Ignitabull Services Inc. is the operator and controller of the Ignitabull website and provides Amazon consulting, legacy agency services for existing clients, and a secure client workspace for connected reporting and service delivery. This policy explains what information we collect, why we use it, how we protect it, when we share it, and how you can request access or deletion.
Ignitabull does not ask for or store your Amazon password. The client workspace's core SP-API integration does not request Restricted Data Tokens and is designed not to retain restricted buyer names, addresses, telephone numbers, email addresses, or payment-card data.
Joining the agency waitlist does not create an agency engagement, reserve capacity, authorize Amazon access, or subscribe you to marketing. The marketing checkbox is off by default. If you explicitly consent, the request records that choice for a separately reviewed marketing handoff. Hostinger Reach receives only explicitly consented marketing contacts after an approved handoff.
We do not sell seller data or personal information, use Amazon data for unrelated advertising, or share it except as described below and as permitted by Amazon's agreements and applicable law.
Public forms are handled by Cloudflare Pages Functions. After origin, size, rate-limit, and field validation, sales and relationship records are written to Ignitabull's access-controlled Notion CRM. The CRM record stores supported contact details, source, request context, status, routing, qualification, next action, and a submission identifier used to prevent accidental duplicates.
Cloudflare D1 may retain a technical secondary or recovery copy for audit and reliability purposes. D1 does not replace the Notion CRM as Ignitabull's operating sales system. The agency waitlist form reports success only when the Notion CRM confirms the record. Blueprint intake may return a recovery state if D1 accepted the submission but Notion was temporarily unavailable, so the intake can be reconciled instead of silently lost. The public forms currently send no automatic receipt email.
Amazon Selling Partner API and Amazon Advertising access use separate OAuth consent flows. Connecting one does not grant the other, and purchasing a service grants neither. Access is limited to the connected organization and the roles and marketplaces authorized by the seller. The current Ignitabull client-workspace SP-API path is read-only and does not perform Amazon writes.
You can revoke an Amazon authorization from the applicable Amazon permission surface. Revocation stops new collection through that connection; it does not automatically erase records we must retain for security, contractual, or legal purposes. You may separately request deletion as described below.
We disclose only the information needed for providers to perform services for Ignitabull. Cloudflare is used for website hosting, application runtime, rate limiting, technical storage, and audit/recovery records. Notion is used for Ignitabull's CRM, internal operating records, and selected delivery workflows. Supabase remains part of the secure application and client-workspace infrastructure where required; it is not the authoritative public CRM. Hostinger Reach is used for marketing contacts only after explicit consent and an approved handoff. Other current service categories include Amazon for authorized API access, Stripe for checkout and billing, and Composio and Google only for separately authorized, reviewed workflows.
We may also disclose information to professional advisers, regulators, law enforcement, or another party when required by law, necessary to protect rights and security, or involved in a business transaction subject to appropriate confidentiality safeguards. Data may be processed in Canada, the United States, or other locations where these providers operate.
Data is transmitted over HTTPS. Amazon OAuth credentials are encrypted at rest with server-only key material and are not exposed to browser code. OAuth state is organization-bound, provider-bound, single-use, and time-limited. Application records, connections, reports, and permissions are scoped to the authorized organization. Access is role-based, security events are logged, and raw Amazon report download URLs are not retained.
No system can guarantee absolute security. We review access boundaries and incident evidence and will provide required notifications if a qualifying breach occurs.
We retain CRM, connected data, and service records while reasonably needed for the relationship, engagement, follow-up, handoff, dispute resolution, security, or legal obligations. Short-lived authorization state expires in minutes. Some billing, audit, fraud-prevention, backup, contractual, or legal records may be retained longer where reasonably necessary or required by law.
You may request access, correction, export, or deletion. After verifying the requester and organization, we will delete or de-identify eligible active records and instruct applicable processors as required. Deletion may be limited where retention is legally required, needed to establish or defend legal claims, or technically pending within secured backup rotation.
Ignitabull's client workspace and business services are not directed to children, and we do not knowingly collect children's personal information through them.
We may update this policy when the product, providers, or legal requirements change. We will post the revised date here and provide additional notice when a material change requires it.
For privacy questions or requests, email jeremy@ignitabull.com. Identify the organization and request type, but do not send passwords, API keys, access tokens, or Amazon secrets.
Last updated: September 9, 2026
Back to Ignitabull