Privacy Policy
Summary
Flip IQ Batch processes the supplier files you upload, plus a minimum set of Amazon Selling Partner data, to surface profitable products. In My store, it also shows you the state of your own Amazon store. We comply with Amazon's Data Protection Policy (DPP) and applicable regional regulations including GDPR (EU/UK), CCPA/CPRA (California) and LGPD (Brazil). We don't sell your data, don't share it with unrelated third parties, and don't train shared models on it. You can revoke access and delete your data at any time.
What we collect
- Account data: name, work email, organization, billing details.
- Supplier files you upload, including any product identifiers and cost data they contain.
- Amazon Selling Partner data accessed via SP-API — see the next section for the exact scopes and purposes.
- Usage telemetry: which features you use and how often, to improve the product.
- Brand complaint reports you choose to submit: the brand, the marketplace, the type of intellectual property complaint you received and, if you add them, the ASIN, the date and a note. See “Brand complaint reports you share” below.
- If you link Discord: your Discord user ID and the ID of the server you linked from, to deliver the bot's answers and your alerts.
- Your acceptance of this Privacy Policy in My store: the version you accepted and when, as a record of your consent.
Amazon Selling Partner data we access
- Product Listings (read) — To verify ASINs, confirm sellability, and detect restricted categories per marketplace. In My store we also read the issues Amazon reports on your own listings: the message, the issue categories, the attributes affected and the actions Amazon takes on the listing, with their dates. We use them to warn you, for example, that Amazon will remove the option to buy one of your listings on a specific date.
- Pricing (read) — To pull Buy Box, FBA/FBM offer signals, and competition data per ASIN. In My store we also read pricing for your own products: your price, the Buy Box price and who holds it (you, another seller or Amazon), the number of offers and the Best Sellers Rank (BSR). We use it to show you where you stand against the Buy Box and to alert you to changes: you lost the Buy Box, Amazon joined the listing, the price dropped or the number of offers went up. We keep a daily history of these figures for up to 90 days, saving an entry only when something changes, plus a control entry every 14 days. The history is deleted with the rest of your store data when you disconnect your Amazon account or revoke our access (see “How long we keep it”).
- Inventory (read) — Read under the authorization you grant in Amazon when you connect your account. We use it to show your FBA stock in My store (available, inbound, reserved and unsellable units), to keep a daily history of those totals for up to 90 days, and to flag products you already stock so you don't re-buy them. You can turn it off at any time in My store; turning it off deletes the stock data we have read.
- Amazon Fulfillment (read) — To show your FBA reports in My store: inventory health, stranded inventory and inventory reimbursements. Inventory health covers units shipped to customers in the last 7, 30, 60 and 90 days (as totals per SKU), the age of your inventory, the estimated storage cost and aged inventory surcharges. For reimbursements, we don't keep order identifiers. Units shipped to customers are read only if you turn on “Sales” in My store.
- Fulfillment Inbound (read) — To follow your shipments to FBA: the status of each shipment and the units sent and received per SKU, so we can alert you if Amazon receives fewer units than you sent.
- Finance and Accounting (read) — Only once Amazon grants Flip IQ Batch this access. To show your real profit in My store: your settlements and financial events (sales, Amazon fees, refunds and reimbursements), which we keep as totals per SKU and per day. We don't keep order identifiers or your bank details.
- Catalog (read) — To enrich rows with title, brand, category and dimensions.
Alerts about your store
We send My store alerts by email, through Resend. We also send them as a Discord direct message, but only if you turn that on and link your Discord account. The Discord message carries the same facts as the email: the product, the SKU and what changed. Alerts already delivered stay in your email inbox or your Discord messages; deleting your data or disconnecting doesn't remove them.
What we don't collect
- Buyer PII (names, shipping addresses, payment details).
- Order-level data unless you explicitly enable an optional integration that requires it. Turning on “Sales” in My store doesn't change this: we read units shipped as totals per SKU, not individual orders.
- Browsing or storefront-scraping data — all Amazon data comes from the official SP-API.
How we protect it
- In transit: TLS 1.2+ (TLS 1.3 by default) on every endpoint.
- At rest: AES-256 encryption managed by our cloud providers.
- Refresh tokens encrypted at the application layer; credentials live in our platform secret store — never in code, never in repos.
- MFA enforced on all internal accounts; account lockout after 10 failed attempts.
- Monthly vulnerability scans; critical vulnerabilities resolved within 7 days, high within 30.
- Centralized logging with 12-month retention and bi-weekly access review.
Where it lives
Customer data is stored with our managed database provider on AWS infrastructure in the United States, matched to the US marketplace we serve today. Backups are encrypted.
How long we keep it
- Non-PII Amazon data (catalog, pricing, inventory, listings, FBA reports and shipments, and financial totals): retained up to 18 months maximum, in line with Amazon's Data Protection Policy. Older data is automatically purged.
- Uploaded supplier files: retained for the lifetime of the job plus 30 days for re-export, unless you delete sooner.
- Files we couldn't read because of an error on our side: kept for up to 7 days in a separate, private storage area that only our team can open, so we can review and process your list. Then they are deleted automatically. You can ask us to delete one sooner.
- Job results and exports: retained per your retention setting (7 / 30 / 90 / 365 days). Default is 90 days.
- Account data: kept until you delete the account.
- Brand complaint reports: kept until you delete them or delete your account. A deleted report leaves the shared aggregate at the next nightly update.
- On OAuth revocation or account deletion: all customer data is purged within 30 days using NIST SP 800-88r1 methods.
Compliance with Amazon's Data Protection Policy
AMONCA Technology Solution LLC, the company behind Flip IQ Batch, is a registered Amazon Selling Partner Solution Provider and operates under the Solution Provider Agreement, the SP-API Acceptable Use Policy and the SP-API Data Protection Policy. We maintain an incident response plan reviewed every 6 months, a designated Incident Management Point of Contact (IMPOC) reachable at security@flipiqbatch.com, and we notify Amazon of security incidents within 24 hours as required by the DPP.
AI / ML use disclosure
Flip IQ Batch uses machine learning for opportunity scoring and explanation. Inference runs over your authorized data inside our infrastructure. We do NOT train shared or proprietary models on Amazon-sourced data, and Amazon Information is never used to develop or improve AI systems, in compliance with the November 2025 update to Amazon's Acceptable Use Policy.
Sub-processors
We rely on a small set of vendors to operate the service: Render (application hosting), Vercel (frontend hosting), Supabase (database and authentication, on AWS), a licensed market history data provider (market analytics), OpenRouter (LLM inference gateway for column mapping, product explanations, analysis reports and the in-app assistant; requests are relayed to commercial model APIs — currently Google and OpenAI models — solely to generate the response, and OpenRouter does not use inputs or outputs for model training, per its privacy policy), Stripe (billing), Resend (transactional email, including My store alerts), PostHog (product analytics and session replay: which steps of the product you reach and how you move through the interface, so we know where the experience breaks. Inside the workspace every piece of text and every form field is masked in your browser before anything leaves it, so your catalog, your ASINs, your costs and your Amazon data never reach PostHog — a recording shows layout and interaction, not content. Recordings are kept for 30 days). All sub-processors are bound by data processing agreements and reviewed annually. We also deliver messages through Discord when you use our Discord bot or turn on Discord alerts; Discord handles them under its own Terms of Service and Privacy Policy.
Brand complaint reports you share
Inside the product you can record that a brand filed an intellectual property complaint against you. A report is yours: only you see it, and you can delete it at any time. If you tick the sharing box on a report, we count it in an anonymous per-brand aggregate that other Flip IQ Batch users can see on that brand.
That aggregate only appears once at least three different accounts have reported the same brand within the last 24 months, and it never includes your name, your email, your ASIN or your note — only the number of accounts and the date of the most recent report. Reports you don't share are never counted for anyone else. Reports are not Amazon data and are never sent back to Amazon or to any brand.
Your rights
You can request a full export or deletion of your data at any time by emailing privacy@flipiqbatch.com. We respond within 30 days, in accordance with GDPR, CCPA/CPRA and LGPD. You can revoke our access to your Amazon account at any time from Seller Central — see the Seller Authorization page for details.