Privacy Policy
How the THG Ingenuity Agentic Commerce applications — Shopping Assistant and Virtual Try-On — handle the data they are given, including the Google account data accessed when a merchant connects their Google Merchant Center account.
Who we are
These applications are operated by FIC Shareco Limited, trading as THG Ingenuity. This policy covers the Agentic Commerce products described on this site and the Google application named “THG Ingenuity Agentic Commerce”. For THG Ingenuity’s general handling of personal data — including your rights, our lawful bases, and international transfers — see the THG Ingenuity privacy policy, which this page supplements rather than replaces.
Google account data
A merchant can connect their Google Merchant Center account so that their product catalogue is read directly from Google rather than crawled from their storefront. That connection is made by a merchant administrator through Google’s own consent screen.
What we request
One scope, and only when a merchant chooses to connect an account:
| Scope | Why we request it |
|---|---|
https://www.googleapis.com/auth/content | To read the product listings of the Merchant Center account the merchant nominates, so that their AI shopping assistant can answer shopper questions from their real, current catalogue. |
We do not request access to Gmail, Drive, Calendar,
Contacts, Photos, or location, and we do not request the
email or profile scopes. We do not read the
personal Google profile of the person who grants consent.
What we access and how we use it
Product listing data for the nominated Merchant Center account: titles, descriptions, prices, availability, images, product identifiers and product attributes. It is used for one purpose — building and refreshing that merchant’s own product catalogue, which powers the AI shopping assistant on that merchant’s own storefront.
We do not use this data for advertising, we do not sell or rent it, we do not share it with other merchants or with third parties beyond our infrastructure providers, and we do not use it to train generalised machine-learning models.
Where it is stored, and for how long
- Catalogue data is stored on Google Cloud in europe-west2 (London), isolated per merchant. Each scheduled refresh replaces the previous copy in full, so the stored catalogue reflects the merchant’s current Merchant Center data.
- The OAuth refresh token that permits those unattended refreshes is held in Google Secret Manager, encrypted at rest, readable only by the ingestion service account. It is never written to logs, source control, or the browser.
- Both are retained for as long as the connection is active and the merchant’s assistant is in service.
Withdrawing access
A merchant can revoke our access at any time from Google Account → Third-party apps. Revocation takes effect immediately: the stored token stops working and catalogue refreshes stop. To also have the stored credential and the ingested catalogue deleted, contact us at dl-isc@thehutgroup.com or speak to your THG Ingenuity representative.
Limited Use
THG Ingenuity’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Shopper data
When the Shopping Assistant runs on a retailer’s storefront, it processes the shopper’s messages in order to answer them, grounded in that retailer’s catalogue. Each storefront is isolated — sessions, keys and conversations never cross brands — and the assistant does not access a shopper’s basket or place orders. For that processing the retailer is the data controller and THG Ingenuity acts as a processor under its agreement with that retailer, so the retailer’s own privacy notice governs what shoppers are told. How the assistant is constrained and what it will not do is described in Trust & safety.
Security
The services run on Google Cloud. Merchant-facing and shopper-facing endpoints sit behind an API gateway with per-storefront keys and quotas; internal services are not publicly reachable and authenticate to each other with short-lived Google-issued credentials. Secrets are held in Google Secret Manager, and access to production is restricted to named personnel.
Contact
Questions about this policy, or requests to delete data we hold on your behalf: dl-isc@thehutgroup.com. For commercial enquiries, contact THG Ingenuity.
Changes
We will update this page when the data these applications handle changes, and revise the date above. Material changes affecting an active integration are raised with the merchant directly.