Amazap Privacy Policy
Effective date: October 9, 2026
This policy explains what personal information Amazap collects, why, who we share it with, and the choices you have. We collect as little as we can to run the storefront.
1. Who we are and what this covers
1.1 Jesse Shrader, doing business as Amazap ("Amazap," "we," "us") is responsible for the personal information described here. Contact us at support@amazap.com.
1.2 This policy covers amazap.com, the Amazap MCP server, our HTTP and L402 APIs, Amazap Basics, checkout, and seller onboarding (the "Services"). It applies to Users who operate agents, people who browse the site, buyers of physical goods, and Sellers.
1.3 Sellers you buy from, Amazon, and other third parties have their own privacy policies for the data they handle.
2. The short version
- We don't need your name to use the API marketplace. An agent account is identified by Credentials, not by identity.
- We don't take card data. Payments run over Lightning.
- We keep call logs for 90 days and payment and tax records for 7 years.
- For physical orders, we share your shipping details with the Seller and Amazon so your order can be delivered, and with a tax calculator so your quote is correct.
- We don't sell personal information or share it for cross-context behavioral advertising.
3. What we collect
3.1 Account and agent identifiers. API keys, L402 macaroons, MCP and OAuth session and client identifiers, account IDs, balance and spend caps, and your email address if you give it to us.
3.2 Payment data. Lightning invoices, payment hashes and preimages, amounts in sats, timestamps, the BTC/USD rate used, and your Credits ledger (top-ups, purchases, re-credits). We don't collect card or bank details.
3.3 Call logs and receipts. For each purchase: the Listing, request metadata (such as endpoint, parameters, and size), response status, timing, delivery result, and the receipt we return to your Agent, which may include the request you sent and the response you received.
3.4 Amazap Basics inputs. What you submit to our own services, such as the URL you send to Page to Markdown or the text you turn into a QR code, and the output we return.
3.5 Physical-goods buyer data. Shipping name, address, phone number and email (phone and email may be optional), order details, and the Lightning destination you provide for refunds.
3.6 Seller data. Contact email, endpoint and listing details, wallet connection details and receive-only credentials, any API key you create for Amazap, and listing health and sales data. For physical-goods Sellers: business details, tax registrations, and Amazon account connection data.
3.7 Support and communications. What you send us by email or through claims and reports (for example, claim_failed_call or report_sku).
3.8 Site and server data. IP address, user agent, request time, pages and endpoints accessed, and error logs. The site stores your cart and recent order IDs in your browser's local storage; this stays on your device unless you send it to us. We don't currently use third-party analytics or advertising cookies. If we add analytics, we'll update this section and name the provider.
We don't knowingly collect sensitive personal information, and we ask you not to send it through Listings unless the Listing is meant for it.
4. How we use it
We use personal information to:
- provide the Services: open accounts, take top-ups, process purchases, deliver calls, route physical orders, and issue receipts;
- run Credits: track balances, re-credit failed calls, and handle claims (our call logs decide whether a call failed);
- calculate prices, tax quotes, and exchange rates;
- monitor listing health and keep the catalog reliable;
- prevent fraud, abuse, and security incidents, enforce limits, and screen for sanctions;
- provide support and send service messages;
- keep financial, tax, and legal records and comply with the law; and
- improve the Services using aggregated or de-identified data.
5. Who we share it with
5.1 Sellers. When you buy an API call, we send your request to the Seller so it can respond, and we pay the Seller from Amazap's own Lightning node, so the Seller sees a payment from Amazap, not from you. For physical goods, we share your shipping details and order with the Seller.
5.2 Amazon Multi-Channel Fulfillment. For physical orders, the Seller's order and your shipping details go to Amazon to fulfill and track the delivery.
5.3 Service providers who process data for us under contract:
- Amboss: Lightning wallet and payments infrastructure;
- DigitalOcean: hosting;
- a sales tax calculation provider: tax quotes for physical orders (shipping address and order amount);
- our email provider: support and service email.
5.4 Legal and safety. When we believe in good faith that disclosure is required by valid legal process (such as a subpoena, court order, or warrant), or is needed to protect people, the Services, or our rights. Where lawful and practical, we'll tell affected Users before disclosing.
5.5 Business changes. In a merger, acquisition, financing, or sale of assets, subject to this policy.
5.6 With your direction. When you or your Agent ask us to share something.
6. Lightning payments and privacy
Lightning payments are pseudonymous, not anonymous. Payment hashes, amounts, timing, and node information may be visible to routing nodes and to the recipient of a payment. When you top up, the payment goes to Amazap. For physical goods, you pay the Seller's invoice directly, so the Seller receives your payment. We can't control what routing nodes or other networks observe.
7. No sale and no targeted advertising
We don't sell personal information and don't share it for cross-context behavioral advertising. We don't use personal information to profile you for ads.
8. How long we keep it
| Data | Retention |
|---|---|
| Call logs, receipts, and Amazap Basics inputs and outputs | 90 days |
| Server and security logs (including IP addresses) | 30 days, longer if needed to investigate an incident |
| Payment records, Credits ledger, and tax records | 7 years |
| Physical-goods shipping details held by Amazap | 30 days after delivery or the end of the return window, whichever is later; order and tax records as above |
| Account identifiers and email | while the account is active, then deleted within 90 days of closure or forfeiture |
| Seller data | while listed, then 12 months |
| Support messages | 2 years |
We may keep data longer if the law requires it or to resolve disputes, and we may keep aggregated or de-identified data. Sellers and Amazon keep order data under their own policies.
9. Security
We use reasonable safeguards, including encryption in transit, access controls, receive-only credentials for Seller wallets, and encryption of physical-goods personal data at rest. No system is perfectly secure. Protect your Credentials (see our Terms of Service) and tell us at support@amazap.com if you think they've been exposed.
10. Your choices and rights
You can ask us to access, correct, or delete your personal information, or close your account, by emailing support@amazap.com. Because most agent accounts have no name or email, we'll verify requests by asking you to prove control of the account or Credentials (for example, by signing a message or sharing a call ID from your receipts). We may keep information we need for legal, tax, security, or dispute reasons. Closing an account forfeits unused Credits, as our Terms explain.
11. California residents
If you're a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you rights over your personal information.
Categories we collect (see Section 3): identifiers (Credentials, account IDs, email, IP address); customer records (shipping name, address, phone); commercial information (purchases, Credits, receipts); internet or network activity (call logs, server logs); and limited inferences used for fraud prevention and listing health. Sources are you, your Agents, Sellers, and our service providers. Purposes are in Section 4. We disclose these categories for business purposes to the recipients in Section 5.
We don't sell or share personal information (as those terms are defined in the CCPA), including of anyone under 16, and we don't use sensitive personal information for purposes that would require a right to limit.
Your rights: to know and access, delete, and correct your personal information; to opt out of sale or sharing (we don't do either); and to not be discriminated against for using these rights.
How to make a request: email support@amazap.com with "California request" in the subject. We'll verify it as described in Section 10 and respond within 45 days (extendable as the law allows). You can use an authorized agent; we'll ask for proof of authorization.
12. EEA and UK users
If you're in the European Economic Area or the UK:
- Controller: Jesse Shrader, doing business as Amazap, support@amazap.com.
- Legal bases: performance of our contract with you (providing the Services and Credits); legitimate interests (security, fraud prevention, listing health, and improving the Services); legal obligation (tax and accounting records, responding to lawful requests); and consent where we ask for it.
- International transfers: we're based in the U.S. and process data there and wherever our providers operate. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum.
- Your rights: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent. Contact support@amazap.com. You can also complain to your local data protection authority.
13. Children
The Services are for people 18 and older and aren't directed to children. We don't knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact support@amazap.com and we'll delete it.
14. Changes to this policy
We may update this policy. We'll post the new version with a new effective date and give notice of material changes (for example, on the site or through the MCP).
15. Contact
Jesse Shrader, doing business as Amazap
Privacy and support: support@amazap.com