Privacy Policy

Last updated: August 24, 2026

This policy explains how the operator of asinassets.com, trading as ASIN Assets, handles personal data. ASIN Assets is not affiliated with Amazon. Use the public Contact page and choose “Privacy request” to reach the controller without signing in.

Data we process and why

  • Account and security: email, optional name, password hash, security-question identifiers and answer hashes, session records, role, and credit balance to create and protect your account.
  • Guest access: a random guest cookie, domain-separated HMAC of the network address, ASIN, marketplace, quota event, and request identifier to enforce the rolling allowance and prevent abuse. Raw IP addresses are not stored in guest-usage tables.
  • Lookups and files: submitted ASINs or product URLs, marketplace, normalized public listing data, job status, selected media, errors, and generated file metadata to provide the requested service.
  • Billing: invoice reference, pack quantity, amount, payment status, and credit-ledger entries to reconcile purchases and disputes. We do not receive or store card numbers.
  • Support: name, reply email, topic, subject, message, account email when signed in, delivery status, and a reference number so we can answer and audit delivery.
  • Aggregate product metrics: allowlisted event names, date, route, and campaign dimensions to understand the funnel. We do not put ASINs, raw IP addresses, message text, or lookup payloads in analytics events.

Necessary browser storage

Authentication and guest-limit cookies are strictly necessary. A guest claim token is held in session storage so a result can be attached after signup; it is removed after a successful claim or when the browser session ends. Allowlisted UTM values and only the referrer category (such as EasyParser, Google, Bing, or other) are also kept for the browser session to attribute aggregate funnel events. Measurement is disabled when Global Privacy Control or Do Not Track is enabled. ASIN Assets does not enable third-party advertising or analytics cookies.

Service providers and transfers

We disclose only the data needed for each service:

  • EasyParser: processes lookup requests and provides the hosted App Store checkout. Payment-card entry happens on its hosted page.
  • Render: hosts the web service and PostgreSQL database; the configured production region is Frankfurt.
  • DigitalOcean Spaces: stores private temporary ZIP, MP4, and cached media objects and returns short-lived signed download links.
  • Discord: receives a support notification containing contact-form details when delivery is configured. The message is also stored in our support record before or alongside that notification.
  • Amazon public endpoints: are the source of public listing and media URLs; ASIN Assets does not ask for Seller Central credentials.

These providers may process data in countries different from yours under their own contractual and security safeguards.

Retention

  • Guest claim results expire after 24 hours; guest quota and abuse events are deleted after 30 days.
  • Detailed normalized job output is cleared after 90 days while non-content history totals may remain.
  • Generated ZIP and MP4 files and signed access expire after 24 hours. Provider caches may remain for up to 30 days without extending the user download window.
  • Contact messages are kept for up to 24 months unless a legal, security, or dispute need requires longer retention.
  • Daily aggregate funnel metrics are deleted after 24 months.
  • Credit-ledger and payment records are kept as required for billing, fraud prevention, accounting, and legal obligations.
  • Account data remains until deletion, subject to records we must retain.

Your choices and rights

Depending on your location, you may ask to access, correct, export, restrict, object to, or delete personal data, and may complain to your local data-protection authority. Submit a public Contact request with the Privacy topic. We may verify control of the account or email before acting. Deletion removes account-linked operational data except records that must be retained for billing, security, disputes, or law.

Security and changes

We use hashed passwords and security answers, HTTP-only session cookies, private object storage, signed download URLs, access controls, and data minimization. No system is risk-free. Material policy changes will update the date above and, where appropriate, be shown in the product.