Automated Commerce

Cookie Policy

Version 1.1
Effective Date: June 7, 2026
Last Updated: August 22, 2026

1. About this policy

This Cookie Policy explains how Automated Commerce B.V. ("Automated Commerce", "we", "us") uses cookies and similar technologies on our website at automatedcommerce.ai (the "Website") and within our platform (the "Service").

This Cookie Policy should be read together with our Privacy Policy, which explains how we process personal data more broadly.

This Cookie Policy is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), the Dutch Implementation Act GDPR (Uitvoeringswet AVG), and Article 11.7a of the Dutch Telecommunicatiewet (which transposes the ePrivacy Directive 2002/58/EC into Dutch law).

2. What are cookies and similar technologies?

Cookies are small text files placed on your device by websites you visit. "Similar technologies" means other client-side storage and tracking mechanisms — including local storage, session storage, pixels, tags, web beacons, and software development kits — that fulfil the same function as cookies.

Throughout this policy, "cookies" includes both classic cookies and these similar technologies.

Cookies can be:

  • First-party — set by the domain you are visiting (in our case, automatedcommerce.ai).
  • Third-party — set by another domain (for example, a service provider whose script we have embedded).
  • Session — deleted when you close your browser.
  • Persistent — stored for a fixed period or until you delete them.

3. Consent

Under Article 11.7a Telecommunicatiewet, we may place strictly necessary cookies without your consent. For all other cookies (functional, analytics, and marketing), we ask for your consent through our cookie banner before any non-essential cookies are placed.

Our cookie banner allows you to:

  • Accept all cookies.
  • Reject all non-essential cookies.
  • Set preferences by category (functional, analytics, marketing).

You can change or withdraw your consent at any time by . Withdrawing consent does not affect the lawfulness of placement before withdrawal.

4. Categories of cookies we use

4.1 Strictly necessary cookies

These cookies are essential for the Website and Service to function and cannot be switched off. They are typically set in response to actions you take, such as logging in, filling in forms, or setting language preferences. The Service will not work properly without them. They do not require consent under Article 11.7a Telecommunicatiewet.

4.2 Functional cookies

These cookies enable enhanced functionality and personalisation, such as remembering your preferences and settings. They may be set by us or by third parties whose services we use on our pages. If you reject them, some functionality may not work as expected. Consent is required.

4.3 Analytics cookies

These cookies help us understand how visitors interact with our Website and Service so that we can improve them. They count visits, identify which pages are most and least popular, and connect behaviour across sessions through a pseudonymous first-party visitor ID. The information they collect is aggregated and, where technically feasible, pseudonymised. Consent is required.

First-party analytics: With your consent, we use our self-hosted Umami and PostHog analytics systems and, on participating merchant storefronts, the AC collector to understand consented journeys and reconcile commerce events. These paths are independently blocked until analytics consent. On the marketing Website, PostHog browser storage is enabled only after analytics consent. We do not send names, raw email addresses, CRM IDs, or internal user IDs to browser analytics.

Cookieless analytics: We use Vercel Web Analytics, which is a cookieless analytics service that does not place any cookies on your device and does not track individual users across sessions or sites. Because no information is placed on or read from your device, Vercel Web Analytics falls outside Article 11.7a Telecommunicatiewet and does not require your consent.

4.4 Marketing cookies

These cookies are set by us and by advertising partners. They are used to build profiles of your interests and to show you advertisements that are relevant to you on our Website and on other websites. They typically work by uniquely identifying your browser and device. Consent is required.

5. Cookies in use

The following table lists the cookies and similar technologies we currently use. We update this list when our deployment changes.

Cookie nameProviderPurposeTypeLifetime
ac_cookie_consentAutomated Commerce (first-party)Stores your cookie preferences.Strictly necessary12 months
ac_analytics_idAutomated Commerce Analytics (first-party)Stores a pseudonymous visitor ID to connect consented website journeys across sessions.Analytics12 months
ac_vidAutomated Commerce Analytics (first-party)On an approved headless storefront using the exact-origin collector, stores a pseudonymous visitor ID after analytics consent. It is HttpOnly and is not available to storefront JavaScript. Other storefront modes do not receive this cookie.AnalyticsUp to 400 days
AC / Umami requestAutomated Commerce Analytics (first-party or approved merchant proxy)Sends consented behavioral and commerce telemetry to the AC collector or the separately operated Umami tracker. Umami does not add its own browser cookie in this configuration.Analytics technologyPurpose-specific merchant retention
ph_ac_posthog*PostHog (self-hosted, first-party)Stores a pseudonymous visitor and session identifier for consented marketing-site analytics.Analytics12 months
ac_posthog_consentPostHog (self-hosted, first-party)Mirrors the analytics consent choice so PostHog stays disabled unless consent is granted.Strictly necessary12 months
better-auth.session_tokenAutomated Commerce (first-party)Maintains user session and authentication state.Strictly necessary7 days
better-auth.csrf_tokenAutomated Commerce (first-party)Protects against cross-site request forgery attacks.Strictly necessarySession
NEXT_LOCALEAutomated Commerce (first-party)Remembers your selected language preference.Functional12 months

Analytics storage and requests are only enabled after you grant analytics consent. This table describes the current Website and Service deployment. Advertising destinations are not enabled by joining the analytics pilot and require their own approval and disclosure.

Analytics disclosure / Analyticsverklaring

Storefront analytics data flow

For participating merchant storefronts, Automated Commerce acts as the merchant's processor for consented behavioral analytics and attribution. The merchant remains responsible for the legal basis and the consent message shown on its storefront.

After analytics consent, the storefront may send page views, product and cart interactions, checkout events, campaign parameters, timestamps, page and referrer URLs, and related product, cart, checkout, or order references. Requests use https://collect.automatedcommerce.ai/v1/collect or an exact merchant-owned proxy approved for that storefront. The AC collector and the separately operated Umami tracker remain blocked before consent.

The data can include pseudonymous visitor, session, consent, event, and commerce identifiers. On an approved headless storefront using the exact-origin collector, the collector may set the HttpOnly first-party ac_vid cookie after consent. It expires after at most 400 days. Other storefront modes do not receive ac_vid. Identifiers are used to deduplicate events, connect consented interactions, reconcile Shopify orders and refunds, and calculate descriptive attribution. They are not used to guess a person-level link when the evidence is missing.

Accepted raw envelopes are temporarily stored in Cloudflare R2. Canonical events, permitted identity links, touches, journeys, and attribution outputs are stored in our self-hosted ClickHouse analytics environment on Hetzner infrastructure in Germany. Cloudflare D1 stores bounded consent, delivery, and privacy-workflow evidence. Neon PostgreSQL stores tenant configuration, approvals, and operational references. Destinations for advertising remain off unless separately approved.

Retention is approved per merchant and purpose. Raw events, canonical behavioral events, identity links, journeys and touches, consent state, delivery evidence, privacy receipts, and non-identifying aggregates can therefore have different periods. Personal derived data inherits the earliest applicable source expiry. Automated expiry and bounded cleanup apply across R2, ClickHouse, and D1. We do not present one raw-event period as the retention period for every store.

Withdrawing analytics consent stops later browser telemetry and new analytics identity use. A shopper can also request access or erasure through the merchant, or contact us where Automated Commerce is the controller. Verified erasure covers the applicable R2, ClickHouse, identity, consent, delivery, cache, and pending-job records. Separately permitted operational order records may remain where the merchant has a documented legal or contractual reason.

The processors used for this flow are Cloudflare for edge collection, queues, R2, D1, and secure connectivity; Hetzner for the self-hosted Umami, PostHog, Kafka, PostgreSQL, and ClickHouse analytics stack; and Neon for the main PostgreSQL control records. Umami, PostHog, and ClickHouse are self-hosted software in this flow, not cloud subprocessors that receive the data on their own account. See the current subprocessor list.

Gegevensstroom voor storefront-analytics

Voor deelnemende webwinkels verwerkt Automated Commerce analytics- en attributiegegevens in opdracht van de winkelier. De winkelier blijft verantwoordelijk voor de rechtsgrond en de toestemmingsmelding in de webwinkel.

Na toestemming voor analytics kan de webwinkel paginaweergaven, product- en winkelwageninteracties, checkoutgebeurtenissen, campagneparameters, tijdstippen, pagina- en verwijzende URL's en bijbehorende product-, winkelwagen-, checkout- of orderreferenties versturen. Verzoeken gaan naar https://collect.automatedcommerce.ai/v1/collect of naar een voor die webwinkel goedgekeurde proxy op het eigen domein. De AC-collector en de afzonderlijk werkende Umami-tracker blijven vóór toestemming geblokkeerd.

De gegevens kunnen pseudonieme bezoeker-, sessie-, toestemming-, gebeurtenis- en commerce-identificatoren bevatten. Bij een goedgekeurde headless webwinkel met de collector op hetzelfde domein kan de collector na toestemming de HttpOnly first-party cookie ac_vid plaatsen. Deze verloopt uiterlijk na 400 dagen. In andere storefrontmodi wordt ac_vid niet geplaatst. De identificatoren worden gebruikt om dubbele gebeurtenissen te voorkomen, toegestane interacties te verbinden, Shopify-orders en terugbetalingen te controleren en beschrijvende attributie te berekenen. Bij ontbrekend bewijs raden wij geen persoonskoppeling.

Geaccepteerde ruwe berichten worden tijdelijk opgeslagen in Cloudflare R2. Canonieke gebeurtenissen, toegestane identiteitskoppelingen, touchpoints, klantreizen en attributieresultaten worden opgeslagen in onze zelf beheerde ClickHouse-analyseomgeving op infrastructuur van Hetzner in Duitsland. Cloudflare D1 bevat begrensd bewijs over toestemming, levering en privacyprocessen. Neon PostgreSQL bevat tenantconfiguratie, goedkeuringen en operationele referenties. Advertentiebestemmingen blijven uitgeschakeld zonder afzonderlijke goedkeuring.

De bewaartermijn wordt per winkelier en doel goedgekeurd. Ruwe gebeurtenissen, canonieke gedragsgebeurtenissen, identiteitskoppelingen, klantreizen en touchpoints, toestemmingsstatus, leveringsbewijs, privacybewijzen en niet-identificerende aggregaten kunnen daarom verschillende termijnen hebben. Afgeleide persoonsgegevens erven de vroegste toepasselijke vervaldatum van de bron. Automatische verwijdering en begrensde opschoning gelden voor R2, ClickHouse en D1. Eén termijn voor ruwe gebeurtenissen wordt niet voorgesteld als bewaartermijn voor alle opslag.

Na intrekking van analytics-toestemming stopt latere browsertelemetrie en nieuw gebruik van de analytics-identiteit. Een bezoeker kan ook via de winkelier om inzage of verwijdering vragen, of rechtstreeks contact met ons opnemen wanneer Automated Commerce verwerkingsverantwoordelijke is. Geverifieerde verwijdering omvat de toepasselijke gegevens in R2, ClickHouse, identiteit, toestemming, levering, caches en wachtende taken. Afzonderlijk toegestane operationele ordergegevens kunnen blijven bestaan wanneer de winkelier daarvoor een vastgelegde wettelijke of contractuele grond heeft.

Voor deze gegevensstroom gebruiken wij Cloudflare voor edge-collectie, wachtrijen, R2, D1 en beveiligde verbindingen; Hetzner voor de zelf beheerde Umami-, PostHog-, Kafka-, PostgreSQL- en ClickHouse-analysestack; en Neon voor de belangrijkste PostgreSQL-controledata. Umami, PostHog en ClickHouse zijn in deze stroom zelf beheerde software en geen cloudsubverwerkers die de gegevens voor eigen rekening ontvangen. Bekijk de actuele lijst met subverwerkers.

6. Third-party cookies and international transfers

We do not currently install Google Analytics, Meta Pixel, Google Ads, or LinkedIn Insight cookies on the Website. The analytics tools listed above are operated by us on hosting infrastructure supplied by our processors. Those processors act on our instructions and are listed on our Sub-processors page.

Vercel Web Analytics processes cookieless request data on Vercel's infrastructure. Cloudflare may process requests through its globally distributed edge. Our Privacy Policy and current Sub-processors page explain the applicable processors, locations, and transfer safeguards.

7. Managing cookies

You can control cookies in several ways:

Through our cookie banner. to change your settings at any time.

Through your browser. Most browsers allow you to refuse cookies, accept only certain types, or delete existing cookies:

Through opt-out tools. Some advertising networks offer industry opt-outs at:

Note: blocking strictly necessary cookies will prevent the Website and Service from functioning correctly.

8. Do Not Track signals

Some browsers transmit "Do Not Track" signals. Because there is no common standard for what these signals mean and how they should be respected, we do not currently respond to them. We respect your cookie preferences as set through our cookie banner.

9. Changes to this Cookie Policy

We may update this Cookie Policy from time to time. The latest version is always available at automatedcommerce.ai/policies/cookie-policy. Material changes will be communicated through the Website.

10. Contact

Questions about this Cookie Policy can be sent to business@automatedcommerce.ai. You may also lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), the Dutch supervisory authority.

Automated Commerce B.V.

Chamber of Commerce (KvK) Number: 98684213

VAT Number (BTW): NL004708975B53

Registered Office: Herengracht 451, 1017 BS Amsterdam, Netherlands

Want to change your cookie choices?

Stay Ahead: Newsletter

Get the latest insights from the AI-industry and updates on new platform features