1. Who we are
Arlanix ("we", "us") develops extensions for Magento 2 (Adobe Commerce and Magento Open Source), sells them through Adobe Commerce Marketplace, and supports them by email. This policy explains the little personal data we handle in doing so, and what our extensions do — and do not do — with data once installed. Questions go to [email protected].
2. Data we hold and why
We run no shop, no customer accounts, no newsletter and no analytics. Personal data reaches us in only three ways:
| How | What | Why |
|---|---|---|
| You buy an extension on Adobe Commerce Marketplace | The order details Adobe shows us as the seller — name, company, email address and the licensed product. Payment is handled entirely by Adobe; we never see card or bank details. | To honour the license and provide updates and support |
| You email us | Your name and email address, your message and anything you attach — logs, screenshots, configuration | To answer your request and, where needed, reproduce a problem |
| You visit this website | Nothing we collect. The site is static, sets no cookies and loads nothing from third parties; our hosting provider keeps ordinary access logs (IP address, browser, page, time) for security | To keep the site available and secure |
Purchases on Adobe Commerce Marketplace are also governed by Adobe's privacy policy; Adobe is the controller for the account and payment data it collects there. If you send us access to a staging or production environment for support, we use it only for that request and recommend that you revoke it afterwards.
Where the GDPR or UK GDPR applies, we process this data to perform our contract with you (license, updates, support) and in our legitimate interest in keeping the website secure.
3. Sharing, providers and retention
We do not sell, rent or share personal data with anyone for their own purposes. The only providers that touch it are our website host and our email provider, each of which processes data on our instructions; they may be located outside the EEA and UK, in which case we rely on an adequacy decision or standard contractual clauses. We disclose personal data beyond that only when the law requires it.
Support emails are kept for two years after the last message, so that we can follow up on a recurring issue. Marketplace order records are kept for as long as the license is valid and afterwards only as long as accounting law requires.
4. Your rights
You may ask us at any time what personal data we hold about you, have it corrected or deleted, receive a copy of it in a portable format, or object to a use you disagree with. Write to [email protected]; we answer within thirty days and never charge for a reasonable request. If you are in the EU, EEA or UK you may also complain to your data protection authority.
5. What our extensions do with data
Our extensions are software you install and run on your own Magento server. Once installed they operate entirely within your environment:
- they make no requests to Arlanix servers and contain no analytics, telemetry, crash reporting or other "phone home" functionality — we do not learn where they are installed, how they are used or whether they fail;
- they read only the store data their feature needs. Our feed extensions read the catalogue, inventory and store configuration, and nothing from customer, order or account tables;
- anything they store lives in your own Magento database and stays there until you delete the record in the admin or uninstall the extension.
Where an extension connects to a third-party service on your behalf — a marketplace, an advertising platform, a feed destination — the connection is made directly from your server to that service, using credentials you provide. Those credentials are stored in your Magento database, encrypted with your installation's encryption key. Arlanix is never in the data path and has no access to the credentials, the data sent or the data received. For any personal data our extensions process inside your installation, you are the data controller; Arlanix is neither a controller nor a processor of it.
6. Google Merchant Center connector
Because it uses Google sign-in, our Google Merchant Center connector (part of Arlanix Feed) warrants a specific notice. When you connect Google Merchant Center, the connector talks to the Google Merchant API (merchantapi.googleapis.com) directly from your server:
- it sends your product catalogue — titles, descriptions, prices, availability, images, links, categories, identifiers such as GTIN or MPN — to your own Merchant Center account;
- it reads back account details, data sources and product statuses to show them in your Magento admin;
- the Google credentials you provide — a service account key you upload, or an OAuth 2.0 authorization you grant by signing in with Google — are stored in your Magento database encrypted with your installation's encryption key, and short-lived access tokens are cached the same way until they expire.
Google user data and Limited Use. The connector requests the https://www.googleapis.com/auth/content scope, which grants management of your Merchant Center account. Its use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, it:
- uses Google data only to publish and maintain your product listings and to display their status in your Magento admin;
- does not transfer Google data to anyone other than Google and your own Magento installation — Arlanix included;
- does not use Google data for advertising, for building profiles, or for training machine-learning models;
- does not allow humans to read Google data, other than you and the administrators you authorize in your Magento admin.
Revoking access. You can disconnect at any time: delete the account in Arlanix → Google Merchant → Accounts (its credentials and tokens are removed with it), delete the service account key in the Google Cloud console, or revoke the connector's access from your Google account permissions. Any of these stops the connector from reaching your Merchant Center account.
Google's handling of your account and product data is governed by the Google Privacy Policy and the Merchant Center terms you agreed to.
7. Changes and contact
This version is effective 17 September 2026. If the policy changes, the new version is published at https://arlanix.com/privacy-policy with an updated date; a change that affects what an extension collects always comes with a corresponding change in the extension itself, noted in its release notes.
Questions about this policy or your data: [email protected]