1. Scope
This Privacy Policy explains how Macentra Technologies Inc. and CommerceOS collect, use, store, disclose, and protect information when visitors use the corporate website and when merchants, staff, customers, or authorized users use CommerceOS.
It also applies to information received when an authorized merchant connects a third-party service, including Google Gmail, Meta, WhatsApp Business, cloud storage, messaging, and payment-related business services.
2. Corporate website information
This informational website does not currently use advertising trackers, analytics scripts, account registration, or contact forms. Hosting and security providers may process standard technical request information, such as IP address, browser type, request time, requested page, and security logs, to deliver and protect the website.
Information voluntarily provided by telephone or email is used to respond to the applicable business, support, privacy, or partnership inquiry.
3. Merchant and operational information
CommerceOS may process merchant account details, business and location information, products, menus, catalogs, pricing, availability, customer contact details, orders, payment requests, transaction records, staff activity, support communications, and related operational metadata.
4. Google Gmail data
A merchant may voluntarily authorize CommerceOS to access a designated Gmail mailbox using Google OAuth. CommerceOS requests read-only Gmail access for payment-reconciliation purposes.
- Message identifiers and Gmail history identifiers
- Sender and recipient information
- Message subject, timestamp, and relevant message content
- Payment amount, memo, and transaction reference
- Structured information derived from payment-confirmation messages
CommerceOS does not use Gmail authorization to send email, modify messages, or delete messages.
5. How Google data is used
- Identify supported payment-confirmation messages
- Match payments to merchant orders and payment requests
- Prevent duplicate processing
- Present uncertain transactions for authorized human review
- Maintain reconciliation, support, security, and audit records
- Protect merchants against incorrect or duplicate settlement
Google-derived data is not used for advertising, unrelated marketing, consumer profiling, or the sale of personal information. CommerceOS does not use Google-derived data to train or improve generalized artificial-intelligence or machine-learning models.
6. Google API Limited Use
CommerceOS use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Meta and WhatsApp Business data
When a merchant connects Meta or WhatsApp Business through an authorized onboarding flow, CommerceOS may process business account identifiers, WhatsApp Business Account identifiers, phone-number identifiers, display names and numbers, onboarding and registration status, webhook and delivery metadata, merchant-authorized credentials, customer phone numbers, message content needed for authorized inbox and order workflows, catalog identifiers, product publication status, and related operational records.
This information is used to connect authorized business assets, provide messaging and order context, administer catalog publication, troubleshoot delivery, enforce tenant isolation, and provide audit and support functions.
8. Connected-service credentials
Connected-service credentials and refresh tokens are handled by restricted backend systems and are not exposed through the merchant browser. Credentials may be stored using protected secret-management infrastructure and referenced by CommerceOS rather than stored directly in general application records.
9. How information is used
- Provide storefront, order, payment, messaging, catalog, and support functionality
- Authenticate users and enforce roles and tenant boundaries
- Operate, secure, monitor, troubleshoot, and improve the platform
- Detect duplicate, suspicious, unauthorized, or harmful activity
- Comply with law, resolve disputes, and enforce agreements
- Communicate about service, security, support, and account matters
10. Sharing and service providers
CommerceOS may use infrastructure, database, storage, messaging, hosting, monitoring, support, and security providers to operate the platform. Providers receive only the access reasonably needed to provide their services.
Macentra does not sell Gmail data, WhatsApp message data, merchant credentials, or customer personal information to advertisers. Information may be disclosed when required by law or reasonably necessary to protect rights, safety, security, and service integrity.
11. Storage and retention
CommerceOS may retain structured operational data, message and event identifiers, transaction references, security logs, conversation and order context, and relevant supporting information for as long as reasonably needed to provide the service, maintain auditability, prevent fraud, resolve disputes, provide support, and meet legal or accounting obligations.
Retention periods may vary by information type, merchant configuration, contractual requirement, and applicable law. Backup copies may remain until overwritten or expired through normal backup rotation.
12. Control, disconnection, and deletion
Where supported, a merchant may disconnect a connected service through CommerceOS settings and may also revoke access through the applicable provider account. Deletion requests may be submitted through the Data Deletion page.
Some records may be retained where reasonably necessary for legal, accounting, fraud-prevention, dispute-resolution, contractual, audit, or security purposes.
13. Security
CommerceOS uses restricted service identities, role-based access, authenticated routes, protected secret storage, encrypted network connections, tenant-aware controls, and operational logging to reduce unauthorized access and misuse.
No information system can guarantee absolute security. Merchants should use strong passwords, multi-factor authentication, dedicated business accounts, and appropriate staff-access controls.
14. Children's privacy
The corporate website and CommerceOS merchant services are not directed to children under 13, and Macentra does not knowingly collect personal information directly from children under 13 through these services.
15. Changes
We may update this Privacy Policy as the website, CommerceOS, law, or connected services change. The current version and effective date will remain available on this page.
16. Contact
Privacy, disconnection, and deletion questions may be sent to support@macentratech.com or discussed by phone at +1 (321) 202-0709.