Privacy Policy
This policy explains what data AMPES collects, why, how it is protected, who it is shared with, how long it is kept and how you can exercise your rights. It applies to ampes.ai and the AMPES application at app.ampes.ai.
1. Data we collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Account data | Name, email address, password (stored as a bcrypt hash), company name, role, invitations | You | Sign-in, team access, communication about your account |
| Amazon seller data | Seller ID, marketplace, product listings (SKU, ASIN, title, images, dimensions, barcodes, status), selling and list prices, FBA and referral fee estimates, and — as features are released — inventory levels and sales history | Amazon Selling Partner API, with your authorisation | Keeping your product master, unit economics and (later) planning current |
| Amazon authorisation | The refresh token Amazon issues when you authorise AMPES | Amazon | Calling the Selling Partner API on your behalf |
| Business data you enter | Suppliers, contacts, terms, banking details, costs, price breaks, units of measure, planning parameters | You (forms or Excel upload) | Sourcing, costing and procurement features |
| Technical data | IP address, browser type, timestamps, error logs | Automatic | Security, reliability, debugging |
We do not request or receive Amazon buyer personal information. AMPES does not request the Selling Partner API roles that expose customer names, addresses or order-level personal data (Direct-to-Consumer Shipping, Tax Invoicing).
2. How we use data
- To provide the service: sync your Amazon catalogue, compute unit economics, run sourcing and (later) planning features.
- To operate your account: authentication, invitations, password reset, email confirmation, security notices.
- To keep the service secure and reliable: monitoring, abuse prevention, error diagnosis.
- We do not sell data, use it for advertising, or train models on your data without your explicit agreement.
3. How data is protected
- All traffic uses HTTPS/TLS.
- Amazon authorisations and supplier banking fields are encrypted at rest with AES-256-GCM using a key held outside the database.
- Each company's data is isolated with PostgreSQL row-level security enforced by the database, plus role-based access inside the application.
- Passwords are bcrypt-hashed; sessions are opaque tokens stored hashed; password-reset and invitation links are single-use and time-limited.
- Access to production systems is limited to authorised personnel with multi-factor authentication; changes are deployed only after automated tests pass.
- We follow Amazon's Acceptable Use Policy and Data Protection Policy for Selling Partner API data.
4. Where data is stored and who processes it
Data is hosted in the United States. We use the following subprocessors under contract: Render (application hosting and managed PostgreSQL), Cloudflare (DNS and domain registration), Resend (transactional email), GitHub (source code, no customer data), and Amazon Web Services / Amazon Selling Partner API (the source of your Amazon data). We do not share your data with anyone else except when required by law.
5. Retention and deletion
- Amazon seller data and business data are kept while your workspace is active.
- Disconnecting Amazon deletes the stored authorisation immediately; syncing stops.
- When you delete your workspace or ask us to, we delete your data (including Amazon-derived data) within 30 days, except minimal records we must keep for legal or accounting reasons. Backups roll off within a further 30 days.
- Access and error logs are kept for up to 90 days.
6. Your rights
You can export your data at any time (Excel download in the app), correct it in the app, and request access, correction, deletion or a copy of your data by emailing privacy@ampes.ai. Depending on where you live (for example the EU/UK under GDPR or California under CCPA/CPRA) you may have additional rights; we honour them regardless of location. You can revoke AMPES's Amazon authorisation at any time in Seller Central (Apps & Services → Manage your apps) or by clicking Disconnect in AMPES.
7. Cookies
AMPES uses one strictly necessary, HttpOnly session cookie to keep you signed in. We do not use advertising or tracking cookies.
8. Children
AMPES is a business tool and is not directed at children under 16.
9. Changes
We will post changes here and, for material changes, notify account owners by email before they take effect.
10. Contact
GravityIO Inc., Maryland, USA · privacy@ampes.ai
AMPES