Privacy Policy

How data is handled across the ClaiStore website, the ClaiStore WordPress plugin, and the ClaiStore Connector Broker.

Last updated: 10 September 2026

1. Who we are

ClaiStore ("ClaiStore", "we", "us") publishes the claistore.com website, the ClaiStore — WordPress & WooCommerce MCP for ChatGPT & Claude plugin, and the ClaiStore Connector Broker hosted at broker.claistore.com. This policy explains what personal data each of these processes and why.

2. Scope and our roles

  • Website (claistore.com) — we are the data controller. It is a static marketing site; see section 3.
  • ClaiStore plugin — the plugin is self-hosted on a WordPress site that you operate. It runs on your server, under your control. For the content, customers, orders and analytics inside your site, you are the data controller and ClaiStore has no access to that data unless it passes through the Connector Broker (section 5).
  • Connector Broker — an optional agency-hosted relay that connects your site to Meta and Google when you choose to use those channels. For data that flows through it, ClaiStore acts as your data processor / service provider, processing it only on your instructions to deliver the feature you enabled.

3. The website

The website is a set of static pages. It:

  • sets no advertising or tracking cookies and embeds no third-party analytics or social pixels;
  • is served through a content-delivery network (Cloudflare), which keeps short-lived, aggregated request logs (IP address, timestamp, URL, user agent) for security and abuse prevention on our behalf;
  • loads the 3D graphics library three.js from the Cloudflare (cdnjs) CDN when you view the home page — a standard asset request, not a tracking call.

We do not build profiles of website visitors and we do not sell any data.

4. The ClaiStore plugin

On activation the plugin operates entirely within your WordPress installation. It creates a dedicated low-privilege agent account, issues an MCP access token and an application password (shown once), seeds writing-skill templates from your setup answers, and exposes an authenticated Model Context Protocol endpoint so AI assistants you authorise can read and act on your site.

None of this sends your site's data to ClaiStore. Tokens, secrets and the activity log are stored in your site's own database. When an AI assistant connects, its requests go directly between that assistant's provider and your site. The exceptions are the Meta and Google channels, which use the Connector Broker.

5. The Connector Broker

If you connect a Meta or Google channel from ClaiStore → Channels, your site registers with the Connector Broker and the broker then relays authorised API calls between your site and the provider. Through the broker we process:

  • Registration data — your site's host name, a per-site shared secret, the plugin version, and the site URL.
  • OAuth tokens — access and refresh tokens for the providers you connect, held to make and refresh authorised calls on your behalf.
  • Proxied API traffic — the request path, parameters and response for each call your site or its connected AI makes to the provider (for example: listing campaigns, updating a product catalog item, fetching a Page's messages).
  • Webhook events — notifications the providers send (for example a new Facebook comment or message), which the broker verifies and forwards to the originating site over a signed channel.
  • Operational logs — timestamps, the site, the channel, HTTP status and error slugs, kept transiently for reliability and abuse prevention. We do not retain proxied message content or catalog payloads beyond what is needed to complete the request.

The broker runs on Cloudflare's edge platform. Traffic is encrypted in transit (HTTPS), provider tokens are stored encrypted, and every broker-to-site delivery is signed with your site's secret so your site can reject anything it did not expect.

Sub-processors: Cloudflare, Inc. (edge hosting and CDN); Meta Platforms, Inc. and Google LLC (the destination providers you connect).

6. Meta Platform Data

When you connect a Meta (Facebook / Instagram) channel, ClaiStore accesses only the Platform Data needed for the features you turn on, and only for the Pages, Instagram accounts, ad accounts, businesses and catalogs you select. Depending on your configuration this can include:

  • Page and Instagram account metadata, published posts and their insights;
  • comments and direct messages on your connected Page / Instagram account, and the sender's name and platform-scoped ID, so the customer-inbox features can read and reply to them;
  • ad accounts, campaigns, ad sets, ads, audiences and delivery insights;
  • Business-owned product catalogs, catalog items and product feeds.

How this data is used and not used:

  • Used only to carry out the actions you or your authorised AI assistant request through your site, and to show you the results.
  • Passed through the Connector Broker to your site; it is not stored in a central ClaiStore database of customer content.
  • Never sold, licensed, or used for ClaiStore's own advertising, profiling, or model training.
  • Handled in line with Meta's Platform Terms and Developer Policies.

Disconnecting the Meta channel in ClaiStore → Channels revokes the broker's tokens and stops all further access. See section 10 for deletion.

7. Google user data

If you connect Google Analytics 4 or Google Search Console, ClaiStore accesses those properties read-only to return reports to you, through the Connector Broker, using tokens you granted. This data is used solely to provide the reporting and site-care features in the plugin, is not transferred to others except as needed to provide those features, is not used for advertising, and is not used to train generalised AI models. ClaiStore's use of information from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

8. AI providers

The plugin connects to the AI assistants you authorise (for example OpenAI's ChatGPT or Anthropic's Claude). When you use one, the content and instructions in that session are processed by that provider under its terms and privacy policy. Some optional plugin features (such as drafting inbox replies) can call a generative model using an API key you supply, or fall back to a model call proxied by the Connector Broker; in that case only the text needed to produce the draft is sent, and it is not retained by the broker after the response.

9. Retention

  • CDN request logs (website and broker): short-lived, per our host's defaults, then deleted or aggregated.
  • Broker registration + tokens: kept while the channel is connected; deleted or invalidated on disconnect or on request.
  • Broker operational logs: a rolling short window for reliability and abuse prevention.
  • Proxied content (messages, catalog payloads, reports): held only for the lifetime of the request and not persisted.
  • Data inside your WordPress site is retained according to your settings and policies.

10. Deleting your data

You can remove data ClaiStore holds at any time:

  1. In ClaiStore → Channels, click Disconnect on each connected channel. This revokes the broker's provider tokens and deletes the stored token and selection for that channel.
  2. Deactivating and deleting the plugin removes its accounts, tokens and options from your site (the uninstaller handles this).
  3. To have any residual broker registration record or operational log entry for your site erased, email privacy@claistore.com from a domain you control, or the site administrator address, with your site's host name. We action verified requests within 30 days.

For Meta-related data specifically, you may also remove ClaiStore from Facebook Settings → Business Integrations, which revokes access immediately.

11. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. Because ClaiStore typically acts as your processor for connected-channel data, we will forward or help you satisfy requests from your own end users, and we will handle requests about data we control directly. Contact us at privacy@claistore.com.

12. Security

We use HTTPS everywhere, encrypt provider tokens at rest, sign every broker-to-site delivery with a per-site secret, scope each site to its own credentials, and apply least-privilege access on the agent account the plugin creates. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as required by law.

13. Changes to this policy

We may update this policy as the product changes. Material changes will be reflected by a new "last updated" date and, where appropriate, a notice in the plugin or by email.

14. Contact

Privacy questions and requests: privacy@claistore.com
General support: support@claistore.com