Stabile: Loyalty Rewards Agent and StabileRewards AI — ChatGPT plugins & MCP Server
Developer: StabileRewards •
Effective Date: 2026-10-08 •
Contact: privacy@stabilerewards.com
This Privacy Policy describes how Stabile: Loyalty Rewards Agent and StabileRewards AI (“we”, “our”, or “us”) handles data when shoppers, merchants, and AI agents invoke our tools via our ChatGPT plugins and MCP (Model Context Protocol) server. We are committed to full transparency about the data categories our tools receive, return, and log for service operation, security, and support.
Shoppers can use Stabile in three ways, each described below: by signing in with a participating store’s own customer account (section 1.1), by asking about a store’s reward terms without signing in (section 1.2), and by requesting a store that doesn’t use Stabile yet (section 1.3). Some other MCP connections to our server, used by other AI assistants and integrations, accept an email address or customer ID instead of a sign-in (section 1.4).
When you connect the app, you choose a participating store and sign in on that store’s own website with its customer account, then approve “Check my reward”. We never see your store password. You can instead choose the shared test account, a test shopper used for trying the app and for app review; it contains no personal data and its test points are shared by everyone who chooses it.
| Data | Source and purpose | Returned to the AI assistant? |
|---|---|---|
| Shopify customer ID at the chosen store | Provided by the store through Shopify after you sign in. Used to find your rewards at that store. Stored with a pseudonymous identifier for this connection; we do not receive your password. | No |
| Your approval (consent record) | What you approved, when, for which store and AI assistant, and whether you later disconnected. | No |
| Access and refresh tokens | Issued to the AI assistant after you approve. Access tokens last 5 minutes; refresh tokens up to 30 days. We store only hashes of refresh tokens. | Held by the AI assistant, not shown in responses. |
| Reward values you can use | Calculated from your loyalty balance and the store’s program, optionally for a cart subtotal you give. | Yes: reward values, currency, and how many unused codes you hold. Not your points balance. |
| Your unused reward codes | Only when you approved sharing codes. Read from the store; never created or spent by the app. | Yes: each code, its value, currency, expiry, and whether it works only while signed in to your store account. |
| Store domain and store link | Identifies which store the rewards belong to. | Yes. |
Signed-in checks never return your email address, name, orders, or points balance, and they cannot create codes, spend points, or apply discounts. While a store’s pilot runs, we record your approval and each reward check to measure the pilot. These records are linked to the pseudonymous identifier and include the outcome and, when applicable, the cart subtotal you supplied, currency, maximum eligible reward value, and number of unused codes. We do not store the codes themselves in pilot measurement records. You can disconnect at any time on the store’s “Check my reward” page, which stops further checks immediately; removing the app in your AI assistant also stops it from checking.
You or your AI assistant can ask about a store’s reward program without signing in. The request contains only the store’s name, website, or Shopify domain and a cart subtotal; it never includes your email, customer ID, or other identity. We return the store’s public program terms (earn rate, minimum spend, first-order bonus, reward tiers) and what that cart would earn, but only for stores that chose to make their program visible to AI assistants. If a store isn’t available, we return a link to request it (section 1.3). We log the store as given and the outcome to learn which stores shoppers ask about.
If you request a store that doesn’t use Stabile yet, we receive the store name or website you enter and, only if you choose to give it, your email address. We use the request to ask the store to join and, if you gave an email, to tell you when it does. We save the request and use Resend to send a notification, including any email you gave, to our team; the request remains saved if email delivery is unavailable. We don’t store your network address with the request; we keep only a keyed one-way hash of it, to limit repeated requests.
Some connections to our MCP server, used by other AI assistants and integrations, identify a shopper by an email address or customer ID supplied in the request instead of a store sign-in. The table below lists the input fields accepted by those tools, their purpose, and whether the same field or a derived value may be returned in a response.
| Field | Category | Purpose | Returned in response? |
|---|---|---|---|
customer_email |
Buyer identifier | Identifies the buyer with shopper consent so rewards can be looked up, redeemed, or issued to the correct account. | The full email is not returned. Masked email may be returned for win-back customers. |
customer_id |
Buyer identifier | Shopify customer identifier or GID used when a direct customer id is available instead of an email address. | No |
customer_key |
Buyer identifier | Opaque customer key returned by the win-back context tool and used to issue a reward to an eligible configured customer. | Yes, when needed to confirm the selected win-back customer. |
cart_total |
Transaction data | Current cart value in USD. Used to calculate eligible reward options and their economic impact. | May be returned in nested cart outcome fields such as cart total before or after a reward. |
cart_id |
Session identifier | Merchant-provided checkout session ID. Used to correlate reward actions to a specific cart. Not returned in tool responses. | No |
transaction_id |
Transaction reference | Merchant’s reference ID for the underlying commerce transaction. Associates reward issuances with the correct order. | Yes. We may return the normalized value recorded for auditability. |
reward_amount |
Reward data | Quantity of loyalty points to be issued for a permitted win-back reward. | Yes. |
idempotency_key |
Technical identifier | Caller-generated key used to safely deduplicate retried redemption or issuance requests. | Yes. We may return a derived hash value used for deduplication. |
shop_domain |
Merchant identifier | Shopify merchant domain used to route requests to the correct connected store. | Yes. |
option_id |
Reward selection | Reward option selected from the options returned for a cart. | Yes. |
unit |
Reward unit | Unit label supplied for a win-back issuance. The current tool accepts points only. | Yes, as a normalized unit value. The raw value may be recorded in audit logs. |
reason |
Reward reason | Required fixed reason for permitted win-back issuances. | May be returned in customer eligibility context. |
force_new |
Reward instruction | Indicates whether the shopper explicitly asked to create a new reward code even if an unused equal-or-better code already exists. | No |
Data is used exclusively to:
We do not use any data for advertising, profiling, model training, or any purpose beyond delivering the loyalty reward service.
Tool requests are processed at request time. We do not create a general buyer profile in the MCP server. The merchant loyalty system may retain reward, balance, redemption, and issuance records as needed to operate the merchant’s loyalty program.
For service reliability, security, and support, the MCP server writes audit events to infrastructure logs and, when configured, Redis. The rolling Redis event list is retained for up to 7 days. Daily audit lists, including store reward-terms lookups and the keyed hashes and redacted tool arguments described in section 1, are retained for up to 90 days by default, unless configured differently. Session state required for SSE transport is held in Redis and scoped to the active connection.
For signed-in reward checks and store requests:
Email notifications and related correspondence are separate from the application database record. Resend documents 30-day email and log retention on its Free, Pro, and Scale plans; Enterprise retention can differ, and its backups persist for 7 days. See Resend’s retention information. Messages already delivered to our team’s inbox are not automatically deleted by the application’s 180-day database cleanup. We retain correspondence as needed to handle your request, follow up about the store, and respond to support or privacy inquiries. You can request deletion of these copies by contacting us.
When a store uninstalls Stabile or asks us to delete a customer’s data through Shopify, we delete the related links, approvals, and measurement records.
We do not sell buyer or merchant data. We may share data only in these limited situations:
All data is transmitted over TLS-encrypted connections. Access to infrastructure is restricted to authorized personnel. We apply industry-standard access controls and secure communication protocols throughout our stack.
You can disconnect a signed-in store at any time on that store’s “Check my reward” page. To delete a store request or your email from it, contact us with the store you requested and the approximate time.
For questions about data processed during a specific transaction, contact us with the relevant transaction_id, idempotency_key, reward code, store, or approximate request time for investigation. Please do not send passwords or API keys.
To submit a data inquiry or exercise any rights: privacy@stabilerewards.com
We may update this policy from time to time. The effective date above reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.