Privacy Policy
Last updated: September 21, 2026
This policy explains what data Recomaze Inc., 115 Wild Basin Rd S, Suite 307, Austin, TX 78746, United States ("Recomaze", "we", "us") collects, why, how long we keep it, who we share it with, and what you can do about it. It covers our websites (recomaze.ai and its subdomains, including custom.recomaze.ai and audit.recomaze.ai), our free tools, the Recomaze platform and our apps and plugins for ecommerce platforms, and the social and business platforms you can connect to your account (together, the "Services"). It forms part of our Terms of Service.
Three kinds of people meet this policy, and each has its own section: businesses that use Recomaze ("you", the "Customer"), visitors and buyers on the stores of those businesses, and visitors of our own websites.
The short version
- We collect what we need to run your account, generate your content and publish it where you tell us to. We do not sell your data, and we do not use it to advertise to you.
- When you connect a platform such as a Facebook Page, an Instagram account or a LinkedIn Page, we store the access credentials that platform gives us and the identity of the page, and we use them only to do what you asked in the app. You can disconnect at any time, and the credentials are deleted when you do.
- On the stores that use Recomaze, we act on the store's instructions as its processor. We do not build profiles of shoppers across stores.
- Our own website uses analytics and advertising cookies only with your consent.
- You can ask for a copy of your data or have it deleted at any time: see how to delete your data or write to better@recomaze.ai.
This summary is for convenience. The full policy below governs.
1. Customers: the data we collect and why
1.1. Account data. When you create an account we collect your name, email address, password (stored hashed), company name, the website or store you connect, your language and country, and the plan you choose. We use it to create and secure your account, to provide the Services, to send you service messages about your account, your content and your billing, and to answer your support requests. Legal basis: performance of our contract with you.
1.2. Billing data. Payments are handled by our payment processor or by the app store through which you installed Recomaze. We receive confirmation of payment, the last digits of the card and the billing address, not the full card number. Legal basis: performance of our contract and our legal obligations to keep accounting records.
1.3. Customer Data. This is the data you submit to the Services or that the Services collect on your websites for you: your product catalog and feeds, documents, your Knowledge Base, the company information you enter (your Company ID), settings, the content you generate and edit, and the conversations, orders and behavior data collected on your websites by our apps and plugins. We process Customer Data to provide the Services to you, on your instructions. Legal basis: performance of our contract; for the personal data of your visitors, see Section 3.
1.4. Usage and technical data. We log how the Services are used (pages opened, features used, actions taken, credits consumed, errors), the IP address, browser and device of the person using the account, and the time of each action. We use these logs to keep the Services secure, to bill correctly, to debug problems and to improve the product. Legal basis: our legitimate interest in running a secure, reliable service.
1.5. Communications. If you write to us, we keep the correspondence so we can answer and so we can see what was agreed. Legal basis: our legitimate interest in supporting you, or your consent where you opt in to product news.
2. Connected platforms
2.1. What you can connect. Depending on your plan you can connect to your Recomaze account the platforms where you publish: your ecommerce store (Shopify, BigCommerce, WooCommerce, WordPress, Nuvemshop or a custom site through a webhook) and your business profiles and pages on social and business platforms, such as a Facebook Page, an Instagram professional account, a LinkedIn Page, an X account, a Reddit account or a Google Business Profile. Each connection is your decision, made by you in the app.
2.2. What we ask for. When you connect a platform you are sent to that platform to sign in and approve a set of permissions. We ask only for the permissions needed for what the app does with that platform: to see which pages or accounts you manage so you can choose one, to publish the posts and page content you approve or schedule in Recomaze, to add a comment to a post we published where the platform's own guidance puts a link in the first comment, and to read back the posts we published so the app can show you that they went live. We do not ask for permission to read your messages, your followers' personal data or your advertising accounts.
2.3. What we store. For each connection we store the access token and, where the platform issues one, the refresh token that the platform gives us; the identifier and name of the page or account you chose; the permissions you granted and when; and, for each post we publish, the platform's identifier and address of the published post so it appears in your content library. Tokens are transmitted only over encrypted connections, are stored in our database, are never displayed in the app and are used only by the service that publishes on your behalf.
2.4. What we do with it. We use a connection only to carry out the actions you take in Recomaze: publishing what you approved, at the time you chose, to the page or account you chose, and showing you the result. We do not post anything you did not approve or schedule, we do not read or store the content of other people's posts, comments or profiles, we do not use data from a connected platform to build profiles of anyone, to serve advertising or to train models, and we do not share it with anyone other than the platform itself and the subprocessors that host and run the Services.
2.5. Platform terms. Data we receive from a platform is handled under that platform's terms as well as this policy, including Meta's Platform Terms and Developer Policies, LinkedIn's Marketing API Terms and Google's API Services User Data Policy. Where those terms restrict what we may do with data, the stricter rule applies.
2.6. Disconnecting. You can disconnect any platform at any time in Settings → Connectors. When you disconnect, or when a platform tells us that you removed Recomaze from your account, we delete the tokens and the page or account identifier for that connection. Posts already published stay on the platform, where you control them, and the copies in your Recomaze library stay until you delete them or close your account. You can also revoke our access on the platform itself, for example under Settings → Apps and websites on Facebook, Website permissions on Instagram, or Settings → Data privacy → Permitted services on LinkedIn; access ends immediately, and the stored connection data is deleted as described on our data deletion page.
2.7. Google Search Console and Google Analytics. From the Recomaze WordPress plugin (SEO → Analytics) you can connect your Google account so Recomaze shows you how your site performs in Google Search. We ask Google for read-only access only: the Search Console scope (webmasters.readonly) to list the properties you have access to, so you can pick your site, and to read that property's search performance rows (date, query, page, country, device, clicks, impressions, click-through rate and average position); and the Analytics scope (analytics.readonly) to list your Google Analytics 4 properties and, once you choose one, to read its landing-page and referrer reports. We keep a copy of these rows on our servers for up to 16 months and refresh it once a day, and we show it only to your Recomaze account, on your Analytics page. We do not write anything to Search Console or Analytics, do not sell this data, do not use it for advertising or to train models, and do not share it with anyone other than the subprocessors that host and run the Services. Disconnecting Google in the plugin revokes our access token and deletes the copied rows. Recomaze's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Visitors and buyers on stores that use Recomaze
3.1. Roles. If you shop on a store that uses Recomaze, the store is the controller of your personal data and Recomaze is its processor. The store's privacy policy explains what it collects and why; we process data only on the store's instructions and this section describes what that involves.
3.2. What is processed. Our apps and plugins collect, for the store, interaction data on that store: products viewed, searched, liked and added to cart, questions asked to the store's AI sales assistant and the answers given, and, where the store enables it, orders. This data is used to answer questions, recommend products and measure results on that store. We do not use it to identify you across stores, we do not sell it, and we do not use it for advertising.
3.3. AI assistant. Questions you ask a store's AI sales assistant are processed by AI model providers (Section 6) to produce an answer. Do not enter health, financial or other sensitive personal data into a store's assistant; the store is responsible for telling you when you are talking to an AI.
3.4. Your rights. Requests to access, correct or delete your data on a store should be sent to that store. If you contact us instead, we will forward your request to the store and help it respond.
4. Visitors of our websites and users of our free tools
4.1. Cookies and similar technologies. recomaze.ai uses cookies and similar technologies in three groups. Necessary ones keep the site working and remember your consent choice; they are always on. Analytics ones (Google Analytics, Microsoft Clarity and HubSpot) show us which pages are read, where visitors get stuck and aggregate session replays so we can fix the site. Marketing ones (Meta Pixel and Reddit Pixel) tell us whether the ads we run bring people who find the product useful. Analytics and marketing cookies are set only after you accept them in the consent banner, and you can change your choice at any time from the banner or from your browser settings.
4.2. Free tools. When you run one of our free audits, scans or generators, we store the website address you entered and the result. Results pages are visible to anyone who has the link. If you leave your email to receive a report, we use it to send that report and, if you agreed, product news you can unsubscribe from at any time.
4.3. RecomazeBot. Our crawler reads publicly available pages of websites submitted to our tools and of our customers' websites. It identifies itself by its user agent; how to allow or block it is explained at recomaze.ai/bot.
4.4. Server logs. Our servers record the IP address, user agent, pages requested and time of each request, kept for security and debugging.
5. Where the data comes from
Most data comes directly from you, from your websites through our apps and plugins, and from the platforms you connect. We also read the public pages of your website and public information about your company to fill in your Company ID and to check how AI assistants describe you; you can review and correct all of it in the app.
6. AI providers
To generate content, answers and scores, we send the necessary text and images to AI model providers such as Google and OpenAI under their business terms, which do not allow them to use that data to train their models. We send what the task needs: your company information, catalog and documents, the brief you wrote, and, for a store assistant, the conversation. We do not send access tokens or payment data to AI providers.
7. Who we share data with
7.1. Subprocessors. We use service providers to deliver the Services: cloud hosting and storage, a payment processor, email delivery, customer support and analytics tools, and the AI model providers named above. They process data under contracts that bind them to confidentiality and data protection obligations, and only for the purposes we set. A current list is available on request.
7.2. Platforms you connect. When you publish through a connection, the content you approved is sent to that platform. When you install Recomaze through an app store, that platform receives what its own terms describe.
7.3. Legal and corporate. We disclose data where the law requires it, to protect our rights and the safety of others, and, if Recomaze is involved in a merger, acquisition or sale of assets, to the parties involved, under the same protections as this policy.
7.4. We do not sell personal data and we do not share it for cross-context behavioral advertising.
8. How long we keep data
- Account data and Customer Data: for as long as your account is active. After your account ends you can ask for an export for 30 days; after that we delete Customer Data, except where the law requires us to keep records, such as invoices.
- Connected platforms: tokens and account identifiers are deleted when you disconnect, when the platform tells us you removed Recomaze, or when your account is deleted. Records of what was published and when are kept with your content library.
- Search Console and Analytics rows (Section 2.7): up to 16 months, and deleted when you disconnect Google or delete your account.
- Publishing and delivery logs: 90 days.
- Usage and server logs: up to 12 months, or longer where needed to investigate a security incident.
- Store interaction data (Section 3): for as long as the store uses the Services, then deleted with the store's account.
- Free tool results and website analytics: according to the retention set in each tool; you can ask us to delete a free tool result at any time.
- Support correspondence: three years after the last message.
9. Security
All data travels over encrypted connections and is stored on infrastructure that encrypts data at rest. Access to production systems is limited to the people who need it to run the Services and is logged. Passwords are stored hashed; platform tokens are stored in our database, are never shown in the app and are used only by the publishing service. No system is entirely secure; if a breach affects your personal data we will tell you and, where required, the competent authority, without undue delay.
10. Your rights
10.1. Depending on where you live, you have the right to access the personal data we hold about you, to have it corrected or deleted, to receive it in a portable format, to restrict or object to our processing, and to withdraw a consent you gave. In the European Economic Area and the United Kingdom these rights come from the GDPR; in California and other US states, from state privacy laws, including the right to know, delete and correct, and not to be discriminated against for exercising them.
10.2. To exercise a right, write to better@recomaze.ai from the email address on your account, or use the steps on our data deletion page. We answer within 30 days. We may ask you to confirm your identity first.
10.3. If you are not satisfied with our answer, you can complain to your local data protection authority.
11. Deleting your data
You can disconnect a platform, delete content, or close your account in the app, and you can ask us to delete everything we hold about you. The steps, and what is deleted when, are on our data deletion page.
12. Children
The Services are for businesses and the people who work for them and are not directed at anyone under 18. We do not knowingly collect personal data from children; if you believe a child gave us data, write to us and we will delete it.
13. Changes to this policy
We update this policy when the Services or the law change. The date at the top tells you when. For changes that reduce your rights we will notify account holders by email or in the app before they take effect.
14. Contact
Recomaze Inc.
115 Wild Basin Rd S, Suite 307
Austin, TX 78746, United States
Email: better@recomaze.ai