LEGAL · SECURITY
Where your data goes.
Your selected AI client independently processes the conversation and returned Output under its own terms. Its tool request goes to Retail Reason and its configured OpenAI API model to produce the answer and run an automated second-pass review. Retail Reason holds no retailer-portal credentials, connects to no retailer account, and reads nothing from your systems.
- Reach into your systems
- None. No retailer-portal credentials, no retailer-account access, nothing read from your systems, and no portal-data connector. Retail Reason does not automate actions in retailer systems.
- What is sent
- The current question or draft, pasted context, selected reference material, and, when a session identifier is used, up to three recent question or draft excerpts of no more than 300 characters each. An automated second-pass answer review may also send the generated draft answer and sanitized evidence needed to assess it; no person sits between the question and the delivered answer.
- Who processes it
- The customer-selected AI client independently processes the client conversation and returned Output. Retail Reason processes the tool request on Cloudflare and sends the disclosed model inputs to the configured OpenAI API model. Identity, billing, and transactional email use the separately limited providers in the subprocessor register.
- What Retail Reason retains
- Retail Reason stores no raw prompt, pasted context, or answer in its D1 query log. Up to three 300-character session excerpts expire 24 hours after the latest session write; the pasted-context field is not kept in session state. Ordinary resolved operational metadata is generally removed after 90 days. Invitation, recovery, and ordinary security or administration records may be retained for about 365 days. Necessary commercial, legal, billing, tax, refund, and approval evidence is generally retained for 7 years. Account and workspace configuration is designed to remain recoverable for 30 days after access ends. Unresolved obligations, legal holds, provider copies, and managed recovery residue follow different periods described in Privacy.
- Provider use and retention
- Retail Reason does not train its own models on customer content. OpenAI states that API content is not used for model training unless the customer organization affirmatively opts in. Retail Reason sets
store: falseand explicit-only prompt caching: only an eligible static Service-instruction and skill-workflow prefix may be cached, with the API’s currently supported minimum cache lifetime of 30 minutes; the question, context, session excerpts, per-request references, and review material follow the cache boundary. OpenAI states encrypted cache state may remain eligible for reuse for up to 24 hours under current controls, separately from abuse-monitoring logs that may contain prompts and responses for up to 30 days. - Identity and access
- Claude hosted uses account sign-in. Claude Code and Codex CLI use per-person, per-account access keys that are displayed once, hashed at rest, expire after 180 days, and can be revoked immediately. Product access is determined by Retail Reason’s account, role, workspace, billing, and revocation records.
- Account isolation
- Each request is bound to one account and an authorized workspace. Cross-account, archived, invalid, and inaccessible workspace identifiers receive the same non-enumerating response. Client guests can access exactly one workspace and cannot see account-wide information.
- Compliance artifacts
- No SOC 2 report. No penetration-test report. Send vulnerability disclosures to [email protected] with the subject “Security Report”; reporting guidance is in security.txt.
- Who holds production access
- One person, Matt Drake, the operator.
Everything an approver asks, in intake-form order, is on the vendor facts page. The named vendors and what each processes are on subprocessors.