Aisle — Privacy Policy
Last updated: August 16th, 2026.
In short
Aisle runs entirely on your own server. We never receive your data — not your products, not your customers, not your conversations.
The plugin makes no external network requests. There is no API key, no cloud service, no analytics, and no telemetry. Webtech Solutions LLC has no technical means of accessing anything an Aisle installation stores.
What this policy covers
This policy describes the Aisle plugin — software you install on your own WordPress site.
It does not cover webtechdigitalsolutions.com, our website, which has its own privacy policy covering our contact form and mailing list.
Aisle is published by Webtech Solutions LLC, a limited liability company registered in Florida, United States.
What Aisle stores, and where
Aisle creates several tables in your WordPress database. Everything below stays there, on infrastructure you control, alongside everything else WordPress already stores.
Conversations
Each shopping session records the state of the conversation, the answers given, the shopping list being built, a budget if one was set, and timestamps.
Sessions are identified by a random session key. For signed-in customers this is derived from the WordPress user ID; for guests it is a random value with no relation to any personal identifier.
Messages
The text of the conversation, both what the customer typed and what the assistant replied.
Customers type free text, so these messages can contain anything they choose to write — including personal information they were never asked for. This is the most sensitive data Aisle holds, and it is why the retention setting below exists.
Custom requests (optional feature)
If you enable the custom-request feature, a customer asking for something you do not stock can submit a request. This records their name, email address, one contact detail they supply, a budget if given, and their description of what they want.
This is the only place Aisle deliberately collects contact details, and only when a customer actively fills in and submits the form.
Product index
A search index built from your own catalogue — product names, categories, brands, descriptions, prices. No personal data. Rebuilt from your products; never uploaded anywhere.
Order attribution
When an order contains a product the assistant recommended, Aisle records that association so it can report assisted revenue to you. It stores the connection between an order and a conversation, not additional customer detail.
Cookies
Aisle sets one first-party cookie, aisle_sid.
| Purpose | Lets a guest’s conversation survive page loads. Without it the assistant would forget the conversation on every click. |
| Contents | A random identifier. No personal data, no tracking value. |
| Flags | HttpOnly, SameSite=Lax, Secure on HTTPS |
| Expiry | 30 days |
It is not used for advertising, cross-site tracking, profiling, or analytics. Signed-in customers do not need it — their session is identified by their WordPress user ID.
What Aisle does not do
Stated plainly, because it is unusual:
- No external HTTP requests. None. The plugin does not contact our servers or anyone else’s.
- No API keys, because there is no third-party service to authenticate with.
- No analytics or telemetry. We do not know how many sites use Aisle, how often, or how well.
- No data sharing or sale. We have nothing to share, because we receive nothing.
- No advertising identifiers, no fingerprinting, no cross-site tracking.
- No catalogue upload. Product search is a local index. Your catalogue never leaves your server.
- No AI or language model. Aisle does not send text to any AI service. Recommendations come from a search index over your own products — which is also why it cannot recommend something you do not stock.
Who is responsible for this data
You are. As the store operator you are the data controller for everything Aisle stores, exactly as you are for your WooCommerce orders and customer accounts.
Because Aisle transmits nothing to us and we have no access to your installation, Webtech Solutions LLC is neither a data controller nor a data processor for your customers’ data. There is no data transfer between us, so there is nothing to process on your behalf.
One practical consequence: we cannot retrieve, delete, or produce your data if you ask us to — we do not have it. Those operations happen in your own WordPress admin, using the tools below.
Retention
Aisle includes a configurable retention period for conversation transcripts. A scheduled task deletes conversations and messages older than that period automatically. The default is designed to be a sensible balance, and you can shorten it.
Custom requests are retained until you delete them, since they are business records of a customer asking you for something.
Set the retention period to match your own privacy policy and your legal obligations. Shorter is usually better for free-text conversation logs.
Data subject rights — GDPR, CCPA, and similar
Aisle registers WordPress’s built-in personal data exporter and personal data eraser. When you handle an export or erasure request through Tools → Export Personal Data or Tools → Erase Personal Data, Aisle’s records for that person are included automatically alongside WordPress and WooCommerce data.
You do not need to contact us, and there is nothing for us to do — the request is served entirely from your own database.
For store operators: what you should do
Aisle stores data on your behalf, which means a few obligations sit with you:
- Disclose it in your own privacy policy. Mention that a shopping assistant records conversation content, sets a functional cookie, and — if enabled — collects contact details for custom requests.
- Mention the
aisle_sidcookie in your cookie notice. It is strictly functional, so in most jurisdictions it does not require consent, but it should be listed. - Choose a retention period and state it.
- Decide whether to enable custom requests. That feature is the only one that deliberately collects contact details. If you do not need it, leave it off.
Security
Aisle follows WordPress security practice: all database queries are prepared statements, all output is escaped, administrative actions are capability-checked and nonce-protected, and customer-facing endpoints are rate-limited.
The security of the data ultimately depends on the security of your WordPress installation and hosting, which are outside our control. Keep WordPress, WooCommerce, and your plugins updated.
Children
Aisle is business software for store operators. It is not directed at children and does not knowingly collect data from them. If your store serves customers under the age of digital consent in their jurisdiction, that obligation sits with you as the store operator.
Changes to this policy
If Aisle’s data handling changes, this page is updated and the date above revised. A change that introduced any external data transmission would be announced in the plugin changelog and in the release notes, not made quietly.
Contact
Questions about how Aisle handles data:
contact@webtechdigitalsolutions.com
Webtech Solutions LLC · Florida, United States
