Privacy Policy
Last updated: January 2025
Third-Party Marketplace Data (Amazon AUP)
BeyondCTO strictly adheres to Amazon's Acceptable Use Policy (AUP). We do not store PII beyond 30 days, we do not aggregate seller data for competitive intelligence, and we enforce AES-256 encryption at rest.
- PII Retention: Personally identifiable information accessed via Amazon SP-API is purged within 30 days of the operational need ending.
- No Competitive Aggregation: We never aggregate or benchmark seller-specific data across clients for competitive intelligence purposes.
- Encryption at Rest: All marketplace data is encrypted with AES-256 at rest and transmitted over TLS 1.2+.
- Access Control: Role-based access with full audit logging is enforced on every system handling marketplace data.
1. Information We Collect
We collect information you provide directly to us, including:
- Name, email address, and contact information.
- Company and brand information.
- Amazon seller account information (when provided for services).
- Financial Account Data: If you choose to link your bank account to our services, we collect account information including your institution name, account type, and transaction history (such as dates, amounts, merchant names, and categories). This data is accessed through our third-party provider, Stripe.
- Communication history with our team.
- Payment and billing information.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services.
- Financial Insights: Analyze your bank transaction history to provide financial reporting and automate expense tracking.
- Communicate with you about our services.
- Send you marketing communications (with your consent).
- Analyze and understand how our services are used.
- Protect against fraud and unauthorized access.
3. Third-Party Financial Data Aggregation
We use Stripe Financial Connections to retrieve data from your linked bank accounts.
- Data Access: By linking your account, you acknowledge that your data will be treated in accordance with Stripe's Privacy Policy.
- Credentials: We do not see, collect, or store your bank login credentials (username or password). These are provided directly to Stripe or your financial institution via a secure connection.
- Permissions: We only collect the specific categories of data you authorize during the connection process.
4. Information Sharing
We do not sell your personal information. We may share your information with:
- Stripe: To facilitate the connection to your financial institution and retrieve transaction data.
- Service providers who assist in our operations.
- Professional advisors (lawyers, accountants).
- Law enforcement when required by law.
- Business partners with your consent.
5. Cookies and Tracking
We use cookies and similar technologies to:
- Remember your preferences
- Analyze website traffic and usage
- Improve user experience
- Deliver targeted advertising
You can control cookies through your browser settings.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including encryption for sensitive financial data. However, no method of transmission over the Internet is 100% secure.
7. Data Retention
We retain your personal information for as long as necessary to provide our services.
Financial Data: If you disconnect your bank account, we will cease collecting new transaction data. You may request the deletion of previously collected historical transaction data by contacting us at the email below.
8. Your Rights
Depending on your location, you may have the right to:
- Access your personal information
- Correct inaccurate data
- Delete your data
- Opt out of marketing communications
- Data portability
- Withdraw consent
9. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
10. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children.
11. International Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last updated" date.
13. Contact Us
For questions about this Privacy Policy or your personal information, please contact us at:
- Email: privacy@beyondcto.com
- Address: BeyondCTO, 123 Business Ave, Wilmington, DE 19801