1. Who we are

Arlanix ("we", "us") develops extensions for Magento 2 (Adobe Commerce and Magento Open Source), sells them through Adobe Commerce Marketplace, and supports them by email. This policy explains the little personal data we handle in doing so, and what our extensions do — and do not do — with data once installed. Questions go to [email protected].

2. Data we hold and why

We run no shop, no customer accounts, no newsletter and no analytics. Personal data reaches us in only three ways:

HowWhatWhy
You buy an extension on Adobe Commerce MarketplaceThe order details Adobe shows us as the seller — name, company, email address and the licensed product. Payment is handled entirely by Adobe; we never see card or bank details.To honour the license and provide updates and support
You email usYour name and email address, your message and anything you attach — logs, screenshots, configurationTo answer your request and, where needed, reproduce a problem
You visit this websiteNothing we collect. The site is static, sets no cookies and loads nothing from third parties; our hosting provider keeps ordinary access logs (IP address, browser, page, time) for securityTo keep the site available and secure

Purchases on Adobe Commerce Marketplace are also governed by Adobe's privacy policy; Adobe is the controller for the account and payment data it collects there. If you send us access to a staging or production environment for support, we use it only for that request and recommend that you revoke it afterwards.

Where the GDPR or UK GDPR applies, we process this data to perform our contract with you (license, updates, support) and in our legitimate interest in keeping the website secure.

3. Sharing, providers and retention

We do not sell, rent or share personal data with anyone for their own purposes. The only providers that touch it are our website host and our email provider, each of which processes data on our instructions; they may be located outside the EEA and UK, in which case we rely on an adequacy decision or standard contractual clauses. We disclose personal data beyond that only when the law requires it.

Support emails are kept for two years after the last message, so that we can follow up on a recurring issue. Marketplace order records are kept for as long as the license is valid and afterwards only as long as accounting law requires.

4. Your rights

You may ask us at any time what personal data we hold about you, have it corrected or deleted, receive a copy of it in a portable format, or object to a use you disagree with. Write to [email protected]; we answer within thirty days and never charge for a reasonable request. If you are in the EU, EEA or UK you may also complain to your data protection authority.

5. What our extensions do with data

Our extensions are software you install and run on your own Magento server. Once installed they operate entirely within your environment:

Where an extension connects to a third-party service on your behalf — a marketplace, an advertising platform, a feed destination — the connection is made directly from your server to that service, using credentials you provide. Those credentials are stored in your Magento database, encrypted with your installation's encryption key. Arlanix is never in the data path and has no access to the credentials, the data sent or the data received. For any personal data our extensions process inside your installation, you are the data controller; Arlanix is neither a controller nor a processor of it.

6. Google Merchant Center connector

Because it uses Google sign-in, our Google Merchant Center connector (part of Arlanix Feed) warrants a specific notice. When you connect Google Merchant Center, the connector talks to the Google Merchant API (merchantapi.googleapis.com) directly from your server:

Google user data and Limited Use. The connector requests the https://www.googleapis.com/auth/content scope, which grants management of your Merchant Center account. Its use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, it:

Revoking access. You can disconnect at any time: delete the account in Arlanix → Google Merchant → Accounts (its credentials and tokens are removed with it), delete the service account key in the Google Cloud console, or revoke the connector's access from your Google account permissions. Any of these stops the connector from reaching your Merchant Center account.

Google's handling of your account and product data is governed by the Google Privacy Policy and the Merchant Center terms you agreed to.

7. Changes and contact

This version is effective 17 September 2026. If the policy changes, the new version is published at https://arlanix.com/privacy-policy with an updated date; a change that affects what an extension collects always comes with a corresponding change in the extension itself, noted in its release notes.

Questions about this policy or your data: [email protected]