisle Commerce, LLC ("Aisle", "we", "us"), 418 Broadway, Albany, New York 12207, the data controller for the processing it describes. Aisle is a scanner for commerce websites, plus a simulated storefront environment for testing shopping agents. We collect the minimum information we need to run the service, maintain your account, and prevent abuse. We do not sell personal data and we do not run advertising trackers. Scan reports are publicly accessible at their permanent URLs. This policy covers aislecommerce.com and storefront.aislecommerce.com.

What we collect

Account information:

  • Email address (required for sign-up).
  • Password, stored only as a one-way hash by our auth provider, if you use password sign-in.
  • If you sign in with Google, the profile Google shares with us: email address, name, and avatar. We never see your Google password.
  • Plan tier and account settings.

Dispatches signups:

  • The email address you submit to receive our dispatches, the date and source of the submission, and, when you sign up from the scan form, the URL you were asking us to scan at the time. You can subscribe without creating an account.

Service usage:

  • URLs you submit for scanning, the scan reports they produce, and the crawl artifacts behind them (copies of the publicly available pages we fetched, kept so reports can be re-scored without re-crawling).
  • Monitoring configurations (which URLs you track) and their scan history.
  • Alert settings, including any extra recipient email addresses you add (for example a developer or agency inbox). We use those addresses only to deliver the alerts you configured; you are responsible for having the recipient's permission, and you can remove them in settings at any time.
  • Simulation runs: the target URL, step-by-step results, screenshots of the tested site, and a session recording of the browser walk. These depict the merchant site, not you.
  • Fix-center engagement: which remediation artifacts you download or copy, tied to your account, so we can see which fixes are actually being used and improve them.
  • Report views: when you are signed in and open a scan report, we record that your account viewed that report and when, so your dashboard can show reports you have looked at.
  • Feedback you submit through the product: the message text, the page you sent it from, and your account, kept so we can respond and improve Aisle.
  • Scan quotas, timestamps, and rate-limit counters.
  • IP address and user agent on requests, used for rate limiting and abuse prevention.
  • Standard server logs, retained briefly for debugging and security.
  • Error reports (when our error monitoring is enabled): stack traces and request context from server failures, used only to fix bugs.

Aisle Storefront:

  • A functional cookie that tracks your progress inside a simulated shopping episode (cart contents, steps completed). It contains no identity and expires with the episode.
  • Your best level scores, stored in your own browser (local storage), never sent to us.
  • Aggregate usage statistics for hosted agent runs (step counts, token counts, completion), with no personal identifiers attached.

Payments (when paid plans are active): handled by our payment processor. We store your customer and subscription identifiers; card numbers never touch our servers.

We do not use third-party advertising or tracking cookies. The cookies we set are strictly necessary or functional: authentication cookies for your session; on the Storefront, episode state; and a scan-claim cookie holding a random token (no identity) for up to 30 days, used only to attach scans you ran before creating an account to that account when you sign up. Page-view analytics on our sites are cookieless and aggregate. Because we do not track users across third-party websites, we do not respond to browser Do Not Track signals; there is no cross-site tracking to turn off.

We may create and use aggregated or de-identified data (for example, readiness statistics across many storefronts, or anonymous agent-run metrics) for any lawful purpose; such data does not identify you and is not personal data.

How we use it

  • To operate the scanner, simulations, and storefront, return reports, and maintain your account and plan.
  • To enforce rate limits and prevent abuse.
  • To improve Aisle (for example, aggregate patterns across scans or which remediation artifacts get used).
  • To send service-related emails (sign-in links, verification, account notices).
  • To send occasional dispatches to subscribers. Dispatches mix educational content (agent-readiness patterns, essays) with product news (rubric updates, feature announcements). Signing up for the dispatches is the opt-in. You can unsubscribe at any time by emailing support@aislecommerce.com or via the unsubscribe link in the email.

AI processing

Report narratives are written by Clerk, Aisle's AI assistant. To produce them, content fetched from the scanned site (which is publicly available by definition) is processed by our AI infrastructure providers. Prompts contain the scanned site's content and our scoring data; they do not contain your account identity, email, or payment information. We do not permit our AI providers to train their models on this data.

Who we share it with

We use a small set of service providers ("subprocessors") who process data on our behalf to run the platform. Each is bound by a data-processing agreement:

  • Supabase: authentication, database, file storage.
  • Vercel: hosting and edge network for both sites, plus cookieless, aggregate page-view analytics.
  • Resend: email delivery for account emails, monitoring alerts, and the dispatches.
  • Google: OAuth sign-in, when you choose it.
  • Upstash: rate-limit counters.
  • Firecrawl: rendered-page fetching of scanned sites on behalf of Aisle.
  • Browserbase: cloud browser sessions for Simulations, including the session recordings described above.
  • OpenRouter: inference routing for Clerk, Aisle's AI assistant. Routes requests across upstream model providers based on availability.
  • Sentry (when enabled): server-side error monitoring.
  • Stripe (when paid plans are active): payment processing and subscription management.

Some further recipients are not subprocessors but receive limited data as part of how the product works. For the Discoverability feature (formerly named Visibility), generic shopping queries are sent to the third-party search and assistant services we measure against: Ceramic and Exa (search services used by AI agents) and, where enabled, OpenAI, Perplexity, Google, and Anthropic, whose assistant answers we record cited sources and recommendations from. The queries may be authored from your storefront's category, the public product catalog observed during your scans, or descriptions and query lists you provide; unless you write them into your own custom queries, they never contain your storefront name, your brand names, or anything identifying you or your customers. When direct crawling of a scanned site is blocked or incomplete, we may query public web archives (the Internet Archive's Wayback Machine and Common Crawl) for that site's URL; the query contains the scanned URL and nothing about you. And the viewer for simulation session recordings loads its player assets from a content-delivery network (jsDelivr), which sees the standard web request your browser makes when you watch a recording.

For the Launch Lab feature, customer reviews are processed to build audience segments and simulated customer panels: reviews published as structured data on a scanned storefront's own product pages, and review exports the storefront operator chooses to upload. We use this data only to provide the feature to that operator, we do not use it to contact anyone, and we ask operators to strip customer contact details before uploading. Review excerpts may appear inside that operator's own study results. Uploaded review data is deleted on account deletion like all other account data.

We do not sell or rent personal data to third parties. We may disclose data: when required by law (subpoena, court order, or comparable legal process); when we believe in good faith that disclosure is necessary to protect our rights or property, investigate fraud or abuse, enforce our Terms of Use, or protect the safety of any person; and in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal data may be transferred to the successor entity subject to this policy's commitments.

Legal bases (EU and UK users)

Where GDPR or UK GDPR applies, we process personal data on these legal bases: performance of a contract (operating your account, running scans and simulations you request, fulfilling purchases); legitimate interests (securing the service, preventing abuse, improving the product, and analyzing aggregate usage, balanced against your rights); consent (the dispatches, which you may withdraw at any time); and legal obligation (tax and accounting records for payments).

Public scan reports and simulated twins

When you run a scan, the resulting report is stored at a permanent, shareable URL (/scan/<id>). Anyone with the link can view the report, and selected reports appear in our public Explore listing. Reports do not include your account email or other account-level personal information; they describe the scanned site's publicly available signals.

Some scans generate a "twin": a simulated storefront styled after the scanned site using its publicly available signals (name, product names, images), clearly labeled as a simulation and hosted on the Storefront. Twins contain no personal data. If you operate a scanned site and want a report or twin removed, contact support@aislecommerce.com.

Signed links

Certain artifacts (for example, the machine-readable fix plan for coding agents) can be shared through signed URLs that work without a login for anyone holding the link. These links expire automatically (currently about 48 hours). Anyone with an unexpired link can fetch that artifact, so share them deliberately.

Retention

  • Account data is retained while your account is active and deleted on verified request.
  • Scan reports and their crawl artifacts are retained indefinitely so shared links remain valid, unless removal is requested.
  • Simulation results (including screenshots) are retained with your account; the underlying cloud browser recordings are additionally subject to our provider's retention window.
  • Dispatches signup emails are retained until you ask us to delete them or unsubscribe.
  • Request logs are retained for up to 30 days for debugging and security.
  • Fix-center engagement records are retained with your account.

Your rights

Depending on where you live (for example, the EU or UK under GDPR, or California under CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to non-discrimination for exercising those rights. To exercise them, email support@aislecommerce.com from the address on file; we will verify the request and respond within the timelines required by applicable law. We do not sell personal data, so there is nothing to opt out of selling.

California residents

In the terms of the CCPA/CPRA, the categories of personal information we collect are: identifiers (email, name if provided by your sign-in provider, IP address); commercial information (purchases, plan tier, scan and simulation history); and internet activity (interactions with our own service, as described above). We collect them from you directly, from your sign-in provider, and from your use of the service. We use them for the business purposes described in "How we use it" and disclose them only to the service providers listed above. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing personal information of consumers under 16. You have the rights to know, access, correct, delete, and port your information, and to not be discriminated against for exercising these rights. You may designate an authorized agent to submit requests on your behalf; we will verify the agent's authority and your identity. California's "Shine the Light" law does not apply to us because we do not disclose personal information to third parties for their direct marketing purposes.

Security

We use TLS for data in transit, encryption at rest through our infrastructure providers, scoped service credentials, and row-level access controls in our database. Admin functions are restricted to designated accounts. No system is perfectly secure; notify us at support@aislecommerce.com if you believe your account has been compromised.

Children

Aisle is not intended for children under 16 and we do not knowingly collect data from them. If you believe a child has submitted personal data to us, contact support@aislecommerce.com and we will delete it.

International transfers

Our service providers operate primarily in the United States. By using Aisle you consent to the transfer and processing of your data in the US and other jurisdictions where our subprocessors operate, subject to the safeguards in their data-processing agreements.

Changes

We may update this policy. Material changes will be posted here with a revised effective date, and, when required, communicated by email.

Contact

Privacy questions or requests: support@aislecommerce.com, or by mail to Aisle Commerce, LLC, 418 Broadway, Albany, New York 12207.

Privacy policy · Aisle