Privacy Policy
AirShelf Catalog MCP connector · last updated July 30, 2026
Scope
This policy covers the AirShelf Catalog MCP server at https://mcp.airshelf.ai/mcp (and per-merchant endpoints https://mcp.airshelf.ai/<merchant>/mcp), used as a Model Context Protocol connector by AI agents. The connector requires no account and no authentication.
What we collect
- Catalog queries. The search/compare/lookup terms an agent sends to read-only tools (e.g.
search_catalog). These describe products, not people. - Quote requests. When an agent calls
request_quote, we receive the buyer-provided contact details (name, work email, optional company), the products of interest, optional quantity, and any notes. - Operational metadata. Request IP (for rate limiting) and standard server logs.
- Chat conversations. Messages exchanged with the assistant on our
/chatpages are recorded to improve the service, with email addresses and phone numbers masked before storage.
Beyond the chat pages, we do not collect data beyond what an agent explicitly sends to a tool.
How we use it
- Catalog queries are used to return product results from the AirShelf catalog. They are not tied to an identity.
- A quote request is confirmed by the buyer before it goes anywhere. The details an agent submits are held temporarily and we email a confirmation link to the address in the request; the merchant is told nothing at this stage. Only when that link is opened and confirmed do we create a sales lead and notify the merchant's sales team.
- IP is used only for per-IP rate limiting and abuse prevention.
Sharing
A confirmed request_quote lead is shared with the specific merchant it is addressed to, so they can follow up — that is the intended outcome, and it happens only after the buyer confirms. An unconfirmed request is never shared with a merchant. For brands in the wider AirShelf network that have no merchant account, a confirmed request goes to the AirShelf team and is passed on to that brand by a person, never automatically. We use these processors to operate the service: Vercel (hosting), Neon (database), Upstash (temporary storage and rate limiting), and an email provider for confirmation and notification email. We do not sell personal data or use it for advertising.
Retention
An unconfirmed quote request is held for up to 72 hours and then deleted automatically; if the buyer never confirms, nothing about it reaches a merchant and no lead is created. Confirmed quote leads are retained for as long as needed to service the merchant relationship and as required by law. Operational logs are retained for a limited period for security and reliability.
If you received a confirmation email you did not ask for
Nothing is sent to a merchant unless you confirm, and the request is deleted within 72 hours — the email exists precisely so that an address an agent supplies cannot be passed to a sales team without the person it belongs to agreeing. Use the “Don't contact me again” button to stop future confirmation emails for your address, or simply ignore the message: after three ignored confirmations they stop automatically. To report misuse, contact us below.
Your choices & contact
To request access to, correction of, or deletion of a lead you submitted, or with any privacy question, contact founders@airshelf.ai.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above.