Amazap Privacy Policy

Effective date: October 9, 2026

This policy explains what personal information Amazap collects, why, who we share it with, and the choices you have. We collect as little as we can to run the storefront.

1. Who we are and what this covers

1.1 Jesse Shrader, doing business as Amazap ("Amazap," "we," "us") is responsible for the personal information described here. Contact us at support@amazap.com.

1.2 This policy covers amazap.com, the Amazap MCP server, our HTTP and L402 APIs, Amazap Basics, checkout, and seller onboarding (the "Services"). It applies to Users who operate agents, people who browse the site, buyers of physical goods, and Sellers.

1.3 Sellers you buy from, Amazon, and other third parties have their own privacy policies for the data they handle.

2. The short version

3. What we collect

3.1 Account and agent identifiers. API keys, L402 macaroons, MCP and OAuth session and client identifiers, account IDs, balance and spend caps, and your email address if you give it to us.

3.2 Payment data. Lightning invoices, payment hashes and preimages, amounts in sats, timestamps, the BTC/USD rate used, and your Credits ledger (top-ups, purchases, re-credits). We don't collect card or bank details.

3.3 Call logs and receipts. For each purchase: the Listing, request metadata (such as endpoint, parameters, and size), response status, timing, delivery result, and the receipt we return to your Agent, which may include the request you sent and the response you received.

3.4 Amazap Basics inputs. What you submit to our own services, such as the URL you send to Page to Markdown or the text you turn into a QR code, and the output we return.

3.5 Physical-goods buyer data. Shipping name, address, phone number and email (phone and email may be optional), order details, and the Lightning destination you provide for refunds.

3.6 Seller data. Contact email, endpoint and listing details, wallet connection details and receive-only credentials, any API key you create for Amazap, and listing health and sales data. For physical-goods Sellers: business details, tax registrations, and Amazon account connection data.

3.7 Support and communications. What you send us by email or through claims and reports (for example, claim_failed_call or report_sku).

3.8 Site and server data. IP address, user agent, request time, pages and endpoints accessed, and error logs. The site stores your cart and recent order IDs in your browser's local storage; this stays on your device unless you send it to us. We don't currently use third-party analytics or advertising cookies. If we add analytics, we'll update this section and name the provider.

We don't knowingly collect sensitive personal information, and we ask you not to send it through Listings unless the Listing is meant for it.

4. How we use it

We use personal information to:

5. Who we share it with

5.1 Sellers. When you buy an API call, we send your request to the Seller so it can respond, and we pay the Seller from Amazap's own Lightning node, so the Seller sees a payment from Amazap, not from you. For physical goods, we share your shipping details and order with the Seller.

5.2 Amazon Multi-Channel Fulfillment. For physical orders, the Seller's order and your shipping details go to Amazon to fulfill and track the delivery.

5.3 Service providers who process data for us under contract:

5.4 Legal and safety. When we believe in good faith that disclosure is required by valid legal process (such as a subpoena, court order, or warrant), or is needed to protect people, the Services, or our rights. Where lawful and practical, we'll tell affected Users before disclosing.

5.5 Business changes. In a merger, acquisition, financing, or sale of assets, subject to this policy.

5.6 With your direction. When you or your Agent ask us to share something.

6. Lightning payments and privacy

Lightning payments are pseudonymous, not anonymous. Payment hashes, amounts, timing, and node information may be visible to routing nodes and to the recipient of a payment. When you top up, the payment goes to Amazap. For physical goods, you pay the Seller's invoice directly, so the Seller receives your payment. We can't control what routing nodes or other networks observe.

7. No sale and no targeted advertising

We don't sell personal information and don't share it for cross-context behavioral advertising. We don't use personal information to profile you for ads.

8. How long we keep it

DataRetention
Call logs, receipts, and Amazap Basics inputs and outputs90 days
Server and security logs (including IP addresses)30 days, longer if needed to investigate an incident
Payment records, Credits ledger, and tax records7 years
Physical-goods shipping details held by Amazap30 days after delivery or the end of the return window, whichever is later; order and tax records as above
Account identifiers and emailwhile the account is active, then deleted within 90 days of closure or forfeiture
Seller datawhile listed, then 12 months
Support messages2 years

We may keep data longer if the law requires it or to resolve disputes, and we may keep aggregated or de-identified data. Sellers and Amazon keep order data under their own policies.

9. Security

We use reasonable safeguards, including encryption in transit, access controls, receive-only credentials for Seller wallets, and encryption of physical-goods personal data at rest. No system is perfectly secure. Protect your Credentials (see our Terms of Service) and tell us at support@amazap.com if you think they've been exposed.

10. Your choices and rights

You can ask us to access, correct, or delete your personal information, or close your account, by emailing support@amazap.com. Because most agent accounts have no name or email, we'll verify requests by asking you to prove control of the account or Credentials (for example, by signing a message or sharing a call ID from your receipts). We may keep information we need for legal, tax, security, or dispute reasons. Closing an account forfeits unused Credits, as our Terms explain.

11. California residents

If you're a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you rights over your personal information.

Categories we collect (see Section 3): identifiers (Credentials, account IDs, email, IP address); customer records (shipping name, address, phone); commercial information (purchases, Credits, receipts); internet or network activity (call logs, server logs); and limited inferences used for fraud prevention and listing health. Sources are you, your Agents, Sellers, and our service providers. Purposes are in Section 4. We disclose these categories for business purposes to the recipients in Section 5.

We don't sell or share personal information (as those terms are defined in the CCPA), including of anyone under 16, and we don't use sensitive personal information for purposes that would require a right to limit.

Your rights: to know and access, delete, and correct your personal information; to opt out of sale or sharing (we don't do either); and to not be discriminated against for using these rights.

How to make a request: email support@amazap.com with "California request" in the subject. We'll verify it as described in Section 10 and respond within 45 days (extendable as the law allows). You can use an authorized agent; we'll ask for proof of authorization.

12. EEA and UK users

If you're in the European Economic Area or the UK:

13. Children

The Services are for people 18 and older and aren't directed to children. We don't knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact support@amazap.com and we'll delete it.

14. Changes to this policy

We may update this policy. We'll post the new version with a new effective date and give notice of material changes (for example, on the site or through the MCP).

15. Contact

Jesse Shrader, doing business as Amazap

Privacy and support: support@amazap.com