Legal · Magento AI Operator
Magento AI Operator Privacy Policy
How Toweringmedia processes data when merchants use Magento AI Operator with the hosted ChatGPT app and Operator gateway. Contact us with privacy questions.
Who this covers
- Merchants who buy the Magento AI Operator module and Operator subscription
- Employees who use the published Toweringmedia Magento AI Operator ChatGPT app (ChatGPT Business or Enterprise)
- The Magento store paired to Toweringmedia’s hosted Operator gateway
This is not the privacy policy for ChatGPT itself (see OpenAI), Magento hosting, or separate Toweringmedia extensions such as Search Intelligence or Nora AI.
How the product works
- ChatGPT talks only to Toweringmedia’s Operator gateway at
https://operator.toweringmedia.com. - Customers do not paste OpenAI API keys into Magento or into Operator.
- Customers do not create a Google Cloud project for Operator.
- One shared Toweringmedia gateway and one Toweringmedia ChatGPT app serve paired stores.
- The merchant’s developer installs the Magento module and pairs the store from Magento admin (or Magento CLI). Pairing codes are not pasted into ChatGPT.
- Store data is read from that store’s Magento database through typed Operator tools.
- Writes go through the Operator proposal ledger. ChatGPT proposes a change (old/new preview). Magento applies only after a person explicitly says approved. Each applied change records before-image, after-image, actor, and timestamp for audit and revert.
What Toweringmedia processes
Through the hosted gateway and Magento pairing, Toweringmedia may process:
- Employee identity used to sign in to the Operator gateway (for example email and password hash, or future Toweringmedia SSO)
- OAuth tokens for the ChatGPT connection (hashed or encrypted at rest as implemented)
- Site pairing metadata (hostname, site id, installation id)
- Encrypted Magento integration token and HMAC secret used for gateway → Magento calls
- Tool names, correlation ids, and entitlement decisions (not license keys)
- Bounded Magento tool results in transit to ChatGPT (reports, catalog reads, proposal previews)
Magento itself continues to hold the store’s catalog, orders, customers, and the Operator ledger tables on the merchant’s Magento installation.
What we do not send to ChatGPT
- Magento administrator passwords
- Broad Magento admin session tokens
- Provider API keys (OpenAI, DataForSEO, Google, and similar)
- License keys
- Raw catalog dumps beyond the typed tool result for the requested action
Separate extensions and third-party keys
API keys and connection settings for DataForSEO, Google Search Console, Google Analytics 4, LLM providers, and similar belong only to those separate Magento extensions (for example Search Intelligence modules). Magento AI Operator detects whether an extension is installed and either uses it or returns a structured purchase/unavailable result. Operator does not collect or store those third-party keys for other products.
Retention
- Gateway OAuth access tokens are short-lived; refresh tokens rotate.
- Pairing secrets are removed when the store disconnects Operator.
- Gateway operational audit rows are not a substitute for Magento’s merchant ledger.
- Magento Operator ledger rows (proposals, before/after images, actor, timestamps) follow Magento retention and the merchant’s own backup practices.
Roles and choices
- Merchants control Magento access, pairing, and who may approve proposals.
- Merchants can disconnect Operator from Magento admin.
- ChatGPT Business / Enterprise workspace admins control which apps are available to their employees.
Children
Magento AI Operator is a business product for Magento merchants and their staff. It is not directed at children under 13.
Changes
We may update this policy as the product changes. The “Last updated” date at the top will change when we publish a material update.
Contact
Privacy questions: branden.thomas@toweringmedia.com or contact us.