FAQ
The cross-cutting questions that come up when someone is first encountering Firmly. For deeper questions, use the FAQ closest to what you’re working on:
What Firmly is and isn’t
Is Firmly the agent?
No. Firmly is the commerce backend an AI surface integrates with. The destination owns the conversation, the consent layer, and the user-facing experience. See Agentic Commerce overview.
Is Firmly the merchant of record?
No. The merchant is always the merchant of record. They are the seller, their PSP charges the card, and their order management system is the source of truth for fulfillment. Firmly is the orchestration layer in between.
That is deliberate, and it works in a destination’s favor:
| You don’t take on | Because the merchant is MoR |
|---|---|
| Payment licensing and PCI scope | The merchant’s PSP charges the buyer, so you never become a payment facilitator or hold card data |
| Tax registration and remittance | Sales tax is calculated and remitted by the merchant in their own jurisdictions |
| Chargebacks and disputes | Raised against the merchant’s PSP account and handled in their existing process |
| Returns, refunds, and support | Run in the merchant’s back office, on their own policy — no returns desk for you to staff |
| Inventory and pricing risk | You never buy or hold stock; price and availability stay the merchant’s |
What you get instead is reach: you add merchants without adding regulatory surface, so onboarding the tenth merchant costs you no more compliance work than the first.
Does Firmly process payments?
Firmly’s vault submits the card to the merchant’s PSP, which returns a payment token — the PSP mints the token, Firmly orchestrates the call. The actual payment processing happens at the PSP. Card data passes through Firmly’s encrypted vault layer (PCI-scoped) — see Smart Payment Selection.
What does Firmly NOT do?
Firmly’s scope ends at order placement. Everything after that — fulfillment, shipping, returns, refunds, customer service — runs in the merchant’s existing back-office workflows. Firmly doesn’t run those operations. It does expose a read-only order status lookup so you can show a buyer where their order is, but the work itself happens in the merchant’s systems.
Which solution fits me?
I’m a…
| If you are… | Start with |
|---|---|
| An AI app, chatbot, AI assistant, or wallet | Agentic Commerce |
| A deal publisher, affiliate network, or retail-media partner driving ad traffic to checkout | Branded Commerce |
| An ad platform or DSP | Ad Commerce |
| Linking identity / SSO across merchant and destination | Firmly Connect |
| A multi-brand or aggregator surface across many merchants | Marketplace |
| A publisher, media, or content platform | Publisher Commerce |
If you’re not sure, Destinations walks through which solution shape fits which kind of company.
Can I use more than one solution?
Yes. The solutions share the same underlying platform (cart, discovery, payment, tax, shipping, order placement). They differ in destination shape and contractual posture. Many destinations use multiple solutions — for example, Branded Commerce + Agentic Commerce is common (the destination runs deal-driven hosted checkout AND exposes the same merchants to AI agents).
Compliance basics
Does Firmly see the conversation between the user and the agent?
Firmly receives only the fields your API calls actually contain — cart contents, address, payment details. The surrounding conversation isn’t part of any request. The one exception is Agentic Pay, where you can optionally pass a short consumer_prompt string that the card network shows the cardholder during authorization.
Where does payment card data live?
Card data is JWE-encrypted client-side using Firmly’s public key. Firmly’s payment vault decrypts it in memory and submits it over TLS to the merchant’s payment processor or platform. The cleartext card is never written to storage. See Get Payment Public Key and the Security model.
How long does Firmly retain cart and order data?
| Data | Retention |
|---|---|
| Session JWT | 1 hour active; renewable while session state persists (~7 days from last activity) |
| Cart state (Firmly’s session store) | 7 days |
| Card number | Never stored. The order record keeps the last four digits and the card brand |
| Order references | Per merchant policy |
| Conversation context | Not part of any request — Firmly gets only the fields you send |
See Consent & Disclosure.
Who’s responsible for user consent before placing an order?
The destination. Firmly does not enforce a “review and confirm” step — that’s the destination’s responsibility because consent UX varies wildly across surfaces (chat, voice, ambient, autonomous).
For merchants
Is my commerce platform supported?
Most likely, yes. Firmly supports a wide range of industry-standard commerce platforms and speaks each store’s native API, so the large majority of stores connect without a custom build — and if yours is less common, we can usually add it. We confirm your specific store during onboarding — to check, reach out at contact@firmly.ai.
How long does it take to go live?
It depends on your store and readiness (business verification, catalog, and a go-live review). We confirm a timeline with you during onboarding — start the conversation at contact@firmly.ai.
Who handles payments, chargebacks, and returns?
Your existing setup does — you stay the seller of record, your PSP charges the card, and fulfillment, returns, and refunds run in your back-office as they do today (see What does Firmly NOT do?). The specifics for your setup are covered during onboarding — reach out at contact@firmly.ai.
Pricing and getting started
How does Firmly price?
Pricing varies by solution, volume, and merchant set. There’s no published price card — reach out at contact@firmly.ai for the commercial conversation.
Is there a free tier?
For destinations: sandbox access is provisioned for evaluation; production usage is contracted.
For merchants: there’s no separate sandbox or trial mode — onboarding is the path to live, with two Firmly-reviewed gates (KYB and Go-live) along the way. See Merchant quickstart.
How do I contact Firmly?
| You want… | Where to go |
|---|---|
| Docs feedback, technical questions, bug reports, integration scoping | Email firmlydocs@firmly.ai — see /contact for what to include |
| Commercial / sales conversation | Email contact@firmly.ai |
| Account-team support for a live engagement | Use the contact you’ve been working with at Firmly directly — see Contact us |
Related
- Technical FAQ — auth, environments, protocols, idempotency, rate limits
- Agentic Commerce FAQ — solution-specific
- Branded Commerce FAQ — solution-specific
- Common issues — symptom-and-fix pairs
- Errors & Conventions — specific error codes
- Contact us — how to reach the docs team