Privacy policy
What we collect, why we collect it, who else touches it, how long we keep it, and how to make us delete it.
Version 1.4 · Last updated 4 September 2026
Who we are
The Barkworth & Hathaway Group Ltd (“we”, “us”) is the data controller for the information described in this policy. We are registered in England and Wales, company number 11255288.
25 West Street, Storrington, United Kingdom, RH20 4DZFor any question about this policy or to exercise your rights, email support@chat-ppc.ai.
What we collect
We keep three categories separate, because they are treated differently and come to us in different ways.
1. Account data. Your name, email address and billing details. You give us these directly when you create an account or join the waiting list. Payments are handled by Stripe, which collects your card details directly — we never see or store a card number. Stripe also calculates the VAT shown at checkout. What we hold is your name, email address, billing address and, where you give one, your VAT number.
2. Amazon data, accessed on your authorisation. Advertising campaign data, sales and traffic reports, inventory levels, listing status, and per-SKU fee estimates. We access this through Amazon’s APIs using the authorisation you grant, and only for the accounts you connect.
3. Cost information you supply. What your goods, freight, duty and packaging cost, and how you derived those figures. This is commercially sensitive and is yours. We use it only to calculate your break-even and to show our working back to you.
We receive no buyer personal data
ChatPPC requests no restricted Amazon roles and holds none. In practice that means we never receive your customers’ names, addresses, email addresses or phone numbers. That data never enters our systems, so it cannot be exposed by us.
We do receive order and inventory records, because working out whether a product can be advertised profitably requires knowing what sold and what is in stock. Those records reach us with the buyer’s identity absent: Amazon gates those fields behind roles we neither request nor hold, so they are withheld at source rather than discarded on arrival.
This is a deliberate design decision rather than a limitation, and we do not intend to change it.
Website visitors and the waiting list
This website sets no advertising or analytics cookies, and we run no third-party analytics on it. There is nothing to consent to, which is why you have not been shown a cookie banner.
If you join the waiting list we store the email address you give us, and optionally the marketplace and ad-spend band you select. We use it only to contact you about early access: one confirmation when you join, and then nothing until a place opens up. We do not sell it or pass it on for anyone else’s purposes. We are the controller for it, it is handled by the providers named below acting on our instructions, and you can ask us to remove it at any time.
Abuse prevention. When you submit that form we also store a one-way salted hash of your IP address, purely to rate-limit automated submissions. It is a hashed identifier, not a stored IP address, we do not use it to identify or profile you, and it is automatically deleted within 24 hours.
Why we are allowed to process it
For customers, our lawful basis is performance of a contract: we process this data to provide the service you have subscribed to. For the waiting list, our basis is your consent, which you may withdraw at any time by emailing us. For the abuse-prevention hash described above, our basis is our legitimate interest in keeping the form usable.
How it is stored and protected
- Encrypted in transit using TLS, and encrypted at rest.
- Amazon refresh tokens are encrypted at rest with a separate key, decrypted only inside the request handler, and are never logged, never returned in an API response, and never exposed to a language model.
- Each customer’s data is logically isolated, enforced at the database layer rather than in application code.
- Access is limited to those who need it, with multi-factor authentication on every system holding customer data.
Who else processes it
Two different relationships sit behind that question, and which one applies depends on whose data it is.
Where we decide why data is processed — your account details, your billing, the waiting list — we are the controller and the providers below are our processors. They act on our instructions under contract.
Where you decide — the Amazon data you authorise us to access, and the cost information you give us — you are the controller and we are your processor. The providers we use for that are sub-processors under our Data Processing Agreement, which records what each one does, where the data sits, and makes us liable for them as if they were us.
Most of them are both, because the same request path and the same database carry both kinds of data. Where one is not, it says so:
- Vercel — application hosting.
- Supabase — database hosting.
- Resend — email delivery.
- Stripe — payment processing. Our processor only — it handles your account and billing data, and never data we hold on your behalf. Stripe also uses payment data for its own fraud prevention, anti-money-laundering screening and legal compliance. For those purposes it acts as its own controller rather than on our instructions, and its own privacy policy governs them.
Separately, and at your direction: when you ask ChatPPC a question inside your own AI assistant, the Amazon-derived data needed to answer it is returned into that assistant’s session. That happens because you asked for it. Your subscription with that provider, and their handling of your conversation, is between you and them.
We update this list before adding a provider. Where the change is to a sub-processor — a provider handling data we hold on your behalf — we also give 30 days’ notice by email under the Data Processing Agreement, and you may object. That notice is a promise about sub-processors specifically; a change to a provider we use as controller is published here rather than notified.
International transfers
Your data is stored in the European Economic Area, and each provider named above is configured to keep it there. Where one of them transfers data outside the UK or EEA in the course of operating its own service, it does so under the safeguards its own data processing terms provide, such as UK International Data Transfer Agreements or Standard Contractual Clauses. We do not transfer your data outside the EEA for our own purposes.
Some categories of provider cannot work this way. A payment provider, for example, has anti-money-laundering and fraud obligations of its own that require processing across its whole network. Where we use one, we say so above, name what it does for its own purposes, and state where its data goes — rather than making a blanket claim about every provider that a later one would break.
How long we keep it
- Account and cost data: for as long as your account is open, and for up to six years afterwards where we are required to retain records for tax and accounting purposes.
- Amazon data: refreshed continuously while your account is active, and deleted when your account is deleted.
- Waiting list entries: until you ask us to remove them, or until we close the waiting list.
- Rate-limiting hashes: deleted within 24 hours, automatically.
Deletion
On a verified deletion request we hard-delete your data within 72 hours. The Amazon refresh tokens we hold are destroyed with it, irrecoverably, so ChatPPC can no longer act on your Amazon accounts; because Amazon does not let an application withdraw its own authorisation, our written confirmation includes the short steps to remove ChatPPC’s access on Amazon’s side too. We confirm in writing when it is done.
You can also export everything you have given us — cost bases with their derivations, your settings, your proposal and audit history — at any time.
Your rights
Under UK GDPR you have the right to:
- be told what we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we process it;
- receive your data in a portable format;
- withdraw consent, where consent is what we relied on.
Email support@chat-ppc.ai to exercise any of these. We will respond within one month.
If you are not satisfied with our response, you can complain to the Information Commissioner’s Office at ico.org.uk, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.
If something goes wrong
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high. Where the incident involves Amazon information we will also notify Amazon within 24 hours, as their data protection policy requires.
Changes to this policy
If we change this policy we will update the version and date at the top of the page. Where a change materially affects you, we will tell you by email rather than relying on you to notice.