Aisle — Privacy Policy

Last updated: August 16th, 2026.

In short

Aisle runs entirely on your own server. We never receive your data — not your products, not your customers, not your conversations.

The plugin makes no external network requests. There is no API key, no cloud service, no analytics, and no telemetry. Webtech Solutions LLC has no technical means of accessing anything an Aisle installation stores.


What this policy covers

This policy describes the Aisle plugin — software you install on your own WordPress site.

It does not cover webtechdigitalsolutions.com, our website, which has its own privacy policy covering our contact form and mailing list.

Aisle is published by Webtech Solutions LLC, a limited liability company registered in Florida, United States.


What Aisle stores, and where

Aisle creates several tables in your WordPress database. Everything below stays there, on infrastructure you control, alongside everything else WordPress already stores.

Conversations

Each shopping session records the state of the conversation, the answers given, the shopping list being built, a budget if one was set, and timestamps.

Sessions are identified by a random session key. For signed-in customers this is derived from the WordPress user ID; for guests it is a random value with no relation to any personal identifier.

Messages

The text of the conversation, both what the customer typed and what the assistant replied.

Customers type free text, so these messages can contain anything they choose to write — including personal information they were never asked for. This is the most sensitive data Aisle holds, and it is why the retention setting below exists.

Custom requests (optional feature)

If you enable the custom-request feature, a customer asking for something you do not stock can submit a request. This records their name, email address, one contact detail they supply, a budget if given, and their description of what they want.

This is the only place Aisle deliberately collects contact details, and only when a customer actively fills in and submits the form.

Product index

A search index built from your own catalogue — product names, categories, brands, descriptions, prices. No personal data. Rebuilt from your products; never uploaded anywhere.

Order attribution

When an order contains a product the assistant recommended, Aisle records that association so it can report assisted revenue to you. It stores the connection between an order and a conversation, not additional customer detail.


Cookies

Aisle sets one first-party cookieaisle_sid.

PurposeLets a guest’s conversation survive page loads. Without it the assistant would forget the conversation on every click.
ContentsA random identifier. No personal data, no tracking value.
FlagsHttpOnly, SameSite=Lax, Secure on HTTPS
Expiry30 days

It is not used for advertising, cross-site tracking, profiling, or analytics. Signed-in customers do not need it — their session is identified by their WordPress user ID.


What Aisle does not do

Stated plainly, because it is unusual:

  • No external HTTP requests. None. The plugin does not contact our servers or anyone else’s.
  • No API keys, because there is no third-party service to authenticate with.
  • No analytics or telemetry. We do not know how many sites use Aisle, how often, or how well.
  • No data sharing or sale. We have nothing to share, because we receive nothing.
  • No advertising identifiers, no fingerprinting, no cross-site tracking.
  • No catalogue upload. Product search is a local index. Your catalogue never leaves your server.
  • No AI or language model. Aisle does not send text to any AI service. Recommendations come from a search index over your own products — which is also why it cannot recommend something you do not stock.

Who is responsible for this data

You are. As the store operator you are the data controller for everything Aisle stores, exactly as you are for your WooCommerce orders and customer accounts.

Because Aisle transmits nothing to us and we have no access to your installation, Webtech Solutions LLC is neither a data controller nor a data processor for your customers’ data. There is no data transfer between us, so there is nothing to process on your behalf.

One practical consequence: we cannot retrieve, delete, or produce your data if you ask us to — we do not have it. Those operations happen in your own WordPress admin, using the tools below.


Retention

Aisle includes a configurable retention period for conversation transcripts. A scheduled task deletes conversations and messages older than that period automatically. The default is designed to be a sensible balance, and you can shorten it.

Custom requests are retained until you delete them, since they are business records of a customer asking you for something.

Set the retention period to match your own privacy policy and your legal obligations. Shorter is usually better for free-text conversation logs.


Data subject rights — GDPR, CCPA, and similar

Aisle registers WordPress’s built-in personal data exporter and personal data eraser. When you handle an export or erasure request through Tools → Export Personal Data or Tools → Erase Personal Data, Aisle’s records for that person are included automatically alongside WordPress and WooCommerce data.

You do not need to contact us, and there is nothing for us to do — the request is served entirely from your own database.


For store operators: what you should do

Aisle stores data on your behalf, which means a few obligations sit with you:

  • Disclose it in your own privacy policy. Mention that a shopping assistant records conversation content, sets a functional cookie, and — if enabled — collects contact details for custom requests.
  • Mention the aisle_sid cookie in your cookie notice. It is strictly functional, so in most jurisdictions it does not require consent, but it should be listed.
  • Choose a retention period and state it.
  • Decide whether to enable custom requests. That feature is the only one that deliberately collects contact details. If you do not need it, leave it off.

Security

Aisle follows WordPress security practice: all database queries are prepared statements, all output is escaped, administrative actions are capability-checked and nonce-protected, and customer-facing endpoints are rate-limited.

The security of the data ultimately depends on the security of your WordPress installation and hosting, which are outside our control. Keep WordPress, WooCommerce, and your plugins updated.


Children

Aisle is business software for store operators. It is not directed at children and does not knowingly collect data from them. If your store serves customers under the age of digital consent in their jurisdiction, that obligation sits with you as the store operator.


Changes to this policy

If Aisle’s data handling changes, this page is updated and the date above revised. A change that introduced any external data transmission would be announced in the plugin changelog and in the release notes, not made quietly.


Contact

Questions about how Aisle handles data:

contact@webtechdigitalsolutions.com

Webtech Solutions LLC · Florida, United States

Scroll to Top