Privacy Policy

ACE uses the minimum data needed to answer a request or deliver a service. This page describes what the public ACE website and the managed AEO, SEO and GEO service collect today. It will be updated before any materially different data collection, payment flow or account feature is enabled.

Pre-launch scope: the public launch surface is the managed AEO, SEO and GEO service described on this site. Hosted payment, subscription and account features are not enabled at this time. Some earlier public marketplace surfaces remain in the codebase but are not part of the launch navigation.

What the public website processes

  • Standard connection metadata needed to deliver and protect the site, processed by the hosting and network infrastructure.
  • Email you choose to send to ACE, including your website address and the details you include, used to respond to your request and to prepare a Readiness Audit.
  • The Readiness Audit request form: business name, website address, your name, work email, optional phone, business type, a short description and your consent. ACE stores the request for up to 90 days in its request queue, uses it to run a public-evidence audit and to email you the results, and keeps a truncated hash of the sending connection for one to two hours to limit abuse. Requests are pulled into ACE's local operations system for review; they are never published.
  • If any earlier public search surface is used, the request text, country or region context and a postal code only when you enter one. Those surfaces store a browser-local market preference only, and do not treat an IP-derived location as a shipping destination.

What the managed service processes

  • Public evidence about your website, such as pages, metadata, structured data and public configuration, which ACE reads to audit and monitor the site.
  • Authorized sources you grant, such as a repository, a CMS connector or read-only measurement access. Access is scoped to the fulfillment mode you choose and can be revoked.
  • Evidence bundles, receipts and Value Ledger records that document baselines, findings, approved changes, verification results and monitoring events for your account.

Credentials and secrets

Connector credentials and tokens are stored outside business state, are scoped to the narrowest supported access, and are never exposed to the AI models ACE uses. ACE does not ask for unrestricted website, database or shell credentials.

Application telemetry

The public website records aggregate, event-level usage counts to understand how the site performs. The application contract is aggregate-only: no raw request text and no session identifier are stored in funnel telemetry. Aggregate operational signals may be retained for service analytics. They cannot change ACE scores, evidence or verification results.

Infrastructure and external destinations

ACE public surfaces are designed to run on Cloudflare-hosted infrastructure. Links to external sites, tools or services take you to a destination with its own privacy practices.

What ACE does not do with your data

  • ACE does not sell personal profiles and does not build advertising products around them.
  • Payment never buys a different ACE score, verification result or organic outcome.
  • Internal customer, sales and lab state are not published to any public surface automatically.

Contact and policy changes

Questions about how ACE handles your data can be sent to aeo@agentcommerceexchange.com. ACE will update this page before enabling materially different data collection, real-money flows or account features.