Last Updated: June 4, 2026
This draft is provided as a business privacy policy template for review by qualified counsel before publication.
This section applies specifically to data Hologrow receives from Amazon via the Selling Partner API (SP-API), including but not limited to order identifiers, shipping addresses, customer contact information, and other Personally Identifiable Information (“Amazon Data”), and supplements the rest of this Privacy Policy. In the event of any conflict between this section and other provisions of this Privacy Policy, this section governs with respect to Amazon Data.
We collect Amazon Data solely via Amazon's Selling Partner API (SP-API) for the purpose of generating carrier-compliant shipping labels (USPS, UPS, FedEx), validating shipping addresses, tracking delivery confirmations, and enabling direct-to-consumer shipping workflows on behalf of our business customers. We do not collect Amazon Data for any other purpose.
Amazon Data is used exclusively to provide shipping and fulfillment services to the business customer that authorized the connection. We do not use Amazon Data for advertising, marketing, building customer profiles, or any purpose unrelated to shipping execution. We do not use Amazon Data to train, fine-tune, or improve any AI or machine learning models, including foundation models, unless expressly authorized in a separate written agreement with the relevant customer and in compliance with Amazon's Data Protection Requirements.
Amazon Data is processed and stored in Google Cloud Platform (GCP) in the us-central1 region. All Amazon Data is encrypted at rest using AES-256-GCM and encrypted in transit using TLS 1.3. Access to Amazon Data is restricted to employees with a strict need-to-know basis, governed by Google Workspace SSO, GCP IAM role-based access control (RBAC), and multi-factor authentication (MFA). All access events are logged via Cloud Logging.
Amazon Data is shared only with third-party carrier APIs (USPS, UPS, FedEx) as strictly necessary to generate shipping labels and track deliveries. We do not sell, rent, license, or otherwise commercialize Amazon Data. We do not share Amazon Data with subprocessors not essential to the shipping workflow unless the customer provides prior written authorization and the subprocessor is bound by equivalent data protection obligations.
Amazon PII is retained for a maximum of thirty (30) days from the date of collection or fulfillment completion, whichever is later, consistent with Amazon's Data Protection Requirements. After this period, Amazon PII is purged through automated soft-deletion and cryptographic erasure. Non-PII transactional metadata necessary for billing, audit trails, or legal compliance may be retained in de-identified or aggregated form for longer periods as permitted by applicable law and customer agreements.
Employee access to Amazon Data is individually identified through unique Google Workspace accounts and scoped via least-privilege IAM conditions to a dedicated Amazon-data project. Quarterly access reviews are conducted, and access is automatically revoked upon employee offboarding. Anomalous access patterns (e.g., new geolocation, off-hours bulk exports) trigger automated alerts to security@hologrow.io.
Where Amazon Data includes personal information of data subjects (e.g., end customers), Hologrow processes such data solely as a processor or subprocessor on behalf of our business customers. Individuals seeking to exercise rights (access, correction, deletion, restriction, or portability) with respect to their Amazon Data should contact the business customer that placed the relevant order. Hologrow will assist the customer in responding to such requests as required by our agreement with the customer.
In the event of a security incident involving unauthorized access to, disclosure of, or loss of Amazon Data, Hologrow will notify the affected customer and Amazon promptly and in any case within twenty-four (24) hours of discovery, or as otherwise required by Amazon's Data Protection Requirements. We will cooperate fully with Amazon and applicable authorities in investigating and remediating such incidents.
Hologrow agrees to comply with the Amazon Services Business Solutions Agreement, Amazon Data Protection Requirements, and all applicable SP-API policies and guidelines in connection with the collection, processing, storage, use, sharing, and disposal of Amazon Data. We will promptly implement any required security updates or policy changes communicated by Amazon.
This section applies specifically to data Hologrow receives from Meta Platforms, Inc. and its affiliates (collectively, “Meta”) via the Meta Marketing API, Business Manager API, Conversions API, or any other Meta Platform interface (collectively, “Meta Platform”), including but not limited to advertising account identifiers, Business Manager metadata, campaign structures, ad sets, ads, creatives, spend, impressions, clicks, conversions, audience attributes, Pixel event data, access tokens, app secrets, and Meta user identifiers (collectively, “Meta Data”), and supplements the rest of this Privacy Policy. In the event of any conflict between this section and other provisions of this Privacy Policy, this section governs with respect to Meta Data.
For purposes of the Meta Platform Terms, Hologrow acts as a Tech Provider. We access and Process Meta Data solely on behalf of and at the direction of our business customers (each, a “Client”) to help such Client use Meta Products in accordance with Meta's terms and policies.
We collect Meta Data solely via read-only permissions granted by our Clients through Meta's authorized connection flows (e.g., OAuth through Meta Business Manager or Facebook Login for Business). We collect Meta Data only for the purpose of providing advertising analytics, reporting, dashboards, performance monitoring, budget insights, alerts, and AI-assisted operational outputs within Hologrow Pulse, in each case as configured and authorized by the Client whose data is being accessed. We do not collect Meta Data for any other purpose, including for our own advertising, marketing, or product development purposes unrelated to the Client's authorized use of Hologrow Pulse.
Meta Data is used exclusively to provide the authorized services to the Client that granted the connection. We do not use Meta Data in any manner that would violate the Meta Platform Terms or Meta Developer Policies, and specifically we do not:
We request only the minimum permissions necessary to provide the services requested by the Client. Unless specifically requested by a Client and justified by a permitted use case under Meta's Developer Docs, we do not request permissions to write, modify, or manage Meta advertising assets. We do not request Restricted Platform Data unless it is necessary to meaningfully improve the quality of the Client's experience in Hologrow Pulse and the purpose of the request is clear.
Meta Data is processed and stored in Google Cloud Platform (GCP) in the us-central1 region. All Meta Data is encrypted at rest using AES-256-GCM and encrypted in transit using TLS 1.3. Access to Meta Data is restricted to employees with a strict need-to-know basis, governed by Google Workspace SSO, GCP IAM role-based access control (RBAC), and multi-factor authentication (MFA). All access events are logged via Cloud Logging. We maintain administrative, physical, and technical safeguards designed to meet or exceed industry standards given the sensitivity of Meta Data and to prevent unauthorized access, destruction, loss, alteration, disclosure, distribution, or compromise.
Meta Data is shared only under the following circumstances:
We do not sell, rent, license, or otherwise commercialize Meta Data. We maintain Meta Data for each Client separately and do not combine or commingle one Client's Meta Data with another Client's data. We maintain an up-to-date list of Clients and their contact information and will provide it to Meta if asked.
Unless required to keep Meta Data under applicable law or regulation, we will (and will make reasonable efforts to ensure our Service Providers):
If we are required to keep Meta Data under applicable law or regulation, we will retain proof of the applicable legal or regulatory requirement and provide it to Meta if asked. If we receive Meta Data in error, we will immediately report it to Meta via https://developers.facebook.com/incident/report, delete that Meta Data, and provide proof of deletion if Meta asks for it. We may retain aggregated, anonymized, or de-identified information that cannot be associated with a particular Client, user, browser, or device for legitimate business purposes where permitted by law.
Where Meta Data includes personal information of end users (e.g., individuals who interact with a Client's advertisements), Hologrow processes such data solely as a processor, subprocessor, or Tech Provider on behalf of our Clients. Individuals seeking to exercise rights (access, correction, deletion, restriction, or portability) with respect to Meta Data should contact the Client that operates the relevant advertising account. Hologrow will assist the Client in responding to such requests as required by our agreement with the Client.
Clients and their authorized end users may request modification or deletion of Meta Data by contacting us at internal@hologrow.ai with the subject line “Meta Data Request.” We will process such requests promptly and in accordance with Meta's terms and applicable law.
In the event of any unauthorized access to, disclosure of, loss of, or other compromise of Meta Data, or any incident reasonably likely to compromise the security, confidentiality, or integrity of our IT systems or those of our Service Providers, we will:
Employee access to Meta Data is individually identified through unique Google Workspace accounts and scoped via least-privilege IAM conditions to dedicated projects or datasets. Quarterly access reviews are conducted, and access is automatically revoked upon employee offboarding. Anomalous access patterns (e.g., new geolocation, off-hours bulk exports, unauthorized permission elevation) trigger automated alerts to security@hologrow.io.
We do not use a Service Provider in connection with Meta Data unless such Service Provider first agrees in writing to:
We ensure that any Service Provider and Sub-Service Provider complies with Meta's terms as if they were in our place, and we are responsible for their acts and omissions, including their noncompliance. When we cease using a Service Provider, we ensure they immediately cease using Meta Platform and Processing Meta Data and promptly delete all Meta Data in their possession or control. Upon Meta's request, we will provide a list of our Service Providers and Sub-Service Providers, including up-to-date contact information for each, the types and volume of Meta Data shared, and proof of written agreements demonstrating compliance.
Hologrow agrees to comply with the Meta Platform Terms, Meta Developer Policies, Meta Business Tools Terms, Meta Advertising Guidelines, and all other applicable terms and policies in connection with the collection, processing, storage, use, sharing, and disposal of Meta Data. We agree to:
We will promptly implement any required security updates or policy changes communicated by Meta. We will not create or maintain Apps to circumvent Meta's enforcement actions. If Meta prohibits our use of a Service Provider or requests that we terminate a Client's access, we will comply promptly.