Effective date: September 17, 2026
Who we are and how to contact us
UpMarket Lab LLC, trading as UpMarketLab, provides Amazon consulting and account services. This policy explains how we handle personal information received through our website, inquiries, and client engagements. It also describes our rules for handling confidential client business information.
Andrea Bergamelli is our privacy contact. For questions, requests, or security concerns, email [email protected]. We are based in McKinney, Texas, United States.
Information we collect
- Inquiries and business contacts: names, business email addresses, contact details, company information, and correspondence you provide.
- Client service information: product details, listing assets, account identifiers, sales and advertising reports, project communications, and other records needed for the agreed work.
- Business administration: agreements, billing contact information, invoices, and service records.
- Website technical information: IP addresses, browser and device details, request times, and similar information processed by our hosting provider to deliver and protect the website.
We receive information directly from you, from people you authorize, from Amazon through authorized access, and from public product or marketplace sources. We limit collection to information relevant to the service or other purposes explained here.
How we use information
We use information to respond to inquiries, prepare quotations, deliver agreed services, analyze account performance, prepare content and recommendations, communicate with clients, administer contracts and billing, protect systems, and meet legal obligations.
Client account information is used for the authorized engagement. We do not sell personal information, use confidential client information for unrelated advertising, or share one client’s confidential account information with another client.
Amazon account access and buyer information
Access to Amazon accounts must use Amazon’s authorization mechanisms. Each employee uses an individual account, with permissions limited to assigned duties. We do not request or accept a seller’s password or authentication codes. Clients retain control over the authorization they grant.
For listing, advertising, and performance-reporting work, our standard is to use product information and reports without buyer personal details. We do not collect buyer names, addresses, payment details, or individual order information unless a specific authorized service requires it and Amazon permits that use. Customer information must not be used for unsolicited marketing, review manipulation, or other unauthorized purposes.
Storage, personnel, and service providers
Employees use company-managed Google Workspace and AI accounts. Our standard client file location is a company-controlled Google Drive folder, with access limited to assigned personnel. Client information must not be shared through public folder links or personal employee accounts. Any other service used to handle client information must be approved for its purpose.
We may share necessary information with assigned employees and contractors, and with providers supporting email and file storage, reporting, project work, approved AI assistance, and website hosting. These recipients must be authorized for the task and subject to appropriate confidentiality and data-protection requirements. We assess providers before allowing them to handle confidential client information. Clients may contact us for information about the providers used in their engagement.
We may also disclose information where required by law or a valid legal process, or where necessary and legally permitted to protect rights, investigate misuse, or respond to a security incident. Such disclosures remain subject to applicable restrictions on Amazon information.
AI-assisted services
We may use approved AI tools to assist with research, drafting, analysis, and internal task support. Employees must use company-managed accounts for this work. Human review is required before AI-generated work is used in client deliverables or account decisions.
Before confidential client information is provided to an AI service, we must review the provider’s terms, security, data retention and model-training practices, available account settings, and the client’s authorization. We limit inputs to what the task needs and explain relevant data sharing to the client. Company-managed accounts alone do not establish that every upload is permitted.
Our rules prohibit entering passwords, authentication codes, payment credentials, or buyer personal information into AI tools. Confidential client information must not be used to train general-purpose AI models. Client permission does not override Amazon restrictions or applicable law.
Security and access controls
Our operating rules require individual accounts, multi-factor authentication, access limited by job responsibilities, secure connections, encrypted work devices, endpoint protection, software updates, and automatic screen locking. Devices handling client information must meet company security requirements.
We require periodic access reviews and prompt removal of access when a person leaves or changes roles, within 24 hours where required by Amazon. Personnel must receive security guidance and keep client information confidential. Security concerns are escalated to Andrea for investigation, containment, and any notifications required by Amazon or applicable law.
No system can eliminate every security risk. If you suspect unauthorized access or disclosure, contact us promptly using the address above.
Retention, return, and deletion
We retain information only while necessary for its authorized purpose, the agreed engagement, or applicable legal obligations. During an engagement, relevant historical reports may be retained for performance comparisons. Unnecessary duplicates and information outside the service scope should be removed.
When an engagement or authorization ends, we begin offboarding: removing access, returning agreed deliverables where authorized, and deleting information we are no longer entitled to retain. For information covered by Amazon’s deletion requirements, our policy requires secure deletion within 30 days of the earliest applicable trigger, including Amazon’s deletion notice, the client’s revocation or termination, loss of our authority to process the information, or termination of our participation in the relevant Amazon services. A shorter applicable requirement takes priority.
The deletion process must address relevant copies in cloud folders, local or synced devices, email attachments, reporting tools, approved AI services, and backups, including copies held by providers. Moving a file to trash or removing account access alone does not complete deletion. Provider retention and backup settings must support the applicable deadline, and completion must be recorded.
Contracts, invoices, and records required by law are handled separately and retained only to the extent and for the period required for their applicable purpose. A legal retention requirement does not authorize retaining unrelated client reports. Any information retained under a legal exception remains restricted to that purpose. Where Amazon permits processing of buyer personal information, the stricter rules for that information apply.
Your requests and choices
You may contact us to ask about your personal information or request access, correction, deletion, or limits on its use. Depending on applicable law, you may also have rights to a copy of your information, to object to processing, or to withdraw consent where processing relies on consent. We may verify your identity and authority before responding.
We handle requests within the time required by applicable law. If we cannot fulfill a request, we will explain the relevant reason where permitted. You can reply to request a review of our decision and may contact an appropriate privacy authority where applicable. If we handle information on a client’s instructions, we may refer the request to that client or assist them in responding.
Clients can revoke permissions through Amazon. Revocation also triggers our review of retained information; it does not by itself erase previously downloaded files.
Website hosting and cookies
This website is hosted through Cloudflare. The hosting service may process technical information and use features necessary for security, access control, and delivery. Our website code does not set analytics or advertising cookies, use browser storage to track visitors, or maintain a contact-form database. Email links open your email application.
International processing
We are based in the United States. Approved personnel and providers may process information in other countries. Where a transfer requires additional contractual or legal safeguards, those safeguards must be established before the transfer. You may contact us about the locations and providers relevant to your engagement.
Children and external services
Our website and services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information so we can address it. External websites and services, including Amazon and your email provider, have their own privacy policies.
Policy updates
We will update this policy when relevant practices or requirements change and show the revised effective date. Where applicable law requires additional notice or consent for a change, we will provide it. Privacy questions and requests can be sent to [email protected].