Privacy Policy

Stabile: Loyalty Rewards Agent — ChatGPT App & MCP Server
Developer: StabileRewards  •  Effective Date: 2026-08-28  •  Contact: privacy@stabilerewards.com

This Privacy Policy describes how Stabile: Loyalty Rewards Agent (“we”, “our”, or “us”) handles data when shoppers, merchants, and AI agents invoke our tools via the ChatGPT App and MCP (Model Context Protocol) server. We are committed to full transparency about the data categories our tools receive, return, and log for service operation, security, and support.

1. Data We Process

Our tools receive only the information required to check, redeem, and issue loyalty rewards. The table below lists the input fields accepted by our MCP tools, their purpose, and whether the same field or a derived value may be returned in a response.

Field Category Purpose Returned in response?
customer_email Buyer identifier Identifies the buyer with shopper consent so rewards can be looked up, redeemed, or issued to the correct account. The full email is not returned. Masked email may be returned for win-back customers.
customer_id Buyer identifier Shopify customer identifier or GID used when a direct customer id is available instead of an email address. No
customer_key Buyer identifier Opaque customer key returned by the win-back context tool and used to issue a reward to an eligible configured customer. Yes, when needed to confirm the selected win-back customer.
cart_total Transaction data Current cart value in USD. Used to calculate eligible reward options and their economic impact. May be returned in nested cart outcome fields such as cart total before or after a reward.
cart_id Session identifier Merchant-provided checkout session ID. Used to correlate reward actions to a specific cart. Not returned in tool responses. No
transaction_id Transaction reference Merchant’s reference ID for the underlying commerce transaction. Associates reward issuances with the correct order. Yes. We may return the normalized value recorded for auditability.
reward_amount Reward data Quantity of loyalty points to be issued for a permitted win-back reward. Yes.
idempotency_key Technical identifier Caller-generated key used to safely deduplicate retried redemption or issuance requests. Yes. We may return a derived hash value used for deduplication.
shop_domain Merchant identifier Shopify merchant domain used to route requests to the correct connected store. Yes.
option_id Reward selection Reward option selected from the options returned for a cart. Yes.
unit Reward unit Unit label supplied for a win-back issuance. The current tool accepts points only. Yes, as a normalized unit value. The raw value may be recorded in audit logs.
reason Reward reason Required fixed reason for permitted win-back issuances. May be returned in customer eligibility context.
force_new Reward instruction Indicates whether the shopper explicitly asked to create a new reward code even if an unused equal-or-better code already exists. No

Tool responses may include these categories

Service logs may include these categories

2. How We Use This Data

Data is used exclusively to:

We do not use any data for advertising, profiling, model training, or any purpose beyond delivering the loyalty reward service.

3. Data Retention

Tool requests are processed at request time. We do not create a general buyer profile in the MCP server. The merchant loyalty system may retain reward, balance, redemption, and issuance records as needed to operate the merchant’s loyalty program.

For service reliability, security, and support, the MCP server writes audit events to infrastructure logs and, when configured, Redis. The rolling Redis event list is retained for up to 7 days. Daily audit lists are retained for up to 90 days by default, unless configured differently. Session state required for SSE transport is held in Redis and scoped to the active connection.

4. Data Sharing and Disclosure

We do not sell buyer or merchant data. We may share data only in these limited situations:

5. Data Security

All data is transmitted over TLS-encrypted connections. Access to infrastructure is restricted to authorized personnel. We apply industry-standard access controls and secure communication protocols throughout our stack.

6. Your Rights

For questions about data processed during a specific transaction, contact us with the relevant transaction_id, idempotency_key, reward code, store, or approximate request time for investigation. Please do not send passwords or API keys.

To submit a data inquiry or exercise any rights: privacy@stabilerewards.com

7. Changes to This Policy

We may update this policy from time to time. The effective date above reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.