Last updated: 29 July 2026
Goppa helps online stores be found and understood by AI shopping agents, and measures the result. This page explains what data we handle, why, and for how long. It covers both the Goppa website and the Goppa Agentic Commerce plugin.
Goppa ("we") operates the Goppa service and publishes the Goppa Agentic Commerce plugin. For questions about this policy or to exercise any of the rights below, contact privacy@trygoppa.com.
Out of the box, the plugin only serves files on your own domain
(/.well-known/ucp, /llms.txt, /mcp,
/goppa/catalog). It contacts no external server, and no data
leaves your site. Reporting is opt-in by design.
If you paste a token from your Goppa account into
Settings → Goppa, the plugin queues one small record each time an
AI agent requests one of those endpoints, and sends the batch to
https://trygoppa.com/api/ingest after the response to the
agent has already been delivered.
| Field | What it is | Example |
|---|---|---|
origem | Which endpoint was requested | mcp |
ua | The User-Agent string sent by the agent. We classify it server-side into a known agent name and store only that classification | GPTBot/1.2 |
detalhe | Which MCP tool was called | search_products |
consulta | The search term or product identifier the agent asked for | running shoes |
produto | Name of the product returned first | Aurora Run |
Each record is tied to your store by the token. Text fields are capped at 200 characters.
Human traffic is not recorded at all — only requests to the four agentic endpoints above. Your ordinary page loads never touch this code path.
Clear the token field in Settings → Goppa and reporting stops immediately. Deactivating the plugin stops it and removes its scheduled task. Deleting the plugin erases every option it created, including the token.
| Data | Why | Kept |
|---|---|---|
| Email address and account identifier | To create and authenticate your account | Until you delete the account |
| Domains you scan, and the resulting reports | To show the report and let you compare over time | Until you delete them; free-plan reports may expire earlier |
| Agent activity reported by the plugin (section 2) | To show what AI agents do on your store | Until you delete the store or the account |
| Visibility measurements | To show whether AI assistants recommend your store, and how that changes | Until you delete the account |
| Billing details | To process subscriptions — handled by Stripe; we never see or store card numbers | As required by Stripe and by tax law |
We do not sell data, and we do not use it for advertising.
We process account and store data to perform the contract you have with us, and technical data to run and secure the service (legitimate interest). Agent-activity reporting is enabled only by your own act of configuring a token.
You have the right to access, correct, export, restrict and delete your data, and to object to processing. Write to privacy@trygoppa.com and we will respond within 30 days. You may also complain to your local data protection authority.
Data is transmitted over HTTPS and stored on managed infrastructure with access limited to what the service needs. Your store token authorises writing agent activity for that one store and nothing else; if it leaks, clear the field and reconnect the store to get a new one. Deleting your account removes your stores, reports, measurements and agent activity.
If this policy changes materially we will update the date above and note it in the plugin changelog.