Stabile: Loyalty Rewards Agent — ChatGPT App & MCP Server
Developer: StabileRewards •
Effective Date: 2026-08-28 •
Contact: privacy@stabilerewards.com
This Privacy Policy describes how Stabile: Loyalty Rewards Agent (“we”, “our”, or “us”) handles data when shoppers, merchants, and AI agents invoke our tools via the ChatGPT App and MCP (Model Context Protocol) server. We are committed to full transparency about the data categories our tools receive, return, and log for service operation, security, and support.
Our tools receive only the information required to check, redeem, and issue loyalty rewards. The table below lists the input fields accepted by our MCP tools, their purpose, and whether the same field or a derived value may be returned in a response.
| Field | Category | Purpose | Returned in response? |
|---|---|---|---|
customer_email |
Buyer identifier | Identifies the buyer with shopper consent so rewards can be looked up, redeemed, or issued to the correct account. | The full email is not returned. Masked email may be returned for win-back customers. |
customer_id |
Buyer identifier | Shopify customer identifier or GID used when a direct customer id is available instead of an email address. | No |
customer_key |
Buyer identifier | Opaque customer key returned by the win-back context tool and used to issue a reward to an eligible configured customer. | Yes, when needed to confirm the selected win-back customer. |
cart_total |
Transaction data | Current cart value in USD. Used to calculate eligible reward options and their economic impact. | May be returned in nested cart outcome fields such as cart total before or after a reward. |
cart_id |
Session identifier | Merchant-provided checkout session ID. Used to correlate reward actions to a specific cart. Not returned in tool responses. | No |
transaction_id |
Transaction reference | Merchant’s reference ID for the underlying commerce transaction. Associates reward issuances with the correct order. | Yes. We may return the normalized value recorded for auditability. |
reward_amount |
Reward data | Quantity of loyalty points to be issued for a permitted win-back reward. | Yes. |
idempotency_key |
Technical identifier | Caller-generated key used to safely deduplicate retried redemption or issuance requests. | Yes. We may return a derived hash value used for deduplication. |
shop_domain |
Merchant identifier | Shopify merchant domain used to route requests to the correct connected store. | Yes. |
option_id |
Reward selection | Reward option selected from the options returned for a cart. | Yes. |
unit |
Reward unit | Unit label supplied for a win-back issuance. The current tool accepts points only. | Yes, as a normalized unit value. The raw value may be recorded in audit logs. |
reason |
Reward reason | Required fixed reason for permitted win-back issuances. | May be returned in customer eligibility context. |
force_new |
Reward instruction | Indicates whether the shopper explicitly asked to create a new reward code even if an unused equal-or-better code already exists. | No |
Data is used exclusively to:
We do not use any data for advertising, profiling, model training, or any purpose beyond delivering the loyalty reward service.
Tool requests are processed at request time. We do not create a general buyer profile in the MCP server. The merchant loyalty system may retain reward, balance, redemption, and issuance records as needed to operate the merchant’s loyalty program.
For service reliability, security, and support, the MCP server writes audit events to infrastructure logs and, when configured, Redis. The rolling Redis event list is retained for up to 7 days. Daily audit lists are retained for up to 90 days by default, unless configured differently. Session state required for SSE transport is held in Redis and scoped to the active connection.
We do not sell buyer or merchant data. We may share data only in these limited situations:
All data is transmitted over TLS-encrypted connections. Access to infrastructure is restricted to authorized personnel. We apply industry-standard access controls and secure communication protocols throughout our stack.
For questions about data processed during a specific transaction, contact us with the relevant transaction_id, idempotency_key, reward code, store, or approximate request time for investigation. Please do not send passwords or API keys.
To submit a data inquiry or exercise any rights: privacy@stabilerewards.com
We may update this policy from time to time. The effective date above reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.