Pulse Pilot
Privacy Policy
Effective date: May 6, 2026
1. Introduction
Pulse Pilot is a software-as-a-service product offered by AMP IP Holdings LLC, a New Jersey limited liability company (“Pulse Pilot,” “we,” “us,” or “our”). The service helps Amazon sellers manage and automate Sponsored Products, Sponsored Brands, and Sponsored Display advertising campaigns, and integrates with Amazon Advertising and (where authorized by Amazon) Selling Partner APIs to read data from a seller’s own Amazon account on the seller’s behalf.
This Privacy Policy explains what information we collect, why we collect it, how it is stored and protected, who else can see it, and what choices you have. It applies to anyone who creates an account with us, anyone who connects an Amazon account to our service, and anyone who visits our website. By using Pulse Pilot you agree to the practices described here.
2. Information We Collect
2.1 Account information
When you sign up, we collect the email address you use to log in and, if you choose to provide it, your name and the name of your business. We use these to identify your account, send transactional messages related to the service, and respond to support requests.
2.2 Amazon Advertising API data
Once you authorize Pulse Pilot to access your Amazon Advertising account, we read advertising data on your behalf using the credentials you grant. This includes:
- Campaigns, ad groups, keywords, product targets, and negative targets, including their states, match types, and creative settings;
- Search-term reports, placement reports, and other performance reports we request through the Amazon Ads Reports API;
- Bids, budgets, daily and lifetime caps, and bidding strategies;
- Performance metrics such as impressions, clicks, spend, sales, orders, ACoS, ROAS, and conversion rate, at hourly and daily granularity;
- Brand and account metadata returned by the Amazon Profiles API (profile id, marketplace, currency, time zone).
2.3 Amazon Selling Partner API data (forward-looking)
We are in the process of applying for Amazon Selling Partner API (“SP-API”) access. If and when SP-API access is approved and you authorize it, we may also collect, on your behalf, data that includes orders, listings and listing performance, inventory, shipments, FBA fees, and settlement reports. The categories of data we request will be limited to what is needed to provide and improve the advertising-related features you use.
Some SP-API roles can return Amazon customer personally identifiable information (“Amazon PII”) such as buyer names, shipping addresses, and contact details. We treat Amazon PII according to the additional rules in Section 5 below.
2.4 Usage telemetry
We log application errors, server-side request logs, and aggregate usage events (for example, which page you visited and which feature you triggered). These are used to debug failures and to make the product more reliable. We do not currently use any third-party analytics, advertising trackers, or behavioral profiling tools, and we do not embed third-party tracking pixels in the application. If we ever add any, we will update this policy and notify you in advance.
2.5 Cookies
We use a small number of first-party cookies that are strictly necessary to keep you signed in (session cookies issued by our authentication provider). We do not set advertising or cross-site-tracking cookies. Most browsers let you reject cookies, but rejecting our session cookies will prevent you from staying signed in.
3. How We Use Information
We use the information described above to:
- Provide the service you requested — render dashboards, run reports, generate recommendations, and make changes to your Amazon advertising on your behalf when you authorize them;
- Generate AI-driven recommendations and automation rules. When we send your data to an AI provider for inference, we send only the minimum needed to produce a recommendation (for example, a campaign’s recent performance metrics), never your account credentials or Amazon refresh tokens;
- Send transactional communications about your account, billing, service status, and security. We do not send marketing emails today; if we ever do, you will be able to opt out;
- Investigate and prevent abuse of the service or violations of our Terms of Service;
- Improve the product. Where we use customer data for service improvement, we work in aggregate, anonymized form whenever possible.
4. How We Protect Information
We take reasonable administrative, technical, and physical safeguards to protect your information. Specifically:
- Encryption at rest. Customer data is stored in a managed PostgreSQL database (Supabase) with AES-256 encryption at rest. Backups are encrypted with the same standard.
- Encryption in transit. All connections to our application, our database, and to upstream Amazon APIs use TLS 1.2 or higher.
- Tenant isolation. Each customer’s data is scoped to their account at the database layer using row-level security policies, so one customer cannot read or modify another customer’s rows even if a frontend bug were to attempt it.
- Least-privilege access. Only personnel who need production access in order to operate or support the service have it, and that access is limited to the narrowest credential scopes consistent with their role. Access to production systems is logged.
- Secret management. Amazon refresh tokens and any other long-lived credentials are stored encrypted, never logged, never returned to the browser, and used only by server-side workers.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the appropriate authorities consistent with applicable law.
5. Amazon Data Specifics
We comply with the Amazon Acceptable Use Policy, the Amazon Marketplace Web Service / Selling Partner API Data Protection Policy, the Amazon Advertising API Acceptable Use Policy, and the applicable Amazon Developer Agreements. The following rules apply specifically to data we receive from Amazon on your behalf:
- Purpose limitation. Amazon data is used only to operate the features you use within Pulse Pilot and to improve those features for you. We do not use Amazon data for unrelated purposes, do not combine it with data from other sellers’ accounts to draw individual conclusions about other sellers, and do not advertise to your customers using Amazon data.
- Amazon PII handling. Where SP-API roles cause buyer names, addresses, or contact details to be transmitted to us, that data is encrypted at rest and in transit. We retain Amazon PII for no longer than 30 days unless retaining it for longer is strictly required to provide service continuity for you (for example, to surface a return or fee dispute), and we never share Amazon PII with third parties.
- No resale or sharing. We do not sell, rent, license, or otherwise share Amazon data with third parties for their own use. The only third parties that ever process your Amazon data are the infrastructure providers listed in Section 6, and they process it strictly on our behalf under written data processing terms.
- Deletion on request. You may request deletion of all Amazon-derived data tied to your account at any time by emailing us at the address below. We process deletion requests within 30 days. Deletion will also occur automatically when you disconnect your Amazon account from Pulse Pilot or close your account.
- Geographic scope. We do not transfer Amazon data outside the United States without first notifying you, except where transfer is technically incidental to delivery (for example, a content delivery network terminating an HTTPS connection).
6. Service Providers
We do not sell customer data. To run the service we use the following infrastructure providers, each of which is contractually bound to process your data only on our instructions:
- Supabase. Managed PostgreSQL database and authentication.
- Vercel. Application and edge hosting for the web dashboard.
- Amazon Web Services. Background workers and scheduled jobs that synchronize data with Amazon APIs.
- Anthropic. AI model provider used to generate recommendations and natural-language summaries of advertising performance, on the minimized inputs described in Section 3.
If we add or change service providers in a way that materially affects how your data is handled, we will update this policy.
7. Your Rights
Depending on where you live, you may have the following rights with respect to your personal information, including under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and similar laws:
- Access. You can ask for a copy of the personal information we hold about you.
- Correction. You can ask us to correct information that is inaccurate or incomplete.
- Deletion. You can ask us to delete your account and the personal information associated with it, subject to limited exceptions where retention is required by law.
- Portability. You can ask for your data in a portable, machine-readable format.
- Opt out of communications. You can opt out of any non-essential communications at any time.
- Non-discrimination. We will not deny you the service or charge you a different price for exercising any of these rights.
To exercise any of these rights, contact us at the address below. We may need to verify your identity before fulfilling certain requests.
8. Children’s Privacy
Pulse Pilot is a business tool intended for use by Amazon sellers and their authorized employees. The service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected such information, please contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by a banner in the dashboard before the changes take effect. The most recent version of this policy is always available at this URL. Continued use of the service after the effective date of an update means you accept the updated policy.
10. Contact
If you have questions about this Privacy Policy or about how we handle your data, please reach out: