Privacy Policy

Last updated: September 2, 2026

Overview

RIPPL Marketing ("RIPPL", "we", "us") operates the RIPPL platform at app.ripplmarketing.com ("the Service"): an e-commerce operations platform for Amazon and Shopify sellers providing sales analytics, advertising intelligence, inventory forecasting, client reporting, and an AI connection (the RIPPL AI MCP) that lets you connect assistants such as Claude or ChatGPT to your data. This policy describes what we collect, how we use it, and the choices you have.

Data We Collect

  • Account information: Name, email address, password (stored as a salted hash), company name, and your plan and billing status.
  • Amazon business data: When you connect Seller Central, Vendor Central, or Amazon Ads, we sync data through Amazon's official APIs on your behalf: sales and traffic reports, orders and transaction records, catalog and listing content, inventory levels, fees, advertising campaigns and performance, and search query data. This is your business data; we process it to provide the Service.
  • Shopify store data: When you connect a Shopify store, we sync data through Shopify's Admin API on your behalf: orders (order number, date, status, totals, discounts, shipping, tax, refunds, and line items with product, SKU, quantity, and price), products and inventory levels, abandoned checkouts (the cart contents and totals, not the shopper's contact details), and Shopify Payments payouts. To measure repeat purchasing and customer lifetime value we read each order's Shopify customer id and store only a one-way hashed reference derived from it, which links a customer's own orders together and cannot be reversed into a Shopify record or identify a person. We do not request or store your customers' names, email addresses, shipping or billing addresses, or phone numbers.
  • Google Analytics data: If you connect a Google Analytics 4 property, we read aggregate traffic and e-commerce reports for that property through Google's Analytics Data API: sessions, users, page views, add-to-cart and checkout counts, purchases, and revenue, by day, traffic source, campaign, and landing page. We request read-only access, store only these aggregate report rows, and never read or store data about individual visitors. You can disconnect Google Analytics at any time from the Traffic tab, which deletes the stored reports and revokes our access. RIPPL's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Payment information: Payments are processed by Stripe. Your card number never touches our servers; we store only your Stripe customer reference, plan, and subscription status.
  • Usage data: Log and diagnostic data (such as errors and page requests) used to keep the Service reliable and secure, and session cookies used to keep you signed in.

How We Use Your Data

  • To provide the Service: dashboards, forecasts, reports, alerts, and the AI features you use.
  • To operate your subscription, billing, and support.
  • To send service emails you enable or that the Service requires (such as verification, alerts, and digests).
  • To secure the platform and prevent abuse.

We do not sell your data. We do not use your business data to train AI models.

AI Features

When you use the built-in AI chat, relevant portions of your business data are sent to our AI model provider (Anthropic) to generate the answer. When you connect your own AI assistant through the RIPPL AI MCP, the assistant you choose can read the data your plan and permissions allow; your use of that assistant is governed by its provider's terms. See our AI Assistant Terms.

Service Providers

We share data only with the providers needed to run the Service: Render (cloud hosting, US region), Stripe (payments), Anthropic (AI chat responses), Sentry (error monitoring), Google (Analytics reporting, only for properties you connect), and our email delivery provider (for service emails). Each processes data only to provide its service to us. Data in transit is encrypted with TLS.

Amazon Data

Data received through Amazon's Selling Partner API and Amazon Ads API is used only to provide the Service to the account that connected it, consistent with Amazon's Acceptable Use and Data Protection Policies. You can disconnect an Amazon integration at any time from Settings, which revokes our access.

Shopify Data

Data received through Shopify's Admin API is used only to provide sales, inventory, and payout reporting to the account that connected the store, and only for the purposes stated when you authorize the connection. We process the minimum needed for that purpose and do not use it for advertising, personalization, or any other purpose. You can disconnect a store at any time from Settings → Connections, which revokes our access and deletes the store's synced data from RIPPL. If you uninstall RIPPL from your Shopify admin instead, we stop syncing immediately and erase the store's data within 48 hours when Shopify sends its data-erasure notice. We honor Shopify's customer data request and customer data erasure notices; because we hold no customer-level data, there is nothing to return or erase in response to them.

Data Storage & Security

Data is stored on secure cloud infrastructure in the United States, encrypted at rest. Amazon, Shopify, and other integration credentials are additionally encrypted before storage. Data in transit is encrypted with TLS. Each customer's data is isolated by organization, and access requires authentication. Sessions and forms are protected against cross-site request forgery.

Retention & Deletion

We retain your data while your account is active, including on the free plan, where syncing continues so your AI connection stays useful (syncing may pause after roughly 90 days without use, and resumes when you return). Shopify store data is deleted when you disconnect the store, and within 48 hours of uninstalling the app from Shopify. If you cancel and want your data removed, email us and we will delete your organization's data. We may retain minimal billing records where the law requires.

Your Rights

You may access, correct, export, or request deletion of your data, and disconnect any integration, at any time. Depending on where you live, you may have additional rights under laws such as the CCPA or GDPR; we honor verified requests regardless of location.

Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.

Changes

If we make material changes to this policy, we will notify account owners by email before the changes take effect.

Contact

For privacy questions or requests, contact us at info@ripplmarketing.com.