MURRE / LEGAL
Privacy policy
How we handle information when you visit Murre, sign in, or connect a website.
Effective September 14, 2026 · Contact james@murre.ai
1. Who we are and what this covers
Murre.ai (“Murre”) provides website outcome attribution and agents for website teams. This policy covers murre.ai, app.murre.ai, and the Murre service. For privacy questions or requests, contact james@murre.ai.
Murre handles its own website, account, and business-contact information. When a merchant connects a store, we process the store’s analytics and order data to provide the service for that merchant. The merchant remains responsible for its own shopper notices, permissions, and instructions to Murre.
2. Information we collect
- Account information: your email address, name when provided, company memberships, roles, invitation status, sign-in method, and most recent successful login. Passwords are stored as password hashes, not readable passwords.
- Business inquiries: the email, company, store URL, platform, and annual-sales range you provide when requesting an install, plus communications you send us.
- Store analytics: session and visitor identifiers, pages and products visited, referral and campaign information, timestamps, device and browser signals, and interaction events such as a checkout or form interaction. The tracking collectors are designed to exclude typed form values and copied text. Separately, website agents retrieve public pages and store bounded extracted page evidence, approved factual guidance, recommendations, content changes and restoration records to provide the agent service.
- Orders: order identifiers, amounts, currency, products, timestamps, attribution information, and identifiers needed to connect orders to sessions. Murre’s order-ingestion fields do not include shopper names, email addresses, postal addresses, or payment-card numbers.
- Agent and security signals: user agents, selected request headers, verification results, and network information used to identify automated visitors. Analytics records store a salted IP hash and a network prefix instead of a raw IP address. These identifiers are pseudonymous, not necessarily anonymous.
- Operations: service and security logs, API-key usage metadata, and records of administrative changes. Our hosting and infrastructure providers also process connection information, which may include IP addresses, to deliver and protect the service.
3. Google sign-in
If you choose Sign in with Google, Google provides an identity credential containing your Google account identifier, email address, email-verification status, and name when available. Murre verifies the credential and uses this information to authenticate you, associate your Google account with your Murre account, and accept an invitation addressed to that email.
We store the Google account identifier, account email, and name when provided for a new account. We do not request access to your Gmail, Drive, Calendar, contacts, or other Google content. Google sign-in does not give Murre your Google password. We do not retain Google API access or refresh tokens through this sign-in flow.
Google account data is used for account access and related support and security, not advertising, sale, or training AI models. It is shared only with service providers and authorized people who need it to operate the account or service, or as described below. Murre’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
You can review or remove Murre’s access through your Google Account connections. Removing Google access does not itself delete your Murre account or end an existing Murre session. Sign out and contact us if you also want your Murre account deleted.
4. How we use information
We use information to authenticate users, manage workspaces and invitations, attribute orders, report on store and agent activity, provide support, respond to install requests, secure the service, maintain service reliability, and meet applicable legal obligations. Company administrators can see their team’s account details and roles. Authorized Murre staff can access company and account records to operate and support the service.
Where privacy law requires a legal basis, we rely on providing the requested service or fulfilling a contract, legitimate interests such as service security and support, legal obligations, and consent where required. Merchants are responsible for establishing the appropriate basis for collection on their storefronts.
5. Cookies and local storage
The dashboard uses a session cookie and a security cookie to keep you signed in and protect account actions. Their configured lifetime is up to 14 days. The dashboard also remembers preferences such as the selected store and reporting period in local storage.
On connected storefronts, the Murre snippet uses a first-party visitor cookie named _mur, configured for up to 396 days, to associate visits with orders. On Shopify, the snippet waits for Shopify’s analytics consent signal and stops collection when that consent is withdrawn; it also respects Global Privacy Control. Merchants must configure their consent controls and provide required storefront notices. Our marketing site does not currently use advertising or marketing-analytics cookies. Google may use its own cookies and technology when its sign-in feature loads or is used, under Google’s privacy policy.
6. Sharing and service providers
We do not sell personal information or share it for cross-context behavioral advertising. We share information as needed with:
- Your company and its authorized users, according to workspace permissions.
- Providers that host and operate Murre, including Render for the application and database, Netlify for the marketing site, Google for optional authentication, and Resend for transactional email. Resend processes delivery addresses, message contents, and delivery events. Payment providers may process information when those services are used.
- Providers used for optional service features. When website-agent diagnosis is enabled, relevant pseudonymous journey evidence, extracted public-page evidence and approved factual guidance are sent to the configured reasoning provider (currently Anthropic). Optional generated summaries can send reporting metrics. Google sign-in information is not used for those purposes.
- Professional advisers or authorities when required by law or reasonably needed to protect rights, safety, or service security.
- Parties involved in a proposed business transfer, subject to appropriate protections and applicable notice requirements.
Providers and connected platforms process some data under their own policies. Information may be processed in countries other than where you live. Where required, appropriate contractual or other safeguards must apply to international transfers.
7. Storage, retention, and security
We use access controls, HTTPS, password hashing, and protected storage for integration credentials. No service can guarantee absolute security.
Test-checkout diagnostics are removed by the daily retention job 30 days after their most recent receipt. Shopify customer deletion requests remove linked orders and journeys; hash-only suppression records prevent erased data from being re-imported. Store erasure requests following uninstall remove the store’s stored data. Website owners can select 30–400 days of analytics and agent-history retention in Setup, with a default of 400 days. Daily cleanup removes expired events, sessions, analytics outcomes/orders, copied agent evidence and reports; filtered learning records expire with their source. Minimal publishing and restoration records remain while live or unresolved changes require rollback. Approved target configuration remains until changed or removed. Account, company, billing, invitation and founder-audit records have separate retention while needed to provide the service or process an applicable request, subject to legal, security and backup requirements. Unused invitation links expire after seven days; expired invitation records can remain for administration.
Optional shared learning
Sharing is off by default. A company owner may accept the versioned shared-learning terms in Setup to contribute filtered summaries from new investigations. These records describe broad goal, website, page, visitor and action categories, decisions, sample counts, elapsed measurements and agent/model/prompt/policy versions. The shared projection excludes names, domains, URLs, visitor/session identifiers, page text, approved copy, credentials and financial values. Private source links remain to support withdrawal and erasure; we describe this internal data as pseudonymous, not irreversibly anonymous.
Other customers do not receive individual cases or source identities. Eligible patterns may prioritize locally supported investigations after independent-company and sample-size checks; they do not authorize changes or establish causal improvement. This release does not fine-tune models on customer data. Owners can use shared ranking without contributing, withdraw sharing and delete contributions, or erase private agent history while preserving required restoration records. Backup copies follow the infrastructure provider’s backup lifecycle.
Read the shared-learning terms.
8. Your choices and requests
Contact james@murre.ai to request access, correction, export, or deletion of your account information, or to raise a privacy concern. Depending on your location, you may also have rights to object to or restrict processing, withdraw consent, or complain to a supervisory authority. We may need to verify your identity and authority before acting on a request.
If your information relates to shopping on a merchant’s store, contact that merchant first. We assist merchants with requests involving information we process on their behalf. Removing a company membership or revoking an invite does not automatically delete all of that person’s account data.
9. Children and changes to this policy
Murre is a business service and is not directed to children. If you believe a child has provided personal information to Murre, contact us. We may update this policy as the service changes; the effective date above identifies the current version. We will provide additional notice of material changes where required.
See also our Terms of Service and attribution methodology.