Legal
Last updated: September 2026
What we collect
When you submit a form on this site we collect the details you provide: name, email, phone, company, revenue and budget bands, the services you're interested in, and your message. We also record the page you submitted from and standard campaign attribution (UTM source, medium, campaign) so we know how you found us.
How we use it
Submitted details are used solely to respond to your enquiry and run our engagement with you. We do not sell, rent or share your personal information with third parties for their marketing.
Amazon Information (Heterize AI Engine)
The Heterize AI Engine connects to your Amazon Selling Partner account through the Amazon Selling Partner API (SP-API). This section describes how we handle the data we access on your behalf, which Amazon calls Amazon Information.
What we access
Only the data required by the modules you have switched on: your listings and catalogue attributes, pricing and fee estimates, orders and order line items, FBA and AWD inventory, inbound and outbound shipments, brand analytics reporting for your own brand, financial events and settlement reports, tax invoicing and remittance detail, buyer messaging eligibility and solicitation eligibility, notification events, and the authorisation state of the application on your account. A role-by-role breakdown is published on the Heterize AI Engine page.
What we do not access
We do not request Amazon's Restricted Data (PII) role. Buyer names, shipping addresses, email addresses and phone numbers are never retrieved, processed or stored by us. We never ask for and never store your Seller Central password — authorisation is through Amazon's own Login with Amazon consent flow.
Legal basis and purpose
We process Amazon Information solely to provide the features you have enabled, on the basis of the contract between us and the authorisation you granted in Seller Central. We do not use it for any other purpose. Specifically: we do not sell, licence, resell, redistribute or publish Amazon Information in any form, including aggregated or anonymised; we do not pool one Selling Partner's data with another's; we do not use it to train AI models; and we do not use Brand Analytics data to compete with Amazon or with any other Selling Partner. This is consistent with sections 4.4 and 4.5 of the Amazon Acceptable Use Policy.
How it is protected
Amazon refresh tokens are encrypted with AES-256-GCM before storage and are never returned by an API response or written to a log. All data is encrypted in transit with TLS and encrypted at rest. Each Selling Partner's data is held in an isolated, access-controlled scope. Employee access to Amazon Information is granted by job function only, protected by multi-factor authentication, reviewed regularly, and logged for audit. Our network is protected by firewalls, intrusion detection, endpoint anti-malware and network segmentation.
Retention and deletion
Amazon Information is retained only while your authorisation is active and only for as long as it is needed to provide the service. Disconnecting your Amazon account, or revoking access from Seller Central, revokes the refresh token immediately and cascade-deletes the catalogue, order, analytics, shipment, tax and settlement data we held for that account within 30 days. Personally identifiable information, were any ever to be received, is deleted within 30 days of order delivery. You can export your data to Excel or CSV at any time, including on the day you leave, at no charge.
Sub-processors
We share Amazon Information only with infrastructure providers acting on our instructions and under contract: Google Cloud / Firebase (hosting, database and authentication) and Google Gemini (AI content generation, on the product data you submit). We do not share Amazon Information with advertisers, data brokers or any third party for their own purposes, and we do not sell it.
Security incidents
We maintain a documented incident response plan with defined roles, reviewed at least every six months. Any security incident involving Amazon Information is reported to Amazon at security@amazon.com within 24 hours of detection, and affected Selling Partners are notified without undue delay.
Analytics
We use Firebase/Google Analytics to understand aggregate site usage (pages viewed, approximate region, device class). This data is aggregated and not used to identify you personally. It is entirely separate from Amazon Information.
Storage & security
Data is stored on Google Cloud (Firebase) infrastructure with access restricted to authorised Sunyata Ventures team members under role-based permissions and audit logging.
Your rights
You may request a copy of the data we hold about you, or ask for it to be corrected or deleted, at any time by emailing us. We respond within 30 days.
Contact
Questions about this policy: sunyataglobalventures@gmail.com.