Agent Commerce
HomeProtocolsTransaction FlowGuidesDocs
Star on GitHub
Home/Legal

Privacy policy

This website is a brochure and a manual. It has no accounts, no carts and no tracking beyond one analytics tool you can refuse.

Last updated 20 Sep 2026 · Operated by DevLab

This policy covers Agent Commerce Gateway's website, operated by DevLab. It explains what we collect when you read these pages or write to us, why, and what you can ask us to do about it.

It does not cover the software. Agent Commerce Gateway is open source and self-hosted: you run it in your own environment, it holds your own keys and settlement destination, and it sends nothing to us. Whatever passes through your deployment stays between you, your buyers and your own providers — we never see it.

#Analytics, only with your permission

If you allow it, we load Google Analytics 4 to count visits and see which pages get read. It records the pages you open, the site or search that sent you, approximate location derived from your IP address, and basic device and browser details. We use it to decide what to write next — nothing more.

Until you agree, no analytics script loads and no analytics cookie is set. You can change your answer at any time on the cookie policy — the link sits in the footer of every page — and we honour the browser signal Global Privacy Control as a refusal. We have advertising signals switched off, so this data is not used to build advertising profiles.

#When you contact us

If you book a call or email us, we receive your email address, the time you picked, the timezone your browser reports, and whatever you choose to tell us. We use it to answer you and to keep a record of the conversation. We do not add you to a marketing list, and we do not sell or share it.

The booking form is protected by Cloudflare Turnstile, which checks that you are a person rather than a bot. It runs invisibly: when you submit the form, your browser loads a script from Cloudflare, and Cloudflare receives your IP address along with browser and device details in order to score the request. Cloudflare states that this data is not used for advertising or cross-site tracking. See the Turnstile privacy policy. Nothing is sent to Cloudflare while you are only reading the page.

#Server logs

The provider that serves these pages keeps standard request logs — IP address, time, page requested, browser — for a short period, to keep the site running and to defend it against abuse. This is ordinary infrastructure logging, not analytics, and it happens whether or not you accept cookies.

#What we do not do

  • No accounts, passwords or payment details are collected here.
  • No advertising, retargeting or cross-site tracking.
  • No third-party fonts, embeds, chat widgets or social buttons: every asset on these pages is served from this site, so nobody else gets a request when you read them. The one exception is the Turnstile check above, and it loads only when you submit the booking form.
  • We do not sell personal data, and we never have.

#Why we are allowed to (GDPR)

WhatBasis
AnalyticsYour consent, which you can withdraw at any time
Answering your messageOur legitimate interest in replying to you, or steps ahead of a contract
Server logs, securityOur legitimate interest in keeping the site available and safe
Turnstile check on the booking formOur legitimate interest in keeping the form free of bots and spam

#Who else sees it

  • Google — analytics, only after you accept. See Google's privacy commitments.
  • Cloudflare — runs the Turnstile check when you submit the booking form. See the Turnstile privacy policy.
  • Our hosting provider — serves the pages and keeps the request logs described above.
  • Our email provider — carries the messages you send us.

Some of these providers operate outside the EEA and the UK. Where that happens, the transfer relies on the European Commission's standard contractual clauses or an adequacy decision.

#How long we keep it

Analytics data expires on Google's retention schedule, which we set to the shortest useful window. Messages and call requests are kept while the conversation is live and for a reasonable period afterwards, then deleted. Server logs rotate on the provider's schedule, typically within weeks.

#Your rights

If you are in the EEA or the UK you can ask us for a copy of what we hold about you, ask us to correct or delete it, object to our use of it, or ask for it in a portable form. You can withdraw analytics consent whenever you like — it takes one click and does not affect anything that happened before.

Write to [email protected] and we will answer within a month. If you are not satisfied, you can complain to your national data protection authority.

#Children

This is a developer tool. The site is not directed at children, and we do not knowingly collect anything from anyone under 16.

#Changes

When this policy changes we update the date at the top of the page. If the change is material we will say so on the site rather than quietly editing it.

Questions: [email protected].

The three documents

  • Privacy policy
  • Terms of use
  • Cookie policy

Questions about any of this go to [email protected].

AGENT COMMERCE GATEWAY

Your API. Their agents. Every transaction controlled. Self-hosted, non-custodial, open source — the gateway never holds your money or your keys.

npx @devlab.group/agent-commerce init
GitHub[email protected]

Product

  • Overview
  • How it works
  • Proposals
  • Protocols
  • All guides
  • Press kit
  • Architecture (PDF)
  • Presentation (PDF)

Documentation

  • Quickstart
  • Integration guide
  • Configuration
  • API reference
  • CLI reference
  • Examples

Guides

  • Make an API agent-ready
  • Monetize an API for agents
  • Protocols compared
  • Monetize an MCP server
  • How agents pay for APIs
© 2026 DevLabv1.4.0 · updated 6 days agoApache-2.0
Privacy policyTerms of useCookie policy
Built by DevLab