Search Results :

×

Privacy Policy – miniOrange MCP Server for Magento

This policy outlines how our Secure MCP Server collects, stores, processes, and protects your authorized data connections between your AI assistant and your Magento environment.

Last updated: August 03, 2026

miniOrange is committed to protecting the privacy and security of information processed through its products and services. This Privacy Policy explains how Xecurify Inc. ("Xecurify", "miniOrange", "we", "our", or "us") may collect, process, use, store, and disclose information in connection with the miniOrange MCP Server for Magento / Adobe Commerce ("Service").

The Service enables authorized AI assistants and other Model Context Protocol (MCP)-compatible clients to securely interact with Magento Open Source and Adobe Commerce stores based on the permissions configured by the store administrator.

This Policy applies specifically to the miniOrange MCP Server for Magento / Adobe Commerce.

1. Overview

The miniOrange MCP Server for Magento / Adobe Commerce allows a Magento store administrator to connect an MCP-compatible AI client or application to their Magento environment. Depending on the permissions configured by the store administrator, the connected AI client may retrieve Magento store information or perform permitted actions through the MCP Server. Access to Magento resources is governed by the permissions assigned by the store administrator through Magento's access-control mechanisms. The store administrator remains responsible for determining which Magento resources and operations are made available to connected AI clients.

2. Information We Process

The information processed through the Service depends on how the Magento MCP Server is configured and which permissions are granted by the Magento store administrator.This Policy applies specifically to the miniOrange MCP Server for Magento / Adobe Commerce.

2.1 Magento Store Connection Data

To establish and maintain an MCP connection, the Service may process information required to identify and communicate with the Magento / Adobe Commerce store, including:

• Magento / Adobe Commerce store URL

• MCP endpoint URL

• Connection identifiers

• CAuthentication and authorization information

• Integration configuration information

• Connection status and related technical metadata

The Magento MCP Server may use authentication mechanisms including Magento Integration Tokens and OAuth 2.0.
Authentication credentials are used only to authorize requests to resources permitted by the Magento store administrator.
The Service does not require users to provide their Magento administrator username or password directly to the connected AI assistant.

2.2 Magento Store Data Processed Through MCP

When a user submits a request through a connected AI assistant, the MCP Server may process Magento store information necessary to fulfill that request.
Depending on the permissions granted by the Magento administrator, this information may include:

• Product catalogue information

• Product attributes and pricing

• Inventory and stock information

• Orders and order status

• Customer information

• Invoices

• Shipments and fulfilment information

• Promotions and related commerce configuration

• Product reviews

• Store analytics and operational information

• Other Magento resources explicitly made available through configured MCP tools

Some of this information may contain Personal Data, including information associated with Magento customers, administrators, or other users.
The scope of data accessible through the MCP Server is determined by the permissions assigned to the MCP connection.

2.3 MCP Tool Requests and Responses

When a connected AI client invokes an MCP tool, the Service processes the information necessary to execute the requested operation.

This may include:

• The MCP tool being requested

• Parameters provided with the request

• Magento data required to fulfil the request

• Results returned by Magento to the connected AI client

• Technical information required to process the operation

The Service processes this information for the purpose of completing the requested MCP operation.
miniOrange does not require access to the user's complete AI assistant conversation history. However, information from a conversation may be included in an MCP request where the connected AI platform determines that such information is necessary to invoke a particular tool.

2.4 Authentication and Authorization Data

The Service may process authentication and authorization information required to validate MCP requests.

Depending on the selected configuration, this may include:

• Magento Integration Tokens

• OAuth 2.0 access tokens

• OAuth authorization information

• Token identifiers

• Authorization state

• Permission information

Access is restricted according to the permissions assigned by the Magento store administrator.
Store owners may configure the MCP integration with limited or read-only permissions or authorize additional operations according to their requirements.

2.5 Operational and Security Data

We may process limited technical information required to operate, secure, troubleshoot, and protect the Service.

This may include:

• Request timestamps

• Connection identifiers

• Request status or outcome

• Error information

• IP addresses

• Device or client information where technically necessary

• Security and abuse-prevention information

Operational information may be used for security monitoring, debugging, rate limiting, fraud prevention, abuse prevention, and maintaining the reliability of the Service.

Authentication secrets should not be intentionally recorded in application logs in plaintext.

2.6 Support and Contact Information

If you contact miniOrange for technical support, product enquiries, demonstrations, licensing, or other assistance, we may process information you voluntarily provide, including:

• Name

• Business email address

• Phone number

• Organization name

• Technical configuration information

• Support correspondence

• Diagnostic information you choose to share

Support information is used only for providing the requested assistance and related business purposes.

3. How We Use Information

We may process information described in this Policy to:

• Establish and maintain authorized connections between Magento / Adobe Commerce and MCP-compatible AI clients.

• Authenticate and authorize MCP requests.

• Retrieve Magento information requested through MCP tools.

• Perform Magento operations explicitly permitted by the store administrator.

• Return requested information or operation results to the connected AI client.

• Maintain, secure, troubleshoot, and improve the reliability of the Service.

• Prevent unauthorized access, abuse, fraud, and security threats.

• Provide technical and customer support.

• Comply with applicable legal and regulatory obligations.

miniOrange does not sell Personal Data processed through the Magento MCP Server.

miniOrange does not use Magento customer or store data processed through MCP for targeted advertising.

miniOrange does not use Magento store data processed through the MCP Server to train general-purpose AI models.

4. Access Control and Customer Responsibility

The Magento store administrator controls which resources the MCP Server is authorized to access.
Magento access-control permissions may be used to restrict the MCP connection to specific resources and operations.
Depending on the permissions granted, an MCP connection may be configured for read-only access or may be allowed to perform additional authorized actions.

Customers are responsible for:

• Configuring appropriate permissions for the MCP connection.

• Following the principle of least privilege when granting access.

• Ensuring that users connecting AI clients are authorized to access the relevant Magento data.

• Revoking credentials when access is no longer required.

• Reviewing the privacy and security practices of the AI platforms they choose to connect.

• Complying with applicable privacy and data-protection requirements relating to data stored within their Magento environment.

Removing the MCP configuration from the AI client or revoking the relevant Magento integration credentials prevents those credentials from continuing to authorize access to the Magento store.

5. Sharing and Recipients

Information processed through the Magento MCP Server may be exchanged with the following parties where necessary to provide the Service.

Magento / Adobe Commerce Store

MCP requests are sent to the Magento environment associated with the configured MCP endpoint. The Magento store processes the request according to its own configuration and permissions.

Connected AI Platform

Information requested through MCP may be returned to the AI client or platform selected by the customer, such as ChatGPT, Claude, Cursor, or another MCP-compatible application.

Once information is transmitted to a third-party AI platform, that platform's handling of the information is governed by its own privacy policy, terms, data controls, and contractual arrangements with the customer.

Customers should review the privacy practices of any AI platform before connecting it to their Magento environment.

Service Providers and Infrastructure Providers

Where miniOrange uses third-party infrastructure or service providers to deliver, secure, maintain, or support the Service, those providers may process limited information on our behalf and only for the purposes for which they have been engaged.

We require applicable service providers to protect information in accordance with contractual, security, and confidentiality requirements.

Legal and Security Requirements

We may disclose information where reasonably necessary to:

• Comply with applicable law, regulation, legal process, or governmental request.

• Protect the security or integrity of the Service.

• Investigate fraud, misuse, or security incidents.

• Protect the rights, property, or safety of miniOrange, our customers, or others.

6. Data Retention

We retain Personal Data only for as long as reasonably necessary to provide the Service, fulfil the purposes described in this Policy, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Magento store information processed as part of an MCP request is intended to be processed only as necessary to fulfil the requested operation unless retention is required for a separately disclosed operational, support, security, or legal purpose.

Authentication and connection information, where retained by miniOrange-managed components, is retained only for as long as necessary to maintain the applicable connection or meet legitimate security, contractual, or legal requirements.

Operational and security logs may be retained for a limited period where necessary for security, troubleshooting, abuse prevention, compliance, or service reliability.

When information is no longer required, it is deleted, anonymized, or otherwise handled in accordance with applicable retention requirements.

7. Data Processed by Connected AI Platforms

The Magento MCP Server may be connected to third-party AI clients or platforms.

When an AI client sends an MCP request, information required to perform that request may be transmitted between the AI platform and the Magento MCP Server.

miniOrange does not control how an independent third-party AI platform processes information after it is provided to that platform.

Customers should review the applicable AI platform's:

• Privacy policy

• Terms of service

• Enterprise or business data-processing terms

• Data-retention settings

• Model-training controls

• Administrator controls

before allowing that platform to access Magento information.

8. Data Protection Roles

Magento merchants and organizations generally determine why their Magento store data is processed, which users may access it, and which resources are made available to MCP clients.

Where miniOrange processes Personal Data solely on a customer's behalf to provide the Service, the respective roles of miniOrange and the customer will depend on the particular deployment, contractual relationship, and applicable data-protection law.

Customers remain responsible for establishing an appropriate legal basis for processing Personal Data contained within their Magento environment and for providing any notices or obtaining any permissions required by applicable law.

9. Your Rights and Choices

Depending on your location and applicable privacy law, you may have rights relating to Personal Data controlled by miniOrange, including the right to:

• Request access to your Personal Data.

• Request correction of inaccurate Personal Data.

• Request deletion of Personal Data.

• Request restriction of certain processing.

• Object to certain processing.

• Request information about how your Personal Data is processed.

• Exercise applicable data portability rights.

• Withdraw consent where processing is based on consent.

To exercise an applicable privacy right, please contact us using the information provided in the Contact Us section below.

Certain information processed through a customer's Magento environment may be controlled by the Magento merchant rather than miniOrange. In such cases, requests regarding that information should be directed to the applicable Magento merchant or organization.

10. Security

miniOrange applies appropriate technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or misuse.

Security measures may include:

• Transport Layer Security (TLS) for data transmitted over supported network connections.

• Authentication and authorization controls.

• Magento ACL-based permission enforcement.

• Principle-of-least-privilege access.

• Protection of authentication credentials.

• Access controls for systems processing Service information.

• Security monitoring and abuse-prevention measures.

Customers should assign only those Magento permissions that are necessary for the intended MCP use case.

No method of transmitting or storing information is completely secure, and therefore no system can guarantee absolute security.

11. International Data Transfers

miniOrange and its service providers may process information in countries other than the country in which the customer or user is located.

Where Personal Data is transferred internationally, we take appropriate measures as required by applicable data-protection laws.

Where required, such measures may include contractual safeguards or other legally recognized transfer mechanisms.

12. Children's Privacy

The Magento MCP Server is intended for business, administrative, development, and commerce use and is not directed to children under the age of 13.

We do not knowingly collect Personal Data directly from children through the Service.

If you believe Personal Data relating to a child has been provided directly to miniOrange inappropriately, please contact us so that we can review and, where appropriate, delete the information.

Magento merchants remain responsible for data contained within their own Magento stores, including any customer information that may relate to minors.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to the Service, our privacy practices, applicable laws, or regulatory requirements.

When we make material changes, we will update the Last Updated date displayed at the top of this page and may provide additional notice where required.

We encourage customers to review this Privacy Policy periodically.

Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or miniOrange's privacy practices, you may contact us at:

Email: info@xecurify.com

Phone: +1 978 658 9387

Form: Contact Us / Visit miniOrange

Hello there!

Need Help? We are right here!

support