Last updated: 11 July 2026
This Privacy Policy explains how the Angeo MCP Checkout connector (“the Connector”, “we”, “us”) handles data when it is used through an AI assistant such as Claude. It applies to the Model Context Protocol (MCP) endpoint operated at mcp.angeo.dev and to the open-source module angeo/module-mcp-checkout when connected to an AI assistant.
1. Who we are
The Connector is operated by Angeo (angeo.dev), based in the Netherlands. Angeo is the data controller for the limited operational data described in section 5. For questions about this policy or your data, contact us at info@angeo.dev.
2. What data we process
The Connector enables an AI assistant to complete a guest checkout on a Magento 2 / Adobe Commerce store. To do this, it passes through the following data that you provide during a checkout conversation:
- Contact details: first name, last name, email address, and telephone number
- Shipping address: street, city, region/state, postcode, and country
- Order details: the products, quantities, and totals you choose to purchase
- Optional company name, if provided
The Connector does not collect, request, or process payment card data. Card payment, where applicable, is completed separately through the store’s own PCI-compliant payment gateway or a payment link, entirely outside the Connector. The Connector never holds, transfers, or has access to funds.
3. What we deliberately do NOT collect
The Connector is designed for data minimisation. It does not:
- collect, read, or store your conversation with the AI assistant, or any part of it, including for logging purposes;
- access, query, or store the AI assistant’s memory or your previous chats;
- access, query, or store your files;
- store the contents of the requests or responses that pass through it (see section 5);
- use your data to train any AI model;
- serve advertising, sponsored content, or product placements.
The Connector requests only the data strictly necessary to place the order you have asked for, and nothing else.
4. How we use this data
The data listed in section 2 is used solely to create and place your order in the merchant’s store. Specifically, it is passed to the connected Magento store to:
- Create a guest shopping cart and add the products you select
- Calculate shipping options for your address
- Set the shipping and billing details on the order
- Place the order in the store on your instruction and after your explicit confirmation
We do not use your data for advertising, profiling, or any purpose unrelated to completing the order you requested. Under the GDPR, our legal basis for this processing is the performance of a contract you have requested (Art. 6(1)(b)), and, for the security logging described in section 5, our legitimate interest in operating the service securely (Art. 6(1)(f)).
5. Data storage and retention
The Connector does not maintain a persistent store of your personal data. The checkout data you provide is passed through to the connected merchant’s Magento store, where it becomes part of that store’s order records and is subject to the merchant’s own privacy policy and retention practices. The Connector does not retain a copy.
Operational log. For security, rate-limiting, and abuse prevention, the Connector writes a minimal technical log entry per request containing only:
- a timestamp;
- the identifier of the connecting application and the authorised session;
- the name of the tool that was invoked (for example,
search_products); - whether the request succeeded, and how long it took.
This log deliberately excludes the contents of requests and responses. It therefore contains no names, addresses, email addresses, telephone numbers, order contents, order references, or payment information. Access tokens are never logged.
Retention. Operational log entries are retained for a maximum of 90 days and are then deleted. Authorisation records (issued access and refresh tokens) are retained only for the lifetime of the token and are deleted or invalidated on expiry or on disconnection.
Location. Data processed by the Connector is stored on servers located in the European Union. No personal order data is retained by the Connector outside the pass-through described above.
6. Sharing with third parties
Your order data is shared only with:
- The merchant’s Magento store you are checking out on — this is the destination of your order and the essential purpose of the Connector.
- Infrastructure providers used to host and operate the endpoint, acting solely as processors on our behalf, under contract and within the European Union.
We do not sell your personal data, we do not share it with advertisers, and we do not share it with any unrelated third party.
7. The AI assistant
The Connector is invoked through an AI assistant (for example, Claude, operated by Anthropic). Your conversation with the assistant is governed by that assistant provider’s own privacy policy, not by this one. The Connector receives only the specific checkout data the assistant sends to it in order to fulfil your request, and has no visibility into the rest of your conversation.
8. Security
The Connector applies the following safeguards:
- All traffic is served exclusively over HTTPS (TLS). Plain HTTP is rejected.
- Access is authenticated using OAuth 2.1 with PKCE (S256). Unauthenticated and invalid requests are rejected.
- Every access token is verified on every request, including its signature, issuer, expiry, and intended audience. Tokens issued for a different service are rejected.
- Your access token is never forwarded to the merchant’s store. The Connector authenticates to the store with its own separate credential, so your credentials are never re-used elsewhere.
- Rate limiting protects against abuse.
- Order placement requires explicit user confirmation and is never performed autonomously.
9. Your rights
Because order data becomes part of the merchant’s store records, requests to access, correct, or delete that data should be directed to the merchant operating the store, who is the controller of those records. For the limited operational data processed by the Connector (section 5), you may contact us at info@angeo.dev to exercise your rights.
Depending on your location, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right to lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
10. Disconnecting
You can disconnect the Connector at any time in your AI assistant’s settings. On disconnection, the assistant removes its stored tokens. You may also contact us at info@angeo.dev to request that we invalidate any tokens issued to you.
11. Children
The Connector is not directed at children and is not intended to be used by anyone under the age required to enter into a purchase contract in their jurisdiction.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be reflected on this page.
13. Contact
For any questions about this Privacy Policy or about how the Connector handles data, contact:
Angeo
Email: info@angeo.dev
Web: https://angeo.dev