Legal & Compliance

MarginLane Privacy Policy

Last Updated: September 14, 2026 • Document Code: ML-PRIVACY-v1.0

This Privacy Policy explains how MarginLane (“we,” “our,” or “us”), operated by Invora Digital Technologies, collects, processes, stores, protects, shares, and deletes your data when you use our web application, website, and related services (collectively, the “Service”).

We are committed to full compliance with global privacy regulations, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Amazon Selling Partner API Data Protection Policy (DPP).

1. Information We Collect

We collect information you provide directly and data received through authorized API integrations:

  • Account & Profile Information: Name, business email address, company name, phone number, and hashed password when registering an account.
  • Billing Information: Billing address, tax identification numbers, and subscription transaction history. Payment card details are handled directly by PCI-DSS certified payment processors (Stripe or Iyzico); MarginLane never stores raw payment card numbers.
  • Wholesale Supplier Data (User Uploads): Product spreadsheets (CSV, XLSX) containing manufacturer SKUs, barcodes (EAN, UPC, GTIN), wholesale unit costs, and supplier names uploaded for analysis.
  • Amazon Selling Partner Data (OAuth): Upon explicit seller authorization, we receive encrypted refresh tokens to access non-restricted SP-API endpoints: Catalog Items, Listings Items, Product Pricing, Product Fees, aggregate store sales metrics, and FBA inventory summaries.
  • Security & System Telemetry: IP addresses, browser user-agents, request timestamps, and anonymized diagnostic logs necessary to protect system integrity and prevent unauthorized brute-force attempts.

Sources of Information

We obtain data strictly from the following verifiable channels: (a) directly from you when creating an account or submitting support requests, (b) wholesale spreadsheet files uploaded by your team, (c) the official Amazon Selling Partner API pursuant to your OAuth authorization, (d) Keepa under a dedicated commercial data agreement for historical sales ranks, and (e) automated server security monitoring logs.

2. Strict Zero Buyer-PII Architectural Guarantee

In accordance with MarginLane’s V1 Developer Scope and Amazon Data Protection Policy:

MarginLane NEVER requests, collects, processes, or stores any Personally Identifiable Information (PII) of Amazon buyers or retail customers. We do not access customer names, residential or delivery addresses, buyer email addresses, or recipient phone numbers. Our API integration strictly uses non-restricted roles and endpoints focused exclusively on product catalog, competitive pricing, fee estimation, and seller aggregate performance.

3. How We Use Your Information

We use collected data solely to deliver, improve, and secure our arbitrage intelligence services:

  • To match supplier inventory against Amazon catalog identifiers (PMS-1.0 engine).
  • To compute official Amazon referral and FBA fee estimates for your product scenarios.
  • To evaluate price volatility, historical buy box averages, and calculate net margins and ROI.
  • To authenticate your workspace and maintain secure tenant isolation.
  • To prevent fraudulent activity, rate limit abuse, and unauthorized access.
  • To communicate important service notifications, security alerts, and customer support responses.

4. Data Storage, Security & Encryption

We implement industry-leading technical and administrative safeguards to protect your data against unauthorized disclosure, loss, or alteration:

  • Encryption in Transit: All web traffic and API calls are strictly protected using TLS 1.2+ with HSTS enabled.
  • Encryption at Rest: Sensitive seller credentials and refresh tokens are encrypted using AES-256-GCM before database storage.
  • Tenant Logical Isolation: Data queries enforce strict tenant boundary filters, preventing cross-tenant exposure.
  • Access Controls: Internal administrative access requires hardware-backed multi-factor authentication and role-based privileges.

5. Data Sharing & Subprocessor Register

We do NOT sell, rent, monetize, or trade your supplier catalogs, margin calculations, or seller business data to any third party.

In full alignment with GDPR Article 28 and the Amazon Selling Partner API Data Protection Policy (DPP), we engage only vetted, industry-leading sub-processors under strict Data Processing Agreements (DPAs):

Vendor / EntityProcessing PurposeLocation / RegionSecurity & Compliance
Hetzner CloudDedicated cloud compute, web application backend & encrypted PostgreSQL databaseFalkenstein/Nuremberg, Germany (EU)ISO 27001, DPA, LUKS/AES-256 encrypted at rest
Cloudflare, Inc.DNS routing, edge CDN, WAF, DDoS protection & TLS 1.2+ terminationGlobal Edge NetworkSOC 2 Type II, ISO 27001, Strict HTTPS/HSTS
Amazon Web Services (SP-API)Seller-authorized product catalog, pricing, fee estimations & store metricsEU / NA Regions (Amazon infrastructure)Amazon DPP / AUP, OAuth 2.0 LWA, Zero Buyer PII
Keepa APIHistorical marketplace pricing averages, BSR sales ranks & Buy Box trendsEuropean UnionCommercial API Agreement, Non-PII market telemetry
Iyzico / StripeSubscription billing, credit card tokenization & merchant checkoutTurkey / GlobalPCI-DSS Level 1 Certified, Zero raw card storage
Transactional Email ServiceTransactional system alerts, password resets & MFA backup codesEU / USDPA, SPF / DKIM / DMARC authentication

6. Data Retention, Revocation & Deletion Rights

In accordance with GDPR, CCPA, and Amazon DPP guidelines, you have complete control over your data lifecycle:

  • Supplier Catalogs & Lists: Retained during your active subscription. You can permanently delete any supplier list from your dashboard at any time.
  • Amazon SP-API Authorization Revocation: You can disconnect your Amazon store at any moment from your MarginLane Settings or directly from your Amazon Seller Central Manage Your Apps page. Upon revocation, access tokens and seller synchronization jobs are purged immediately.
  • Right to Erasure (Account Deletion): When an account is terminated, all associated supplier catalogs, historical calculations, shortlists, and encrypted credentials are permanently expunged within 30 days. To prevent promotional trial abuse, only the email address is preserved in an inactive blocked tombstone state.

7. International Data Transfers

MarginLane processes and stores data primarily within the European Union (Hetzner Cloud datacenters in Germany). Edge distribution, DDoS mitigation, and DNS caching are handled globally via Cloudflare’s global network.

Whenever data is transferred across international borders to authorized sub-processors (such as AWS SP-API endpoints or Keepa servers), we ensure adequate data protection safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission and GDPR Article 46-compliant Data Processing Agreements.

8. Cookies & Tracking Technologies

MarginLane uses only strictly necessary first-party cookies required to operate the web application:

  • Session & Authentication Cookies: Secure, HttpOnly JWT tokens to maintain your authenticated login session and workspace permissions.
  • Security & CSRF Protection: Tokens to prevent Cross-Site Request Forgery and enforce rate limiting.

We do NOT employ third-party advertising, cross-site behavioral tracking cookies, or data-broker pixels in MarginLane V1.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our technological practices, legal obligations, or Amazon SP-API compliance requirements.

When material revisions occur, we will update the “Last Updated” date at the top of this document and notify active users via email or an in-app dashboard banner at least 30 days prior to the effective date. Continued use of MarginLane after changes become effective constitutes acceptance.

10. Data Controller & Privacy Inquiries

The Data Controller responsible for your personal data under GDPR and international privacy legislation is Invora Digital Technologies:

Data Controller: Invora Digital Technologies

Product: MarginLane

Data Protection / Privacy: [email protected]

Security Officer (IMPOC): [email protected]

Customer Support: [email protected]