Privacy policy
How Amazon advertising and product-economics data would be handled in the production service.
Information we may collect
Contact and company information, eligibility answers, engagement communications, advertising reports, product economics, returns, discounts, fees, inventory context, and operational notes needed to perform the service.
ClickCraft does not need your Seller Central password or MFA code and will never ask you to email them.
How information is used
ClickCraft uses this information to determine fit, confirm scope, manage advertising, prepare reports, support the engagement, secure the service, process payment, and maintain required business records.
Providers and access
The website uses Vercel for hosting and privacy-minded, cookie-free traffic analytics; Supabase stores contact details and qualifying account answers after an account matches the launch scope; Resend sends operator notifications; and Cal.com handles optional fit-call scheduling. Stripe may process payment only after the scope and agreement are accepted.
Access follows least privilege. Advertising edit permissions are used only for an agreed management scope; other business information remains read-only where practical. ClickCraft will not sell client data or use it to train a ClickCraft-owned model.
Retention and deletion
Prospect eligibility records that do not become a client engagement are intended to be removed within 12 months. Active-client workpapers are kept only as long as needed to perform and document the service, then removed on a documented schedule after the engagement unless a contract, tax, accounting, security, or legal obligation requires longer retention.
To request access, correction, or deletion, email hello@clickcraft.ink. A request may require reasonable identity or authority verification.
Security and incident limits
ClickCraft intends to use private storage, access controls, signed transfers, separate environments, and reputable infrastructure providers. No internet system can guarantee perfect security. Customers should promptly report suspected exposure and revoke access when an engagement ends.