MarginLane Privacy Policy
Last Updated: September 14, 2026 • Document Code: ML-PRIVACY-v1.0
This Privacy Policy explains how MarginLane (“we,” “our,” or “us”), operated by Invora Digital Technologies, collects, processes, stores, protects, shares, and deletes your data when you use our web application, website, and related services (collectively, the “Service”).
We are committed to full compliance with global privacy regulations, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Amazon Selling Partner API Data Protection Policy (DPP).
1. Information We Collect
We collect information you provide directly and data received through authorized API integrations:
- Account & Profile Information: Name, business email address, company name, phone number, and hashed password when registering an account.
- Billing Information: Billing address, tax identification numbers, and subscription transaction history. Payment card details are handled directly by PCI-DSS certified payment processors (Stripe or Iyzico); MarginLane never stores raw payment card numbers.
- Wholesale Supplier Data (User Uploads): Product spreadsheets (CSV, XLSX) containing manufacturer SKUs, barcodes (EAN, UPC, GTIN), wholesale unit costs, and supplier names uploaded for analysis.
- Amazon Selling Partner Data (OAuth): Upon explicit seller authorization, we receive encrypted refresh tokens to access non-restricted SP-API endpoints: Catalog Items, Listings Items, Product Pricing, Product Fees, aggregate store sales metrics, and FBA inventory summaries.
- Security & System Telemetry: IP addresses, browser user-agents, request timestamps, and anonymized diagnostic logs necessary to protect system integrity and prevent unauthorized brute-force attempts.
Sources of Information
We obtain data strictly from the following verifiable channels: (a) directly from you when creating an account or submitting support requests, (b) wholesale spreadsheet files uploaded by your team, (c) the official Amazon Selling Partner API pursuant to your OAuth authorization, (d) Keepa under a dedicated commercial data agreement for historical sales ranks, and (e) automated server security monitoring logs.
2. Strict Zero Buyer-PII Architectural Guarantee
In accordance with MarginLane’s V1 Developer Scope and Amazon Data Protection Policy:
MarginLane NEVER requests, collects, processes, or stores any Personally Identifiable Information (PII) of Amazon buyers or retail customers. We do not access customer names, residential or delivery addresses, buyer email addresses, or recipient phone numbers. Our API integration strictly uses non-restricted roles and endpoints focused exclusively on product catalog, competitive pricing, fee estimation, and seller aggregate performance.
3. How We Use Your Information
We use collected data solely to deliver, improve, and secure our arbitrage intelligence services:
- To match supplier inventory against Amazon catalog identifiers (PMS-1.0 engine).
- To compute official Amazon referral and FBA fee estimates for your product scenarios.
- To evaluate price volatility, historical buy box averages, and calculate net margins and ROI.
- To authenticate your workspace and maintain secure tenant isolation.
- To prevent fraudulent activity, rate limit abuse, and unauthorized access.
- To communicate important service notifications, security alerts, and customer support responses.
4. Data Storage, Security & Encryption
We implement industry-leading technical and administrative safeguards to protect your data against unauthorized disclosure, loss, or alteration:
- Encryption in Transit: All web traffic and API calls are strictly protected using TLS 1.2+ with HSTS enabled.
- Encryption at Rest: Sensitive seller credentials and refresh tokens are encrypted using AES-256-GCM before database storage.
- Tenant Logical Isolation: Data queries enforce strict tenant boundary filters, preventing cross-tenant exposure.
- Access Controls: Internal administrative access requires hardware-backed multi-factor authentication and role-based privileges.
5. Data Sharing & Subprocessor Register
We do NOT sell, rent, monetize, or trade your supplier catalogs, margin calculations, or seller business data to any third party.
In full alignment with GDPR Article 28 and the Amazon Selling Partner API Data Protection Policy (DPP), we engage only vetted, industry-leading sub-processors under strict Data Processing Agreements (DPAs):
| Vendor / Entity | Processing Purpose | Location / Region | Security & Compliance |
|---|---|---|---|
| Hetzner Cloud | Dedicated cloud compute, web application backend & encrypted PostgreSQL database | Falkenstein/Nuremberg, Germany (EU) | ISO 27001, DPA, LUKS/AES-256 encrypted at rest |
| Cloudflare, Inc. | DNS routing, edge CDN, WAF, DDoS protection & TLS 1.2+ termination | Global Edge Network | SOC 2 Type II, ISO 27001, Strict HTTPS/HSTS |
| Amazon Web Services (SP-API) | Seller-authorized product catalog, pricing, fee estimations & store metrics | EU / NA Regions (Amazon infrastructure) | Amazon DPP / AUP, OAuth 2.0 LWA, Zero Buyer PII |
| Keepa API | Historical marketplace pricing averages, BSR sales ranks & Buy Box trends | European Union | Commercial API Agreement, Non-PII market telemetry |
| Iyzico / Stripe | Subscription billing, credit card tokenization & merchant checkout | Turkey / Global | PCI-DSS Level 1 Certified, Zero raw card storage |
| Transactional Email Service | Transactional system alerts, password resets & MFA backup codes | EU / US | DPA, SPF / DKIM / DMARC authentication |
6. Data Retention, Revocation & Deletion Rights
In accordance with GDPR, CCPA, and Amazon DPP guidelines, you have complete control over your data lifecycle:
- Supplier Catalogs & Lists: Retained during your active subscription. You can permanently delete any supplier list from your dashboard at any time.
- Amazon SP-API Authorization Revocation: You can disconnect your Amazon store at any moment from your MarginLane Settings or directly from your Amazon Seller Central Manage Your Apps page. Upon revocation, access tokens and seller synchronization jobs are purged immediately.
- Right to Erasure (Account Deletion): When an account is terminated, all associated supplier catalogs, historical calculations, shortlists, and encrypted credentials are permanently expunged within 30 days. To prevent promotional trial abuse, only the email address is preserved in an inactive blocked tombstone state.
7. International Data Transfers
MarginLane processes and stores data primarily within the European Union (Hetzner Cloud datacenters in Germany). Edge distribution, DDoS mitigation, and DNS caching are handled globally via Cloudflare’s global network.
Whenever data is transferred across international borders to authorized sub-processors (such as AWS SP-API endpoints or Keepa servers), we ensure adequate data protection safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission and GDPR Article 46-compliant Data Processing Agreements.
8. Cookies & Tracking Technologies
MarginLane uses only strictly necessary first-party cookies required to operate the web application:
- Session & Authentication Cookies: Secure, HttpOnly JWT tokens to maintain your authenticated login session and workspace permissions.
- Security & CSRF Protection: Tokens to prevent Cross-Site Request Forgery and enforce rate limiting.
We do NOT employ third-party advertising, cross-site behavioral tracking cookies, or data-broker pixels in MarginLane V1.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our technological practices, legal obligations, or Amazon SP-API compliance requirements.
When material revisions occur, we will update the “Last Updated” date at the top of this document and notify active users via email or an in-app dashboard banner at least 30 days prior to the effective date. Continued use of MarginLane after changes become effective constitutes acceptance.
10. Data Controller & Privacy Inquiries
The Data Controller responsible for your personal data under GDPR and international privacy legislation is Invora Digital Technologies:
Data Controller: Invora Digital Technologies
Product: MarginLane
Data Protection / Privacy: [email protected]
Security Officer (IMPOC): [email protected]
Customer Support: [email protected]