Brimloop

Privacy

Privacy Policy

Last updated June 25, 2026

Brimloop is a software service operated by Anorcap Private Limited, a company incorporated in India ("Brimloop", "we", "us", "our"). This policy explains what information we collect from the Amazon sellers who use Brimloop and from visitors to this website, how we use it, who processes it on our behalf, and the rights you have under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). Where applicable to cross-border users, the EU and UK General Data Protection Regulation (GDPR / UK GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA / CPRA) may also apply.

Who this policy applies to

It applies to (1) Amazon sellers who connect a Selling Partner account to Brimloop and the users they invite to their workspace, and (2) visitors to our marketing website at brimloop.ai. Brimloop is a business-to-business service and is not directed to consumers or to children.

Information we collect

We collect three categories of data:

  • Amazon Selling Partner data — when you authorize Brimloop through Amazon's Selling Partner API (SP-API), we access your order and sales history, inventory and fulfilment data, product catalog and listing data, and pricing and competitive-offer data for your own listings. We do not collect, request, or store Amazon buyer personally identifiable information (PII) — we have no need for buyer names, addresses, or contact details, and do not retrieve them.
  • Account data — your name and email address, collected through our authentication provider (WorkOS) when you create a workspace or accept an invitation, together with the basic activity needed to operate your account.
  • Marketing-site data — information you submit through our free-trial signup or contact form, such as your name, work email, company, and sales channel. Our marketing site does not use analytics or advertising cookies and does not track visitors; see our Cookie Policy.

How we use your information

We use seller data solely to operate the features you signed up for — demand forecasting, replenishment, and buy-box pricing — for the seller who authorized it. Each seller's data is logically isolated: we never use one seller's data to serve, benchmark, or train features for another. We use account data to authenticate you and administer your workspace, and contact-form data to respond to your enquiry and to provide and operate Brimloop. We do not use Amazon data for advertising, and we do not use it to train models offered to other customers.

Legal bases for processing (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the service you or your organization signed up for); legitimate interests (to secure, maintain, and improve the service and to respond to inquiries, balanced against your rights and freedoms); and consent where required (for example, optional communications), which you may withdraw at any time.

Service providers and sub-processors

Brimloop runs on its own application infrastructure. The providers below process data strictly on our instructions, under contract, as processors or sub-processors, and only to provide that infrastructure. We do not sell your data, and we do not disclose it to third parties for their own purposes.

  • Supabase — primary application database, hosted in an India region.
  • Render — backend application hosting.
  • Vercel — frontend and marketing-site hosting.
  • WorkOS — authentication and identity.
  • Resend — transactional email delivery.

We do not share Amazon Selling Partner data with any party other than these processors acting on our behalf to deliver the service to you.

Our commitments for Amazon data

Consistent with the Amazon Data Protection Policy and Acceptable Use Policy, we additionally commit that:

  • We do not sell Amazon Information.
  • Amazon data is encrypted in transit and at rest.
  • We retain Amazon data only as long as needed to provide the service, and we delete it within 30 days of the end of our relationship with you (for example, when you disconnect Brimloop or close your account) unless we are required to retain it by law.
  • Access follows the principle of least privilege — only authorized personnel with a genuine need may access it, and such access is controlled and logged.

Data retention

We retain account and seller operational data for as long as your workspace is active. Amazon Selling Partner data is deleted within 30 days of a closed relationship as described above. Marketing contact submissions are retained only as long as needed to follow up on your enquiry or trial and are then deleted. We may retain limited records longer where required for legal, accounting, or security purposes, and routine backups may persist for a short, defined period before rotation.

Security

We protect data with encryption in transit (TLS) and at rest, role-based access controls and least-privilege access, and per-seller data isolation. Authentication and Amazon authorization tokens are stored encrypted (sealed) at rest. No method of transmission or storage is perfectly secure, but we take measures appropriate to the sensitivity of the data.

Your rights

Subject to the applicable law (India's DPDP Act, and GDPR / UK GDPR or CCPA / CPRA where they apply), you have the right to access the personal data we hold about you, to request correction of inaccurate or incomplete data, to request erasure / deletion, to request a portable copy (data portability), to restrict or object to certain processing, to withdraw consent, to nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act), and to grievance redressal through our Grievance Officer (see below). Under the CCPA / CPRA you also have the right to opt out of the sale or sharing of personal information — note that we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.

You can disconnect your Amazon authorization at any time, which stops further data access and triggers deletion as described above. To exercise any right, email us at contact@anorcap.com; we will respond within the timeframes required by applicable law.

Grievance Officer (India · DPDP Act)

Under India's Digital Personal Data Protection Act, 2023, you may raise a grievance about how we handle your personal data with our Grievance Officer at Anorcap Private Limited, 133/2, 4th Floor, Janardhan Towers, Residency Road, Bengaluru 560025, email contact@anorcap.com. We will acknowledge and respond to grievances within the timeframes required by the DPDP Act and its rules. If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.

International data transfers

Our primary database is hosted in an India region. Some processors listed above may process limited data in other regions. Where data is transferred outside India, we rely on appropriate safeguards (such as contractual protections) as permitted by the DPDP Act and other applicable law.

Changes to this policy

We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, take reasonable steps to notify affected users.

Contact us

Anorcap Private Limited (India) is the Data Fiduciary (controller) for the purposes of this policy. For privacy questions or to exercise your rights, contact contact@anorcap.com; for DPDP grievances, contact our Grievance Officer (above).