ClaimCatcher — Privacy Policy
Product: ClaimCatcher
Website: claimcatcher.the-atlas-project.net
Operator: The Atlas Project (operating the "An Atlas Project" portfolio)
Effective date: July 18, 2026
This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with ClaimCatcher (the "Service") at claimcatcher.the-atlas-project.net. It applies to the Service and our marketing site. It does not cover Third-Party Services you connect (principally Amazon and Stripe), which have their own policies. Capitalized terms not defined here have the meanings given in the Terms of Service.
Our posture, in plain English: we use essential cookies only (the Supabase auth session), we run no analytics or advertising trackers, we do not sell or share personal information, and we handle data-subject requests by email. ClaimCatcher accesses your Amazon seller data read-only, minimizes and scrubs personal data at ingest, and never benchmarks identifiable seller data across accounts.
§P1 Who we are; scope; roles
This Policy covers ClaimCatcher's website, application, and APIs. It does not cover the Third-Party Services you connect, which have their own policies.
Controller / processor roles. For your account and billing data, we act as controller. For the Amazon seller data the Service accesses on your instruction (transactional inventory, fee, financial-event, and reimbursement records), you are the controller and we are your processor — see the mini-DPA in §P13-DPA. ClaimCatcher's ingested data is largely business/transactional rather than consumer personal data, but the processor terms are provided for completeness and to cover any personal data that appears within it.
§P2 Categories of personal information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, password/OAuth identity, workspace settings | you, at signup (via Supabase auth) |
| Billing data | plan, billing email, partial card metadata, invoice/transaction history, performance-fee statements | you and Stripe (we do not store full card numbers) |
| Amazon connection data | SP-API OAuth tokens (encrypted at rest), marketplace/region, seller/account identifiers | you, on connecting your Amazon account read-only |
| Amazon seller records (processor-role) | inventory, fee, financial-event, and lost/damaged/return records; discrepancies; filed claims; posted reimbursement credits used to verify billing | your Amazon account via SP-API, on your instruction — personal data minimized and scrubbed at ingest |
| Usage & device data | log events, feature usage, IP address, timestamps, error logs | automatically, to run and secure the Service |
| Support data | messages you send us, correspondence | you |
| Essential cookies | Supabase auth-session cookie | your browser session |
We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.
§P3 How and why we use personal information (purposes)
- Provide the Service — authenticate you, connect your Amazon account read-only, run the deterministic audit, surface discrepancies, and — if you enable recovery — file and track eligible claims and record posted reimbursements.
- Billing — compute and charge the 20% performance fee via Stripe on verified, posted reimbursements, or process the optional Flat subscription. Performance-fee statements are generated so you can see what was counted.
- Communicate — send transactional and service messages (e.g., "recovered" notices, security and product notices) via Resend. We send marketing email only where permitted and with an unsubscribe option.
- Secure and maintain — detect abuse, enforce per-account velocity caps, debug, and protect the Service and users.
- Comply — meet legal obligations, Amazon's SP-API data-protection requirements, and enforce our Terms.
- Improve, in aggregate only — understand feature usage and maintain aggregated, anonymized FBA-reimbursement benchmarks. We do not use identifiable seller data to benchmark across accounts, and we do not use the content you connect to train generalized AI models. (ClaimCatcher's money path is a deterministic engine — no AI model processes your data to compute your audit or claims.)
§P4 Legal bases (GDPR / UK GDPR)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, and for limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records; billing substantiation). For processor-role Amazon data, your instructions and the mini-DPA govern; you are responsible for the legal basis as controller.
§P5 Subprocessors and third-party recipients
We use the following subprocessors and service providers for ClaimCatcher:
| Subprocessor | Function |
|---|---|
| Vercel | Application hosting / edge delivery |
| Supabase | Database and authentication |
| Stripe | Payment processing; performance-fee (metered) and optional Flat-subscription billing, via Stripe Connect |
| Resend | Transactional and service email |
| Amazon Selling Partner API (SP-API) | Read-only access to your Amazon seller data, on your instruction |
| Cloudflare (Workers) | Executes the heavy ~18-month SP-API data pull on your behalf; processes your seller data transiently to complete the audit |
We do not use, for ClaimCatcher, any advertising, analytics, or AI/vision subprocessor. We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.
§P6 Cookies and similar technologies
We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.
§P7 Retention
We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Amazon seller records ingested for the audit are retained as needed to provide the Service (ongoing audit and claim tracking) and to substantiate performance-fee billing and handle disputes; they are deleted or de-identified on request or on termination, subject to residual backups purged on our ordinary cycle and records we must keep by law. SP-API OAuth tokens are stored encrypted and are deleted when you disconnect your Amazon account. Consistent with Amazon's SP-API Data Protection Policy, we retain personally identifiable seller information only as long as needed to provide the Service.
§P8 Security
We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, encryption of SP-API tokens at rest (AES-256-GCM), row-level security (read-own; no client writes to audit, discrepancy, recovery, or entitlement tables), least-privilege access, per-account velocity caps, PII scrubbing at ingest, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe, Cloudflare). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.
§P9 Your privacy rights
§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. Where we act as processor for Amazon seller data, we will route your request to the relevant controller (our customer) or assist them.
§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing" and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.
§P9.3 B2B nuance. ClaimCatcher's ingested Amazon data is largely business/transactional data about your own seller account rather than consumer personal information. Where any of it is personal information of individuals, the rights above may apply and are typically directed to you as controller; we assist as processor. California's treatment of business-to-business data continues to evolve — we handle such data consistent with applicable law.
§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law.
§P10 International data transfers
We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.
§P11 Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).
§P12 Changes to this Policy
We may update this Policy. We will post the new version with a revised "Effective date" and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.
§P13 Contact
Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].
§P13-DPA — Mini-Data Processing Addendum (Amazon seller data)
This addendum applies to the personal data, if any, contained within the Amazon seller records the Service processes on your instruction ("Customer Personal Data").
1. Roles. For Customer Personal Data, you are the controller and we are the processor (or, where you are yourself a processor, we are your sub-processor).
2. Instructions. We process Customer Personal Data only (a) to provide and secure the Service, (b) per your documented instructions (your configuration, the read-only scopes you grant, and your recovery on/off setting), and (c) as required by law (we will tell you unless legally barred).
3. Purpose limitation. We will not sell Customer Personal Data, use it for advertising, use it to train generalized AI models, or use identifiable seller data for cross-account benchmarking. Any public benchmarks are aggregated and anonymized only.
4. Confidentiality. Personnel with access are bound by confidentiality. Human access to Customer Personal Data occurs only as needed for security or support.
5. Sub-processors. You authorize the subprocessors listed in §P5. We remain responsible for their performance and will give notice of material changes with a chance to object.
6. Security. We maintain the measures in §P8 appropriate to the risk, including read-only SP-API scope, encrypted tokens, RLS, PII scrubbing at ingest, and velocity caps.
7. Assistance. Taking into account the nature of processing, we will reasonably assist you with data-subject requests, security, breach notification, and DPIAs. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
8. Deletion/return. On termination or your request, or when you disconnect your Amazon account, we will delete or return Customer Personal Data (and delete SP-API tokens), subject to residual backups purged on our ordinary cycle and legal-retention and billing-substantiation requirements.
9. International transfers. Where applicable, the SCCs/UK Addendum referenced in §P10 apply to Customer Personal Data.
10. Audit. We will make available information reasonably necessary to demonstrate compliance and allow for reasonable, confidential audits on notice, subject to appropriate limits.
Effective date: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net
This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.