Privacy Policy
Effective date: August 1, 2026 · Last updated: August 1, 2026
This Privacy Policy explains how Mantaro Partners LLC, doing business as ASINRx (“ASINRx,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you visit our website, create or use an ASINRx account, authorize an integration, communicate with us, or receive our business-to-business software and services (the “Services”).
ASINRx is an independent service provider. Amazon does not own, sponsor, endorse, or operate ASINRx.
1. Scope and roles
This Policy applies to personal information for which ASINRx determines the purposes and means of processing, such as website, account, billing, sales, and support information.
Customers may submit or authorize ASINRx to obtain information that ASINRx processes only to provide the Services for that customer (“Customer Data”). For personal information in Customer Data, the customer is the controller or business and ASINRx is its processor or service provider. Our Data Processing Addendum governs that processing. The customer, not ASINRx, is responsible for its own notices, instructions, and legal basis.
This Policy does not govern:
- Amazon's own services or privacy practices;
- a customer-selected AI assistant, spreadsheet connector, MCP client, or other recipient after the customer directs ASINRx to transmit data to it; or
- third-party sites linked from the Services.
2. Notice at collection
The following table describes the categories we collect, the sources, purposes, recipients, and retention criteria. We do not sell personal information or share it for cross-context behavioral advertising.
| Category | Examples and sources | Business purposes | Categories of recipients | Retention |
|---|---|---|---|---|
| Account and identity | Name, business email, company, role, account membership, verification status; from you, an inviter, or your organization | Create and secure accounts; authorize access; communicate | Hosting/database providers; email provider; authorized ASINRx personnel | Account term plus 30 days, then backups expire within 90 days, except required records |
| Authentication and integration | Password hash, sessions, OAuth state, encrypted Amazon refresh token, scopes, Amazon account/profile identifiers, MCP keys and grants; from you, Amazon, or ASINRx | Authenticate; connect authorized services; prevent fraud; audit access | Hosting/database and security providers; Amazon for OAuth/API operations | Active use; revoked and scrubbed promptly on disconnect or closure; security evidence as below |
| Customer business and Amazon information | ASINs, catalog/listing content, vendor codes, sales, units, COGS, inventory, forecasts, traffic, Net PPM, purchase orders, invoices, settlements, deductions, chargebacks, scan findings, report metadata; from customer uploads or authorized Amazon APIs | Provide analytics, monitoring, recovery, reporting, and customer-requested workflows | Infrastructure providers; authorized personnel; approved processors; customer-authorized recipients | Amazon non-personal information no longer than 18 months unless a shorter purpose applies; Amazon personal information as described in Section 3 |
| Listing and AI content | Titles, bullets, descriptions, brand guidance, ASINs, PDFs/images, prompts, generated outputs, feedback; from you and approved data sources | Produce customer-requested listing analysis and drafts | AI provider only when enabled and disclosed; storage providers; authorized personnel | 90 days for source uploads; outputs until account closure or earlier deletion request; provider retention disclosed at the point of use |
| Billing and transaction | Plan, subscription, Stripe customer/session/payment identifiers, amount, currency, invoice status, billing contact; from you and Stripe | Process payments; administer subscriptions; accounting; prevent fraud | Stripe; accounting/legal advisers; infrastructure providers | Contract term plus 7 years where needed for tax and accounting |
| Support and communications | Email, message content, support actions, invitations, requests, early-access and sales inquiries; from you and our personnel | Respond; onboard; troubleshoot; keep business records | Email provider; authorized personnel; professional advisers | Generally 2 years after closure or last interaction; shorter operational logs as specified |
| Device, usage, and security | IP address, timestamps, requested route/tool, client name, credential identifiers, error class, duration, hashed argument metadata, logs; from browser, API/MCP client, and systems | Operate, secure, debug, meter, investigate incidents, enforce terms | Hosting, monitoring, and security providers; authorized personnel | Security logs at least 12 months; operational records only as long as needed |
| Necessary cookie data | Session identifier, CSRF token, beta-access authorization, preference to remain signed in; from browser | Login, security, continuity, restricted-beta access | Hosting provider; authorized personnel | See the Cookie Notice |
3. Amazon Information
“Amazon Information” means information obtained through Amazon APIs, portals, services, or materials, including information a customer exports from an Amazon portal and provides to us.
We process Amazon Information only:
- for the authorized customer's documented purposes;
- using the minimum data and permissions needed;
- for the customer whose authorization or lawful instruction applies;
- without combining information across authorized customers to sell, disclose, or provide benchmarking, competitor, or shared business insights;
- without selling it, using it for advertising, or using it to build an independent data product;
- without using it to develop or improve a machine-learning or generative-AI model; and
- through personnel and processors with a need to know and written confidentiality, security, retention, and deletion obligations.
We disclose in the Amazon Information Handling Notice the sources, freshness, calculation limits, automated processing, and approved recipients relevant to each feature.
We will not ask for a customer's Amazon password, access key, secret key, session cookie, or shared portal credential. Each customer must use Amazon's prescribed authorization flow. If limited portal access by our personnel is genuinely necessary, the customer must create an appropriately permissioned secondary user and ASINRx must approve the access in advance.
Authorized employees, agents, contractors, and service providers may process Amazon Information only when disclosed here or on the Subprocessor List, bound by written terms, registered or verified in Amazon's Solution Provider Portal when required, and limited to their assigned duties.
Amazon retention and deletion
Subject to a documented legal obligation:
- Amazon customer personal information, if ASINRx ever receives it for an approved use, will be deleted no later than 30 days after the related order is delivered.
- Other Amazon Information will be deleted when no longer necessary and no later than 18 months after collection.
- After Amazon or a customer validly requires deletion, ASINRx will remove affected live copies within 30 days and complete deletion from remaining live online systems no later than 90 days, unless Amazon directs a shorter period.
- Deletion applies to database records, uploads, local caches, cloud-storage objects, generated exports, AI inputs/outputs under our control, and processor copies.
- Media sanitization follows NIST SP 800-88 Rev. 2 or an approved equivalent.
We may retain only the minimum records needed to establish compliance, resolve fraud or security incidents, or meet law, and will isolate them from ordinary product use.
4. How we use information
We use information to:
- provide, maintain, personalize, and secure the Services;
- authenticate users and honor account-level permissions;
- import, validate, analyze, display, export, and monitor customer-authorized business data;
- connect to Amazon, Stripe, email, infrastructure, AI, reporting, and customer-selected integration services;
- generate customer-requested analysis or draft content;
- calculate usage, administer plans, process payments, and enforce quotas;
- provide support, communicate service and security notices, and respond to requests;
- detect abuse, investigate incidents, preserve evidence, and comply with law and Amazon requirements;
- improve ASINRx using product telemetry and feedback that excludes Amazon Information and Customer Data unless the customer separately authorizes a permitted use; and
- establish, exercise, or defend legal claims.
We do not use Amazon Information or Customer Data to train a general-purpose AI model.
5. Legal bases for processing
Where GDPR or similar law applies, we rely on:
- contract, to provide Services requested by you or your organization;
- legitimate interests, to secure, administer, support, and improve our business, balanced against individual rights;
- legal obligation, for tax, accounting, sanctions, security, and lawful process; and
- consent, where a feature or law requires it, which may be withdrawn for future processing.
ASINRx generally processes Customer Data as the customer's processor on the customer's documented instructions, not under ASINRx's independent legal basis.
6. Automated processing and AI
Some optional features use automated rules or a commercial generative-AI provider to analyze listing content and create drafts. Before submission, the interface identifies:
- the data sent;
- the provider and its role;
- the purpose and expected provider retention;
- whether customer authorization is required; and
- the need for human review.
AI output may be inaccurate, incomplete, outdated, or unsuitable. It does not automatically change an Amazon listing or account. A person must review output and independently decide whether and how to use it.
Our commercial AI configuration prohibits model training and opt-in feedback using Amazon Information or Customer Data. ASINRx will not enroll such traffic in a development-partner, feedback, or model-improvement program.
7. How we disclose information
We may disclose information:
- to infrastructure, database, storage, email, payment, monitoring, AI, and support processors listed on our Subprocessor List;
- to content-delivery providers that serve website assets — our pages load fonts from Google Fonts, which receives the requesting browser's IP address and technical request metadata when a page loads;
- to authorized ASINRx personnel and contractors with a need to know;
- to a recipient you direct us to use, including an MCP client or export destination, after an authorization check and appropriate notice;
- to Amazon to authorize integrations, make customer-requested API calls, investigate abuse, report security events, or comply with Amazon policies;
- to advisers, auditors, insurers, regulators, law enforcement, or courts when reasonably necessary and lawful;
- in connection with a merger, financing, reorganization, or asset transaction, subject to appropriate confidentiality and notice; or
- to protect rights, safety, systems, customers, or the public.
We do not disclose one customer's Amazon Information to another customer.
8. International transfers
ASINRx operates from the United States, and its providers may process information in the United States and other countries listed on the Subprocessor List. Where required, we use an approved transfer mechanism, such as the European Commission's Standard Contractual Clauses, the UK Addendum, or another lawful mechanism, plus supplementary measures appropriate to the risk.
9. Security
We use administrative, technical, and physical safeguards designed for the nature of the information, including encryption in transit and at rest, unique accounts, least privilege, tenant isolation enforced at the database layer, credential encryption, logging, vendor review, and an incident-response plan. A factual overview is published at asinrx.com/security.
No safeguard is absolute. Please notify security@asinrx.com promptly if you believe an account, key, integration, or Customer Data is at risk.
10. Data subject and privacy rights
Depending on where you live, you may have rights to:
- know or access personal information and its sources, purposes, recipients, and retention;
- correct inaccurate information;
- delete information;
- receive a portable copy;
- object to or restrict processing;
- withdraw consent;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- appeal a denied request; and
- receive equal service without unlawful discrimination.
ASINRx does not sell personal information or share it for cross-context behavioral advertising. We do not currently use personal information for decisions producing legal or similarly significant effects.
Submit a request to privacy@asinrx.com or through our contact page. We may verify identity and authority, and may direct a request about Customer Data to the relevant customer. Authorized agents may submit requests where law permits. We will respond within the period required by applicable law.
California residents may also request the categories and specific pieces collected, categories of sources, business purposes, and categories of third parties. ASINRx will state in each annual Policy update whether it sold or shared personal information during the preceding 12 months.
EEA, UK, and Swiss individuals may complain to their local supervisory authority. Contact us first if possible so we can try to resolve the issue.
11. Account closure
An authorized customer administrator may request account closure by emailing support@asinrx.com from an owner or administrator address. We will:
- verify authority and applicable legal holds;
- revoke integrations, keys, grants, and sessions;
- stop ordinary processing;
- return or export Customer Data if the contract requires;
- delete or de-identify records and files under the applicable schedule;
- direct processors to delete their copies; and
- document completion.
Some billing, security, consent, legal-hold, or dispute records may remain for a limited period. They will not remain available for ordinary product use.
12. Cookies
We currently use strictly necessary cookies for login, request security, remember-me functionality, and restricted-beta access. We do not currently use advertising or analytics cookies. See the Cookie Notice. If that changes, we will update the notice and obtain consent where required before setting non-essential cookies.
13. Children
The Services are for businesses and are not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child provided information.
14. Changes
We may update this Policy to reflect changes in law, Amazon requirements, providers, or the Services. We will post the revised version and its effective date. If a change materially affects existing processing, we will provide advance notice and obtain consent where required. ASINRx maintains immutable versions so an accepted policy can be identified later.
15. Contact
Data controller: Mantaro Partners LLC d/b/a ASINRx
Address: 600 1st Ave Ste 102 PMB 2276, Seattle, WA 98104, United States
Privacy: privacy@asinrx.com
Security: security@asinrx.com
Support: support@asinrx.com