Amorti
Privacy Policy
The short version
- If you ask an AI assistant to book or order from a business on Amorti, we pass your name, contact details and request to that business so it can respond. We email you its decision if you gave an email address.
- Businesses give us their public profile and may connect systems like Square or Google Calendar. We store those connections encrypted and use them only to run Amorti.
- We log what AI assistants ask each business's Amorti endpoint so we can run the service and show owners their activity.
- We do not sell personal information, and we do not use it for targeted advertising.
Contents
1. Who we are
Amorti is operated by Supreme Technology ("we", "us" or "our"), 133 W 6th St, Tempe, Arizona 85281, USA. This policy explains how we handle personal information in connection with Amorti. That includes the owner dashboard, the Amorti MCP server and gateway (for example mcp.supremetechy.com), our connectors, and the emails we send (together, the "Service"). The Amorti End User License Agreement governs use of the Service.
For customer information that a business receives through Amorti, we process it to provide the Service to that business. The business decides how it uses that information to serve you, under its own privacy practices.
2. Who this policy covers
- Business owners and staff who list a business on Amorti and use the dashboard.
- Customers: people who use an AI assistant (such as Claude, ChatGPT, Gemini or Copilot) to find, book or order from a business listed on Amorti.
- Visitors to Amorti web pages, and people who contact us.
3. Information we collect
From business owners
- Account information: your name, email address and password. We store only a secure hash of the password, not the password itself.
- Business profile: business name, description, category, address, phone, website, hours, service area, services, products and prices, photos, social profiles, ratings and booking links. Most of this is published to AI assistants by design.
- Connected systems: if you connect Square, Google Calendar, Shopify, QuickBooks or another supported system, we store the access credentials it issues, encrypted. We also store the data we read from it to provide the Service, such as catalog items, prices, stock levels and availability.
- Your decisions: whether you confirm or decline each request, and any note you add for the customer.
From customers, through AI assistants
- Request details: when you ask an AI assistant to request an appointment or place an order, it sends us the information you give it. That includes your name, your email address or phone number, the service, time or products you chose, and any note for the business.
- Request records: a reference number, the request's status, the business's response, and any payment link or order reference created for a confirmed order.
- We receive only what the AI assistant sends us. We do not receive your conversation with the assistant or your account with its provider.
Automatically
- AI assistant activity: for each call to a business's Amorti endpoint, we record which tool was used (for example "check availability" or "request appointment"). We also record the query text, a short summary of the result, the assistant's self-reported name and version, and its user-agent string. The query text can include words a customer typed, such as a search phrase.
- Server logs: our servers log technical request data, such as IP address, time, requested path, response status and user agent, for security and troubleshooting.
- Cookies: see Cookies below.
From public sources
- With a business's direction, our crawler "Amortibot" reads that business's public website to help build or check its profile. Amortibot identifies itself and follows the site's
robots.txtrules.
4. How we use information
- To operate the Service. That means publishing business profiles to AI assistants, answering their questions about services, prices, stock and availability, and passing requests to businesses.
- To send service emails: new-request notifications to businesses (with confirm/decline links), and outcome emails to customers who gave an email address.
- To create bookings, orders, invoices or payment links in the business's connected systems once the business confirms a request.
- To show business owners their requests and their AI-assistant activity and monitoring reports.
- To secure the Service: authenticating users and AI assistants, preventing fraud and abuse, and investigating incidents.
- To maintain, debug and improve the Service, including checking how businesses appear to AI assistants.
- To communicate with you about your account, the Service and changes to our terms.
- To comply with law and enforce our agreements.
Where the law of your location requires a legal basis for processing (for example the GDPR), we rely on these bases:
- performing our contract with businesses, and taking the steps a customer asked for;
- our legitimate interests in running, securing and improving the Service;
- compliance with legal obligations; and
- consent, where we ask for it.
5. How we share information
We do not sell personal information. We do not share it for cross-context behavioral advertising. We share it only as follows:
| With | What and why |
|---|---|
| The business you contact | Your request details, including your name and contact information, so the business can confirm, decline and fulfil it. |
| AI assistants | Business profile, catalog and availability information, which is public by design, plus the status of requests an assistant submitted. We do not give AI assistants customers' contact details or business owners' private account information. |
| Systems a business connected | Details of a confirmed request that the business has chosen to use in that system (for example Square, Google Calendar, Shopify or QuickBooks), so the booking, order or invoice can be created there. Those providers handle the data under their own privacy policies. Payments are made on the provider's pages. We never receive payment card numbers. |
| AI model providers | Public business profile information, when we check how a business appears to AI assistants, or run our onboarding demo. Providers include OpenAI and Google. |
| Legal and safety | Information we reasonably believe we must disclose to comply with law or legal process, or to protect the rights, property or safety of our users, the public or us. |
| Business transfers | Information transferred as part of a merger, acquisition, financing or sale of assets. It stays subject to this policy's protections. |
We host the Service and send its email from infrastructure we operate in the United States.
6. Google user data
If a business connects Google Calendar, Amorti asks for permission to view its calendar list, check free/busy times, and create and manage calendar events. We use this access only for these purposes:
- to show AI assistants the business's real availability; and
- to add confirmed bookings to the business's calendar.
Amorti's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Google user data for advertising.
- We do not sell it.
- We do not use it to train generalized AI or machine-learning models.
- We transfer it to others only as needed to provide the Service, for security, or to comply with law.
- People do not read it unless the business has agreed, it is necessary for security or to comply with law, or it has been aggregated and anonymized.
A business can disconnect Google Calendar at any time from the dashboard. When it does, we delete the stored credentials. It can also revoke access in its Google Account settings.
7. AI assistants
AI assistants are products of other companies, such as Anthropic, OpenAI, Google, Microsoft and Perplexity. What you tell an AI assistant, and how it handles that information, is governed by that company's privacy policy, not this one. We receive only the information the assistant sends to Amorti, as described above.
8. Cookies
The Amorti dashboard uses only strictly necessary cookies. They keep you signed in, protect forms against cross-site request forgery, and secure the process of connecting a business system. We do not use advertising cookies or third-party tracking cookies in the Service. You can block cookies in your browser, but the dashboard will not work without them.
9. How long we keep information
- Business accounts and profiles: kept while the account is active. After an account is closed, we delete or anonymize them within 90 days, except where we must keep information to comply with law, resolve disputes or enforce our agreements.
- Requests: a request the business does not act on expires after 48 hours. Request records, including customer contact details, stay available to the business in its dashboard while its account is active. We delete them with the account as described above, or sooner on a valid deletion request.
- AI assistant activity records: kept while the business's account is active, so the owner can see activity over time, and deleted with the account.
- Connected-system credentials: deleted when the business disconnects the system or closes its account.
- AI assistant access tokens issued by our gateway expire automatically and are purged after expiry.
- Server logs: rotated automatically and kept only as long as needed for security and troubleshooting.
10. Security
We use administrative, technical and physical safeguards designed to protect personal information, including:
- HTTPS encryption in transit;
- AES-256-GCM encryption of stored connected-system credentials;
- hashed passwords;
- single-use, hashed tokens for confirm/decline links; and
- OAuth-based authorization for AI assistants, which the business or administrator can revoke.
No system is perfectly secure, and we cannot guarantee absolute security. If we learn of a breach that affects your personal information, we will notify you as the law requires.
11. Your choices and rights
- Business owners can view and edit their profile and settings in the dashboard, disconnect connected systems, control which services and products AI assistants can see, and ask us to close their account.
- Customers can ask the business you contacted about your request. You can also contact us, and we will help or pass your request to the business.
Depending on where you live, including California, other US states, the European Economic Area, the United Kingdom and Canada, you may have the right to:
- know about and get a copy of the personal information we hold about you;
- correct it;
- delete it;
- receive it in a portable format;
- object to or restrict certain processing;
- withdraw consent; and
- not be discriminated against for exercising these rights.
To make a request, email info@supremetechy.com. We may need to verify your identity before acting on it. You may use an authorized agent where the law allows. If you are in the EEA or UK, you may also complain to your local data protection authority.
12. Children
The Service is not directed to children under 13, or under 16 where local law sets a higher age. We do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
13. International users
We operate the Service from the United States. If you use it from another country, your information will be transferred to, stored and processed in the United States, where data protection laws may differ from those in your country. Where required, we use appropriate safeguards for these transfers.
14. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and update the "Last updated" date. If a change is material, we will notify businesses by email or in the dashboard before it takes effect.
15. Contact us
Supreme Technology
133 W 6th St, Tempe, AZ 85281, USA
Email: info@supremetechy.com
Phone: (602) 780-0662