Version: 1.2 · Effective: 2026-07-31 · Reviewer: Kyle Casey — Chief Information Officer
v1.2 (2026-07-31) — corrected the processing-purpose column for listing and inventory
data from "repricing" to "competitive-price retrieval and partner-directed price management".
The product retrieves competitive prices for display and publishes prices the partner sets;
it does not reprice autonomously. This is the same correction as F-2026-034 and it had been
missed here, in a customer-facing document, while the internal wording was fixed.
Issuer: Amplified Inventory LLC, 6241 Yarrow Dr, Suite F, Carlsbad, CA 92011 Review cadence: annually, and on any change to the service, subprocessors, or data flows
Relationship to the published Terms of Service
This Addendum supplements the Terms of Service and Privacy Policy published at amplifiedinventory.com. It does not replace them and does not restate them.
Those published documents govern the commercial relationship — eligibility, accounts, fees and billing, intellectual property, warranties, limitation of liability, governing law, arbitration, acceptable use, and AI-generated content. Those terms continue to apply unchanged, and where this Addendum is silent on a subject the published terms govern.
What the published documents do not address is the processing of buyer personal information obtained from connected marketplaces — data belonging to the Customer's end customers rather than to the Customer. The published Privacy Policy describes the Customer's own account data (name, email, company, payment details); it does not describe buyer names and shipping addresses flowing through the Service from Amazon and other marketplaces. This Addendum covers exactly that gap, which is what a marketplace operator's data-protection review examines.
In the event of a conflict between this Addendum and the published Terms of Service, this Addendum governs solely with respect to the processing of buyer personal information.
1. Roles
For personal information originating from a connected marketplace — principally buyer names, shipping addresses, phone numbers, and email addresses attached to the Customer's orders — the Customer is the controller and Amplified Inventory LLC is the processor, acting only on the Customer's documented instructions. Using the Service to import, view, fulfil, or report on orders constitutes those instructions.
For information about the Customer's own users (names, work email addresses, authentication records, audit logs), Amplified Inventory is the controller for the purpose of operating and securing the Service.
2. What we process
| Category | Examples | Purpose |
|---|---|---|
| Buyer identity & delivery data | name, company, shipping address, phone, email | Fulfilling and shipping the Customer's orders; returns; support |
| Order & transaction data | order numbers, items, quantities, totals, taxes, fees | Order management, reconciliation, reporting |
| Listing & inventory data | SKUs, prices, quantities, attributes | Listing and inventory management, competitive-price retrieval and partner-directed price management |
| Customer user data | user name, email, permissions, login and PII-access audit records | Access control, security monitoring, audit |
We do not process special-category personal data, and the Service is not directed to children.
3. Purpose limitation
We process buyer personal information solely to provide the Service. We do not use it for marketing, do not build buyer profiles, do not sell or license it, and do not use it to train machine-learning models. Our AI-assisted features operate on catalogue and product data on company-controlled infrastructure and are code-verified not to receive buyer personal information.
4. Confidentiality and access control
Access to buyer personal information is restricted to personnel with a role that requires it, enforced in the application by a dedicated permission rather than by convention: sessions without it receive redacted values, and reports whose columns contain buyer identity are withheld from the catalogue and refused on both run and export. Every disclosure of buyer identity is written to an audit log. Personnel are bound by confidentiality obligations and complete security and privacy training.
5. Security measures
envelope encryption and versioned keys; searchable fields use a separately keyed blind index so equality lookups never expose plaintext.
session is granted. Password composition, history, minimum and maximum age are enforced in code on every path that sets a password.
restricted to a VPN with key-only SSH.
runs on a 30-day cadence and static analysis blocks every push that introduces a new finding.
6. Subprocessors
We use the following subprocessors for buyer personal information:
| Subprocessor | Purpose | Data received |
|---|---|---|
| USPS, UPS, FedEx | Shipping label generation | Buyer name and shipping address. A phone field is also present in the payload; where no buyer phone is stored — which is every Amazon order — a fixed placeholder value is transmitted instead |
| Cloudflare, Inc. | Edge TLS termination (Tunnel) in front of the Service | Request and response content in transit, including pages that render buyer name and address. Cloudflare stores no order data on our behalf |
| ShipStation (Auctane, Inc.) | Label generation / order feed | Buyer name, company, postal address, and a customer code (the buyer's eBay username where present, otherwise the buyer's name). No phone number and no email address is sent. The Service's order feed to ShipStation excludes Amazon orders in code — the exclusion is enforced in the database query, not by configuration. Where a Customer has connected its Amazon store to ShipStation directly, ShipStation already holds those orders independently of us; the Service may annotate them with shipping selections and warehouse pick locations but discloses no additional personal information |
Remaining infrastructure — database, cache, email, monitoring, source control, AI gateway, and the backup site — is self-hosted on company-controlled equipment and is not an external processor. Stripe processes Amplified's own subscription billing and receives no buyer personal information.
We maintain the current list in our Sub-Processor / Vendor Risk List and will give notice before adding a subprocessor that would receive buyer personal information.
7. Retention and deletion
Buyer personal information is deleted 30 days after delivery by an automated daily job; non-personal order records are retained for business and tax purposes. Deletion is verified and the verification is recorded.
8. Return and deletion on termination
On termination, or on the Customer's written request, we delete buyer personal information associated with the Customer's account within 30 days and confirm the deletion in writing. Where the Customer withdraws marketplace authorization, the same deletion process applies. Backups age out within their retention window and are not restored to circumvent a deletion.
9. Personal-information rights requests
Where a buyer exercises a right (access, correction, deletion) the Customer, as controller, receives the request. We will assist within the scope of what the Service holds and within the retention window described in B7.
10. Breach notification
If we become aware of a personal-data breach affecting the Customer's data, we will notify the Customer without undue delay and within 72 hours of confirming the breach, with the nature of the incident, the categories and approximate volume of data involved, the likely consequences, and the measures taken. Where a marketplace requires notification, we will notify it in parallel. Our incident-response plan governs the handling.
11. Location of processing
All processing and storage occur in the United States. We do not transfer personal information outside the United States, and no personnel access the systems from outside the United States.
12. Audit
On reasonable notice and no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this addendum, including our policy set, current vulnerability-scan summaries, and access-review records.
13. Affiliates
Amplified Inventory LLC and Computer Headquarters, Inc. are separate legal entities affiliated by common ownership, with shared officers and shared IT infrastructure. Computer Headquarters uses the Service as a customer under its own marketplace authorization and receives no access to any other Customer's data. This relationship is disclosed to Amazon under AUP 3.12.