This policy explains how Randmar Inc. handles information in connection with randmar.io (the "Website") and the Randmar MCP connector (the "Connector"). The Website is a static public website. The Connector is a separate service that lets an authenticated user search Randmar API operations and, when authorized, read or change Randmar business records through those operations.
Information collected and used by the Website
The Website does not provide a visitor account or send form entries to Randmar. Randmar does not collect or retain visitor personal information or Website access logs. The Website's static files are hosted by Microsoft Azure, which processes ordinary network request information as needed to deliver the files; Randmar does not keep those request details as access logs. If you choose to email us, your message and sender details are received by Randmar and its business email provider so we can respond and provide support.
Some learning pages let you create or import a PDF in your browser. They may process the learner or store name, results, decisions, actions, links, and deferred steps that you enter or include in a PDF. The generated or imported PDF is saved in IndexedDB in your browser, not uploaded to Randmar. You can remove it using the page's remove control or clear this Website's browser storage. Do not include passwords, access tokens, payment card details, or other restricted personal information in these learning materials.
Cookies and browser storage
The Website currently does not run analytics or advertising scripts and does not use tracking cookies. Its cookie-preference page stores your accept or reject choice in local storage in your own browser; that choice is not sent to Randmar. The learning pages may save PDFs in IndexedDB in your browser, as described above. You can remove these items through the page controls or clear the Website's browser storage. If optional cookies or analytics are introduced later, we will update this policy and request consent where required. Links to external websites are governed by those websites' own privacy practices.
Information processed by the Connector
When you connect the Connector through an AI client such as ChatGPT, the Connector processes the authenticated Randmar account's verified email address, application ID, and application name when those values are supplied by the authentication service. It also receives the tool requests you choose to make: search terms, category filters, result limits, endpoint identifiers, path and query values, and JSON fields for the selected Randmar API operation. Depending on the operation, those values and results may include partner names and business contact details, billing names and addresses, carts, orders, shipments, invoices, payment records, and supplier bank-account or remittance details used for bank transfers. The Connector may also return a Stripe-hosted payment link for an invoice. The exact fields depend on the operation and your account's authorization.
The Connector uses this information to authenticate and route requests, show available API operations, manage Randmar partner accounts, support billing and invoicing, coordinate orders and shipments, make supplier payments by bank transfer, create or present invoice-payment links, reconcile payments, return results, protect the service, and diagnose failures. It does not retrieve or reconstruct your full AI conversation. Your AI client receives the conversation, tool inputs, and tool results—including supplier bank details if you submit them through a supplier-payment operation—and handles them under its own terms, privacy policy, and account settings.
Billing, supplier payments, and card payments
Randmar stores billing names and addresses and business contact information for most partners in its Warehousing ERP. Contact information may include a contact person's name, business email address, and telephone number. These details are used to administer partner accounts, prepare invoices, coordinate orders and shipments, and contact partners about Randmar services. Randmar also stores supplier bank-account and remittance details when needed to pay a supplier by bank transfer. This is sensitive financial information; it is used for supplier payment setup and accounts payable. Only provide it through a supplier-payment operation when you are authorized to do so, and avoid repeating full bank values in chat or confirmation messages.
Some invoice payments use Stripe. When the Connector returns a Stripe-hosted payment link, the payer enters card details on Stripe's page. Stripe processes those card details; they are not entered as fields in the MCP payment-link request. Randmar may receive payment confirmation and related invoice or transaction information for reconciliation. Do not paste card numbers, expiration dates, security codes, PINs, passwords, or access tokens into the Connector chat. A Stripe payment link may provide access to an invoice or payment action, so handle it as sensitive.
Who receives Connector information
- Your AI client, such as OpenAI's ChatGPT, receives your conversation, tool requests, and Connector results so it can provide the service. The AI provider handles that information under its own terms, privacy policy, and account controls.
- Auth0 (randmar.us.auth0.com) provides sign-in and issues the OAuth access token used for the Connector.
- Randmar Auth (auth.randmar.io) receives the OAuth token for validation and exchange and returns a short-lived Randmar API credential and account context. The original OAuth token is not sent to api.randmar.io.
- Randmar API (api.randmar.io) receives the selected operation and the values you provide for it, together with the authorization credential for the connected route, to perform the requested business operation. On /connect, this is the short-lived credential returned by Randmar Auth; on legacy /mcp, it is the Randmar API bearer credential supplied by the caller and forwarded for that request.
- Randmar's Warehousing ERP stores the business records needed to provide Randmar services, including partner billing names and addresses, partner business contact details, carts, orders, shipments, invoices, payment history, and supplier bank-account or remittance details used for bank transfers. Authorized Randmar staff and service providers receive access only as needed to manage accounts, fulfill orders, bill partners, and process or reconcile payments.
- Stripe receives payment information that a payer enters on its hosted page when paying an invoice, and processes the payment under Stripe's terms and privacy practices. Randmar may receive a payment status and related transaction or invoice information from the payment flow. Banks and other payment providers may receive supplier bank-account and transfer information as needed to issue bank transfers.
- Service providers that host or secure the Connector may process limited technical information needed to operate it. Microsoft Azure hosts the static Website files.
Randmar does not sell Connector information or use it for advertising. We disclose information to the recipients above to provide the requested service, to protect or maintain it, or when disclosure is required by law.
Retention
- The static Website does not retain visitor information or access logs. The cookie-preference choice and any learning PDFs remain in your browser until you clear them, delete them through the page controls, or your browser removes its stored site data.
- The Connector does not save tool inputs or API responses to durable gateway storage. An exchanged Randmar API credential and account context may be held in gateway memory until shortly before the credential expires, or until the process stops; the cached session is not written to disk.
- The MCP host keeps no long-term logs. Transient host logs are expected to be discarded during a reboot or deployment update; there is no longer-term application log archive. The AI client and upstream Randmar services may have separate records or logs under their own retention practices.
- Partner billing and contact details, supplier bank-transfer details, and other business records sent to Randmar API are retained in the Warehousing ERP according to the applicable account, business-record, payment, and legal retention schedules. This includes carts, orders, shipments, invoices, and payment records. There is no single retention period for every record type. Contact service@randmar.io for information about the schedule that applies to a particular account or record.
- Support emails are retained as business correspondence under the applicable support and legal retention schedules. There is no single retention period for every message. Contact service@randmar.io to ask about a specific correspondence record.
- Auth0, Randmar Auth, Stripe, banks and other payment providers, and the AI client may retain their respective authentication, payment, transaction, conversation, or service records under their own settings, terms, privacy policies, and retention schedules.
Your choices and privacy requests
- Choose whether to connect the Connector, which operation to use, and which task-specific values to provide. You can stop using it and revoke its authorization through your AI client or Randmar account controls.
- Use your AI client's controls to review or delete conversations and manage its retention settings. Those controls do not delete business records already created or updated in Randmar's ERP.
- Ask Randmar to access, correct, or delete personal information associated with your account by contacting service@randmar.io. Some business records may need to be kept to provide services or meet legal obligations.
- Use the unsubscribe link in a Randmar marketing email to stop future marketing messages. The Website itself does not add visitors to a marketing list.
Security and contact
Randmar uses reasonable administrative, technical, and organizational safeguards to protect information in its custody or control. No internet service can guarantee absolute security. For privacy questions, access or correction requests, or complaints, contact us using any of these methods:
- Telephone: 1 (800) 361-6244
- Mail: 290 rue Jacques Laval, Québec, H7P 0N8, Canada
- Email: service@randmar.io
This policy is effective as of 2026-09-30. Randmar may update it when its services or practices change. We will post the revised policy on the Website and update the effective date.
