Privacy Policy
Effective September 24, 2026
Foundry IMS ("Foundry", "we", "us"), operated by Better Interaction Inc, provides an inventory management platform for commerce brands. This policy explains what data we collect, how we use it, and the choices you have. It also covers the Foundry IMS connector that lets you access your Foundry data from AI assistants such as Claude and ChatGPT.
Information We Collect
- Account & identity data — name, email, and organization membership, managed through our authentication provider.
- Business data you enter — products, variants, inventory, bills of materials, orders, purchase orders, invoices, shipments, and related records.
- Integration credentials — API keys and tokens you provide to connect sales channels, fulfillment platforms, and other systems, stored encrypted.
- Operational metadata — logs, timestamps, and diagnostic information used to run and secure the service.
How We Use Your Data
We use your data solely to provide and improve the Foundry IMS service: syncing inventory, processing orders, generating reports, securing your account, and providing support. We do not sell your data, and we do not use your business data to train machine-learning models.
The Foundry IMS Connector for AI Assistants
Foundry offers a connector (an MCP server at mcp.foundryims.com) that lets you
work with your Foundry data from AI assistants such as Claude and ChatGPT. It covers your
catalog and assemblies, and your procurement records — purchase orders, supplier
invoices, and the documents and emails attached to them. When you use it:
- You authorize access explicitly. The connector uses OAuth — you sign in and consent before any access is granted, and access is limited to named scopes (catalog, variants, purchase orders, invoices). You can revoke access at any time from your AI assistant's settings or by contacting us.
- Access is scoped to your permissions. The connector acts only within the organization and permissions of the authenticated user or API key. It cannot reach data you could not already access in Foundry.
- The connector is a thin gateway. It reads and writes your Foundry data through our standard API in response to your requests. It does not independently store your business data, and it does not send your data to third parties beyond the API calls needed to fulfill your request.
- Connector telemetry. For reliability and security we record, per tool call: the tool's name, whether it succeeded or failed, its duration, the authentication mode, and a pseudonymous reference to the user or API key. Telemetry contains no request parameters and no business data, and is retained for up to 90 days, as are error diagnostics.
- Your conversations stay with the AI provider. The content of your chats is governed by the privacy policy of the AI assistant you use (for example, Anthropic's policy when you use Claude, or OpenAI's when you use ChatGPT). Foundry does not receive or retain your conversation history.
Data the connector returns to your AI assistant
Responses to connector tool calls are limited to the following categories, all drawn from your own organization's records:
- Catalog & inventory data — products, variants, SKUs and barcodes (UPC/GTIN/MPN), pricing, cost and margin figures, stock and buildable quantities, bills of materials, bundles, brands, categories, and the custom field definitions and values you created.
- Channel listing data — per-channel SKUs, listing status and prices, and the platform record identifiers and storefront domain of each sales channel you connected.
- Organization identifiers — your organization's name and the internal record identifiers (UUIDs) used to address records across calls.
- Operational metadata — record timestamps and sync/listing status.
- Product image links — served as credential-free public URLs, never as signed storage URLs.
- Purchase order records — order numbers, statuses, supplier names, line items and costs, carrier and tracking data, and vendor reference numbers.
- Supplier invoice records — invoice numbers, amounts, dates, reconciliation status, and payment references exactly as printed on the supplier's paperwork (for example a card descriptor or check number).
- Supplier documents — when you ask the connector to read a specific document attached to a purchase order (an invoice, receipt, or packing slip), its full contents are returned as images. Supplier documents can themselves contain names, addresses, email addresses, and partial payment identifiers.
- Supplier email messages — the subject, direction, date, and message text of the email thread on a purchase order. Sender email addresses are not returned.
Connector responses do not include customer or order personal data (the connector has no sales order or customer tools, and shipping addresses are excluded from purchase order results), other users' account details, the email addresses of document uploaders or email senders (provenance is reported as a category such as "vendor email" instead), or stored credentials and secrets of any kind — including vendor portal access tokens and signed storage URLs.
Service Providers
We rely on trusted infrastructure and service providers to operate Foundry — including cloud hosting, database, authentication, and edge/CDN providers. These providers process data only on our behalf and under contractual confidentiality and security obligations.
Data Retention
We retain your data for as long as your account is active or as needed to provide the service. Deleted records are soft-deleted and purged on a rolling schedule. OAuth grants and API keys for the connector remain valid until you revoke them, and revoking one removes the stored credential. Operational logs, connector telemetry, and error diagnostics are retained for up to 90 days. You may request export or deletion of your data at any time.
Security
We protect your data with encryption in transit and at rest, scoped access controls, and audit logging. No system is perfectly secure, but we work continuously to safeguard your information.
Your Rights
You may access, correct, export, or delete your data, and revoke integrations or connector access, at any time. Contact us using the details below to exercise these rights.
Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, notifying you directly.
Contact
Questions about this policy or your data? Email us at support@foundryims.com.