In plain language
- We collect only what we need to answer you, run our products and bill our customers.
- We never sell your data or share it with advertisers.
- This website uses no analytics or advertising cookies.
- Each product's section explains exactly what that product processes.
- You can ask us to access, correct or delete your data.
1. Who we are
Reqursor Technologies ("Reqursor", "we", "us") is a software company based in Rotterdam, The Netherlands. We make two products: Reqursor Platform, an AI platform for ecommerce agencies, and Reqursor Development, a self-hosted AI development agent. Reqursor Development licenses are managed in Reqursor Licensing, our license portal.
We are the data controller for the personal data we process as described in this policy. This policy applies to:
- this website, reqursor.com
- Reqursor Platform, its website (platform.reqursor.com) and its dashboard
- the Reqursor Development website (development.reqursor.com) and the Reqursor Development product
- the Reqursor Licensing portal (license.reqursor.com)
Section 2 covers this website. Sections 3 and 4 explain what each product and its website process. Sections 5 to 9 apply to all of them.
2. This website
Contact form
When you use the contact form on this website, we collect your name, your email address, your company (optional), the subject you choose and your message. We use this information only to reply to you. Your message is delivered to us by email, and we do not use it for marketing.
Cookies and local storage
This website uses no analytics or advertising cookies. If you choose a light or dark theme, that preference is kept in your browser's local storage and is never sent to us.
Technical data
Like any website, our servers process technical data such as your IP address to deliver pages to you and to protect the site against abuse, for example to limit how often the contact form can be submitted.
3. Reqursor Platform
This section applies to Reqursor Platform, its website (platform.reqursor.com) and its dashboard.
Account data
When you create a Reqursor Platform account: name, email address, organization name and authentication credentials (password stored as a salted hash, never in plaintext).
Store configuration data
Store definitions, design tokens, page compositions, managed configuration, deployment history and run artifacts. This is the data that powers the platform's deterministic execution engine.
Store business data
Product catalogs, customer orders, media uploads and store platform settings that are not managed by Reqursor Platform. This data lives in your store's isolated Docker volumes and is not accessed, processed or read by Reqursor except during AI migration (with your explicit consent, read-only, and only for the duration of migration).
Usage data
Platform usage metrics: deployment counts, AI operation counts and feature usage patterns. Used to improve the product and calculate billing. No personally identifiable information from your store visitors is collected.
AI interaction data
When you use AI features, we send store configuration metadata (design tokens, block configurations, drift evidence) to our AI provider (Anthropic, through the Claude API). We never send secret values, database credentials, store business data, customer information or data from other organizations.
AI provider data handling
Reqursor Platform's AI features use the Anthropic Claude API. Data sent to the AI provider is:
- Scoped to one tenant per request: no cross-organization data in any AI prompt.
- Minimized: only the configuration metadata needed for the specific operation.
- Excluded from training: Anthropic does not train models on API customer data.
- Free of secrets: passwords, API keys, salts and credentials are never included.
- Free of business data: orders, products and customer records are never included.
Data isolation
Each organization operates in structural isolation. Your stores run in dedicated Docker containers with private networks and volumes. No store can access another store's data. No organization can see another organization's configuration, health status or operational data. This is enforced architecturally, not by policy.
Data retention
- Store definitions: retained as long as the organization exists.
- Deployment artifacts: 90 to 365 days depending on type.
- Audit logs: 365 days.
- AI interaction logs: 30 days.
- After account deletion: all data permanently purged within 30 days of the grace period ending.
Dashboard cookies
The Reqursor Platform dashboard uses essential cookies for authentication and session management (required). Optional cookies include analytics (to understand usage patterns) and error reporting (Sentry, to fix bugs). You can manage your preferences via the cookie banner or in your account settings under Data & Compliance.
Reqursor Platform website
The early-access form on the Reqursor Platform website collects your first and last name, work email, company or agency name, the number of online stores you manage (as a range) and the biggest operational pain point you want Reqursor Platform to solve. The contact form on that website collects your first and last name, email address, the subject you choose and your message.
Both forms are delivered to us by email, and early-access applications go to our sales team. We use your details only to reply to you and, if you apply for early access, to assess your application. We do not use them for marketing. To prevent abuse, the number of submissions from one email address or IP address is limited.
The Reqursor Platform website uses no analytics or advertising cookies. If you choose a light or dark theme, that preference is kept in your browser's local storage and is never sent to us.
4. Reqursor Development and Reqursor Licensing
Reqursor Development runs on your infrastructure
Reqursor Development is installed on your own Linux server. Its dashboard, worker and agent sandbox run there, together with your tickets, run history, audit log and encrypted secrets.
Reqursor Development sends your code and ticket text only to destinations you choose and configure:
- The model provider you choose: prompts and working context, including the code the agent reads, go to Anthropic, or to Amazon Bedrock, Google Vertex AI or Microsoft Foundry if you use them.
- Your git remote: commits and pull requests go to the repository you connected, on the branches you allow.
- The integrations you connect: your tracker, email, Slack or webhooks receive the updates you switch on.
Secrets you store in Reqursor Development are encrypted at rest and never sent to Reqursor. The Reqursor Development dashboard loads no external scripts, fonts or trackers. Our license server receives only the license information described below, and there is no other telemetry.
The daily license check
Once a day, each install checks its license with our license server at license.reqursor.com. The check contains exactly eight fields of license metadata: the random ID the install created when it first started, the license ID, the Reqursor Development version, the operating system, the processor architecture, the number of active users with a developer seat, the number of active projects and the number of runs started in the last 24 hours. The last three are counts only.
A license check never contains code, ticket text, repository or project names, branch names, prompts, model output, user names or email addresses. The Reqursor Development security page lists the exact fields. An install that runs on an offline license file (Enterprise) sends no license check at all.
License actions you start
Some actions you start yourself also contact the license server, for example activating a license key, starting a trial, buying a license, moving a license to new hardware or managing billing. Each of these requests carries the install's ID and, depending on the action, details such as the license key, a hardware fingerprint, the version, operating system and architecture, the plan and billing interval you chose, or your new number of seats and projects. Starting a trial also sends your company name and work email, so that we can send you a confirmation link.
The hardware fingerprint is a SHA-256 hash of the machine ID and the data volume's ID. The license server uses it to notice when an install has moved to new hardware, and never to lock it out.
The Reqursor Licensing portal
Reqursor Licensing (license.reqursor.com) is where Reqursor Development customers buy a license, see their licenses and installs, move an install to new hardware and manage billing.
- Sign-in: we email you a one-time sign-in link, so there is no password. Sign-in works for the contacts on a license or trial.
- Payments: payments run through Stripe. You pay with Stripe Checkout, and you manage invoices, payment methods and cancellation in the Stripe customer portal.
- Licenses and installs: the portal shows each license on your account, its status and renewal date, and which installs use it.
- Emails: we email you a link to confirm a trial, and your license key when you buy a license.
- Cookies: the portal sets only strictly necessary cookies. One keeps you signed in for up to 7 days after you sign in, or until you sign out. While you buy a license, another cookie remembers your checkout for up to 24 hours. The portal uses no analytics or advertising cookies. If you choose a light or dark theme, that preference is kept in your browser's local storage and is never sent to us.
Demo requests
The contact form on the Reqursor Development website, used to request a demo, the license terms or a security review, collects your first and last name, work email, company, the number of developers on your team, the plan you are interested in, where you would run Reqursor Development and an optional message. Your request is delivered by email to our sales team, and we use your details only to reply to it. To prevent abuse, the number of requests from one email address or IP address is limited.
5. How we use data
We use personal data only for the purposes described in this policy:
- To reply to you: answering contact form messages, early-access applications, demo requests and other questions.
- To provide our products: running Reqursor Platform, and licensing and supporting Reqursor Development.
- To bill our customers: processing payments and invoices for the products they use.
- To keep our services secure: protecting our websites and products against abuse.
- To communicate with customers: service notifications, security alerts and, with your consent, product updates.
We never sell personal data or share it with advertisers.
6. Your rights
Under the GDPR and other applicable data protection laws, you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted.
- Restriction: have the processing of your data limited.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to the processing of your data.
- Withdrawal of consent: withdraw your consent at any time, where we process data based on it.
To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with a data protection authority. In the Netherlands, that is the Autoriteit Persoonsgegevens.
Some products also let you act on your data directly:
- Reqursor Platform: access and export your data in standard formats (JSON, CSV) with the Data Export feature, update your profile and organization data, delete your account and all associated data, and object to analytics through your cookie preferences.
- Reqursor Licensing: see your licenses and installs in the portal, and manage invoices, payment methods and cancellation in the Stripe customer portal.
7. Security
We protect personal data with appropriate technical and organizational measures.
For Reqursor Platform, we use TLS encryption for all data in transit, encrypt secrets at rest, enforce per-store isolation via Docker, drop all Linux capabilities from containers, and never store plaintext credentials in Git, logs or artifacts.
For Reqursor Development, the security page describes what the product sends where, what the license check contains and how the agent is isolated.
8. Changes to this policy
We may update this policy when our websites, products or practices change. The latest version is always published on this page, and the date and revision number at the top show when it last changed.
9. Contact
For questions about this policy or your personal data, or to exercise your rights, email [email protected]. For other legal questions, email [email protected].
Data Protection Contact
[email protected] · Reqursor Technologies, Rotterdam, The Netherlands