Privacy policy
This policy explains what information Opsacta collects, why, where it is kept, who can see it and when it is deleted. "Opsacta", "we" and "us" mean Amazon 360 Inc. It covers this website, our sales conversations, and the Opsacta app that brands authorise to read their Amazon data.
1. Information we collect
From brands that authorise the Opsacta app (Amazon data). Through the Amazon Selling Partner API and Amazon Ads API, and only for brands that authorise us: settlement and financial transaction reports, FBA inventory and Inventory Ledger reports, reimbursement reports, inbound shipment items, fee estimates and storage fees, offer prices and competitive summaries, listing status, the Sales and Traffic report, the seller performance report, AWD inventory, and advertising reports (campaign, targeting, search term, advertised product, budget usage and recommendations). The full list, and the reason for each, is on the app page.
From brands directly. Landed cost per SKU, which the brand supplies to us, and the business contact details of the people we work with.
When you book a call or email us. Your name, email address, brand name, store or website address, approximate annual Amazon revenue and anything you choose to tell us.
For our own outreach. Business contact details of people at Amazon brands (name, job title, work email address, company and its public website), from commercial business-data providers and public company websites. You can ask us to stop contacting you and delete these details at any time by replying to any email from us or writing to [email protected].
When you visit this website. The website sets no cookies, runs no analytics and loads nothing from third parties. Our hosting and security provider processes standard request data (such as IP address, browser type and the page requested) to deliver the site and protect it from attacks.
2. Information we never collect
We do not request or store Amazon customers' personal information: no buyer names, addresses, email addresses, phone numbers or order-level buyer data. The Opsacta app does not use the Orders API, does not request restricted reports and does not message buyers. Settlement report lines include an order ID; we total them per SKU and day when we import them and do not keep the order ID.
3. How we use it
- To provide the service the brand signed up for: computing price floors and findings, preparing sourcing-cost uploads, monitoring ad spend and inventory, and producing the monthly scorecard and completion ledger for that brand.
- To contact brands that may be a fit for Opsacta, respond to enquiries, run sales calls and manage our relationship with clients.
- To keep our systems secure and meet our legal obligations.
Each brand's Amazon data is used only to serve that brand. We do not combine one brand's data with another's, do not sell it, do not use it for advertising, and do not use it to train any machine-learning or AI model.
4. Amazon's Data Protection Policy
We handle Amazon data in line with Amazon's Selling Partner API Data Protection Policy and Acceptable Use Policy, and the Amazon Ads API terms. Where this policy and Amazon's terms differ, the stricter of the two applies to Amazon data.
5. Where it is stored and how it is protected
- Client data is stored in a database in the United States that is used only for client data. It is kept apart from the systems we use for our own sales.
- Each brand's data sits in its own separate database schema. Access is limited by role to what each process needs.
- Data is encrypted in transit (TLS) and at rest.
- A web application firewall sits in front of our services.
- Security and access logs are kept for at least 12 months.
6. Who can access it
Today, only Opsacta's founder can access client data. Before any employee or contractor is given access, they will be registered with Amazon as required by its policies and this policy will be updated to say so.
7. Service providers we share it with
We use these service providers (subprocessors) to run Opsacta. Each receives only what it needs to do its job:
| Provider | What it does | Data |
|---|---|---|
| Supabase | Database hosting (United States) | Client data, in its own project; sales records, in a separate one |
| Cloudflare | Website hosting, firewall and network security | Request data; client data in transit |
| Anthropic, OpenAI | Writing the text of alerts and monthly summaries, through their commercial APIs | The findings being summarised. Their commercial terms bar them from training models on it; they may keep it for up to 30 days for abuse monitoring, then delete it |
| Google Workspace | Email and calendar | Messages and booking details |
| Cal.com | Booking intro calls | What you enter when you book |
| Apollo.io | Business contact data for our outreach | Prospect business contact details |
| Instantly | Sending our outreach email | Prospect business contact details and messages |
| HighLevel | Customer relationship management | Contact and booking details |
| DigitalOcean | Hosts the automation that moves bookings into our CRM | Booking details in transit |
We do not sell personal information or Amazon data to anyone. We disclose information if the law requires it, and only to the extent it requires.
8. How long we keep it
- Raw Amazon report files: deleted 30 days after we process them.
- Per-SKU totals, computed results and the completion ledger: kept for 18 months on a rolling basis, then deleted.
- Security logs: kept for at least 12 months.
- Outreach, enquiry and booking details: kept while we are in contact and for up to 24 months after, unless you ask us to delete them sooner.
A scheduled job enforces the time limits for client data automatically.
9. When a brand leaves
When a contract ends, or when a brand removes Opsacta's access in Seller Central or Amazon Ads, we stop collecting data, export the brand's data to it on request, and delete all of that brand's data within 30 days. We confirm the deletion in writing.
10. Your choices and rights
You can ask us what information we hold about you, ask us to correct it, or ask us to delete it, by emailing [email protected]. Brands can remove Opsacta's access to their Amazon data at any time, as described on the app page. Depending on where you live, you may have further rights under local privacy law; we will honour them.
11. Security incidents
If we discover a security incident affecting Amazon data, we notify Amazon within the time its policies require and notify affected brands without undue delay.
12. Changes to this policy
We will post any change here and update the date at the top. If a change affects how we handle a client's data, we will tell that client before it takes effect.
13. Contact
Amazon 360 Inc. (Opsacta), 30 N Gould St Ste 11548, Sheridan, WY 82801-6317, USA · [email protected]